Google Ads Customer Match Best Practices

This page is updated every two months with current best practices for Google Ads Customer Match. Your own customer data is one of the strongest signals you can give Google, but match rates, policy compliance and consent decide how much of it you can actually use. Each update draws on our own experience plus authoritative industry sources and verified real-time research. Bookmark this page and check back for the latest Customer Match best practices. Each update includes worked examples with the arithmetic shown.

Last updated: 6 August 2026

In This Guide

  1. Executive Summary
  2. Benchmarks & Numbers at a Glance
  3. What Customer Match Is
  4. Eligibility & Policy
  5. Data Sources & Lists
  6. Uploading & Automation
  7. Improving Match Rates
  8. Targeting vs Observation
  9. Across Campaign Types
  10. Privacy & Consent
  11. Common Mistakes to Avoid
  12. What Changed Recently
  13. References

Reading this to build your own campaign? Skip the learning curve — we’ll build the whole thing for you for $129, delivered within 24 hours as a spreadsheet you own. See how it works →

1. Executive Summary

Google Ads Customer Match remains the most precise first-party targeting tool available to Australian advertisers in 2026. Five principles define best practice at this level of sophistication.

  • Consent before upload, always. You may only upload data collected in a first-party context where the customer shared their information directly with your organisation. Consent must be explicit, documented, and auditable before any record reaches Google Ads.[11]
  • More identifiers, better matching. Upload every permitted identifier—email address, phone number, and physical address—for the same person in the same row. Google’s matching process combines these signals to improve both match rate and list size.[1]
  • Freshness determines eligibility. A Customer Match list must have at least 100 members added or updated within the last 540 days to remain eligible. Lists that go stale lose their serving eligibility and their value as Smart Bidding signals.[11]
  • Use lists as signals, not just gates. The highest-leverage use of Customer Match in 2026 is as a quality signal fed into Smart Bidding and optimised targeting, not simply as a hard audience restriction. This applies across Search, Performance Max, Demand Gen, and YouTube.[1]
  • Targeting eligibility is tiered. All policy-compliant advertisers can use Customer Match for Observation and Exclusions. Targeting—restricting delivery to matched audiences—requires 90 days of Google Ads history and more than USD $50,000 in lifetime spend.[11]

2. Benchmarks and Numbers at a Glance

Metric Typical range or threshold Applies when Source
Customer Match match rate 29%–62% of uploaded records Vendor claim; Google Ads Help states this as the range for most advertisers [1]
Minimum matched members to serve on Search, YouTube, and Display 1,000 matched members Required before a list can be used for targeting or observation on these surfaces [6]
Recommended upload volume for reliable matching At least 5,000 uploaded records Google Ads API guidance; ensures enough matched, active users remain after attrition [8]
Minimum records for match-rate reporting via Google Ads API 100 rows matched to unique users Vendor claim; Google Ads API help; below this threshold, match rate is not displayed [3]
Maximum Customer Match list membership duration 540 days Applies to all Customer Match lists; memberships older than 540 days are automatically removed [11]
Minimum active members to maintain list eligibility 100 members added or updated within the last 540 days Applies to all Customer Match lists; lists below this threshold become ineligible [11]
Targeting eligibility: minimum account history 90 days of Google Ads history Required in addition to spend threshold to unlock Targeting (as distinct from Observation and Exclusions) [11]
Targeting eligibility: minimum lifetime spend More than USD $50,000 lifetime spend Required in addition to 90-day history; vendor claim per Google policy page [11]
Reachable share of a list 1%–99% of matched records Vendor claim; Google Ads API docs; varies based on how active matched users are on Search, Gmail, and YouTube [13]
Maximum identifiers per OfflineUserDataJob request Up to 100,000 identifiers per request Google Ads API operational guidance; larger batches reduce RESOURCE_EXHAUSTED errors [8]
Recommended minimum practical upload for useful audience volume At least 2,000 uploaded users Practitioner heuristic; lists near the 1,000-member threshold may fall below serving minimums after natural attrition [2]
API access restriction for inactive developer tokens Tokens with zero Customer Match API requests between 1 Oct 2025 and 31 Mar 2026 are blocked from 1 Apr 2026 Applies to OfflineUserDataJobService and UserDataService; affected tokens receive CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE errors [3]

3. What Customer Match Is and Why It Matters

Customer Match is Google’s mechanism for using your organisation’s first-party CRM data—email addresses, phone numbers, and physical addresses—to find and target your existing customers across Google’s signed-in ecosystem: Search, YouTube, Gmail, Display, Demand Gen, and Performance Max.[11]

The practical value is precision. Rather than targeting based on inferred interest signals or third-party cookie pools that are increasingly restricted, Customer Match anchors your audience to people who have already raised their hand with your business. This makes it useful for three distinct commercial purposes: re-engaging known customers, suppressing them from acquisition campaigns, and providing a high-quality seed signal so Google’s AI can find more people who behave like your best customers.[1]

In 2026, the broader significance of Customer Match has grown as third-party cookie deprecation, privacy regulation, and Apple’s App Tracking Transparency have eroded the reach and reliability of inferred audiences. Advertisers with large, well-maintained CRM databases now hold a structural advantage: their Customer Match lists produce signals that competitors relying on interest-based or contextual audiences simply cannot replicate.[1][11]

Customer Match data is processed by Google using SHA-256 hashing—either applied by Google or by you before upload—so that raw personally identifiable information is never stored in the Google Ads system in plain text.[14] The matching itself happens against Google’s signed-in user base, which is why match rates vary: a user who signed in to Gmail with a different email address from the one in your CRM will not be matched regardless of how clean your data is.[1]

