Protecting your Shopify store with CrowdHandler

Protecting your Shopify store with CrowdHandler

This guide explains how the CrowdHandler app decides which parts of your Shopify store get a waiting room, how to set that up, and how to make sure only shoppers who came through the queue can buy.

It covers:


Why use a waiting room on Shopify?

Picture a limited drop. Thousands of shoppers land at the same moment. Within seconds the product is gone. Hundreds of people who had it in their cart reach the checkout only to find it has sold out under them. Bots and resellers, who are faster than any human, take a disproportionate share. Your customer service inbox fills up, and the shoppers who missed out remember the experience.

A waiting room fixes this by managing throughput: how many shoppers are allowed onto your product pages at once. Instead of everyone rushing in together, shoppers join a queue and are let through at a steady pace. Each group has a fair chance to add to cart and check out before the next group arrives. Stock sells in an orderly way, carts actually convert, and far fewer people are left holding an empty basket.

The app gives you two layers of protection, and you can use one or both:

  1. The waiting room. This controls the flow of shoppers onto your pages. You set it up on the Mapping page of the app.
  2. Anti cheat. This makes sure that only shoppers who came through the queue can buy. It is switched on from the app's home page.

The waiting room on its own paces the crowd. Adding anti cheat means that someone who finds a way around the queue still can't complete a purchase, so the stock goes to the shoppers who waited their turn.

Before you can set up either, you'll need to have completed the first steps on the app's home page: saving your API keys and activating the CrowdHandler app embed in your theme.

Where the pace is set

The rate at which shoppers are let through is set for your domain in the CrowdHandler dashboard, and it applies across all of your waiting rooms. Adding or removing waiting rooms in the app doesn't change it. Individual rooms control which pages are protected and what shoppers see while they wait: the room's title, its message, and when it is active.


The three protection modes

On the Mapping page you'll see a card called What to protect. This is where you choose your protection mode. There are three options, and one is active at a time.

Mode What it protects Best for
Entire store Every page on your store, with one waiting room Launches where the whole store will be busy, or when you'd rather not manage products one by one
Collections Whole collections. Each protected collection gets its own waiting room, covering the collection page and every product in it Drops where a range of products goes on sale together
Individual products Specific products. Each protected product gets its own waiting room One or a few limited products, while the rest of the store trades as normal

When you first install the app, no mode is selected and the card shows Not set up, with a message inviting you to Choose what to protect. Nothing is protected until you pick one.

Whichever mode you choose, the waiting rooms themselves are created for you in your CrowdHandler account. You can then adjust each room's title, message and schedule by clicking Edit waiting room, which opens it in the CrowdHandler dashboard.

A note on waiting room limits

Each protected product or collection uses one waiting room from your CrowdHandler plan. Entire store mode uses just one room, so it works on every plan, including the free one. If you plan to protect many individual products, it's worth checking that your plan has enough rooms.


Protecting your entire store

This is the simplest option. One waiting room covers every page of your store, so every shopper who arrives during a busy period joins the same queue and is let through at your domain's rate. You may also hear this called a catch-all waiting room, because it catches all visitors.

When to use it

  • You want a single queue that is easy to manage and easy to explain to customers.
  • You have a collection that is too large to protect on its own. The app will suggest Entire store in this case.
  • You're on a plan with only one waiting room.

How to set it up

  1. Open the Mapping page in the CrowdHandler app.
  2. In the What to protect card, choose Entire store.
  3. A confirmation appears: "One waiting room will cover every page of your store." If you already had waiting rooms set up for products or collections, it also lets you know that those rooms will be removed.
  4. Click Protect entire store.
  5. Keep the page open until it finishes. You'll see the message "Your whole store is now protected."

The app creates one waiting room for you, named after your store (for example, "My Shopify Store waiting room"), with the message "Our store is very busy right now."

The Mapping page then shows a Your waiting room card with the room's title and message. Click Edit waiting room to change the wording or set when the room switches on. Remember that the pace shoppers are let through at is a domain setting in CrowdHandler, not a room setting.

Things to know about Entire store mode

  • It really does mean every page. Your home page, collection pages, search, blog posts and everything else are covered. If you'd rather shoppers browse freely and only queue for certain products, one of the other modes will suit you better.
  • The room is managed from the Mapping page. If the store-wide room is deleted in the CrowdHandler dashboard, the app notices and returns you to Not set up, so your store isn't left half configured. To switch off store-wide protection, change the mode on the Mapping page instead.
  • Anti cheat is stricter in this mode. With anti cheat on, every item in a shopper's cart must have come through the queue. See Anti cheat for what that means in practice.

