Nobody decides to give their customer list to Meta. Someone installs the Facebook & Instagram app, a setup screen offers “Maximum” data sharing because it sounds better than “Standard”, and the box gets ticked. An agency links a Google Ads account and accepts the customer data terms on your behalf. A platform changes a default and emails a notice that nobody reads.
Menu names change often. Where we’re sure of a path, we give it; where we aren’t, we say “look for”. Each item was checked against the provider’s own documentation on 20 September 2026.
Shopify
Shopify Audiences and Shopify Network Intelligence. Shopify Audiences builds ad audiences from pooled data across participating merchants and exports them to connected ad accounts. Shopify lists Meta, Google, Criteo, Pinterest, Snapchat and TikTok. It needs Shopify Plus, Shopify Payments and sales in the US or Canada, so most UK shops can’t use it. But it rests on a wider setting, Shopify Network Intelligence, which lets Shopify use your customer data together with other merchants’ data to power “Enhanced Services”, including some that target advertising. Shopify describes it as something you can opt out of, and the updated terms it applies to took effect on 25 July 2025.
Where: Settings > Customer privacy > Shopify Network Intelligence. What to do: Disable it. Shopify will tell you which apps and features it removes, and you type UNINSTALL to confirm. If you had Audiences, the lists it created stay in your ad accounts marked as no longer maintained. Delete them there too.
Facebook & Instagram channel app. It offers three data sharing levels. Standard uses the Meta pixel. Enhanced adds the Conversions API, sending customers’ name, location, email address and phone number server to server. Maximum does the same plus what Shopify calls Meta’s “latest” advertising technology. Shopify’s help page is candid about the selling point: server-to-server data “can’t be blocked by browser-based ad blockers”.
Where: Sales channels > Facebook & Instagram > Settings > Data sharing settings. What to do: Turn customer data sharing off entirely. Standard is not a safe middle setting. It is still an ad pixel (ruling R-003).
Google & YouTube app. Connecting Google Ads sets up conversion tracking automatically, with purchase, add to cart and checkout started as the suggested events. Enhanced conversions is a separate opt-in that asks you to agree to customer data terms.
Where: in the app, Settings > Google Ads settings. Conversion tracking and enhanced conversions are both managed there. What to do: Turn off enhanced conversions and opt out of conversion tracking. The product feed can stay; a catalogue isn’t customer data.
TikTok app. TikTok’s own help page lists three levels. Standard is the TikTok Pixel. Enhanced adds the Events API and Advanced Matching. Maximum adds Shopify APIs and in-app checkout. Where: look for Data sharing in the TikTok app’s settings inside Shopify. What to do: Turn data sharing off.
Google Ads
Enhanced conversions (web and leads). These send hashed email addresses, phone numbers and names back to Google so it can match conversions to signed-in users. Hashing doesn’t change what this is (see “Hashed isn’t anonymous”). Google has been folding the two versions together. Its help centre says that from June 2026 enhanced conversions for web and for leads become a single on/off setting, and that existing users who had agreed to the customer data terms were migrated automatically. At account level, conversion actions without it are switched on unless they were explicitly opted out, and new ones inherit the account setting.
Where: Goals > Settings. Look for the enhanced conversions or “customer data use” section. Check individual conversion actions as well. What to do: Turn it off at account level and on every conversion action. Offline conversion imports and click-ID uploads count too (ruling R-004).
Conversion-based customer lists. This one fits the title best. It uses the hashed data you send for enhanced conversions to build Customer Match lists. Search Engine Land reported in June 2026 that Google would switch it on automatically for eligible advertisers already using enhanced conversions and Customer Match, with processing from 18 August 2026.
Where: Admin > Account settings > Customer match. What to do: Untick it. Then open Audience manager and delete every list built from your customers. Do the same in Meta for custom audiences and any lookalikes built from them (rulings R-002 and R-005).
Google Analytics 4
Google signals. Signals associates your analytics data with signed-in Google users. It sits under Admin > Data collection and modification > Data collection. Turning it off is not enough. Google says that from 15 June 2026 its Consent Mode ads settings, not Signals, control whether Google Ads cookies and IDs are collected, and that IP addresses GA4 collects are shared with linked Google Ads accounts.
What to do: Under the Standard, GA4 is out whatever its settings (ruling R-006). Unlink Google Ads, then replace GA4 with cookieless counting.