Worked example

Quantifying the value of Customer Match for a subscription retailer

  • Setup: An Australian e-commerce subscription retailer spending $18,000 per month on Google Ads has a CRM of 45,000 consented contacts. The account has been running for 14 months and has exceeded USD $50,000 in lifetime spend.
  • Numbers: Uploading all 45,000 records with email, phone, and postal address. At the midpoint of Google’s published 29%–62% match-rate range[1], a 45% match rate produces approximately 20,250 matched members—well above the 1,000-member serving threshold[6] and the 5,000-record API recommendation.[8] Even at the floor of 29%, 45,000 × 0.29 = 13,050 matched members, still comfortably above threshold.
  • Decision: Proceed with full CRM upload using email + phone + postal address in a single row per contact, targeting mode enabled, with a separate exclusion list for active subscribers applied to all acquisition campaigns.
  • Why: At any point in the published 29%–62% match-rate range, the matched list exceeds 1,000 members, satisfying the serving threshold on Search, YouTube, and Display.[6]

4. Eligibility and Policy Requirements

Access to Customer Match is not universal—it is granted in tiers based on account standing and spend history, and it can be revoked for policy violations.[11]

Account standing

Your account must have a good history of policy compliance. Google does not publish a precise definition of “good standing” in numerical terms, but in practice this means no active policy suspensions, no history of serving prohibited content, and compliance with Google’s personalised ads policies. An account that has had enforcement actions may find Customer Match unavailable even if it meets the spend threshold.[11]

Tiered access levels

Access level Requirements What is unlocked
Standard (all compliant advertisers) Policy-compliant account in good standing Observation, Exclusions
Full access (eligible advertisers) 90+ days of Google Ads history AND more than USD $50,000 lifetime spend Targeting, Observation, manual bid adjustments, Exclusions

Both conditions—the 90-day history and the USD $50,000 spend—must be met simultaneously to unlock Targeting. An account that has spent $60,000 AUD but has only been active for 60 days does not qualify. Note that the $50,000 threshold is denominated in USD regardless of your billing currency.[11]

Data collection requirements

You may only upload customer information that was collected in a first-party context: your website, your app, your physical store, or another direct interaction where the customer gave you their information.[11] Purchasing third-party contact lists and uploading them to Customer Match is a policy violation. The consent requirement is separate from—and additional to—the first-party collection requirement; see Section 10 for the full privacy and consent framework.

List-level eligibility

A Customer Match list must maintain at least 100 members added or updated within the last 540 days to remain eligible.[11] Lists that drop below this threshold become inactive. Memberships that are older than 540 days are automatically removed from the list.[11]

Worked example

Checking Targeting eligibility for a new account before campaign launch

  • Setup: A Melbourne B2B software business opened a Google Ads account on 1 March 2026 and has spent AUD $85,000 (approximately USD $55,000 at a 0.65 AUD/USD rate) by 1 August 2026—153 days of account history.
  • Numbers: History check: 153 days ≥ 90 days. ✓ Spend check: USD $55,000 > USD $50,000. ✓ Both thresholds are met.[11] The account can use Targeting, Observation, manual bid adjustments, and Exclusions with Customer Match.
  • Decision: Enable Targeting mode on the Customer Match audience within the Search campaign for the high-value enterprise segment, set a +30% Smart Bidding signal adjustment for matched members.
  • Why: Both the 90-day history requirement and the USD $50,000 lifetime spend requirement are satisfied simultaneously, unlocking full Customer Match Targeting access.[11]

5. Data Sources and List Building

The quality of a Customer Match list is determined upstream—by which data you collect, how you segment it, and what business logic governs which contacts belong in which list. Getting this right before you touch Google Ads saves significant remediation time later.[1]

Permitted identifiers

Google’s API documentation specifies three categories of contact information that can be uploaded via the CONTACT_INFO key type: email addresses, mailing addresses (including first name, last name, postal code, and country), and phone numbers.[8] You should upload all identifiers you hold for each customer, not just email. Google’s best-practices guidance explicitly states that supplying multiple identifiers in the same row improves both match accuracy and list size.[1]

Segmentation strategy

Building a single monolithic Customer Match list for all contacts is a common missed opportunity. Effective list architecture separates contacts by commercial purpose so that targeting, observation, and exclusion logic can be applied independently.[6]

  • Active customers (purchased or subscribed in the last 12 months): use for upsell targeting and exclusion from new-customer acquisition campaigns.
  • High-value customers (top 20% by lifetime value): use as the seed for optimised targeting signals; apply the most aggressive bid adjustments.
  • Lapsed customers (no purchase in 13–36 months): use for re-engagement campaigns with tailored messaging.
  • Leads not yet converted (in CRM pipeline but not yet a customer): use for lower-funnel nurture targeting.
  • Opted-out or unsubscribed contacts: exclude from all lists before upload; never upload these to Google Ads.[11]

CRM as the system of record

Your CRM should be the authoritative source for both segmentation and consent status. Build your export query so that only records where marketing_consent = TRUE and consent_date IS NOT NULL are included.[4] Apply the consent filter before any other segmentation logic so that consented status is never assumed from list membership alone.

