The 5 unglamorous commits I made before turning on paid traffic
Why clean house first
Organic traffic forgives a lot. If the page loads slowly or the metric is wrong, you lose a visit that cost nothing.
Paid traffic does not forgive. Every click has a price, and the ad algorithm learns from the conversions you send it. If you measure wrong, it optimizes for the mistake.
So before turning on Google Ads for Estoque Simples, I made five commits nobody will ever see. Each one came with a test.
1. A single domain, with a 301
The hosting provider gives you a technical domain in addition to the brand domain. Both served the same page. To Google, that is two copies of the site. To users, it is a shared link with the wrong address.
The fix is a middleware that, in production, redirects any host other than the configured one to the official domain with a 301, preserving the path and the query string.
The detail that matters is in the exceptions: webhooks and the health check are left out. They are called by machines, and most HTTP clients do not repeat a POST after a redirect. Redirecting the payment gateway webhook would silently break subscription confirmations.
The tests cover the cases that matter: a wrong host becomes a 301, the right host passes, webhooks and the health check never redirect, and outside production nothing changes.
2. The captcha loads only when it shows up
I use Cloudflare's Turnstile on public forms. Its script pulls in a challenge platform of around 800 KB.
On the landing page, the only widget lives inside a modal that is closed by default. In other words: every visitor paid 800 KB for a form almost nobody opens.
Now the script is only injected when a widget enters the viewport, using an IntersectionObserver. Browsers without support load it immediately, as before. A test makes sure the page no longer references the script directly.
With paid traffic, page weight is money: landing page quality feeds into the price of each click.
3. The conversion fires once, and only once
The conversion that matters is a completed signup. The naive approach is putting the event on a "thank you" page. The problem is that page can be reloaded, reopened from history, or not exist at all, because signup already drops the user straight into the panel.
What I did: when signup completes, the system writes a flag to the session. The first panel screen reads that flag and removes it in the same operation. If the flag exists, the conversion event goes along. Reloading does not count again.
The tests check that the flag is written when signup succeeds, is not written when it fails, and that the panel fires the event exactly once.
4. A command to fully delete test accounts
Testing the signup funnel in production creates fake accounts. Emails get stuck, including those of already-deactivated users, and you cannot sign up again with the same address.
I built a command that deletes a company along with everything that belongs to it: users, products, stock movements, documents, images, invitations, subscriptions and payments. It accepts the ID, the exact name, or the email of any user in the company, and shows a summary before asking for confirmation.
And one safeguard: if the company has a live subscription at the payment gateway, the command refuses to run. Deleting the account while leaving the charge active is the worst possible combination. It only goes through with an explicit flag, and the message warns that billing continues until it is canceled there.
5. Legal documents pointing to the right domain
The terms of use and privacy policy were created when the system still ran on another address. The internal links in those documents pointed there.
A command rebuilds those links using the configured public domain, and the seeder now generates the documents with the right address from the start. It looks like a detail, until someone clicks "privacy policy" from an ad and lands on a technical page.
The pattern behind all five
None of these changes increases conversion by itself. What they do is make sure the money invested in acquisition arrives intact: on the right page, loading fast, with the right metric flowing back to the ad.
If you are turning on paid traffic tomorrow, this is my minimum list:
- One canonical domain, with a 301, and webhooks excluded from the redirect.
- Third-party scripts loaded only when they are actually used.
- Conversions fired exactly once, driven by the server.
- A safe way to clean up whatever your own tests left behind.
Related posts
Hiding the menu is not access control: how I built modules each customer can switch on and off
A small shop does not want to see commissions, invoicing and a customer portal on day one....
My second SaaS started from the code of the first: what I could reuse and what I had to rewrite
Oficina Simples was born as a fork of Estoque Simples. Login, plans, billing, privacy comp...
A stockroom is not a store: the inventory nobody sells and everybody loses
Gloves, toner, cleaning supplies, parts: internal-use inventory costs money, runs out at t...