SSL and HTTPS for Merchant Center: what has to be secure
Google’s checkout requirements say you must secure your checkout with a valid SSL certificate, covering payments and every piece of personal data. Put the whole store on HTTPS, make one certificate cover every hostname you use, and check for pages that still load parts over plain HTTP. Most stores have a certificate; the trouble is the one that quietly expired or only covers www.
What does Google Merchant Center require for SSL and HTTPS?
HTTPS with a valid certificate, at least on checkout, and in practice everywhere. Google’s “Checkout requirements and best practices” page says “you must secure your checkout with a valid SSL certificate” and must protect payments, transactions and all personally identifiable information, such as name, email, physical address and payment details. Third-party payment options must be HTTPS-secure too, and must not ask for personal data the payment doesn’t need. The Shopping ads policy on irresponsible data collection gives, as its example of unsafe collection, taking names, addresses, phone numbers or card numbers over a page that is not SSL protected. Most stores have a certificate. The trouble is the one that quietly expired. Check four things: it hasn’t expired and renews automatically; it covers every hostname you use, bare domain and www included; every http:// address redirects permanently to https://; and no HTTPS page pulls images or scripts over plain HTTP, which browsers treat as not fully secure. Use https:// in the product links you send to Merchant Center as well.
Why this matters
Google's “Checkout requirements and best practices” page puts it as a requirement: “To protect your customers, you must secure your checkout with a valid SSL certificate. Specifically, you must protect payments, transactions, and all personally identifiable information (such as name, email, physical address, and payment details).” It adds that third-party payment options must be “HTTPS-secure” and must not ask for personal information the payment does not need.
The Shopping ads policy on irresponsible data collection gives the other half. Its example of unsafe collection is taking names, addresses, phone numbers or card numbers “over an unsecured page which is not SSL protected and without a valid certificate”. And “Building trust with your customers” asks you to “Install an SSL certificate so customers know that their sensitive data is retrieved and stored securely”, and to “Ensure a secure checkout process.”
In practice the failure is rarely a store with no certificate at all. It is a certificate that expired when automatic renewal quietly stopped, one that covers www but not the bare domain, a checkout step or payment page on another domain, or mixed content: a page served over HTTPS that still pulls an image or script over plain HTTP, which browsers treat as not fully secure.
The free scan flags a certificate the browser cannot verify, a checkout page not served over HTTPS, and HTTPS pages that load images or scripts over plain HTTP, in one pass. Certificates lapse quietly; SSL expiry covers renewals. See every checkout check on the misrepresentation checker.
Typical evidence
The padlock is the floor, and half a store can fail it
A normal browser can check whether the certificate is trusted, in date and names the hostname being served. A certificate for one hostname but not another throws a security warning on every affected page.
The public signals this check looks for:
The certificate expired because automatic renewal stopped working and nobody noticed
The certificate expired because automatic renewal stopped working and nobody noticed.
The certificate covers www…
The certificate covers www.yourstore.com but not yourstore.com, or the other way round, so one address shows a browser warning.
A checkout or payment step runs on another domain that is not on HTTPS, or asks for more p…
A checkout or payment step runs on another domain that is not on HTTPS, or asks for more personal data than the payment needs.
A product page on HTTPS loads an image, script or font from an http
A product page on HTTPS loads an image, script or font from an http:// address.
Old http
Old http:// links in emails, ads or bookmarks land on pages that do not redirect to HTTPS.
What it looks like once it is right
One certificate covers acme.co.uk and www.acme.co.uk and renews automatically. The bare domain redirects to www with a 301, every checkout step and form is on HTTPS, and the browser console shows no mixed content.
Common mistakes
Common mistake
Fix checklist
The report that shows what a browser can verify
SSL Labs shows the expiry date, hostnames the certificate covers, protocol versions and whether the chain is complete in one grade. Aim for an A.
Questions merchants ask
Does Google Merchant Center require an SSL certificate?
For checkout, yes. Google's checkout requirements say you must secure your checkout with a valid SSL certificate and protect payments, transactions and all personally identifiable information. Its “Building trust with your customers” page also asks you to install an SSL certificate. In practice, put the whole store on HTTPS.
What happens if my SSL certificate expires?
Browsers show a security warning in place of your page, so shoppers cannot reach the store without clicking through it, and your checkout no longer meets Google's requirement for a valid certificate. Renew it, check the new expiry date, and re-test every checkout step and form.
Does mixed content matter on an HTTPS store?
Yes. Browsers treat a page that loads parts of itself over plain HTTP as not fully secure and may block those parts. Open the browser console on a product page, find anything requested over http://, and switch it to https:// or remove it. The free scan reports HTTPS pages that load content over plain HTTP.
Remediation
Risk signal
Similar cases
Sources
Last reviewed 23 Sep 2026.
That is one issue. The library documents 134.
The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.