Worked example

Building a high-value seed list for a national furniture retailer

  • Setup: A national Australian furniture retailer has 120,000 total CRM contacts. Of these, 95,000 have explicit marketing consent. Within the consented pool, 22,000 have made a purchase in the last 18 months, and 4,400 (the top 20% by revenue) account for 62% of total customer revenue.
  • Numbers: High-value segment: 4,400 consented records. At a 29% match rate (floor of Google’s benchmark[1]): 4,400 × 0.29 = 1,276 matched members—above the 1,000-member serving threshold.[6] At a 45% midpoint match rate: 4,400 × 0.45 = 1,980 matched members. The list is marginal at the low end; uploading all 22,000 active customers is safer for volume. 22,000 × 0.29 = 6,380 matched—above the 5,000-record API recommendation.[8]
  • Decision: Create two lists: List A = 22,000 active customers (for exclusion from prospecting); List B = 4,400 high-value customers (for bid signal and optimised targeting seed). Both include email + phone + postal address in each row. Refresh both lists weekly via CRM export.
  • Why: The 4,400-record high-value list produces fewer than 2,000 matched members at midpoint, making the 22,000-record active list a safer primary vehicle while the smaller list serves as a targeted signal layer.[2]

6. Uploading, Hashing and Automation

The upload process has two paths: the Google Ads UI for manual or one-off uploads, and the Google Ads API OfflineUserDataJob for production-scale automated pipelines. In 2026, a third option—the Data Manager API—has become relevant for teams whose developer tokens were inactive between October 2025 and March 2026.[3]

Hashing requirements

Google hashes the following fields using SHA-256 before matching, and you must do the same if you pre-hash the data yourself: email address, phone number, first name, and last name.[14] Country and postal/zip code are not hashed—they are uploaded in plain text.[14] If you let Google Ads hash the data on your behalf (available through the UI), Google applies the same SHA-256 algorithm. Either path is compliant; the key rule is consistency within a single upload.

Formatting before hashing

Normalise all fields to lowercase and remove leading or trailing whitespace before applying SHA-256. Phone numbers should be in E.164 format (e.g., +61412345678). Email addresses should be lowercase with no extra spaces. Inconsistent formatting is the most common cause of avoidable match-rate degradation.[1]

API upload workflow

Google’s recommended pattern for bulk uploads is the OfflineUserDataJob API.[9] Key operational rules from Google’s API documentation include:

  • Only one account should modify a given Customer Match list; do not attempt updates from multiple accounts.[9]
  • Maximise the number of operations per request—up to 100,000 identifiers—to reduce RESOURCE_EXHAUSTED errors.[8]
  • Use daily API appends for production lists rather than full weekly replacements where possible, to reduce processing overhead and keep lists fresher.[1]

Data Manager API migration

From 1 April 2026, developer tokens with no Customer Match API requests recorded between 1 October 2025 and 31 March 2026 are blocked from OfflineUserDataJobService and UserDataService. Affected requests return the error CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE. Google directs these accounts to the Data Manager API.[3] If your automated pipeline was inactive during that window, audit your token status before assuming uploads are succeeding.

Worked example

Setting up a daily automated upload via OfflineUserDataJob for a fitness platform

  • Setup: An Australian online fitness platform with 38,000 active subscribers runs a daily CRM export at 02:00 AEST. The list is maintained in a single Google Ads account under a manager (MCC) account. The developer token has had active Customer Match API calls since February 2026, so it is not affected by the April 2026 restriction.[3]
  • Numbers: 38,000 records. At 100,000 identifiers per request maximum[8], and with each record containing 3 identifiers (email + phone + postal), 38,000 × 3 = 114,000 identifier values. This requires 2 API requests: one of 100,000 and one of 14,000. SHA-256 is applied to email, phone, first name, and last name pre-upload; country (AU) and postal code sent in plain text.[14]
  • Decision: Configure the pipeline to run a daily APPEND job via OfflineUserDataJob from a single designated account (not all sub-accounts under the MCC), batched into 2 requests per run. Validate match-rate reporting after 100 rows match to unique users.[3]
  • Why: Google explicitly states that one account must own all modifications to a list, and that batching up to 100,000 identifiers per request minimises RESOURCE_EXHAUSTED errors.[8][9]

7. Improving Match Rates and Data Hygiene

Google’s published match-rate range for Customer Match is 29%–62%.[1] The gap between those two numbers—at 10,000 uploaded records, the difference between 2,900 and 6,200 matched users—is almost entirely explained by data quality decisions made before the upload reaches Google. This section is about closing that gap.

The three drivers of match rate

  • Identifier completeness: Uploading email alone produces a lower match rate than uploading email + phone + physical address in the same row. Google’s matching process can use any combination of identifiers to find a match, so the more you supply, the more chances it has.[1]
  • Formatting consistency: A Gmail address uploaded as [email protected] will not match the same account hashed as [email protected] if Google normalises differently from your process. Standardise to lowercase, trim whitespace, and validate email syntax before hashing.[1]
  • List freshness: Customers who have lapsed, changed their email address, or deleted their Google account since you collected their data will not match. Stale lists produce lower match rates and also reduce the quality of the signal Google uses for Smart Bidding.[1]

Diagnosing a low match rate

Google recommends treating match rate as a data-quality diagnostic rather than a performance metric in isolation.[1] If match rate is below 29%, the first step is to audit the source data: check for formatting errors in the email field, confirm phone numbers are in E.164 format, and verify that the hashing sequence (normalise, then hash) was applied correctly. Do not assume a low match rate means your customers are not on Google—it almost always means a data or formatting problem upstream.

