GA4 Attribution Is Structurally Wrong for Shopify Stores
GA4 doesn't just occasionally miscount your Shopify revenue — it's structurally set up to. Here's the checkout-domain mechanic everyone explains, the 2026 wrinkle nobody's caught up on yet, and what to actually check.
August 20, 2026 · 5 min read
Two separate structural issues explain most GA4-vs-Shopify revenue mismatches — not one bug, and not a data quality problem you can clean your way out of.
Why GA4 gets Shopify attribution structurally wrong, not just occasionally wrong
First, Shopify's checkout runs on a separate domain from your storefront. Unless cross-domain tracking is configured correctly — and it's easy to get subtly wrong — GA4 can lose session continuity right at the moment a visitor moves from browsing into checkout, which is the worst possible place to lose it. A visitor who arrived from a Meta ad, browsed for ten minutes, then converted can show up in GA4 as a brand-new, sourceless session the instant they hit checkout.
Second, GA4's own attribution model. GA4 defaults to a data-driven model with a lookback window that stretches out to roughly 90 days — a completely different window than Meta's 7-day click default. Two platforms measuring the same customer's path with two different lookback windows will, by construction, disagree about which touch gets credit. On top of that, GA4 samples and models a portion of its conversion data rather than reporting every session as directly observed, which is exactly how you end up staring at a channel row labeled "(not set)" with real revenue attached and no way to know where it actually came from.
One competitor writeup put a number on this: AccessFuel has claimed that 70% of Shopify brands misread their GA4 attribution. Treat that as AccessFuel's own estimate, not an independently verified figure — but directionally it matches what most operators run into. The "(not set)" bucket and channel-total mismatches aren't edge cases; they're close to the default experience.
2026's new wrinkle: iOS 26 is stripping click IDs from a quarter of your traffic
Everything above has been true for years and is reasonably well covered elsewhere. What's new in 2026 — and mostly missing from existing coverage — is Apple's Link Tracking Protection (LTP).
LTP first shipped as an opt-in Private Browsing feature back in iOS 17 (September 2023). The real shift happened later: an expanded, public rollout began September 15, 2025, and iOS 26 extended it to all Safari browsing by default — not just Private mode — plus links opened from Mail and Messages. It strips the platform click ID parameters (gclid, fbclid, msclkid, dclid) before the link ever reaches your site.
Safari carries roughly a quarter of global browser traffic. That's the number that should actually concern you: as of 2026, something like one in four of your visitors can arrive at your store with a click ID silently removed, with no way for you or the visitor to know it happened.
Here's the detail most guides on this bury or miss entirely: standard UTM parameters are not stripped. utm_source, utm_medium, and utm_campaign are treated as informational rather than privacy-invasive, and they survive LTP intact. If your campaigns are properly UTM-tagged, that signal survives on Safari traffic even when the click ID doesn't. We go deeper on exactly what changed and what to do about it in iOS Tracking Loss in 2026.
What GA4 is still good for
None of this means ignore GA4. Session volume, engagement rate, and channel-level traffic shape are still real, useful signals — GA4 is a legitimate window into how people move through your site before you have any idea whether they'll buy. What it isn't, structurally, is a reliable order-level source of truth about which specific channel drove which specific sale on a Shopify store. Treating a GA4 channel total as your revenue attribution is the mistake; treating it as one input among several is not.
How Tutti treats GA4 as corroborating evidence, not a verdict
Tutti never asks GA4 to be the single source of truth, because it structurally can't be. Instead, a GA4 session becomes one piece of evidence Tutti checks alongside your store's own first-party record of the visit and any ad click your pixel captured directly. When a GA4 session lines up on timing, landing page, and device with a real campaign that was running, it corroborates a match — but it's weighted as a weaker signal than a direct click id or your store's own session record, precisely because GA4's own sampling and window-length quirks make it less certain on its own. Full detail on how the ranking works is on how attribution works.
That's why the picture degrades gracefully instead of breaking outright when GA4 goes dark on a given order: it was never the only thing holding the answer up.
What to check in your own GA4 setup today
- Confirm cross-domain tracking is actually configured between your storefront and Shopify's checkout domain — this is the single most common silent misconfiguration.
- Check your consent mode setup if you're running in any region with cookie consent requirements — a gap here silently drops sessions before GA4 ever sees them.
- Look at how much revenue is sitting in a "(not set)" or "Unassigned" channel row for a recent window. If it's a meaningful chunk, that's your structural gap, not a data-quality accident.
- Confirm your ad platforms are still UTM-tagging every campaign, not just relying on auto-tagged click IDs — that's the one signal that survives Safari's Link Tracking Protection.
For the Meta-specific version of this same disagreement, see Why Your Facebook Ads Manager and Shopify Revenue Never Match. For the framing most founders actually care about — which channel deserves the next dollar — see Why Every Platform Shows a Different ROAS for the Same Campaign.
Stop treating a GA4 channel total as your revenue truth. See what Tutti resolves your GA4, Meta, and Shopify data down to instead.