In the last full week of September, four platform changes landed that all do the same thing: they change what your numbers mean without changing what your business did. If a chart moved around 21 September and your bank account did not, the explanation is probably on this page rather than in your account.

This is the least glamorous category of news in paid media and the most expensive to miss, because every one of these produces a graph that looks exactly like a performance story. Teams then spend a fortnight optimising against an artifact.

Shopify redefined what a session is

Rolling out 21 to 23 September 2026. Two changes at once:

Sessions now end based on continued customer activity rather than terminating at midnight UTC. The old behaviour split a single late-night shopping session into two, which inflated session counts and deflated anything measured per session.

And nine session-based metrics now exclude bot and system traffic: sessions, conversion rate, add-to-cart rate, reached checkout rate, checkout conversion rate, bounce rate, pageviews per session, online store visitors, and searches.

Both changes push in the same direction — fewer, cleaner sessions — so the arithmetic is predictable. Sessions down, conversion rate up, and orders, sales and customer counts untouched.

That last part is the whole point. If your conversion rate jumped on 22 September and your order count did not budge, nothing happened to your store. Your denominator got smaller. The number is arguably more honest now; it is also not comparable to the number you were looking at a week earlier, and any month-over-month comparison that straddles the rollout is measuring the rollout.

What to do: annotate the date in whatever your team actually opens, and treat the pre-21-September series as a different metric rather than an earlier value of the same one. If you report conversion rate to anyone who makes decisions on it, say this out loud before they notice it themselves.

Google’s AI Mode checkout fires no client-side pixels

This is the one that creates a genuine gap rather than a restated one, and it has been switched on by default for eligible Shopify stores.

When a purchase completes inside Google’s direct checkout — in AI Mode or Gemini, without the user ever landing on your site — the checkout fires only server-to-server pixels for started and completed. No standard client-side pixel runs. No custom pixel runs. Your GA4 tag does not fire.

So the order is real, the money arrives, Shopify records it, and your analytics never sees it. This is not a tracking bug you can fix by reinstalling a tag; it is a checkout that exists outside the client-side measurement model entirely.

The consequences compound in a familiar direction. Revenue that GA4 cannot see is revenue your attribution model cannot assign, which means it silently lands in the same bucket as everything else that is unobservable — and the gap between what a model can see and what actually happened is already the largest source of bad budget decisions in paid media.

What to do: open Sales channels, then Agentic, and confirm whether direct checkout is on. Make that a decision rather than a default. Then reconcile revenue against Shopify order data rather than GA4, which is the same discipline that the first step of any zero-conversion diagnosis asks for: compare the platform against a source it cannot influence.

GA4 hostname filters can now allowlist — and permanently discard

Added 21 September 2026. GA4’s hostname data filters gained an Include mode: instead of listing the junk domains you want to exclude, you list the domains allowed to send you data and GA4 drops everything else. Events with an empty hostname are blocked automatically.

This is strictly better as a model. An exclude list is only as current as the last spam domain someone noticed; an allowlist is your production domains, written once.

Two caveats that matter more than the feature:

Measurement Protocol events are exempt. Spam sent through that route still arrives, so the allowlist is not the complete defence it appears to be.

Filtered data is permanent. Dropped events cannot be recovered in GA4 or in BigQuery. A typo in an allowlist does not produce an error — it silently discards your real traffic, forever. Google recommends 24 to 36 hours in Testing mode before activating, and that recommendation is doing a lot of work.

What to do: use it, in Testing first, and check it against what is actually landing in your BigQuery tables before you switch it to Active. If the export is where your durable record lives — and it should be, since GA4’s interface forgets and reshapes things the export does not — then a filter that poisons it upstream is the most consequential setting on this page.

Customer Match now takes IP addresses and timestamps

Customer Match accepts two new matching signals: a user IP address and a user interaction timestamp. The details are unusually particular:

  • Both are uploaded unhashed, unlike the email and phone fields everyone has been hashing for years.
  • IPv4 or IPv6, passed as a plain trimmed string.
  • A timestamp cannot be sent without an IP. An IP without a timestamp is accepted, and Google may then associate it with the most recent known user for that address.
  • End users in the EEA, the UK and Switzerland are excluded from IP matching, and Google expects integrators to build that exclusion themselves.

The measurement consequence is the one to plan for: match rates will now differ by region for reasons that have nothing to do with your data quality. A European segment matching worse than a US one is the expected behaviour of the system, not a sign that your CRM export is broken.

Treat the unhashed requirement as the real decision here. Sending raw IP addresses to an ad platform is a different privacy posture from sending hashed emails, it needs whatever consent your jurisdiction requires, and it is worth a deliberate yes rather than an incidental one — much like the server-side setup it usually sits alongside.

The pattern, and the habit it should produce

Four changes, one week, and a single shared property: the platform changed how it counts, and your business did not change at all.

This happens constantly and almost nobody keeps a record of it. So here is the cheap habit that pays for itself the first time it fires:

Keep a measurement changelog. One dated line per platform change that could move a number — rollout date, what moved, which direction. It takes a minute and it converts next quarter’s unexplained cliff into a known event.

Judge every surprise against something the platform cannot influence. Backend orders. Invoices. The bank statement. This is the same instinct behind using blended efficiency as the number that settles arguments, because neither input comes from an ad platform and attribution cannot touch it.

Check the shape of the change before diagnosing it. Artifacts start cleanly on the day a rollout reached your account. Real performance changes ramp. A conversion rate that steps on 22 September and then sits flat is a definition change; one that drifts over three weeks is your market.

Annotate the dashboard, not a document nobody opens. The change has to be visible where the decision gets made, which is the difference between a dashboard your team uses and one they stopped trusting.

This week, concretely

  • Annotate 21–23 September on any Shopify session, conversion-rate or bounce-rate series, and stop comparing across it.
  • Check Sales channels → Agentic and decide about direct checkout on purpose.
  • Reconcile September revenue against Shopify orders, not GA4, and find out how large the invisible slice is.
  • If you turn on a GA4 hostname Include filter, run it in Testing for a day first.
  • Before uploading IPs to Customer Match, confirm your consent basis and build the EEA/UK/CH exclusion.

None of this makes anyone’s numbers better. It makes them mean something, which is the part that has to be true before optimisation does anything at all.

If a chart moved last month and nobody can tell you whether the business did, that is the first thing I untangle in an audit.