Deduplication

Duplicate records inflate apparent list size while reducing effective match rate per record. Deduplicate on email address as the primary key, then on phone number as a secondary key, before export. A list that shows 20,000 uploaded records but contains 3,000 duplicates will produce a misleadingly low match rate.[1]

Worked example

Diagnosing a match-rate problem for a Sydney law firm

  • Setup: A Sydney law firm uploads 8,500 consented client contacts—email only, no phone or address—and observes a 24% match rate: 8,500 × 0.24 = 2,040 matched members. This is below the published 29% floor.[1] The account team suspects a data quality issue.
  • Numbers: Audit reveals: 620 duplicate email records (7.3% of total); 410 email addresses with uppercase characters not lowercased before hashing (4.8%); 180 records with leading whitespace in the email field (2.1%). Corrected upload: 8,500 − 620 duplicates = 7,880 unique records, all normalised to lowercase with whitespace trimmed. Re-upload with email + phone (available for 5,200 of 7,880 records). Expected range: 7,880 × 0.29 = 2,285 matched (floor); 7,880 × 0.45 = 3,546 matched (midpoint).[1]
  • Decision: Rebuild the export pipeline with explicit lowercase normalisation, whitespace trimming, and deduplication on email as primary key. Add phone number (E.164 format) where available. Re-upload 7,880 records.
  • Why: Google identifies formatting inconsistency and missing identifiers as the primary causes of below-benchmark match rates; correcting these before hashing is the recommended diagnostic first step.[1]

Worked example

Lifting match rate by adding phone numbers for a health insurance comparison site

  • Setup: An Australian health insurance comparison platform has 15,000 consented leads uploaded with email only, yielding a 31% match rate: 15,000 × 0.31 = 4,650 matched members—above the 1,000-member threshold[6] but below the recommended 5,000-record API target.[8] The CRM holds mobile phone numbers for 11,200 of these leads.
  • Numbers: Re-upload 15,000 records with email + phone (where available). At midpoint 45% match rate applied to the 11,200 records with both identifiers: 11,200 × 0.45 = 5,040 likely matched from that subset alone, before counting email-only matches from the remaining 3,800. Projected total matched members: conservatively 5,500–6,500, up from 4,650. This exceeds the 5,000 API recommendation.[8]
  • Decision: Update the CRM export query to include mobile_phone in E.164 format (+614xxxxxxxx) for all records where the field is non-null. Re-upload as a full list replacement with both email and phone in each row.
  • Why: Google’s best-practice guidance states that supplying multiple identifiers per row improves match accuracy and list size; phone numbers are a supported CONTACT_INFO identifier.[1][8]

8. Targeting vs Observation and Exclusions

Customer Match lists can be applied to a campaign in three distinct modes: Targeting, Observation, and Exclusion. Choosing the wrong mode is one of the most consequential configuration errors in Google Ads because it either unnecessarily restricts reach (Targeting when Observation would serve) or fails to suppress unwanted audiences (Observation when Exclusion is needed).[11]

Observation mode

Observation adds the Customer Match list as a monitoring and bidding signal without restricting who sees the ad. The campaign continues to serve to all eligible users, but Google layers the Customer Match signal into Smart Bidding decisions and makes audience-level performance data visible in the Audiences report. Use Observation when you want to learn how matched users perform relative to the general audience, or when you want Smart Bidding to use the list as a signal without hard-gating delivery.[11]

Targeting mode

Targeting restricts delivery to the matched audience (or a combination of audiences set to Targeting). This is appropriate when you are running a campaign specifically for a defined segment—for example, a win-back campaign to lapsed customers only—and you do not want spend going to any other user. Targeting requires full Customer Match eligibility (90 days history and USD $50,000 lifetime spend).[11]

Exclusion mode

Exclusions prevent matched users from seeing the campaign. This is the most consistently underutilised Customer Match application. Common exclusion use cases include: removing existing customers from a new-customer acquisition campaign, suppressing recent converters from a promotional campaign, and excluding churned customers from retention-priced offers. Exclusions are available to all policy-compliant advertisers regardless of spend history.[11]

Choosing the right mode

Scenario Recommended mode Eligibility required
Learning how matched customers perform vs. all users Observation All compliant advertisers
Applying a bid adjustment for known high-value customers Observation (with bid modifier) Full access (90 days + USD $50,000)
Running a win-back campaign to lapsed customers only Targeting Full access (90 days + USD $50,000)
Preventing existing subscribers from seeing acquisition ads Exclusion All compliant advertisers
Providing a signal to Smart Bidding without restricting reach Observation All compliant advertisers

Worked example

Using Exclusions to protect acquisition budget for an energy retailer

  • Setup: An Australian energy retailer running a new-customer acquisition campaign on Search at AUD $25,000 per month has 42,000 current residential customers in its CRM. The account has been active for 6 months (below the 90-day threshold ✓ for history but only AUD $105,000 total spend—approximately USD $68,000—so full Targeting access is available).[11] Analysis of the prior quarter shows 12% of acquisition campaign clicks were from existing customers, representing approximately AUD $3,000/month in wasted spend (12% × $25,000 = $3,000).
  • Numbers: Upload 42,000 current customers as a Customer Match exclusion list. At 29% match rate[1]: 42,000 × 0.29 = 12,180 matched members—above the 1,000-member threshold.[6] If the exclusion removes the 12% overlap observed, the monthly saving is AUD $3,000 reallocated to net-new prospects.
  • Decision: Apply the 42,000-record Customer Match list in Exclusion mode to the acquisition Search campaign. Leave the campaign targeting settings otherwise unchanged. Review Audiences report after 30 days to confirm overlap reduction.
  • Why: Exclusions are available to all policy-compliant advertisers with no spend threshold, and suppressing known customers from acquisition campaigns is one of Google’s explicitly recommended exclusion use cases.[11]