Meta Events Manager
Automatic advanced matching. Once on, it reads details people type into your forms, such as email, name, phone and postcode, hashes them in the browser and sends them with pixel events. Where: look for it in your pixel’s (dataset’s) settings in Events Manager.
Conversions API and the Conversions API Gateway. The Gateway runs in your own cloud account and relays pixel events to Meta server to server. Look in Events Manager for any Conversions API connection or partner integration: Shopify, WooCommerce, your tag manager, or a “first-party tracking” service.
What to do: Remove the pixel, disconnect every server-side connection, and remove partner integrations. Our companion piece, “The pixel you can’t see”, explains why the server route is treated the same.
It isn’t only Meta. Trade press reported that OpenAI switched on automatic advanced matching for existing ChatGPT Ads pixels from 17 August 2026 unless advertisers opted out.
Email and CRM tools
Your email tool can be fine under the Standard: opted-in subscribers, acting as your processor, with ad syncs off (ruling R-008). The syncs are the problem.
- Klaviyo can sync lists and segments to Meta, Google Ads, Pinterest, TikTok and Criteo. Look in Integrations for each ad platform, and in any segment set to sync.
- Mailchimp can create Facebook and Instagram ads that target your contacts or lookalikes of them, and offers Google remarketing ads. Also check for automation connectors pushing contacts into custom audiences.
- HubSpot syncs audiences to Facebook, Google, Microsoft and LinkedIn from Marketing > Ads > Audiences, sending names, emails and phone numbers for matching. It can also sync conversion events to Google Ads.
What to do: Disconnect the ad-platform integrations. Deleting an audience in HubSpot stops further syncing, but HubSpot notes you must also delete it in the ad account.
WooCommerce and other platforms
Meta for WooCommerce (formerly Facebook for WooCommerce) installs the pixel and connects the catalogue; its settings live under Marketing > Facebook. Google for WooCommerce advertises automatic Google tagging, conversion tracking and enhanced conversions. Other pixel plugins do much the same.
What to do: Deactivate and delete the plugins, then check the page source and your tag manager for anything left behind.
Agencies
Agencies usually hold the keys. They accept terms, link accounts and install apps in your name. Under the Standard, what they do in your accounts is your responsibility (clause NFS-1.7).
- In Meta business settings, look for Partners and see who has access to your ad account and pixel.
- In Google Ads, look under Admin > Access and security for users and manager accounts.
- Ask your agency, in writing, for a list of every conversion action, audience and integration they have set up, and to confirm the syncs are off.
Fine and Never
The route doesn’t matter. Customer data doesn’t go to an ad platform by pixel, API, list upload or sync (rulings R-003, R-004, R-008 and R-010). A cookie banner doesn’t change that (clause NFS-1.3). Nor does “the agency set it up” (clause NFS-1.7). When you apply, we ask for a data map covering every place above, and read-only access to your ad accounts so a reviewer can check. Most fixes take ten minutes. Finding them all is the longer job.
Sources (24), checked 20 September 2026
- Shopify Help Center: Facebook data sharing
- Shopify Help Center: Shopify Audiences
- Shopify Help Center: Connecting to ad platforms with Shopify Audiences
- Shopify Help Center: Shopify Audiences FAQ
- Shopify Help Center: Requirements when Shopify Network Intelligence is enabled
- Shopify Help Center: Configuring customer privacy settings
- Shopify: Updates to Shopify’s Terms of Service
- Google Ads Help: Set up conversion tracking with the Google & YouTube app on Shopify
- TikTok for Business: Data sharing on TikTok app on Shopify
- Google Ads Help: Updates to your enhanced conversions settings
- Google Ads Help: About enhanced conversions at the account level
- Google Ads Help: Set up conversion-based customer lists
- Search Engine Land: Google Ads automatically enrols advertisers in conversion-based customer lists
- Analytics Help: Activate Google signals for GA4 properties
- Analytics Help: Updates to Google Analytics data controls
- Meta for Developers: Advanced matching
- Meta for Developers: Conversions API Gateway
- PPC Land: ChatGPT advertisers face 10 days to opt out of automatic advanced matching
- Klaviyo: Audience sync
- Klaviyo Help Center: How to determine your Meta audience sync strategy
- Mailchimp: Introducing Facebook ad campaigns
- HubSpot Knowledge Base: Create ads audiences in HubSpot
- WooCommerce: Meta for WooCommerce documentation
- WordPress.org: Google for WooCommerce