Skip to main content

Privacy policy for a Merchant Center store: what Google asks

Google’s Merchant Center pages ask for a privacy policy that is detailed and easy to find, and for customer data handled securely. Write it about what your store actually collects and who receives it, link it from every page, and fill in every template field. Nobody enjoys this page; do it once, properly.

Major4 min read

Why this matters

Google's “Building trust with your customers” page asks you to “provide detailed information about your policies including shipping, returns and privacy policies.” Its “Follow Merchant Center guidelines” page has a section headed “Collect user information responsibly and securely”: collect personal information such as card numbers “securely on an SSL-protected page”, “Don't sell your users' contact info”, and don't use people's personal information or images in ads without their consent.

The Shopping ads policy on “Irresponsible data collection & use” says Google wants users to trust that information about them “will be respected and handled with appropriate care”. It names two failures: collecting personal details “over an unsecured page which is not SSL protected”, and “Using personal information in ways users have not consented to”, such as re-selling contact details. A privacy policy is where you tell shoppers you do neither, and it only helps if it is true.

Product Experts on Google's Merchant Center Community list the privacy policy with terms, payment, shipping, delivery and returns among the policies every store needs, and add that each one “must accurately describe how the business actually operates”. What local law adds is for your adviser; this guide covers what Google asks for.

The free scan flags a privacy policy that is missing, empty, a placeholder, too thin, or behind a broken link, so you find out before a shopper does. Template privacy text is the usual culprit; placeholder text in store policies shows how to find it. See every policy check on the misrepresentation checker.

Typical evidence

A privacy notice that’s still wearing its template

Publish an accurate notice where customers can find it, using the placement and content required for your markets. A particular footer layout is not a universal Merchant Center rule.

Privacy PolicyTemplate — unfinished
“This policy explains how [INSERT COMPANY NAME] collects your data. For questions, contact us at [EMAIL]. Last updated [DATE].”
What data
is collected — state it specifically, not in boilerplate.
Why
it’s collected — state it specifically, not in boilerplate.
How
it’s used — state it specifically, not in boilerplate.
UnfinishedBrackets left in a live policy look unfinished and can mislead shoppers. Replace every placeholder before publishing.

The public signals this check looks for:

  1. There is no privacy policy page, or it exists and nothing on the store links to it

    There is no privacy policy page, or it exists and nothing on the store links to it.

  2. The page is a template with “[INSERT COMPANY NAME]” and “[DATE]” still in it

    The page is a template with “[INSERT COMPANY NAME]” and “[DATE]” still in it.

  3. It describes a newsletter, an app or a loyalty scheme you do not run, and says nothing abo…

    It describes a newsletter, an app or a loyalty scheme you do not run, and says nothing about the payment, email and analytics tools you do use.

  4. The privacy link in the footer returns a 404 after a theme change or a new page address

    The privacy link in the footer returns a 404 after a theme change or a new page address.

  5. A checkout, contact or newsletter form asks for personal details on a page that does not l…

    A checkout, contact or newsletter form asks for personal details on a page that does not load over HTTPS.

  6. A popup or cookie banner sits over the privacy page, so it cannot be read without acceptin…

    A popup or cookie banner sits over the privacy page, so it cannot be read without accepting something first.

What it looks like once it is right

The privacy policy names Acme Goods Ltd, lists the platform, payment provider, email tool and analytics the store uses, says customer details are never sold, gives support@acme.co.uk for questions, and is dated. Every form on the store loads over HTTPS.

Common mistakes

Common mistake

The footer links to “Privacy”, which opens a page reading “This Privacy Policy describes how [Store Name] collects your information” and describes a mobile app the store has never had. The newsletter form on the homepage posts to an http:// address.

Fix checklist

The same page, actually filled in

Specific answers in your own words — the opposite of a bracketed template.

What dataName, address, email and card details at checkout; analytics on browsing.
WhyTo fulfil orders, prevent fraud, and (with consent) send marketing.
How usedStored with our processor; never sold; deleted on request.

Questions merchants ask

Does Google Merchant Center require a privacy policy?

Google's “Building trust with your customers” page asks for detailed information about your policies, naming shipping, returns and privacy, and Product Experts list a privacy policy among the pages every store needs. StoreVerifier's free scan reports a missing privacy policy as a failure. Treat it as required.

What should a privacy policy say for Merchant Center?

What your store collects, why, who receives it, how long you keep it and how customers contact you about it, written for the tools you actually use. Google's guidelines add two things the policy should reflect: personal information is collected only on SSL-protected pages, and customer contact details are not sold.

Can I use a privacy policy generator?

Yes, if you finish the job. Fill every field, remove sections about tools and services you do not use, and add the ones you do. A generated policy that describes a mobile app you never built is a copied policy with extra steps. For what your local law requires, ask a qualified adviser rather than relying on the generator's defaults.

Remediation

Risk signal

A privacy policy is only as good as the data handling behind it. A generic page describing somebody else's tools, next to a form that sends details over plain HTTP, fails twice. Write the policy from your own tools, and fix the forms first.
PriorityAddress and document this finding as part of the store’s remediation work.
EvidenceRecord the current state before each change, apply the fix, then capture the corrected state so every change is evidenced.

Similar cases

Sources

  1. Building trust with your customersGoogle Merchant Center Help — support.google.com
  2. Follow Merchant Center guidelines to keep your account approvedGoogle Merchant Center Help — support.google.com
  3. Irresponsible data collection & use (Shopping ads policy)Google Merchant Center Help — support.google.com

Community guidance

Written by Product Experts, the users Google recognises for their answers on its Merchant Center Community forum. Often stricter than Google’s help pages, and not Google policy.

  1. How to fix your Merchant Center suspension (Misrepresentation), 2026Merchant Center Community · Product Expert guide — support.google.com

Last reviewed 23 Sep 2026.

That is one issue. The library documents 134.

The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.