ReguCartBot is the crawler used by the Shopify app "ReguCart: India Compliance", provided by Shivam Bector, trading as Debug Ninja. If you saw this address in your server logs or analytics, this page explains what the visit was and how to contact us.
1. How to recognise it
ReguCartBot identifies itself with this user agent:
ReguCartBot/1.0 (+https://regucart.com/bot)
It runs a standard headless Chromium browser, so it loads pages, images, styles and scripts as a browser does. It presents itself as a shopper in India (Indian English language setting, India time zone and a Mumbai location), because the checks are about what Indian shoppers see.
If the store owner has created a crawler access signature in Shopify (Online Store > Preferences > Crawler access) and added it in ReguCart's settings, ReguCartBot's requests carry Shopify's signature headers.
ReguCartBot does not use fixed IP addresses. Identify it by its user agent, described above.
2. Which sites it visits
ReguCartBot visits only the storefronts of Shopify stores whose owners have installed the ReguCart app and accepted our Terms of Service, which authorise these visits. It does not crawl the wider web, follow links to other websites, or build a search index.
3. What it does
On each scan, ReguCartBot visits a selection of a store's pages to check what customers see, against Indian e-commerce and consumer rules. The selection typically includes:
- the home page, footer-linked pages, contact page and policy pages;
- a few collection pages, search results for a few test words, and a sample of product pages;
- the account sign-up page;
- the cart, after adding one product to it, and the first page of checkout.
For each page it records the address, the page code and visible text, a screenshot, the scripts and cookies the page loads, and any pop-ups. It may reload a page in a fresh session to test whether a countdown timer restarts. It runs automated accessibility checks on a few pages.
A full scan usually covers up to 40 pages on the Free plan and up to 120 pages on the Pro plan, plus a few repeat visits for specific tests. Daily monitoring on Pro visits up to about 15 pages.
4. What it never does
ReguCartBot:
- never submits forms, including contact, sign-up, newsletter, login and review forms;
- never places orders and never goes beyond the first page of checkout;
- never enters personal data of any kind;
- never solves CAPTCHAs or tries to get around bot protection, passwords or logins;
- never tries to access pages that need a login, and skips password-protected storefronts.
About the test cart
To check prices and fees in the cart, ReguCartBot adds one product to a test cart through the store's own cart API and then loads the first page of checkout. This can create an abandoned cart or checkout session in the store's Shopify admin, which may appear in abandoned checkout reports. No order is placed and no personal data is entered, so no abandoned-checkout email can be sent to anyone.
5. How polite it is
- Rate limit: it starts at most one page load per second on any store. Each page load also fetches that page's images, scripts and styles, as a browser does. In practice it is slower, because it waits for each page to finish loading.
- One store at a time: the crawler handles one scan at a time.
- Backs off: if a store answers "too many requests" (HTTP 429), it waits 30 seconds before one retry. If it meets a bot challenge or "access denied" page twice in a row, it stops the crawl and reports the checks as "not run".
- robots.txt: it reads the store's robots.txt file and follows the rules for the user agent token
ReguCartBot(or*). If robots.txt cannot be read because of a server error, it treats the whole site as disallowed. - Paths the store owner authorises: Shopify's default robots.txt asks crawlers not to visit
/cart,/checkout,/searchand/policies/. Because those pages matter for the checks, the store owner authorises ReguCartBot to visit them when they accept our Terms (for/checkout, the first page only). The store owner can also authorise extra paths in ReguCart's settings. All other paths follow robots.txt.
6. How to limit or stop it
If you own the store:
- exclude specific pages in ReguCart's Settings (Crawler);
- add rules for
ReguCartBotto your robots.txt (they apply to every path except those listed in section 5 that you authorised); - password-protect the storefront (ReguCartBot then skips storefront checks); or
- uninstall the app, which stops all visits.
If you do not own the store, or you think ReguCartBot visited a site in error, email [email protected] with the site address and the approximate time of the visit. We will look into it and stop any visits that are not authorised.
To tell ReguCartBot not to visit a site you control, add this to your robots.txt:
User-agent: ReguCartBot
Disallow: /
On a store where the ReguCart app is installed, the paths in section 5 that the store owner authorised are still visited until the app is uninstalled.
7. What happens to the data
Screenshots and page captures are stored securely and kept for 90 days on Pro, or until the next scan on Free, and are deleted when the store owner uninstalls the app. Page content may be reviewed with the help of AI models. See our Privacy Policy at regucart.com/privacy.