Protecting individual products or collections

Use these modes when you want most of your store to trade normally and only pace the shoppers heading for specific items.

Individual products mode

  1. On the Mapping page, choose Individual products in the What to protect card and confirm.
  2. A Products list appears. Use the search box to find a product. You'll need to type at least 4 characters.
  3. Click Setup waiting room on the product you want to protect.
  4. You'll see "Room protected", and the product now shows a Protected badge.
  5. Repeat for each product you want to protect.
  6. Click Edit waiting room on any product to open its room in the CrowdHandler dashboard and adjust its message and schedule.

Behind the scenes, the app adds a tag called ch-checkout-validator to the product in Shopify. The app manages this tag for you, so there's no need to change it yourself.

Once you've set up some products, the list defaults to showing only your protected products. Untick Filter by ch-checkout-validator tag to see your whole catalogue again.

Collections mode

  1. On the Mapping page, choose Collections in the What to protect card and confirm.
  2. A Collections list appears. Search for the collection you want, using at least 4 characters.
  3. Click Setup waiting room on the collection.
  4. The app creates one waiting room covering the collection page and every product in it, then tags each product. You'll see "Room created. Tagging N products in the background." and a progress bar.
  5. When it finishes, the collection shows a Connected badge.

Collections that are too large. A single waiting room can only cover so many products, roughly 18 depending on how long the product names are. If a collection is bigger than that, you'll see a message saying "This collection is too large to protect with a single waiting room." with a button to Protect entire store instead. Alternatively, cancel and protect the most important products individually.

Collections are a snapshot. The waiting room covers the products that were in the collection when you clicked Setup waiting room. Products added to the collection later aren't protected, and products removed from it stay protected. To update, delete the collection's waiting room and set it up again.

Understanding the badges

In Individual products mode, each product in the list shows a badge:

Badge Meaning What to do
Protected The product has a waiting room and its tag. All good. Nothing
Unprotected No waiting room. Click Setup waiting room if you want to protect it
Collection Covered by a collection's waiting room. Nothing
Handle mismatch The product's URL handle has changed since the room was set up, so the room no longer matches the page. Click Edit waiting room and update the URL pattern in CrowdHandler
Remove tag (red) The product's waiting room was deleted or paused in the CrowdHandler dashboard, so its tag was never cleared. Shoppers can't buy this product while it stays like this. Click Remove tag to clear it, then set the room up again if you still want the product protected
Add tag The room exists but the tag is missing, so anti cheat won't check this product. Click Add tag

Removing protection from a product or collection

Click the trash icon next to the product or collection and confirm Delete Room. The waiting room is deleted and the tag is removed. For a collection, the tags are removed from its products in the background. Products that are also in another protected collection keep their tag.

It's best to remove protection from the Mapping page rather than deleting the room in the CrowdHandler dashboard. Deleting it there leaves the product's tag behind, and a tagged product with no waiting room can't be bought (see the Remove tag badge above).

After changing room settings

If you've changed settings in the CrowdHandler dashboard and the Mapping page looks out of date, click Re-sync at the top of the products list.


Switching modes

You can switch mode at any time from the What to protect card. One thing to be aware of: switching mode deletes waiting rooms, and this can't be undone.

When you switch, the app keeps any waiting rooms that make sense in the new mode and deletes the rest, along with their product tags. For example:

  • Switching to Entire store removes all of your product and collection waiting rooms, because the single store-wide room replaces them.
  • Switching from Entire store to Individual products removes the store-wide room. You start with a clean slate and pick the products to protect.
  • Switching from Collections to Individual products removes your collection rooms. Any product rooms you already had are kept.

The confirmation message lets you know whether rooms will be removed before you commit. Any changes you'd made to those rooms in the CrowdHandler dashboard, such as their messages and schedules, go with them. Your domain's rate setting isn't affected.

Two more things to know:

  • Stock syncing is switched off if you had it on, and stays off. You can turn it back on from the home page if you still want it.
  • Clicking the mode you're already in does nothing, so there's no risk of resetting anything by accident.

Waiting rooms outside this mode. If you set up CrowdHandler before protection modes were introduced, you may see a note that some of your waiting rooms don't belong to the current mode and aren't shown. Those rooms are still live and still queueing shoppers. Switching mode will keep the ones the new mode can use and remove the others.


Anti cheat: making sure queue jumpers can't buy

What it does

A waiting room paces the shoppers who visit your product pages. But determined bots and resellers don't always visit pages. They can add products to a cart directly, share links that skip the queue, or use tools that never load your storefront at all. If they succeed, they take stock from the shoppers who waited, which defeats the point of the queue.

