FAQ

Frequently asked questions

How CartWatch installs, scores checkouts, tags bots, and keeps fake profiles out of your recovery flows.

Getting Started

How do I install CartWatch?
CartWatch is available on the Shopify App Store. Search for CartWatch, click Install, and approve the requested permissions. CartWatch connects to your store via OAuth and begins monitoring checkouts immediately.
Do I need to configure anything after installing?
CartWatch works out of the box. Auto-tagging is enabled by default, so detected bots are tagged in Shopify automatically. You can optionally connect Klaviyo, Omnisend, Mailchimp, Drip, or Brevo in Settings to enable automatic email suppression.
What Shopify permissions does CartWatch require?
CartWatch requests checkout access (to receive webhook events), customer read/write (to apply the CARTWATCH_FLAGGED_BOT tag), and order read access (to flag orders placed by known bots as high risk).
Will CartWatch slow down my checkout?
No. CartWatch processes checkout events asynchronously via webhooks. It has zero impact on your storefront's load time or checkout performance.

Bot Detection

What does CartWatch consider a bot?
CartWatch evaluates a combination of behavioral signals and, when configured, third-party enrichment data. Checkouts that score above the detection threshold are classified as bots.
How does CartWatch score checkouts?
Each checkout is scored in real time as webhooks arrive from Shopify. Multiple signals contribute to a composite score. If the total crosses the confidence threshold, the checkout is flagged as a bot.
What happens when CartWatch flags a checkout as a bot?
CartWatch tags the Shopify customer account with CARTWATCH_FLAGGED_BOT (auto-tagging is on by default and can be toggled in Settings), lists the checkout in your dashboard with its bot risk level and the actions taken, and — if Klaviyo, Omnisend, Mailchimp, Drip, or Brevo is connected — suppresses the email address in those platforms.
What does the CARTWATCH_FLAGGED_BOT tag do?
The tag is applied to the Shopify customer record. You can use it to exclude tagged customers from abandoned cart flows, segments, and marketing lists. It acts as a persistent signal that the account was identified as a bot.
Can CartWatch make mistakes and flag real customers?
CartWatch is designed to be conservative, but no detection system is perfect. Every flagged checkout appears in your dashboard with its risk level and a link through to the checkout in your Shopify admin, so you can look at it yourself. If you believe a real customer was flagged, remove the tag manually in Shopify — and if the checkout is later updated and scores below the threshold, CartWatch reverses its actions automatically.
What if a flagged checkout is later updated by a real customer?
CartWatch monitors checkout updates. If a checkout that was previously flagged receives a fresher update that scores below the threshold, CartWatch automatically reverses its actions: it removes the Shopify tag and unsuppresses the profile in Klaviyo, Omnisend, Mailchimp, Drip, and Brevo.

Klaviyo, Omnisend, Mailchimp, Drip & Brevo

How do I connect Klaviyo?
In CartWatch Settings, click Connect Klaviyo. You'll be redirected through Klaviyo's OAuth flow. Once connected, CartWatch automatically suppresses detected bot profiles in Klaviyo whenever a bot is flagged.
How do I connect Omnisend?
In CartWatch Settings, click Connect Omnisend. You'll be redirected through Omnisend's OAuth flow. Once connected, CartWatch automatically marks detected bot profiles as unsubscribed in Omnisend whenever a bot is flagged.
How do I connect Mailchimp?
In CartWatch Settings, click Connect Mailchimp. You'll be redirected through Mailchimp's OAuth flow. Once connected, CartWatch automatically unsubscribes and archives detected bot contacts in every one of your Mailchimp audiences whenever a bot is flagged.
How do I connect Drip?
In CartWatch Settings, click Connect Drip. You'll be redirected through Drip's OAuth flow to approve access. Once connected, CartWatch automatically unsubscribes detected bot subscribers from all mailings in your Drip account and tags them so you can see which unsubscribes CartWatch performed.
How do I connect Brevo?
Brevo doesn't offer app authorization for third-party apps yet, so you connect with an API key. In Brevo, open Settings → SMTP & API → API Keys and generate a new key. Then in CartWatch Settings, paste it into the Brevo Integration card and click Connect Brevo. CartWatch verifies the key against your account, stores it encrypted, and from then on blocklists detected bot contacts for email and SMS in your Brevo account. One thing to check in Brevo: under Settings → Security → Authorised IPs, blocking of unknown IP addresses must be deactivated, because CartWatch's servers don't use fixed IP addresses.
Why does CartWatch archive Mailchimp contacts instead of just unsubscribing them?
Mailchimp bills on total contacts, and unsubscribed contacts still count toward your billing tier — only archived contacts drop out of it. CartWatch tags the contact as a CartWatch-flagged bot, unsubscribes it, then archives it, so the bot stops sending you a bill as well as stops receiving campaigns. The tag stays with the contact and is segmentable.
What does suppressing a profile in Klaviyo, Omnisend, Mailchimp, Drip, or Brevo do?
In Klaviyo, CartWatch adds the email address to the suppression list, which prevents it from receiving any marketing sends. In Omnisend, CartWatch sets the contact's email status to unsubscribed. In Mailchimp, CartWatch unsubscribes and then archives the contact in every audience. In Drip, CartWatch unsubscribes the subscriber from all mailings. In Brevo, CartWatch blocklists the contact for email and SMS (Brevo doesn't charge for blocklisted contacts). Either way, the address is excluded from abandoned cart recovery flows and future campaigns.
Does CartWatch unsuppress profiles if a bot determination is reversed?
Yes. If CartWatch reverses a bot flag because a real customer updated the checkout, it automatically removes the suppression in Klaviyo, restores the subscribed status in Omnisend, unarchives and restores the contact in Mailchimp, reactivates the subscriber in Drip, and removes the blocklist flags in Brevo.

Billing & Plans

How much does CartWatch cost?
The Free plan detects and scores bot checkouts and lets you block visitors by IP or country. Each paid tier adds one more thing CartWatch does about the bots it finds: Starter ($9/mo) auto-tags bots in Shopify, suppresses them in Klaviyo, Omnisend, Mailchimp, Drip, and Brevo, and flags their orders as high risk; Standard ($19/mo) adds payment blocking, which refuses a flagged bot’s payment so the order never completes and can discourage bots from returning once they can no longer test cards; Pro ($39/mo) adds bot detection analytics. Every paid plan includes a 7-day free trial.
How are plans determined?
By features, not order volume. Every plan — including Free — covers unlimited orders and unlimited bot detections. You only move up a tier when you want CartWatch to take a further action on the bots it finds.
What happens if my store grows?
Nothing changes. There are no order limits, no overage charges, and no grace periods — CartWatch keeps scanning every checkout on whatever plan you're on.
How do I upgrade my CartWatch plan?
Go to the Plan page inside the CartWatch app. Select a plan and confirm — billing is handled through Shopify's standard app billing system.