Heatmaps
Date: 2026-08-17
Aggregated click, move and scroll activity rendered over a screenshot. Persuasive to look at and easy to misread — the rendering assumes every visitor saw the layout in the screenshot, which on a responsive, personalised, dynamically-priced site is rarely true for more than a fraction of them.
The three types, and what each is worth
| Click / tap | Scroll | Move / attention | |
|---|---|---|---|
| Shows | Where taps landed | How far down people got | Cursor position over time |
| Genuinely useful for | Non-clickable elements being clicked; rage-clicking | Whether content below the fold is reached | Little on desktop, nothing on mobile |
| Reliability | Good | Good | Weak — cursor position correlates poorly with gaze |
| Main trap | Absolute counts, not rates | Comparing pages of different lengths | Treating it as attention data |
Move heatmaps are the weak one. They’re often presented as attention maps, and the correlation between mouse position and where someone is looking is loose enough that decisions shouldn’t rest on it. On touch devices there’s no cursor at all, so the data is desktop-only — and desktop is a minority of most commerce traffic.
The rendering problem
This is the failure that invalidates most heatmap findings, and it’s structural rather than a configuration mistake.
the tool captures ONE screenshot and overlays clicks from ALL sessions
but the page each user saw varied by:
· viewport width → a 3-column grid became 1 column
· logged-in state → different header, prices, saved items
· A/B test variant → a different layout entirely
· personalisation → different recommended products
· stock and price → "out of stock" changes button position
· consent banner → covered the top 200px for some users
· dynamic content → a promo bar that appeared for two days
a click at (340, 890) meant something different for each of them.
the heatmap shows them all in the same place.
The consequence: a hot spot in empty space, or a cold spot on your primary call to action, is frequently a rendering artefact rather than a behavioural finding.
Mitigations, and they’re not optional:
- Segment by viewport width and read each separately. Never read a merged desktop/mobile heatmap
- Segment by test variant if a test is running. Otherwise you’re averaging two layouts
- Filter to a stable period where the page didn’t change
- Check the sample per segment before believing anything — 40 sessions on a segment is not a finding
Reading them properly
- Rates, not counts. “1,400 clicks” on a header link that appears on every page tells you the header is on every page. Clicks per view of that element is the number
- Normalise per element, not per page. A tool showing absolute intensity makes high-traffic areas look important by construction
- The absence of clicks is the signal. A prominent CTA nobody taps is more informative than a busy navigation
- Scroll depth needs a rate too, and pages of different lengths can’t be compared on percentage-scrolled — 50% of a 900px page and 50% of a 6,000px page are different behaviours
What they’re genuinely good at
Narrow, and worth naming because the broad use is what fails:
- Clicks on non-interactive elements. People tapping a product image expecting a zoom, tapping a static badge expecting a filter, tapping text that looks like a link. This is the highest-value finding heatmaps produce and it’s hard to get any other way
- Rage clicks — repeated rapid clicks in one spot, meaning something didn’t respond. A direct bug signal — Feedback and System Status
- Content below the fold going unseen. A scroll map showing 12% reaching your key content is a layout decision, immediately
- Communicating to stakeholders. Honestly, this is a real use: a heatmap makes a point in a meeting that a table doesn’t. Just make sure the finding was established elsewhere first
What they can’t tell you
- Why. A cold CTA might be invisible, unappealing, irrelevant, or premature in the journey. The heatmap can’t distinguish them — Session Replay and Usability Testing can
- Whether a change would help. Purely descriptive; the fix has to be tested — A-B Tests
- Anything about people who left before rendering. Heavy pages lose their slowest visitors before the tool loads, biasing the sample towards faster connections — Survivorship Bias
- Anything statistically reliable at low volume. Heatmaps present no uncertainty, so a pattern from 80 sessions looks identical to one from 80,000 — Communicating Uncertainty
The cost people forget
Heatmap and replay tools record a great deal, and both the performance and privacy costs are real:
- A recording script on every page is third-party JavaScript in the critical path — Third-Party Scripts, Tag Manager Performance
- They capture form contents by default in some configurations, which is how card details and addresses end up in a vendor’s system. Masking must be verified, not assumed — PII in Analytics
- Consent applies. Recording behaviour is processing personal data, and the tool must not load before consent — Consent Management, UK GDPR and PECR for Analytics
Where it interacts
- Session Replay — the individual-session counterpart, usually from the same vendor; heatmaps aggregate, replay explains
- Form Analytics — the specialised version for forms, and far more diagnostic than a heatmap over the same area
- Reading Behaviour Online — the research on scanning patterns, which is what heatmaps are usually being used to rediscover badly
- Path Analysis — both are descriptive hypothesis generators with the same limitation: they show what, never why