Skip to content
Can Elmas

CRO · 8 min read

How to Use Heatmaps and Session Recordings to Find Conversion Problems

TL;DR

Don't binge-watch recordings. Start from a funnel step where analytics shows a drop, filter to 20-40 sessions from that segment, and log repeated patterns: rage clicks, dead clicks, hesitation and loops. Split every heatmap by device, treat each finding as a hypothesis backed by a second source, mask personal data, and review on a fixed weekly routine.

· Published · Updated

To analyze session recordings well, start from a funnel step where analytics shows people dropping off, filter to the 20 to 40 sessions that match that drop, and log the patterns that repeat. Heatmaps tell you where to look and recordings show what went wrong, but neither tells you why until a second source backs it up. The method below works in any behavior analytics tool, whether that’s Microsoft Clarity, Hotjar, FullStory or something else.

What heatmaps show and where they mislead

A heatmap aggregates many visits into one picture of a page. The three common types answer different questions, and each has a way of fooling you.

Heatmap typeUseful forMisleads when
Click or tap mapWhich elements get attention, and which non-links get clickedContent moves: carousels, tabs, pop-ups, personalized blocks
Scroll mapHow far down visitors get before leavingThe fold differs by device, or visitors leave because they found what they needed
Move or hover mapRough reading paths on desktopAlways a weak signal; cursor position is not eye position, and it means nothing on touch

The mistakes I see most often:

  • Blending devices. A combined heatmap averages layouts that don’t exist. Split every heatmap by device before reading it.
  • Mixing page versions. If a deploy or new banner went live mid-capture, the map shows two pages at once. Reset or date-filter after every meaningful change.
  • Mixing audiences. Returning customers heading to log in and first-time paid visitors behave nothing alike. Filter by source or new vs returning when the tool allows it.
  • Reading clicks as success. A heavily clicked menu item may be an escape route, not interest.
  • Reading too early. As a rule of thumb, I don’t trust a heatmap until it has at least a few hundred page views per device.

Use heatmaps to pick where to look. Use recordings to see why.

Filtering recordings so you watch the right sessions

Unfiltered recordings are mostly noise: bounces, bots, your own team and loyal customers. Start with a question from your funnel data, then build the filter that answers it.

Question from analyticsFilter to use
Why do visitors leave pricing without starting a trial?Visited pricing, did not reach signup, one device at a time
Why does paid social traffic bounce from the landing page?Campaign source, that landing page, mobile, session longer than about 10 seconds
Why do shoppers view products but never add to cart?Viewed two or more product pages, no add-to-cart event
Why does the demo form get started but not submitted?Interacted with the form, no submit event
Is something broken?Sessions with JavaScript errors or rage clicks on a key page

Then exclude internal traffic and QA testers, sessions under a few seconds (unless you’re studying ad-to-page mismatch), logged-in customers when you’re studying acquisition, and obvious bots.

Watch with inactivity skipped at 1.5x to 2x speed, and stop when patterns repeat. If the same problem shows up in 6 of your first 15 sessions, you have enough to investigate; 50 more won’t change the conclusion.

Patterns to look for: rage clicks, hesitation and loops

Most tools flag rage clicks automatically, and many also flag dead clicks, quick backs or JavaScript errors. Those flags are a starting list, not a diagnosis. These are the patterns worth logging.

Rage clicks

Rapid repeated clicks on one spot. Common causes: a button that doesn’t respond, a response too slow to feel like it worked, or a disabled button with no explanation. Rage clicks that cluster on one element after a release usually mean a bug, so send those to a developer the same day.

Dead clicks

Clicks on non-interactive elements: product images people expect to zoom, underlined text, feature names on a pricing table. Each one tells you what the visitor wanted to happen, and often the fix is to make that element do it.

Hesitation

Long pauses at a specific point: the cursor hovering over a price, a field left empty for 20 seconds, a plan toggle switched back and forth. Hesitation marks uncertainty. On a form, it usually points to a field that feels intrusive or unclear. On pricing, it often points to a missing answer about limits, contracts or what happens after the trial.

Loops

Visitors bouncing between the same pages: product page to size guide and back, pricing to security page to pricing, cart to shipping policy to cart. A loop means the page they keep returning to is missing information they need to decide. Put the answer where the loop starts.

Form thrash and quick exits

Form thrash looks like fields entered, deleted and retyped, repeated error messages, or a submit clicked several times. Quick exits look like a visitor landing, glancing at the top of the page and leaving within seconds, which usually means the page doesn’t match the ad, email or search result that sent them. If your drop-off sits inside the checkout itself, the specific fixes are in the checkout optimization guide.

Mobile vs desktop differences

Treat mobile and desktop as two different sites. Layouts differ, traffic sources differ (mobile often skews toward social and email), and intent differs, especially in B2B, where many people browse on a phone and buy at a desk.