9. Customer Match Across Campaign Types

Customer Match behaves differently across Google’s campaign types because each type has a distinct automation model, serving environment, and audience integration architecture. The underlying list requirements are the same, but how you use the list—and what you expect it to do—should vary by campaign type.[1][11]

Search

In Search campaigns, Customer Match lists can be used in Targeting, Observation, and Exclusion modes. Observation is the most common entry point: add the list at the ad group or campaign level to see how matched customers perform (conversion rate, CPA, average order value) compared with the general audience. Once you have 30 days of performance data, use bid adjustments on the Observation audience to reflect the observed differential.[1][11]

Performance Max

Performance Max does not support audience Targeting in the traditional sense. Instead, Customer Match lists function as audience signals fed to Google’s AI—they tell the system which customer patterns to learn from and optimise toward. In Performance Max, the most impactful use of Customer Match is as a high-quality signal in the audience signals section of the asset group, and as an exclusion at the campaign level to prevent serving to already-converted customers.[1][11]

Demand Gen

Demand Gen campaigns run across YouTube, Gmail, and Discover, and they are designed for upper- to mid-funnel engagement. Customer Match in Demand Gen is most useful for re-engagement (targeting lapsed customers with creative designed to reactivate), for building lookalike-style expansion from a high-value seed list, and for excluding current customers when the campaign objective is net-new awareness.[1][11]

YouTube

YouTube supports Customer Match for Targeting, Observation, and Exclusion. The most common application is frequency and creative personalisation: serving a different message to known customers than to prospecting audiences, or suppressing a product launch ad from users who already own the product.[11]

Campaign type Targeting Observation Exclusion Primary use case
Search ✓ (eligible accounts) Bid uplift for high-value customers; suppress existing customers from acquisition
Performance Max Signal only (no hard targeting) Via signals Audience signal for AI optimisation; exclude converters
Demand Gen ✓ (eligible accounts) Re-engagement; seed for expansion; exclude current customers
YouTube ✓ (eligible accounts) Creative personalisation; frequency management; suppress existing customers

Worked example

Using Customer Match as a Performance Max signal for a B2B SaaS company

  • Setup: An Australian B2B SaaS company spending AUD $12,000 per month on Performance Max has a CRM of 8,200 consented trial and paid customers. The account has 11 months of history and approximately USD $72,000 in lifetime spend—full Targeting access is available, though PMax does not support hard targeting.[11]
  • Numbers: Upload 8,200 records (email + business email domain used as email field, plus phone where available for 5,100 of 8,200). At 29% floor match rate[1]: 8,200 × 0.29 = 2,378 matched members; at 45% midpoint: 8,200 × 0.45 = 3,690 matched. Both are above the 1,000-member threshold.[6] Separate list of 3,400 current paid customers uploaded as a campaign-level exclusion in PMax to prevent serving acquisition ads to existing accounts.
  • Decision: Add the 8,200-record list as an audience signal in the Performance Max asset group. Apply the 3,400-record paid-customer list as a campaign-level exclusion. Review Search Insights report after 4 weeks to assess signal adoption.
  • Why: Google’s guidance states that Customer Match is most valuable in Performance Max as an audience signal for the AI rather than a hard gate, and exclusions are the mechanism for preventing waste on existing customers.[1][11]

Worked example

Re-engagement Demand Gen campaign for a travel booking platform ahead of the 2026 summer school holidays

  • Setup: An Australian online travel platform planning a Demand Gen campaign targeting the period 20 November–20 December 2026 (Southern Hemisphere summer school holiday travel planning window) has 28,000 lapsed customers in its CRM—defined as customers who booked at least once but have not made a booking in the 18 months from 1 May 2025 to 1 November 2026.
  • Numbers: Upload 28,000 lapsed customer records (email + phone). At 29% floor match rate[1]: 28,000 × 0.29 = 8,120 matched members; at 45% midpoint: 28,000 × 0.45 = 12,600 matched. Demand Gen campaign budget: AUD $8,000 for the 30-day flight. A separate active-customer list of 14,000 is applied as a campaign-level exclusion to prevent re-engagement budget reaching customers who have booked in the last 90 days.
  • Decision: Set Demand Gen campaign to Targeting mode using the 28,000-record lapsed list. Apply the 14,000-record active-customer exclusion. Use travel-themed creative tailored to lapsed users (messaging: “It’s been a while—see what’s new for summer 2026”). Refresh both lists on 1 November 2026 before campaign launch.
  • Why: Google’s Customer Match guidance explicitly recommends Demand Gen for re-engagement audiences, and exclusions prevent budget waste on already-active customers.[1][11]

10. Privacy, Consent and Compliance

In Australia in 2026, Customer Match sits at the intersection of Google’s own platform policies, the Australian Privacy Act 1988 (as amended by the Privacy Act Review reforms progressively implemented since 2023), and any sector-specific obligations applicable to your industry. Getting this wrong exposes your organisation to both Google account suspension and regulatory action.[11]

Google’s consent requirement

Google’s Customer Match policy requires that you have user consent before uploading customer data into Google Ads.[11] For advertisers operating in or targeting users in the European Union, the EU User Consent Policy applies additionally, requiring explicit consent for personalised advertising and for the sharing of data with Google.[11] Australian advertisers whose platforms have EU users should treat the EU User Consent Policy as applying to those users and implement a consent management platform (CMP) accordingly.

