Something is loading only my /privacy-policy page a few hundred times a day, 4 months straight

InterschI

Newbie
Joined
Jul 21, 2026
Messages
4
Reaction score
0
Affiliate site, regulated niche. Since mid-April, one URL is getting hammered, and nothing else on the site is touched: /privacy-policy/
  • Started around 13 April from literally zero, stepped up again around 25 May, now a few hundred sessions a day and still climbing
  • 99.8% direct, no referrer
  • 1 page per session, 0s engagement time, almost all new users, nobody returns
  • Nearly every hit is a session start, so they land on it directly, they're not clicking the footer link while browsing
  • It fires GA4, so whatever it is renders JavaScript. Not a curl loop.
  • Page is noindex/nofollow, nothing links to it, no campaigns
One detail that bothers me: in April and May, the average engagement time was 8 seconds. Now it's 0. As the volume grew, the behavior got less human.

Why would anything load one boring legal page a few hundred times a day for four months and touch nothing else on the site?

Best guesses so far: a scraper building a company/contact database off legal pages, a proxy pool health-checking itself against a cheap always-200 URL, or someone quietly padding my analytics with junk sessions.

Anyone seen this pattern or run something that produces it?
 
The 0-second engagement time points toward automated traffic. Server logs should show whether these are real requests.
 
Those are data brokers and aggregators. Block them by user agent and IP range. They usually use outdated versions of Chrome & Firefox (sometimes even newer versions) In those cases, I block them by IP range, especially when the IPs are from data centers but sometimes they use residential IPs, so I’m constantly hunting them down...
 
I'd lean toward the database-scraper theory instead, specifically bc it's a REGULATED niche, privacy policies in regulated industries
 
This pattern definitely points to automated headless traffic, which in regulated niches is often an affiliate compliance check, a legal data scraper, or a proxy health monitor. Before making changes, check your raw server access logs to confirm whether the IP ranges, user agents, and request intervals match the GA4 hits. If the traffic turns out to be an affiliate compliance scanner, filtering it out inside GA4 is safer than blocking the endpoint and risking your account standing. If your logs show it is just low quality bot scraping, placing a path specific managed challenge or rate limit in Cloudflare will clean it up quickly.
 
Back
Top