Skip to main content
GMC Guardian GMC Guardian
EN
CRITICAL

Your GMC Account Was Suspended for Personalized Advertising Policy

This is an account-level suspension - every product listing goes dark until you correct the privacy, consent, and data-collection infrastructure Google requires.

Estimated fix time
5-14 days
DSA channel
Eligible
Last reviewed
2026-04-29
  • #personalized-advertising
  • #consent-mode-v2
  • #privacy-policy
  • #account-suspension
  • #gdpr
  • #ccpa
  • #cookie-consent
  • #data-collection

A suspension for personalized advertising policy is one of the more disorienting outcomes a Shopify merchant can receive from Google Merchant Center, because the account goes dark immediately - free listings, Shopping ads, and Performance Max campaigns all stop serving - and the suspension notice provides no product-specific guidance. The problem is not your catalog. It is the privacy and consent infrastructure your store presents to visitors and to Google’s automated crawlers. That infrastructure has three components, and all three must be correct before Google will reinstate the account.

What Google means by “personalized advertising policy”

Google’s Personalized advertising policy governs any advertiser that runs interest-based or remarketing campaigns - which includes virtually every merchant using Google Shopping. The policy imposes three simultaneous requirements:

  • Your website’s privacy policy must explicitly disclose your use of interest-based advertising technologies and the categories of personal data involved.
  • You must not collect, share, or use personal data in ways that contradict your published privacy policy.
  • Where applicable, you must obtain and transmit user consent before Google’s personalization tags process personal data.

Google requires that your privacy policy clearly and comprehensively disclose how you collect, share, and use personal data - a standard that most unmodified Shopify default policies do not meet. A generic legal boilerplate that omits Google Ads, Google remarketing, or GA4 fails this standard outright. So does a correctly written policy if your actual tag behavior does not match its stated disclosures.

The disapproval is also triggered when Google’s crawlers detect that your storefront deploys Google tags - Ads conversion tracking, remarketing pixels, GA4 with signals enabled - without a functioning consent layer, making it technically impossible for visitors to withhold consent before their data is processed. Both conditions can exist simultaneously and both must be resolved.

Why it triggers a suspension on Shopify

Shopify stores are disproportionately exposed to this suspension for three structural reasons.

The default privacy policy template is under-specified. Shopify generates a privacy policy from a template when you first configure your store. That template covers Shopify’s own data processing but was not authored to satisfy Google’s advertising disclosure requirements. Merchants who add the Google & YouTube sales channel without revising their policy create an immediate gap: tags fire, personal data flows, and the published policy does not acknowledge any of it.

The Google & YouTube sales channel installs Google tags without a built-in consent layer. When you connect the Google & YouTube channel in Shopify admin, the Google tag (gtag.js) is injected into every storefront page. Unless Consent Mode v2 is configured separately through a CMP app, that tag fires personalization signals for every visitor unconditionally - regardless of their preferences and regardless of where they are located. On stores receiving any EU or UK traffic, this is a technical violation that Google’s crawlers can detect without a human reviewer.

Third-party apps expand the data footprint unpredictably. Review platforms, loyalty apps, live-chat widgets, and cart-abandonment tools frequently initialize their own tracking pixels or route data into Google audience lists indirectly via conversion imports. Each undisclosed data flow is a potential flag during review, even if the app itself is not Google’s product.

How to detect the issue on your store

Before submitting any fix, identify which of the three root causes applies. Appealing with an incomplete resolution is the primary reason merchants receive a second rejection.

Check 1 - Privacy policy coverage. Open your live privacy policy and search for the terms “Google”, “interest-based advertising”, “remarketing”, and “personalization”. If none appear, the policy text is the primary gap.

Check 2 - Tag behavior before consent. Open a private browser window with no prior cookies and navigate to your storefront. Open DevTools → Network tab → filter for googletagmanager.com or google-analytics.com. If those requests fire before you interact with any cookie banner, your tags are transmitting data without a consent gate.

Check 3 - Consent Mode v2 signal audit. Open Google Tag Assistant and run a session on your store. In the Tag Assistant panel, inspect the Consent column for your Google tags. If ad_storage and ad_personalization show Granted by default - before the user takes any action - Consent Mode v2 is either missing or misconfigured.

Check 4 - Third-party app inventory. In Shopify admin → Apps, list every installed app and cross-reference each one against your privacy policy. Any app that collects or transmits personal data but is not disclosed in the policy is a compliance gap that can independently cause a rejection.

Step-by-step fix

Work through these steps in order. Each one must be complete before you move to the next.