On mobile, watch for:

  • Rage taps on small or crowded targets
  • Repeated taps on product images or small text, a sign they’re too small to judge
  • Fields tapped repeatedly, then abandoned; replays don’t show the on-screen keyboard, so check on a real phone whether it hides the field or is the wrong type
  • Sticky bars, chat widgets or cookie banners covering the call to action
  • Key information hidden in accordions nobody opens
  • Fast scrolling up and down, which usually means hunting for something

On desktop, watch for:

  • Hovering over navigation without clicking, a sign labels aren’t clear
  • Text selection on prices or product names, often copied to compare elsewhere
  • Long idle stretches, frequently a visitor comparing you in another tab

Cursor paths mean nothing on touch devices. On mobile, read scroll speed, pauses and taps instead.

Turning observations into test hypotheses

An observation is not a hypothesis. “People rage-click the product image” is a fact about behavior. A hypothesis adds a cause, a change and a way to measure it:

Because we saw [pattern] in [X of Y sessions] for [segment], and [second source] supports it, we believe [change] will improve [metric]. We’ll measure it by [method] over [period].

A hypothetical example: 9 of 30 mobile sessions from paid social tap the main product image repeatedly, expecting it to zoom. Two post-purchase survey answers mention being unsure about fabric texture. Hypothesis: adding tap-to-zoom and close-up texture shots will raise mobile add-to-cart rate for paid social visitors.

The second source separates a finding from a hunch: funnel data, survey answers, support tickets, sales call notes or form analytics. If nothing supports a pattern, keep watching before you act.

Log everything in one sheet so patterns accumulate across weeks. A hypothetical row:

DatePage / stepSegmentPatternSeen inSecond sourceHypothesisStatus
Week 1PricingDesktop, organicLoop to security page7 of 253 sales calls asked about SSOAdd security summary to pricingReady

Prioritize by how many visitors the step affects, how close it sits to conversion, and how cheap the fix is. Then decide whether to A/B test or ship and measure. If traffic can’t support a test in a reasonable time, the approach in CRO for low-traffic sites applies.

Recordings capture what visitors type and see, so configure privacy before you start watching, not after.

  • Input masking is on for every form field (default in most tools, but verify it)
  • Text is masked on account pages, order confirmations and anything showing names, addresses or order details
  • Pages that don’t need recording are excluded entirely, especially anything with health or financial detail
  • No emails, names or phone numbers are sent as custom tags or user IDs; use an internal ID instead
  • The script loads only after consent where the law requires it, through your consent management platform
  • Your privacy policy discloses session recording and the vendor
  • Retention is as short as your review cadence allows, and viewing access is limited to people who need it

Consent also shapes your sample. Where recording requires opt-in, you only see visitors who accepted, and they may behave differently from those who declined.

A weekly review routine

Behavior analytics pays off when someone reviews it on a schedule, not when it’s opened after a bad month. Block 60 to 90 minutes, same day each week, with one owner:

  1. Pick the step (10 minutes). Check the funnel against the 4-week average and choose the step with the biggest drop or change. Note any releases, promotions or campaign launches.
  2. Scan for breakage (10 minutes). Review frustration flags and JavaScript errors on your top pages. Anything new since last week goes to a developer now.
  3. Watch (30 to 40 minutes). Filter 20 to 30 sessions for the chosen step, one device at a time, and log patterns in the sheet.
  4. Check the heatmap (10 minutes). Only if the page has enough views since its last change, split by device.
  5. Update the backlog (10 minutes). Move any pattern seen repeatedly and backed by a second source to “ready.”
  6. Commit to one output. One fix shipped, one test briefed, or one bug filed.

Once a month, revisit shipped fixes: did the pattern disappear from recordings, and did the metric move? And now and then, invite the designer or developer to watch ten minutes with you. In my experience, it settles page debates faster than any report.

This routine is the research layer underneath my CRO and landing page work: recordings and heatmaps feed the hypotheses, and every test traces back to something real visitors did.

Get it built

If your recordings pile up unwatched, or you have observations but no shipped fixes, I’ll set up the filters and privacy settings, run the reviews and build the changes. Start with a Growth Audit, $1,500 fixed and credited if we continue. See pricing or get in touch.

FAQ

Frequently Asked Questions

How many session recordings should I watch?

Enough to see a pattern repeat, usually 20 to 40 sessions per segment and funnel step. If a problem hasn't shown up in the first 15 or so, it's probably not your biggest issue, and once it shows up several times, stop watching and confirm it in analytics.

What's the difference between a rage click and a dead click?

A rage click is several rapid clicks on the same spot, usually because something didn't respond or responded too slowly. A dead click is a click on something that isn't interactive, which tells you visitors expected it to be a link or button.

Are heatmaps accurate on pages with dynamic content?

Only partly. Carousels, pop-ups, personalized blocks and layouts that change between breakpoints can attribute clicks to the wrong element, so split by device and check suspicious hot spots against recordings before acting.

Do I need consent to record sessions?

In many jurisdictions, including the EU and UK, session replay is generally treated as non-essential tracking that needs prior consent. Rules vary by region and industry, so confirm with legal counsel and load the tool only after consent where it's required.

Work with me

Let’s find your biggest growth lever

Tell me about your growth challenge. I’ll tell you honestly if I can help — and if I can’t, who can.

  • ✓ No obligation
  • ✓ No sales script
  • ✓ Honest feedback
  • ✓ Clear next steps