I asked Shopify why my store was blocking customers. They told me it was working correctly.
For weeks support told me nothing was wrong and the platform was performing as expected, while Shopify staff were posting in this very thread acknowledging the VPN problem is real and unresolved. I sent them this post. It made no difference.
They would only accept a HAR file showing the full error. Not the videos, not the screenshots, not any of the evidence I and my customers kept sending showing something was definitely wrong. And itās a tricky error to catch, because itās intermittent and by the time you see it, itās gone.
What happened
On 29 July I finally captured it. I opened my own shop in Chrome. Not a script. Not a crawler. Me, clicking through to my homepage like any customer would.
I got a blank white page with two words on it: local_rate_limited. No branding. No products. No way through. My entire store, gone.
I sent the request ID to support. Shopify pulled the logs at edge and origin. A human being looked at a session where a real person was refused entry to a real shop, and wrote back:
āShopifyās bot protection assessed this session as automated traffic and applied rate limiting accordingly. This is expected behavior for that type of connection⦠There is no platform error.ā
Why I was flagged as a bot
A VPN was running. Specifically McAfee Total Protection, ordinary consumer antivirus. It switches its VPN on automatically on unsecured Wi-Fi, and McAfee advertises it for shopping and banking. Norton does it. Google One does it. Appleās Private Relay does it.
Thatās not a datacentre. Thatās a shopper with antivirus software.
Shopify is openly admitting it blocks VPN traffic, while behaving as though only a handful of unusual people use one.
And if thatās the response, what was the point of asking us for request IDs?
It isnāt just me ā and it costs you twice
Iād already sent Shopify video of an actual customer, not me, trying to reach my store from a Facebook link. Three devices. Same blank page every time.
Then they gave me my numbers. 1,688 of these served to my storefront in five days. 91% attributed to āVPNs, hosting providers, datacenters, or Meta infrastructure IPsānot from residential customer connections.ā Edge logs only go back five days, so whatever happened before that is gone.
Read that list again. Meta infrastructure. Some Meta traffic genuinely is crawlers and does need limiting. But traffic from Facebook and Instagram also arrives through Metaās in-app browser, which is how a huge number of paid-social customers reach your store.
And hereās the kicker. You pay Meta to deliver that customer. Meta charges you for the click. Then Shopify refuses to serve them the page. So you have paid for a customer you were never going to be allowed to sell to, and you lose the sale on top. You are being charged twice for the same block, and nothing in your reporting tells you it happened.
I spent £3,531.72 with Meta last month. My Facebook conversion rate has gone from 3.33% in May to 0.78% now.
It isnāt confined to my store
I reproduced the same block on other peopleās stores. Shopify wouldnāt accept those because they werenāt my account. I offered to get written permission from the owners and was told theyād have to contact support themselves. One did.
They were told it would be logged as a āfrustration.ā
So, publicly and on the record:
Shopify is treating VPNs as something a minority of customers use, when it is now standard in most antivirus software. When is Shopify going to stop turning away real customers, and admit the platform is currently broken?