Skip to main content

Policy pages shoppers can’t open: what Google expects

Every policy page has to open for a first-time shopper, signed out, on any device, with no password, login or challenge page in the way. Google’s editorial rules name sites that ask for a username or password before showing the content requested, and a returns page behind a login is exactly that.

Critical4 min read

Why this matters

The “Editorial and professional requirements” cover this under “Usefulness”, in a heading that reads “Login is required or content is unnecessarily difficult or frustrating to navigate”. The examples include “sites that require a visitor to enter a username or password to check the content requested” and sites that “don’t load quickly on most popular browsers and devices, are under construction, not functioning”.

A policy only helps if it opens. Google’s fix page for a missing return policy asks you to “Confirm a return and refund policy is easily accessible by customers on your website.” The “Building trust with your customers” page says your website “should be fully functional, accessible for all customers, easy to navigate, and shouldn’t contain any unnecessary redirects or redirects to broken links.” For product pages, the landing page requirements go further and ask for the same page “regardless of the user’s device, user agent (including bots), browser, location, cookies, your ad targeting choices, or any other consideration.” Your policies deserve the same courtesy.

The usual culprits are not dramatic. A store still on its password page or a “coming soon” template. A returns page built inside the customer-account area. A firewall or country block that shows some visitors a challenge page instead of the policy. A policy that loads through a script and shows a spinner on a slow phone. A page address that redirects to the home page after a migration. Each one leaves the link in your menu and the page unreadable in practice, and none of them shows up in your own signed-in browser. Product Experts on Google’s Merchant Center Community advise checking every policy on several browsers and devices for exactly this reason.

The free scan opens your store and its policy pages the way a first-time visitor does, signed out and with no cookies. It reports a store behind a password or coming-soon page as a failure, and tells you when a returns, shipping or privacy page could not be opened, so you know which one to test by hand. Every access and policy check is on the misrepresentation checker; dead links have their own guide, broken links and 404s.

Typical evidence

Existing and being readable are two different tests

A policy page hidden behind a login, a redirect or a spinner that never stops is not useful to a shopper. Test that it returns, renders and shows readable words without extra clicks.

Members-only302 → /loginPage wants an account before it shows a word
Infinite spinnerloads foreverFirst visit hangs and never settles
Instant redirect200 → bounceResolves, then immediately throws you to login
The checkEach policy page opens in a clean browser without a login wall or a blocked reading path. Test the real routes after theme and consent changes.

The public signals this check looks for:

  1. The store is still behind the platform’s password page, or shows a “coming soon” template …

    The store is still behind the platform’s password page, or shows a “coming soon” template to visitors.

  2. The returns or shipping policy lives inside the customer account area and asks the shopper…

    The returns or shipping policy lives inside the customer account area and asks the shopper to sign in.

  3. A bot-protection, firewall or country-block setting shows some visitors a challenge or “ac…

    A bot-protection, firewall or country-block setting shows some visitors a challenge or “access denied” page instead of the policy.

  4. The policy loads through a script and shows a spinner or a blank box on a slow phone conne…

    The policy loads through a script and shows a spinner or a blank box on a slow phone connection.

  5. The policy address redirects to the home page, or the policy exists only as a PDF download…

    The policy address redirects to the home page, or the policy exists only as a PDF download.

What it looks like once it is right

Returns, shipping, terms, privacy and contact each have a public address, open signed out on a phone in every country the store sells to, and show the full text as soon as the page loads.

Common mistakes

Common mistake

“Please sign in to view our returns policy.” The returns link in the footer opens the account login page, and first-time visitors from outside the UK see a firewall challenge instead of the shipping page.

Fix checklist

What “accessible” looks like in numbers

A first-time visitor should get all four of these. Test the pages directly and treat any gap as work to fix, not as a prediction of account status.

HTTP status200 OK
Redirectnone
Login requiredno
Readable in1.2s

Questions merchants ask

Can my returns policy be behind a customer login?

Not if you want shoppers to read it. Google’s Editorial and professional requirements name sites that require a visitor to enter a username or password to check the content requested. Publish returns, shipping and your other policies as public pages that open without signing in, and link them from the footer.

Is a PDF policy good enough for Merchant Center?

Google’s return-policy fix page asks for a policy that is easily accessible, and the editorial requirements list landing pages that lead to a file among those that are difficult to navigate. An ordinary web page is the safer choice: it opens on any phone and reads like the rest of the site.

My store is still in password mode. Can I submit it to Merchant Center?

Take the password off first. A page that asks for a password is on Google’s list of content that is difficult to reach, and StoreVerifier’s free scan reports a store behind a password or coming-soon page as a failure. See making policy and contact information easy to reach once the store is open.

Remediation

Risk signal

A locked or broken policy page looks perfectly fine from inside your own signed-in browser, which is why it can survive for months. Test like a stranger: signed out, private window, a phone on mobile data, and a country you sell to but do not live in.
PriorityTreat this and any other highest-severity findings as first-priority work, then document each fix.
EvidenceRecord the current state before each change, apply the fix, then capture the corrected state so every change is evidenced.

Similar cases

Sources

  1. Editorial & professional requirementsGoogle Merchant Center Help — support.google.com
  2. Building trust with your customersGoogle Merchant Center Help — support.google.com
  3. How to fix: Missing return and refund policy on your online storeGoogle Merchant Center Help — support.google.com

Community guidance

Written by Product Experts, the users Google recognises for their answers on its Merchant Center Community forum. Often stricter than Google’s help pages, and not Google policy.

  1. How to fix your Merchant Center suspension (Misrepresentation), 2026Merchant Center Community · Product Expert guide — support.google.com

Last reviewed 23 Sep 2026.

That is one issue. The library documents 134.

The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.