Anti cheat closes that gap. When it's on, every shopper who passes through the queue is given an invisible pass. When a protected product is added to the cart, the pass goes with it. At the cart and at the checkout, Shopify checks each protected item for a valid pass, and anything without one is refused.

In plain terms: if you didn't come through the queue, you can't buy the protected products.

Anti cheat is available on every plan.

What anti cheat checks

This depends on your protection mode:

  • Individual products and Collections: only the protected (tagged) products are checked. Shoppers can add and buy anything else freely, even during the sale.
  • Entire store: every item in the cart is checked, including gift cards and anything added by other apps. Because the whole store is behind the queue, everything a shopper adds should have come through it.

How to set it up

Anti cheat needs three things in place. All three are on the app's home page.

1. Activate the CrowdHandler app embed (step 2 on the home page)

Click Activate, which opens your theme editor with the CrowdHandler app embed ready to switch on. Turn it on and save your theme. This is what gives shoppers their pass as they go through the queue. The badge should then show Complete.

2. Add a checkout rule (step 3 on the home page)

Click the link to add the rule in your Shopify checkout settings. This is what tells Shopify to check carts and checkouts. On that Shopify screen:

  • Turn the rule on.
  • Tick Block checkout if app experiences a problem.

Back in the app, the badge should show Complete. If it says Add checkout rule, Turn on checkout rule, or asks you to tick the Block checkout option, anti cheat isn't active yet.

3. Turn on the anti cheat toggle

Under Anti cheat settings (optional), find Prevent adding to cart when bypassing queue and click Turn on. Wait for the badge to show On.

That's it. From now on, protected products can only be bought by shoppers who came through the queue.

What a blocked shopper sees

Shoppers who skipped the queue see one of two messages. They name the product but deliberately don't explain why, so that bots aren't told what to work around:

  • When adding to cart: "Product name" can't be added to your cart right now.
  • At checkout: Please remove "Product name" from your cart, then add it again to continue.

Shoppers can always remove the item from their cart, so nobody gets stuck. If they then visit the product page, go through the queue, and add it again, they can buy it.

These messages can't be customised.

Express checkout buttons

While a waiting room is live and anti cheat is on, the fast checkout buttons on your product pages (Shop Pay, Apple Pay, Google Pay, PayPal) are hidden. Those buttons skip the normal add-to-cart step, so shoppers using them would be turned away at checkout. Hiding them avoids a frustrating dead end. They return when anti cheat is off or the room isn't running.

Order protection

Order protection is a separate, optional feature for Enterprise plans that works alongside anti cheat. Where anti cheat stops queue-jumping carts before an order exists, order protection checks orders after they're placed and flags or cancels any that didn't come through the queue. Its settings sit under Order protection settings (optional) on the home page.


Things to know before your sale

Try it as a shopper first. Before a real launch, set up your protection, turn on anti cheat, and go through the whole journey in a private browser window: reach the product, join the queue, get let through, add to cart, and check out. Also try adding a protected product from a collection page or search results, not just from its own page. It's much easier to sort out any surprises before the sale starts.

A protected product with a missing room can't be bought. If a product is tagged but its waiting room has been deleted or paused, shoppers get the "can't be added to your cart right now" message. The Mapping page shows a red Remove tag badge for these, so a quick look at the page before a sale is worthwhile.

Pausing a room in CrowdHandler doesn't remove protection. With anti cheat on, pausing a product's room stops that product being bought rather than opening it up. If you want a product to trade normally again, delete its waiting room from the Mapping page instead.

Carts filled before you switched on protection. A shopper who added a protected product to their cart before you turned on anti cheat, or before you switched to Entire store, has an item without a pass. They'll be asked to remove it and add it again. Expect a few of these when protection first goes live.

Entire store mode and other apps. In Entire store mode, every cart line is checked, including lines added by free-gift, bundle or subscription apps. Those apps don't go through the queue, so their lines will be refused at checkout. If you rely on apps like these, Collections or Individual products mode is a safer choice, or test carefully first.

Changing a product's URL handle. Waiting rooms match on the product's URL. If you rename the handle, the room stops matching and the product shows Handle mismatch. Update the room's URL pattern in CrowdHandler, or delete and set up the room again.

Collections don't update themselves. A collection's waiting room covers the products that were in it when you set it up. Re-create it after adding new products.

Turning anti cheat off is instant, and nothing else changes. If something unexpected happens mid-sale, click Turn off on Prevent adding to cart when bypassing queue. Your waiting rooms keep pacing shoppers; you simply stop checking carts. You can turn it back on at any time.

The checkout rule is what makes the check happen. If the checkout rule in Shopify is off, nothing is checked at the cart or checkout, whatever the toggle in the app says. The badge for step 3 on the home page tells you its current state.