Everything you need to know about fraud detection, Visitor ID, the Browsify app, and our Bot Protection service.
Getting Started
Browsify is a Shopify security platform with two offerings. The Browsify Shopify app gives you basic, self-serve protection: Visitor ID fingerprinting, fraud risk scoring, IP/country blocking, VPN/proxy/TOR detection, and auto-block rules. Bot detection isn't part of the app — Bot Protection is a separate, team-managed service that monitors your store and blocks advanced threats the app alone can't catch, including sophisticated bots and automation, checkout and payment fraud, and AI chat abuse.
Install our free Shopify app from the Shopify App Store for instant IP blocking and Visitor ID protection. For advanced threats, contact our team to add Bot Protection — a separate, team-managed service where we configure optimal rules, monitor your store, and handle everything for you.
The Shopify app provides strong baseline protection you manage yourself. Bot Protection is a separate, team-managed service that adds an extra layer of security with human monitoring and proactive threat response, catching advanced bots, checkout fraud, and AI chat abuse the app alone can't. Think of the app as your lock and Bot Protection as your security team.
Visitor ID & Fingerprinting
Visitor ID is a unique device identifier that stays the same even when a visitor changes their IP, uses a VPN, or clears cookies. Unlike IP blocking (which only blocks one connection), Visitor ID recognizes the actual device — so the same bad actor can't come back with a new IP. Think of it this way: an IP address is like a phone number — easy to change. A Visitor ID is like a fingerprint — it stays with you.
No. Incognito mode and cookie clearing don't affect Visitor ID — it's based on the device itself, not on stored data. Even switching browsers or using private browsing won't change the identifier.
Yes. A VPN only changes the IP address — it does not change anything about the device or browser. Browsify's Visitor ID tracks the device, not the connection. So even if someone switches between 10 different VPN servers, their Visitor ID remains the same, and Browsify recognizes them every time.
Fraud Detection & Risk Scores
Browsify analyzes multiple signals for every visitor: their Visitor ID (device fingerprint), IP address, location, VPN/proxy usage, browsing behavior, and order patterns like multiple card attempts or billing/shipping mismatches. All these signals are combined into a risk score from 0 to 100 that tells you how likely the visitor is to be fraudulent.
The risk score goes from 0 to 100. Scores 0–33 are Low Risk (green) — these orders are almost always safe. Scores 34–66 are Medium Risk (yellow) — worth a quick look but often legitimate. Scores 67–100 are High Risk (red) — multiple red flags are present and the order should be reviewed carefully or blocked automatically.
Common risk factors include: multiple card attempts (someone tried several different cards), card country mismatch (card from one country, visitor from another), VPN or proxy detected, known fraud device (this Visitor ID has been linked to fraud before), TOR network usage, mismatched billing and shipping addresses, and disposable email addresses. No single factor determines the score — it's the combination that matters.
The dashboard shows flagged visitors with their Visitor ID, risk score, and specific risk factors. You can see a country breakdown (where suspicious traffic comes from), a timeline view (when fraud attempts happen — often at 2–5 AM), and detailed session data for each flagged visitor. Each risk factor is explained in plain language so you know exactly what triggered the flag.
VPN, Proxy & TOR Blocking
No — about 31% of internet users use VPNs for legitimate reasons (privacy, work, travel). Blocking all VPN traffic means losing real customers. Instead, use smart blocking: block TOR traffic entirely (almost never legitimate shopping), block datacenter proxies (used by bots, not shoppers), allow iCloud Private Relay (used by millions of Apple users), and combine VPN detection with risk scoring so VPN users with no other red flags can still purchase.
VPN ($3–$12/month) encrypts all your traffic and routes it through another server — used by millions of regular people for privacy. Proxy (often free or pennies per IP) is a simpler middleman server — datacenter proxies are very suspicious, residential proxies are harder to detect. TOR (free) bounces traffic through multiple random computers worldwide for maximum anonymity — almost no legitimate shopper uses TOR to buy products.
Not if you configure it correctly. Apple's iCloud Private Relay (used by iCloud+ subscribers on iPhone, iPad, and Mac) looks like a proxy to detection systems. Browsify recognizes iCloud Private Relay separately and always allows it through, so your Apple customers are never blocked.