Australian Privacy Act obligations

The Australian Privacy Act’s Australian Privacy Principles (APPs) require that personal information be collected for a specific, disclosed purpose, used and disclosed only for that purpose (or a directly related secondary purpose with consent), and protected against misuse. Uploading a customer’s email address to Google Ads for targeting purposes is a secondary use of data collected for, say, an e-commerce transaction. This secondary use requires either that it falls within a directly related secondary purpose the customer would reasonably expect, or that explicit consent has been obtained for marketing purposes.[4][11]

Consent architecture in the CRM

A compliant consent architecture requires: a Boolean consent flag (marketing_consent = TRUE/FALSE), a consent date field, a consent source field (e.g., “checkout opt-in”, “preference centre”, “phone call”), and a process that sets marketing_consent = FALSE immediately upon opt-out and propagates that status to any Google Ads audience sync within 24 hours.[4][11] Never upload contacts where consent status is null, unknown, or assumed from the absence of an opt-out.

SHA-256 and data minimisation

Google’s hashing requirement is a technical privacy control, not a substitute for consent. Hashing email addresses with SHA-256 before upload means the raw email is not transmitted to Google’s systems in plain text, but the underlying data is still personal information and the consent requirement applies before hashing.[14] Apply data minimisation: only upload the identifiers you need. If email alone will produce a sufficient match rate for your list size, adding physical address increases matching at the cost of transmitting additional personal information—weigh that tradeoff for your sector.

Worked example

Building a compliant consent-filtered export for a financial services advertiser

  • Setup: An Australian personal finance comparison platform has 60,000 total registered users. The CRM consent audit shows: 38,000 with marketing_consent = TRUE and a consent date on or after 1 January 2023 (post Privacy Act reform commencement); 14,000 with consent status unknown or null (legacy records with no explicit opt-in record); 8,000 with marketing_consent = FALSE (opted out).
  • Numbers: Eligible for upload: 38,000 records only. Ineligible: 14,000 (unknown) + 8,000 (opted-out) = 22,000 records excluded. Upload pool: 38,000. At 29% match rate floor[1]: 38,000 × 0.29 = 11,020 matched members. At 45% midpoint: 38,000 × 0.45 = 17,100 matched members. Both outcomes are well above the 1,000-member serving threshold.[6]
  • Decision: Configure the CRM export query with the filter WHERE marketing_consent = TRUE AND consent_date >= '2023-01-01'. Apply SHA-256 hashing to email, phone, first name, and last name before upload. Document the export query and consent filter in the organisation’s privacy register. Exclude the 14,000 legacy records until a re-consent campaign is run.
  • Why: Google’s policy requires consent before upload, and uploading records where consent status is unknown violates both Google’s policy and the Australian Privacy Act’s purpose limitation principle.[11]

11. Common Mistakes to Avoid

The following errors account for the majority of underperforming or non-compliant Customer Match implementations. Each is avoidable with the right process controls in place.[1][8][11][14]

Uploading without consent documentation

The single most consequential error is uploading contacts who have not explicitly consented to marketing communications. Beyond the Google policy risk (which can result in account suspension), this carries regulatory exposure under the Australian Privacy Act and, for EU-targeted campaigns, the EU User Consent Policy. Treat consent documentation—date, source, method—as a prerequisite, not an afterthought.[11]

Hashing in the wrong sequence

SHA-256 must be applied to normalised data: lowercase, no whitespace. Hashing [email protected] and [email protected] produces different hash values, so if your pipeline hashes before normalising, your match rate will be artificially suppressed. Always normalise first, then hash.[14]

Using a single list for all purposes

A single monolithic “all customers” list cannot simultaneously serve as a targeting audience, a high-value seed signal, and an exclusion list. Segment your CRM data into purpose-specific lists before upload. Using the same list for Targeting in one campaign and Exclusion in another requires separate list instances, not the same list in two modes.[6][11]

Neglecting list refresh cadence

A list that has not been updated for more than 540 days begins to lose members, and any list with fewer than 100 active members loses eligibility entirely.[11] Set a calendar reminder or automate a weekly refresh. Even if your customer base does not change substantially week to week, re-uploading the current consented list resets the 540-day clock for those members.[1]

Ignoring the minimum volume buffer

Uploading exactly 1,100 records against a 1,000-member serving threshold provides essentially no buffer. Natural attrition—users changing email addresses, closing Google accounts, or becoming inactive—erodes matched list size continuously. The practical safe minimum is 5,000 uploaded records, and a conservative operational target is to upload at least 2,000 records above your serving threshold minimum at all times.[8][2]

Assuming the API token is still active after the April 2026 restriction

Tokens with no Customer Match API calls between 1 October 2025 and 31 March 2026 are now blocked from OfflineUserDataJobService and UserDataService. If your automated pipeline has been silent since before October 2025, it may be returning silent failures or CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE errors without alerting your team. Audit your API call logs before assuming uploads are succeeding.[3]

Using Customer Match as a hard gate in Performance Max

Performance Max does not support hard audience targeting in the way Search does. Treating a Customer Match list as a targeting restriction in PMax limits the campaign’s ability to find new, high-value users. The correct approach is to use the list as an audience signal so the AI learns customer patterns, not as an audience gate that restricts delivery.[1]

