Full Answer
The problem is architectural. GA4 starts a new session whenever a user arrives from an external domain that is not on your referral exclusion list. PayPal, Stripe hosted checkout, Klarna, and any payment gateway that redirects off-site all trigger this behaviour. The customer clicked a Facebook ad, browsed your store, added to cart, chose PayPal, left your domain, paid, and came back. GA4 now attributes the purchase to paypal.com — not to the Facebook campaign that earned it. Your acquisition reports show PayPal as a top channel, and your actual paid campaigns appear to underperform.
Adding paypal.com (and any other payment redirect domain) to your GA4 referral exclusion list tells GA4 to ignore the return visit as a new referral source and continue the original session. Navigate to Admin, then Data Streams, select your stream, click Configure Tag Settings, then List Unwanted Referrals, and add paypal.com. The change applies from that point forward — it does not fix historical data, so reconciling past reports requires filtering PayPal from your source/medium breakdown manually.
This is one of several places where default browser-based tracking silently loses data. Server-side tracking avoids the redirect problem entirely because the conversion event is fired from your server before the customer ever leaves your domain — the attribution chain never breaks.