Automatic Blocking & Rules
You set a risk score threshold (default is 80 out of 100). Every visitor to your store is scored in real time. Anyone above your threshold is automatically blocked before they can checkout — no manual review needed. You can also set up auto-cancellation for orders that slip through with high risk scores. Both features work 24/7, even while you sleep.
Block shows the visitor an 'access denied' page — the door is shut. Use it for known bad actors and very high-risk visitors. Redirect sends them to a different URL (like a verification page or 'contact us' page). Use it for borderline cases where you want to add friction without completely shutting someone out. Think of it as: Block = locked door, Redirect = detour.
If a real customer contacts you saying they can't access your store, look up their Visitor ID in your Browsify dashboard, check why they were blocked, and if they're legitimate, add them to your whitelist. They'll never be blocked again. To minimize false positives, start with a high threshold (90+) and lower it gradually as you monitor the results.
It depends on what you sell. High-value items ($200+): lower to 60–70 because one chargeback hurts a lot. Low-value items ($10–$30): keep at 80–85 since blocking too many customers costs more than occasional fraud. Digital goods: lower to 50–60 because they're the #1 fraud target with instant delivery and no shipping proof.
Content Protection
Content Protection stops people from easily copying your product photos and descriptions. It turns off right-click (so they can't 'Save Image As'), blocks text selection and copying (so they can't grab your product descriptions), and disables the keyboard shortcuts tech-savvy users rely on to view or copy your page code (like F12 and Ctrl+U). It stops 95% of casual content theft.
For 95% of visitors, it's completely invisible — most people never right-click or press F12 on a product page. We recommend enabling it selectively: turn it on for product pages (where your valuable content lives) and leave it off for blog posts, FAQ pages, and informational pages where customers might legitimately want to copy text like your return policy.
Pricing & Plans
The free Shopify app includes IP and country blocking, Visitor ID fingerprinting, basic fraud scoring, VPN/proxy detection, and visitor analytics. No credit card required.
Bot Protection is billed separately from the app and priced by your store's monthly traffic: up to 10K visits is $19.99/mo, up to 50K is $39.99/mo, and up to 200K is $69.99/mo. Stores above 200K visits should contact us for custom pricing. All plans include a 3-day free trial. Save 20% with annual billing.
Yes. Monthly plans can be cancelled at any time with no cancellation fee. Annual plans are billed upfront with a 20% discount.
Yes. Bot Protection works alongside the Shopify app, not instead of it. The app provides Visitor ID fingerprinting, risk scoring, and the everyday blocking you manage yourself, while Bot Protection adds a team-managed layer for advanced threats and human monitoring. Both are needed for full coverage.
AI Chat Protection
If your store uses an AI chatbot (Tidio, Gorgias AI, ChatGPT widget, etc.), bots and bad actors can spam your chat to drain your AI tokens — costing you real money. They can also extract product info, pricing logic, and internal data through chat. Browsify blocks these bots before they reach your chatbot.
Browsify uses Visitor ID fingerprinting and behavior analysis to detect chat-spamming bots. Automated visitors, repeated chat sessions from the same device, and known bot patterns are blocked before they can send messages to your AI chatbot — so your tokens are only spent on real customers.
Browsify works with any chat widget on your Shopify store, including Tidio, Gorgias AI, Intercom, Zendesk AI, ChatGPT-based widgets, and custom chat solutions. Because Browsify identifies and blocks bots at the visitor level — with Bot Protection adding a team-managed layer for advanced abuse — it protects whatever chat tool you use.
Privacy & Data
Browsify focuses on anonymous identifiers like Visitor IDs and IP addresses — not personal customer data. It complies with Shopify's privacy guidelines and follows industry-standard security practices. We do not sell or rent any data to third parties.
Any fraud detection system can have false positives, but Browsify minimizes them through multi-signal risk scoring (no single factor triggers a block). If someone is blocked incorrectly, you can whitelist their Visitor ID or IP address instantly. You can also increase your risk score threshold to reduce sensitivity, or set borderline cases to 'flag for review' instead of auto-block.
Go to the Configuration section in your Browsify dashboard, find the customer's IP or Visitor ID in your block list, and remove it. You can also add them to a whitelist so they're never blocked again, regardless of their risk score.
We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.