Worked example

Recovering from a stale-list eligibility failure for a professional services firm

  • Setup: A Brisbane accounting firm last refreshed its Customer Match list in September 2025—approximately 11 months before August 2026. The list originally contained 2,200 uploaded records. The firm notices in August 2026 that the Customer Match list shows a status of “Not Eligible” in the Google Ads UI.
  • Numbers: 540-day eligibility window: a member added on 1 September 2025 expires on 24 February 2027—so the list should still be within the window. However, if no new members were added or updated after September 2025, and the list had a high attrition rate (e.g., 15% of members changed email or became inactive), the matched count may have dropped below 100 active members.[11] 2,200 × 0.29 = 638 matched at upload; 638 × 0.85 (15% attrition) = 542 active matched members—still above 100. More likely, the issue is that the list itself had fewer than 100 eligible members at time of creation, or a policy flag has been applied. Recommended action: re-export the current consented CRM with a minimum of 5,000 records[8] and re-upload immediately.
  • Decision: Export 4,800 current consented clients from the CRM (the firm’s full consented base), normalise and hash all fields, and upload as a replacement list. Set a recurring monthly calendar reminder for a list refresh on the first Monday of each month.
  • Why: Google requires at least 100 members added or updated within the last 540 days for list eligibility; uploading a fresh list of 4,800 records resets the active membership clock and provides a buffer well above the 1,000-member serving threshold.[11][6]

12. What Changed Recently (Last 30 Days)

As of August 2026, no new Google-authored Customer Match policy change, eligibility expansion or contraction, new feature launch, or best-practice bulletin has been published in the last 30 days.[1][3] The research conducted for this article does not surface a Google source showing a fresh Customer Match update in the July–August 2026 window.

However, three changes that came into force earlier in 2026 remain operationally live and continue to affect practitioners who have not yet responded to them:

1. April 2026: Google Ads API Customer Match access restriction

From 1 April 2026, developer tokens that had no Customer Match API requests recorded between 1 October 2025 and 31 March 2026 were blocked from OfflineUserDataJobService and UserDataService. Affected tokens receive the error CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE. Google directs these accounts to the Data Manager API as the migration path.[3] If your automated pipeline was dormant during that window, audit your API logs immediately—uploads may have been failing silently since 1 April without dashboard-level alerts.

2. 540-day membership duration cap (2025 rollout, now fully in effect)

Google’s update to Customer Match list membership duration—capping all memberships at 540 days and requiring at least 100 active members within the last 540 days for list eligibility—was rolled out in 2025 and is now fully in effect for all accounts.[11] Any list that was built before mid-2024 and not refreshed since will have lost its oldest members by August 2026. Lists built on contacts who were uploaded in February 2025 will begin losing those members in August 2026 as the 540-day window expires.

3. Data Manager API as the recommended upload path for new integrations

Google’s deprecation documentation now positions the Data Manager API as the preferred path for Customer Match uploads in contexts where the legacy OfflineUserDataJobService is restricted.[3] Teams building new integrations in August 2026 should evaluate the Data Manager API first rather than defaulting to the legacy workflow.

Recommendation: Where sources or timelines are ambiguous about whether a change is fully in force, adopt the most conservative interpretation. Treat the 540-day cap, the API token restriction, and the Data Manager API migration as current operational realities, not future considerations.[1][3][11]

Worked example

Auditing for the April 2026 API restriction before a campaign relaunch in August 2026

  • Setup: An Adelaide retail group reactivating Google Ads after a six-month pause (February 2026 to August 2026) has an automated Customer Match sync pipeline that was last confirmed active in January 2026. The developer token has had zero Customer Match API calls between 1 October 2025 and 31 March 2026.
  • Numbers: API call window for restriction check: 1 October 2025–31 March 2026 = 182 days. Calls in that window: 0. Result: the developer token is restricted from OfflineUserDataJobService as of 1 April 2026.[3] If the team attempts to run the legacy pipeline in August 2026, all requests will return CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE. Migration required: move to the Data Manager API before any Customer Match upload is attempted. Estimated migration effort: 2–5 engineering days based on the complexity of the existing pipeline.
  • Decision: Before reactivating Customer Match audiences in August 2026, engage the development team to migrate the pipeline to the Data Manager API. Do not attempt a legacy OfflineUserDataJobService upload. Validate the first upload via the Data Manager API in a test account before applying to live campaigns.
  • Why: Google’s API deprecation documentation confirms that tokens inactive for Customer Match between 1 October 2025 and 31 March 2026 are restricted from legacy Customer Match API services from 1 April 2026, with the Data Manager API as the designated replacement path.[3]