  1. Rewrite your privacy policy to name Google’s technologies explicitly. In Shopify → Settings → Policies, open the Privacy Policy field. Add a dedicated section - “Advertising and Remarketing” is a clear heading - that names each Google technology in use (Google Ads, Google remarketing, GA4 if applicable), describes what data each collects (device identifiers, browsing behavior, IP address, purchase history used for remarketing audiences), and links to Google’s Ads Settings page where users can manage interest-based ad preferences. Publish and confirm the updated policy is live at your store’s /policies/privacy-policy URL before proceeding.

  2. Install a certified Consent Management Platform from the Shopify App Store. Choose a CMP certified under the IAB Transparency and Consent Framework (TCF) 2.2. CookieYes, Cookiebot, and OneTrust are all compatible with Shopify and integrate with Google’s consent infrastructure. Install the app and complete its initial configuration wizard before touching any Google tag settings.

  3. Configure Consent Mode v2 with default-denied signals. Inside the CMP settings panel, enable “Google Consent Mode v2” or “Advanced Consent Mode”. Map the four required Google signals as follows: analytics_storage → Analytics category; ad_storage, ad_personalization, ad_user_data → Advertising category. Set the default state for all four signals to denied so that no personalization data flows until the user explicitly grants permission. This is the configuration Google’s crawlers verify.

  4. Confirm that the Google & YouTube sales channel respects your CMP. In Shopify admin, open the Google & YouTube channel and locate its Consent Mode status indicator. If it shows “Not configured” or “Inactive”, follow the channel’s in-app instructions to re-authorize it under your CMP’s consent framework. The channel and the CMP must operate together - parallel but disconnected implementations will produce incorrect signal behavior.

  5. Validate your implementation with Google Tag Assistant. Open a fresh private browser window, navigate to your store, and run a Tag Assistant session at tagassistant.google.com. Verify three states: (a) before any interaction, all four consent signals read Denied; (b) accepting analytics cookies only flips analytics_storage to Granted while ad signals remain Denied; (c) accepting all cookies flips all four to Granted. Export this session - it is your primary technical evidence for the appeal.

  6. Disclose or remove every undisclosed third-party tracking app. Return to your app inventory and update the privacy policy to name any tool not already covered. If an app’s data practices are unclear, contact the vendor for their data processing documentation. If you cannot obtain clear documentation, remove the app before filing the appeal.

  7. Align your cookie banner text with your policy categories. The categories visible in your banner (Analytics, Advertising, Functional) must map directly to the technologies named in your policy. A banner that references “Marketing cookies” while the policy does not mention remarketing is a discrepancy a human reviewer will flag.

What to include in your appeal

In Google Merchant Center, navigate to the suspension notice and click Request Review. Structure your submission as a factual checklist - not a narrative - because reviewers are working through a verification list, not reading a story.

  • Live URL of your updated privacy policy. Link to the actual published page, not a PDF or screenshot. The reviewer opens it directly to verify advertising disclosures are live and specific.
  • A Tag Assistant session export showing all four consent signals in their default-denied state and then in their granted state after explicit user interaction. This is the clearest technical proof that Consent Mode v2 is functioning as required.
  • A numbered change log with dates. For example: (1) Added “Advertising and Remarketing” section to privacy policy naming Google Ads and GA4 on 2026-04-22; (2) Installed CookieYes v4 and completed configuration on 2026-04-23; (3) Enabled Consent Mode v2 with default-denied signals for all four consent types on 2026-04-23; (4) Removed [App Name], which was sending undisclosed conversion events, on 2026-04-24.)
  • Screenshots of your Shopify Policies page with the updated text visible alongside a browser timestamp confirming the publication date.

Do not include descriptions of your business, appeals to urgency, or marketing language. These do not affect the reviewer’s decision and can signal that the submission does not address Google’s actual technical requirements.

Edge cases & when to escalate

EU and UK traffic. If your store receives any EU or UK visitors - even a small share from international organic search - GDPR and UK GDPR apply. In these cases, Consent Mode v2 is not optional. It is a contractual requirement under Google’s EU User Consent Policy, which is referenced within the personalized advertising policy itself. A fix that addresses the privacy policy text but not the consent signals is incomplete and will be rejected regardless of how well the policy is written.

Digital Services Act (DSA) overlay. Because DSA obligations apply to this suspension type, merchants selling to EU users via algorithmic advertising - remarketing, dynamic product ads, audience-based targeting - may also need to disclose this in their privacy policy under the DSA’s algorithmic transparency requirements. This does not block your Google Merchant Center appeal, but it is a parallel compliance obligation that should be addressed before re-enabling EU-targeted campaigns post-reinstatement. Omitting it now creates downstream exposure.

