Support
Get help with Cordon
Email the developer directly. Typical response time is under one business day, EU hours.
Include your shop domain (the .myshopify.com one) so we can look at your configuration right away. For data processing agreements, use the subject "DPA request"; details on the DPA page.
How to test that blocking works
Most "it is not blocking me" reports come from a test that could never have blocked in the first place. These steps rule that out.
Leave the theme editor
Cordon never blocks inside the theme editor or a preview link. That is deliberate, so you cannot lock yourself out of your own store while editing. Testing there will always look like nothing is happening.
Open your real storefront domain
Use the address a customer would type, in a normal browser tab. Not the admin preview, and not a URL containing preview_theme_id.
Wait about 90 seconds after saving a rule
Rule changes reach the detection service within roughly 15 seconds, and each browser tab holds its last decision for 60 seconds. Opening a fresh tab or an incognito window skips the second wait.
Check the visitor log
The log is the source of truth. If your visit appears there, Cordon saw you and the decision it made is shown. If nothing appears at all, the app embed is not running on your live theme.
Common questions
I blocked my own country but I can still visit my store
Almost always one of four things. You tested inside the theme editor or through a preview link, where Cordon never blocks on purpose so you cannot lock yourself out while editing. You tested within about 90 seconds of saving, because rule changes take roughly 15 seconds to propagate and each browser tab remembers its last decision for 60 seconds. The app embed is not enabled in your live theme, so nothing runs on the storefront at all. Or you have an allow rule covering your own IP, and allow rules always win. Check the visitor log after testing: if your visit is listed, the decision Cordon made is shown next to it.
Do I need to clear my browser cache to test?
Not the browser cache as such. Cordon stores its last decision in your tab for 60 seconds so visitors are not re-checked on every page view, and a hard refresh does not clear that. Opening a new tab or an incognito window does, and so does waiting a minute.
How do I see what Cordon is doing on a page?
Add ?cordon_debug=1 to any storefront URL and open your browser console. Cordon logs what it decided and why, and that parameter also bypasses the 60 second tab cache so every reload is a fresh check. If you see no Cordon lines at all, the app embed is off in your live theme.
A real customer says they were blocked. What do I do?
Open the live visitor log, find the block event, and check which rule fired. Add the customer to the allowlist for an immediate fix, then loosen the rule if it was too broad. If the log shows a detection error rather than one of your rules, email us the event and we will tune it. Worth knowing: iPhone users on iCloud Private Relay and people on corporate VPNs are ordinary customers who appear to be on a proxy, which is why the VPN challenge setting exists. It asks them to turn the VPN off rather than refusing them.
The visitor log shows nothing. Is Cordon working?
Usually this means the app embed block is not enabled in your theme, or your store runs on a custom domain that finished setup after Cordon was installed. Toggle the embed in Theme settings, and if the log stays empty email us your shop domain; domain sync is on our side.
I turned on VPN or proxy detection and nothing is being blocked
VPN, residential proxy and Tor detection require the Growth plan or higher. On Free and Starter the switches are visible but do not take effect, because the live detection data behind them is a paid service. Country, IP, IP range and ASN rules work on every plan including Free.
Blocking suddenly stopped working
Two usual causes. Either you changed plan and the new plan does not include the detection you were relying on, or you passed your monthly visitor limit. Over the limit, paid fraud detection is switched off to keep costs bounded, but your own country, IP and ASN rules keep running. The dashboard shows your usage and warns before you get there.
How do I change plans or cancel?
Billing runs through Shopify. In your Shopify admin, open the Cordon app and use the Plan and billing page, or manage it like any app subscription under Settings, Apps. Cancelling stops billing at the end of the cycle.
Can you help me pick the right rules?
Yes. Email a short description of the traffic problem (scrapers, fraud from a region, checkout bots) and we will suggest a rule set. The presets cover the common cases: Block China, Anti-scraper, and Strict mode.