References

  1. [1] https://support.google.com/google-ads/answer/10010286?hl=en support.google.com
  2. [2] https://www.youtube.com/watch?v=uEz1NIm3osM www.youtube.com
  3. [3] https://www.youtube.com/watch?v=Ne0am2w8JCc&vl=en www.youtube.com
  4. [4] https://www.youtube.com/watch?v=P1I1YuPE9nw www.youtube.com
  5. [5] https://clickyowl.com/google-ads-customer-match/ clickyowl.com
  6. [6] https://steerads.com/de/blog/customer-match-first-party-data-2026 steerads.com
  7. [7] https://www.youtube.com/watch?v=h6dYV5SJwmg www.youtube.com
  8. [8] https://developers.google.com/google-ads/api/docs/remarketing/audience-segments/customer-m… developers.google.com
  9. [9] https://www.youtube.com/watch?v=gI46u0VVjzM www.youtube.com
  10. [10] https://twominutereports.com/blog/google-ads-best-practices twominutereports.com
  11. [11] https://support.google.com/adspolicy/answer/6299717?hl=en support.google.com
  12. [12] https://www.groas.com/post/google-ads-best-practices-2026-rules-that-actually-matter www.groas.com
  13. [13] https://business.google.com/uk/resources/articles/how-to-drive-ad-performance-with-custome… business.google.com
  14. [14] https://support.google.com/google-ads/answer/7474263?hl=en support.google.com
  15. [15] https://www.dinmo.com/audience-strategies/acquisition/google-ads/ www.dinmo.com
  16. [16] https://www.reddit.com/r/googleads/comments/1qaoyec/its_2026_whats_one_piece_of_google_ads… www.reddit.com
  17. [17] https://support.google.com/google-ads/thread/413560562/google-ads-best-practices-for-2026?… support.google.com
  18. [18] https://www.digitalapplied.com/blog/google-ads-customer-type-labeling-2026-advertiser-guid… www.digitalapplied.com
  19. [19] https://leadsbridge.com/blog/google-ads-best-practices/ leadsbridge.com
  20. [20] https://www.mbadv.agency/google-ads/audience-targeting www.mbadv.agency
  21. [21] https://directiveconsulting.com/blog/the-b2b-marketers-guide-to-google-ads-best-practices-… directiveconsulting.com
  22. [22] https://www.definedigitalacademy.com/blog/how-google-ads-will-work-in-2026 www.definedigitalacademy.com
  23. [23] https://storycatcreative.com/outdated-google-ads-strategies-to-stop-using-in-2026/ storycatcreative.com
  24. [24] https://searchengineland.com/google-to-disable-customer-match-uploads-in-ads-api-470796 searchengineland.com
  25. [25] https://developers.google.com/google-ads/api/docs/deprecations developers.google.com
  26. [26] https://almcorp.com/fr/blog/google-ads-api-customer-match-disabled-april-2026/ almcorp.com
  27. [27] https://searchengineland.com/google-tightens-customer-match-data-rules-in-major-privacy-up… searchengineland.com
  28. [28] https://almcorp.com/blog/google-ads-api-customer-match-disabled-april-2026/ almcorp.com
  29. [29] https://www.searchenginejournal.com/google-is-updating-its-customer-match-policy/532420/ www.searchenginejournal.com
  30. [30] https://ppcnewsfeed.com/ppc-news/2026-03/google-ads-api-ends-customer-match-integrations/ ppcnewsfeed.com
  31. [31] https://searchengineland.com/some-customer-match-features-to-become-available-to-all-polic… searchengineland.com
  32. [32] https://help.salesforce.com/s/articleView?id=004634130&language=sv&type=1 help.salesforce.com
  33. [33] https://ads-developers.googleblog.com/2025/02/update-to-customer-match-membership.html?m=0 ads-developers.googleblog.com
  34. [34] https://help.salesforce.com/s/articleView?id=004634130&language=en_US&type=1 help.salesforce.com
  35. [35] https://overtdigitalmarketing.com.au/google-tightens-customer-match-data-rules-in-major-pr… overtdigitalmarketing.com.au
  36. [36] https://support.google.com/adspolicy/answer/16828044?hl=en support.google.com
  37. [37] https://www.linkedin.com/posts/clicksambo_googleads-customermatch-datamanagerapi-activity-… www.linkedin.com
  38. [38] https://www.realinternetsales.com/google-ads-customer-match-api-changes-april-2026/ www.realinternetsales.com
  39. [39] https://metapixelboise.com/google-ads-customer-match-policy-update/ metapixelboise.com
  40. [40] https://www.youtube.com/watch?v=CFerpJCKaH0 www.youtube.com
  41. [41] https://support.google.com/google-ads/answer/10534785 support.google.com
  42. [42] https://simplee.digital/blog/google-ads-customer-match-lenders-fintech-compliance-playbook… simplee.digital
  43. [43] https://steerads.com/es/blog/customer-match-first-party-data-2026 steerads.com
  44. [44] https://www.adtribute.io/glossary/customer-match www.adtribute.io
  45. [45] https://www.contactlevel.com/playbooks/google-customer-match-b2b www.contactlevel.com
  46. [46] https://deepclickads.com/2026/04/27/google-customer-match-api-post-click-cvr-2026/ deepclickads.com
  47. [47] https://il-webdesign.com/customer-match-google-ads-nyc-small-business-guide-2026/ il-webdesign.com
  48. [48] https://searchengineland.com/instant-match-rates-are-now-available-for-customer-match-list… searchengineland.com
  49. [49] https://developers.google.com/google-ads/api/docs/remarketing/audience-segments/customer-m… developers.google.com
  50. [50] https://www.growthspreeofficial.com/blogs/google-customer-match-from-hubspot-b2b-2026 www.growthspreeofficial.com
  51. [51] https://www.linkedin.com/posts/khandilshadsiraj_googleads-ppc-digitalmarketing-activity-74… www.linkedin.com

Don’t want to do this yourself?

Get a complete, ready-to-launch Google Ads campaign — keywords validated against real search data, copy written to the best practices on this page, and a proper negative-keyword list — built for your business and delivered within 24 hours.

Build my campaign — $129

One-off price · Human-reviewed · No subscription · No access to your Google Ads account

Share the Post:

Related Posts