Second rejection after a technically complete fix. If your appeal is rejected and you are confident the implementation is correct, respond to the rejection notification requesting escalation to a human reviewer. Include your Tag Assistant export as an attachment and a written timeline of every change made. Google’s AI-adjudicated first-pass review occasionally fails to recognize Consent Mode v2 implementations that require user interaction to surface the consent state - a human reviewer can evaluate the dynamic behavior that an automated crawl cannot replicate.

Accounts with prior suspension history. If the account has been suspended for misrepresentation or unidentified-merchant violations within the past 12 months, the reviewer will apply heightened scrutiny to your appeal. The technical fix does not change, but consider engaging a Google-certified Partner agency for the appeal submission - a Partner account can sometimes surface the review to a named specialist rather than the standard automated queue, which matters when the account’s history triggers additional caution.

Stores in regulated categories. For healthcare, pharmaceutical, financial services, or insurance merchants, personalized advertising policy violations carry requirements that extend beyond standard privacy policy disclosures. These may include HIPAA-aligned data handling (US), specific consent mechanisms mandated by sector-specific regulation, or outright restrictions on certain remarketing audiences. A CMP and updated policy are necessary but not sufficient - legal review of your specific data architecture is warranted before re-enabling personalized campaigns after reinstatement.

Frequently asked questions

Frequently asked questions

Does this suspension affect all my products or just some?
This is an account-level disapproval, not a product-level one. Every product in your Merchant Center account is disapproved until the underlying policy issue is resolved and Google approves your appeal. Free listings, Shopping ads, and Performance Max campaigns all stop serving simultaneously. You will not be able to run any Google Shopping activity until reinstatement is confirmed.
I already have a privacy policy on my Shopify store. Why did Google flag me?
Shopify's default privacy policy template does not satisfy Google's personalized advertising requirements on its own. It may not explicitly name Google's advertising technologies, may not describe what personal data each collects, and may not reflect your actual data practices if you have added third-party apps since setup. Google requires that your policy specifically discloses your use of interest-based advertising and the personal data it involves - the default template omits this.
What is Consent Mode v2 and is it required for US-only stores?
Consent Mode v2 is Google's framework for letting tags adjust their behavior based on a user's consent choices. It is mandatory for any store serving EU or UK users under Google's EU User Consent Policy. For stores with exclusively US traffic, Google's requirements focus primarily on a compliant privacy policy and proper data-collection disclosures rather than the technical consent signal - but implementing Consent Mode v2 removes ambiguity during the review and is best practice regardless of geography.
How long does the appeal review take after I fix the issues?
Google's review for personalized advertising policy appeals is AI-adjudicated in the first pass. In cases where all deficiencies are clearly resolved and supporting evidence is provided, merchants typically see a decision within 5-14 business days of submitting. Accounts with prior violations, incomplete fixes, or vague appeal descriptions take longer and may require additional documentation before a human reviewer is assigned.
Can I implement Consent Mode v2 on Shopify without a developer?
Yes. Install a CMP app from the Shopify App Store that is certified under the IAB Transparency and Consent Framework (TCF) 2.2 - CookieYes, Cookiebot, and OneTrust are all compatible with Shopify and integrate directly with your Google tag. These apps inject a cookie banner and transmit the required consent signals automatically. After installing, use Google Tag Assistant at tagassistant.google.com to verify the signals are firing correctly before you submit your appeal.
What happens if my appeal is rejected a second time?
A second rejection moves the case toward human review, which takes longer but allows you to submit richer documentation. Use the cool-down window between attempts to gather additional evidence: a screen recording of your full consent flow, an exported Tag Assistant session, a timestamped screenshot of your published privacy policy, and a written log of every change made with dates. A specific, evidence-backed re-appeal is significantly more likely to succeed than a resubmission of the same materials.

Sources & references

Authoritative sources cited

  1. Google Ads policy: Personalized advertising https://support.google.com/adspolicy/answer/143465
  2. Google Consent Mode overview https://support.google.com/google-ads/answer/10000067
  3. Google EU User Consent Policy https://www.google.com/about/company/user-consent-policy/
  4. Google Tag Assistant https://tagassistant.google.com/

Get the appeal checklist for this suspension

The step-by-step remediation from this page, sent to your inbox so you can work through it while your cool-down runs. No account needed.

Or describe your case and get a human read on it