Your GA4 is lying to you. Seven settings that are wrong right now.
GA4 ships in US dollars, on one domain, closing the day on whatever time zone its creator picked. Seven of those defaults are wrong for a Gulf business.
Nobody made these mistakes
Every list of GA4 problems calls them mistakes. Mistake is the wrong word for a setting you never touched. GA4 ships with defaults that sell in dollars, measure one domain, and close the day on whatever time zone the person who created the property picked. If you run a business in the GCC, you inherited a property configured for somebody else’s company and you have been reading its output ever since.
The settings worth worrying about are the ones that produce believable numbers. Data that is obviously broken gets caught, because somebody looks at a chart, laughs, and files a ticket. Data that is wrong by an amount nobody can name gets presented to the board.
Seven of GA4’s defaults are wrong for a business operating here. Three of them are wrong in every number you read today, and the first of those is deleting history you will never get back, which is why they come first. All seven are settings in the Admin panel, and only one of them needs anything from a developer.
The three that are wrong in today’s numbers
1. Data retention is set to two months
Two months. That is how long a new GA4 property keeps your event and user-level data before it starts deleting the oldest of it. The maximum on a standard property is 14 months, and the distance between those two numbers is two dropdowns on one screen.
What the setting governs is narrower than it sounds, which is why it survives so long. Your standard reports keep working, because Traffic Acquisition and Pages and Screens run on aggregated tables that persist. What expires is everything you build in Explorations: funnels, path analysis, custom segments, cohorts. So the property looks healthy right up until the first time somebody asks a question that needs a real exploration, and then the answer only goes back two months.
Changing the setting does nothing retroactively. The months it already ate are gone. Set it to 14 today, and turn on the BigQuery export while you are in there, because 14 months is a ceiling that keeps moving, and anything older than that has already left the property.
2. Your reporting time zone belongs to someone else
Ask who created your GA4 property. The reporting time zone was chosen at that moment, and it has been closing your day on that clock ever since. A group head office in London, a media agency in New York, the freelancer who built the site in 2021: the time zone is a fossil of whoever clicked Create first, and nothing about it updates when that arrangement ends.
The working week here is what makes it expensive. Saudi Arabia and most of the Gulf run Sunday to Thursday, while the UAE moved its public sector to a Monday-to-Friday week with a half-day Friday in 2022, so the region does not share a single answer with itself. What it definitely does not share is a US or UK calendar. On a New York property the Gulf day starts the previous afternoon, so the first hours of every Sunday in Riyadh land in Saturday’s row. Thursday, the day everything has to close by, gets split across two report dates the same way. The week your reports add up is not the week your business worked, and twice a year, when the clocks change in New York and not in Riyadh, the split moves with them.
You can change it. Admin, then Property, then Property details, where the reporting time zone sits under the property name. Google applies the change going forward only, so expect a flat spot or a spike on the day you switch, and know that your history stays on the old day boundaries permanently. Do it once and leave it alone.
3. Every dirham you earn is being converted to dollars
The third one is arithmetic. Property currency defaults to USD, and GA4 converts every transaction into it at the previous day’s rate, so unless somebody changed it, the revenue in your reports is not the revenue on your invoices.
What makes this one survive for years is that it does not look like an error. Most Gulf currencies are pegged to the dollar, so the conversion is a fixed multiplier and not a drifting one. AED revenue arrives in GA4 divided by the previous day’s rate, and the peg holds that rate at 3.6725, with all the consistency of a real number, and a figure that behaves itself does not get questioned. It also means your reported revenue sits at roughly 27% of what you actually billed, which is the kind of gap that gets blamed on missing transactions for a week before anybody opens a currency dropdown.
Set the property currency to what you actually sell in. Then check the other
half of it: your purchase events need to send a currency parameter alongside
value, because Google’s own reference says revenue metrics cannot be computed
accurately without it. That is how a business selling in two currencies ends up
with revenue that is neither.
The two that hand your conversions to somebody else
4. Your unwanted referrals list is empty
A customer clicks your paid ad, browses, checks out, gets redirected to the payment provider, pays, and comes back. GA4 sees a visitor arriving from a domain that is not yours, starts a new session, and hands the sale to whoever sent them. That is the payment provider. Your ad campaign gets nothing.
The guides written for an American checkout name Stripe and PayPal, which is useful if yours looks like one. Here the layer that breaks it is Tabby, Tamara, PayTabs, Network International, Telr, and HyperPay. Wired as a hosted payment page, every one of them sends the shopper to its own domain and back. Some of them also offer an iframe or an embedded form, which does not, so the wiring is worth establishing before you start listing domains. The buy-now-pay-later options sit on the checkout button rather than behind it, which is exactly where the traffic you paid for is standing when the handoff happens.
The symptom is a referral channel that converts better than every campaign you paid for. If you have ever looked at that row and felt briefly pleased, this is the setting. Admin, data stream, configure tag settings, list unwanted referrals. You get 50 domains per stream, which is plenty. It will not repair the attribution history already written, so the sooner it goes in, the sooner your channel report starts describing reality.
