How FlexifyGuard collects data
Understanding where the numbers come from makes every other page easier to read.
Orders (webhook)
Shopify sends FlexifyGuard every new order as it is created. The order is scored immediately using the buyer's IP, email, billing and shipping addresses, order value and customer history. This works for every order regardless of how the customer reached checkout.
Checkouts (webhook)
Shopify also sends FlexifyGuard every checkout it creates, whether or not the customer completes it. This is how FlexifyGuard sees card-testing bots: they create checkouts directly and never load your storefront, so a storefront script alone would miss them.
Storefront script
FlexifyGuard adds a small script to your Online Store theme. It records visits, sessions and a device fingerprint, and records when a visitor clicks Checkout. It also shows a block page to visitors whose IP or country you have blocked.
The script respects Shopify's cookie consent. If a visitor declines analytics consent, the script records nothing for that visitor. Visitors with ad blockers may also not be recorded. Their orders and checkouts are still scored through the webhooks above.
The script runs only on your Online Store pages. It does not run on Shopify's checkout pages — Shopify does not allow any app script there.
Device fingerprints
When the storefront script runs, it computes a fingerprint from the browser and device characteristics and pairs it with the visitor's IP. Fingerprints are stored per store; a device seen on another FlexifyGuard store is not linked to yours.
IP intelligence
Each new IP is looked up once for country, city, ISP, and whether it is a proxy/VPN or a datacenter (cloud hosting) range. FlexifyGuard distinguishes the two:
- Proxy / VPN — an anonymising network.
- Datacenter — a cloud or hosting range (AWS, Tencent, Google Cloud, etc.). Almost always automated traffic, not a shopper.