How can I remove sync from a cloned ecommerce store?

This happened to my store. We aren’t sure how they did it. At first it appeared that they might’ve been serving up my website on their servers, which were on Cloudflare, Digital Ocean, AWS (Amazon web services), and Paknic (Pakistan). When I updated my website the copycat website updated in real time. They might’ve scraped the code but then there were the instant updates. They had my FB pixel firing from their domains, and my Hot Jar code. I caught them with my Hot Jar recordings. They had six different domain names and I was able to watch their traffic in my Hot Jar. They had a header covering my header on their site, and a fake checkout page. In some Hot Jar recordings there were little things I caught, like seeing my header, then theirs quickly covered it. I saw checkout errors, but then their fake checkout page covered it. They had the secured SSL lock on their domain. They changed my policy pages and footer contact info, etc., to their domain and fake name. They used recently expired domain names that had good standing with Google. I believe they used click farms, or bots, to drive traffic to their site to get their pages indexed. We saw a lot of foreign traffic in Hot Jar. We added code to my website that redirected their traffic back to my website and then we blocked all other countries from accessing my site. But that code didn’t work 100% of the time. I used a service to implement the blocking of known bots and IP addresses. This slowed them down for a little bit but not for long. I had a pending trademark, copyrights, and an intellectual property attorney. At that time the attacks were mostly coming from Cloudflare servers. Cloudflare ignored us, even the attorney demand letters didn’t help. Google also ignored our legal letters. I ran a malware scan on their domains with Quttera .com. They were loaded with malware. Be careful going on to the copycat sites! I had to buy a new computer after all of this mess. I reported the domains, with copies of the malware reports, to Norton, McAfee, and Google. Quttera flagged them as well. On a few of the Quttera reports I caught that the domains were coming from Columbia. Somehow, their Cloudflare glitched, and I was able to catch their exact location. Eventually, the domains were flagged as malicious. In the meantime, I hired a Cloudflare implementation expert, got a Cloudflare account, and we set up all of my firewall rules. I did this in the Spring and left the copycats with Christmas content. They finally all disappeared, but this may have been due to Google removing them, or they gave up because they could no longer update my content. I think Google owns Quttera and my malware reports might’ve gotten Google’s attention. Cloudflare helped too, but we still had 1000’s of bad bots a day accessing my site, including a few DOS attacks. Shopify is on Cloudflare, so that limits the protection I can get on my own. In order for my website to have the best protection, I needed an enterprise level Cloudflare account, to get the “Orange to Orange” switched on. I haven’t had any problems since, but Orange to Orange is for enterprise business, and it’s expensive. You can try a small business account to see if that works for you.