Reconciling those numbers against what your ad platforms claim is a longer conversation, and it goes better once your own data stops crediting the wrong channel.
5. Cross-domain tracking is off
If your Arabic site runs on its own root domain instead of a subdomain of the English one, GA4’s cross-domain defaults were not written for it. Left alone, the platform counts one person crossing between the two halves of your own site as two users across two sessions. Park checkout on its own domain and it happens again. The second session arrives as a referral from yourself, or as direct traffic once the referrer is stripped, so your user count inflates, your session count inflates, and the journey between the halves goes missing.
Cross-domain tracking and the referral exclusion above are easy to mistake for each other, and they do opposite jobs. An exclusion tells GA4 to ignore a referrer so the original source survives the round trip, which is what you want for a payment provider you do not own. Cross-domain configuration passes the client ID between domains so the session itself continues, which is what you want for domains you do own. Use the exclusion on your own domains and you hide the self-referral without joining anything up: the second session arrives as direct, and it is still a second user.
The two that make your numbers look better than they are
6. Your internal traffic filter exists and does nothing
This one is close to a trap. GA4 pre-creates an internal traffic data filter on every new property, and it arrives in Testing state. A filter in Testing is evaluated and applied to nothing. It changes no data. It exists so you can verify it targets the right traffic before you commit.
It goes wrong like this: somebody opens Data Filters during setup, sees a filter sitting there named Internal Traffic, reasonably concludes internal traffic is handled, and closes the tab. A filter in Testing is a smoke detector with the battery still in the packet.
Two things have to be true. The filter needs an actual IP range defined in the data stream settings, because the pre-created one has no addresses in it, and it needs switching to Active. Confirm it is catching the right traffic using the Test data filter name dimension first, because an active filter is permanent in the only way that matters: what it excludes is never processed, and never turns up in Analytics or in BigQuery.
7. Enhanced measurement is on for everything it can measure
Seven automatic measurements switch on with every new data stream, and most of them earn their place. The trouble is how generously they fire.
The scroll event fires once, at 90% page depth. On a short page that is
meaningful. On a long landing page it means somebody reached the footer, which
is also what happens when a reader skims to the bottom looking for a phone
number. Outbound click tracking fires on any link leaving the current domain, and
the only links it spares are the ones on domains you have listed for cross-domain
measurement, which leaves everything an embedded widget or a social plugin points
at. Site search fires on any URL carrying q, s, search, query or keyword, the
five parameters GA4 watches before you nominate one of your own, whether or not a
human searched for anything.
A session counts as engaged on more than ten seconds, a key event or a second page view. A scroll, an outbound click or a site search meets none of those unless you have marked it a key event, so what these settings inflate is the event counts, and every rate built on top of them. Six of the seven measurements can be switched off and page views cannot, so go through the six, turn off the ones you do not report on, and keep the ones you can explain.
Two more that a dropdown will not settle
Reporting identity offers three answers, and Blended is the one that counts modelled users: it resolves a visitor through user ID, then device ID, then behavioural modelling for the ones neither reaches. Modelling only arrives on a property Google has judged eligible, which takes consent mode running on every page, a thousand denied events a day for at least a week, and a thousand consenting users a day across at least seven of the last twenty-eight. Where it does arrive, modelled users are a reasonable engineering answer to a consent-shaped hole in the data, and they are also being counted in a number you present as measured. Observed and Device-based drop the modelling and give you a smaller, harder figure. Which one is correct depends on what you are willing to defend in the meeting, and that is a decision somebody should make deliberately rather than inherit.
The second is vocabulary. In March 2024 Google renamed conversions to key events in GA4 and reserved the word conversion for a key event you import into Google Ads. The tracking did not change. What changed is that half your team learned one word and half learned the other, and they now compare numbers from two different products in the same sentence.
What to do this week
Do them in this order, because the first one is still costing you something while you read.
Data retention to 14 months, first, today. Then the time zone and the currency, which are both single settings that change how every number after them is counted. Then the referral exclusions and cross-domain configuration, which stop the attribution bleeding. Then the internal traffic filter and the enhanced measurement events, which are cleanup rather than emergency.
That is one sitting in the Admin panel, and the numbers you present next month will describe your business instead of somebody else’s. The next layer down is what fires and where it fires from, which lives in your tag manager container rather than the property, alongside the third-party scripts nobody has audited that came with it. A GA4 property you can trust takes in all three.
Our free Site Audit checks whether your tracking is on the page at all, and whether it is there twice. It cannot see any of the seven settings above, because they live behind the tag in a panel only you can open. That part is twenty minutes of your own time, and there is no higher-return use of it for anyone who has to answer questions about these numbers.
Standing offer
The hard part is deciding what to do first
Bring us a URL, an audit report, or a proposal you're not sure about. We'll tell you which problems deserve budget this quarter, and you'll leave with an order of operations you can hand to whoever does the work, whether that's us or not.
Book twenty minutes