How to Create a GMC-Compliant Privacy Policy on Shopify

Google Merchant Center requires every store to have a comprehensive privacy policy that explains how customer data is collected, used, and protected. Shopify stores use multiple third-party services (payment processors, analytics, marketing pixels) that must all be disclosed in your privacy policy.

Why This Happens

Your GMC application was rejected because your privacy policy is missing, too generic, or does not cover required topics

You used Shopify's auto-generated privacy policy without customizing it for the apps and services your store actually uses

Your privacy policy does not mention cookies, tracking pixels, or third-party data sharing — all required by Google and privacy regulations

What Google Requires

A dedicated privacy policy page linked in the footer navigation, accessible from every page of your store

Clear disclosure of what personal data you collect (name, email, address, payment info, browsing behavior)

Explanation of how collected data is used (order fulfillment, marketing, analytics, customer service)

List of third-party services that receive customer data (Shopify, payment processors, shipping carriers, analytics tools, marketing platforms)

Instructions for how customers can request data access, correction, or deletion (required by GDPR, CCPA, and other privacy laws)

Common Mistakes

Using Shopify's auto-generated privacy policy template at Settings > Policies without adding your specific apps, analytics tools, and marketing services

Not mentioning Google Analytics, Facebook Pixel, Klaviyo, or other tracking tools installed on your store

Missing a cookie consent banner — while not strictly a GMC requirement, its absence triggers privacy concerns during manual reviews

Referencing a different company name or website URL in the privacy policy (copied from a template or another store)

How to Fix This

1

In Shopify Admin, go to Settings > Policies > Privacy policy and review the auto-generated template — it is a starting point, not a finished policy

2

Customize the template: replace all placeholder text with your actual business name, domain, and contact email for privacy inquiries

3

Add a section listing every third-party service that processes customer data: payment processors (Stripe, PayPal), analytics (Google Analytics), marketing (Klaviyo, Meta Pixel), and shipping (carrier APIs)

4

Add a cookies section explaining what cookies your store sets (Shopify session cookies, analytics cookies, marketing cookies) and how visitors can manage them

5

Include a data rights section: explain how customers can request access to their data, request corrections, or request deletion — provide a contact email for these requests

6

Add the privacy policy to your footer menu: Online Store > Navigation > Footer menu > Add menu item

7

Consider installing a cookie consent app from the Shopify App Store (like Pandectes or Consentmo) to display a compliant cookie banner

Frequently Asked Questions

Is Shopify's auto-generated privacy policy sufficient for GMC?+

No. Shopify's template is a starting point but needs significant customization. You must add your business name, list all third-party services you use (analytics, marketing, payment), describe your cookie practices, and include data rights information. Generic templates are a common reason for GMC rejection.

Do I need a cookie consent banner for GMC approval?+

Google does not explicitly require a cookie consent banner for GMC approval, but it is required by GDPR (for EU visitors) and recommended as a best practice. During manual reviews, the absence of a cookie banner can raise concerns. Install a Shopify cookie consent app as a preventive measure.

How do I know which third-party services to list in my privacy policy?+

Check your Shopify admin: go to Settings > Apps and sales channels to see installed apps. Also check Online Store > Themes > Edit code > theme.liquid for any tracking scripts (Google Analytics, Meta Pixel, etc.). Each service that collects or processes customer data must be mentioned in your privacy policy.

Check your store now

Free compliance scan — 47 rules checked in minutes.

Run compliance check