Your customer list is still the best ad audience. It is just harder to upload now.
Consent Mode v2, hashed matching and server-side events, explained for people who have to run the campaign rather than argue about it.
Customer-list audiences — uploading hashed emails to build a lookalike or an exclusion — remain the highest-leverage advertising tool a shop has, because they are built on your own first-party data rather than on tracking strangers around the web. What changed is the paperwork and the plumbing around them.
Consent Mode v2, briefly
Since March 2024, advertisers using Google's audience and measurement features for users in the EEA and the UK must pass consent signals to Google. The mechanism is two additional parameters — one covering ad user data, one covering ad personalisation — sent alongside the existing analytics and advertising storage signals. Without them, remarketing and customer-match features are restricted for those users.
- Basic implementation: tags only fire after consent. Simple, and you lose modelled conversions from non-consenting users.
- Advanced implementation: tags load and send cookieless pings that carry the consent state. More data, more implementation work, and more to explain in your privacy notice.
Either way, the consent banner stopped being a legal checkbox and became part of the measurement stack. A banner that does not correctly block and unblock these signals produces campaigns that underperform for reasons nobody can see in the ads interface.
Hashing is not anonymisation
When you upload a customer list, the addresses are hashed with SHA-256 before they leave your systems. It is worth being precise about what that does and does not achieve: hashing protects the data in transit and at rest, but a hash of an email address is still personal data, because it identifies one specific person and can be matched back. The EDPB and national regulators have been consistent on this.
So the question you have to answer before uploading a list is not technical. It is: what is your lawful basis for sharing these customers with an advertising platform, and did you tell them? For most shops the honest answer is consent, collected in a way that mentions advertising — not a line buried in a privacy policy.
Server-side events, and why they exist
Browser-based pixels lose events to ad blockers, tracking prevention in Safari and Firefox, and consent rejections. Server-side conversion APIs — Meta's Conversions API, Google's equivalents — send the event from your server instead, usually deduplicated against the browser event by a shared event ID.
Two honest observations about this:
- It recovers real signal. Match rates and attributed conversions typically improve, sometimes substantially, because the events genuinely happened and were simply not being reported.
- It does not launder consent. Sending an event from a server rather than a browser changes the transport, not the legality. If the user refused advertising cookies, the server-side event for advertising purposes is subject to the same refusal.
Implementations that quietly ignore the second point are the ones that turn into a regulatory problem two years later.
What a small team should actually do
- Fix the banner first. Reject must genuinely block advertising signals, and the choice must be as easy to reverse as to give. Everything downstream depends on this being correct.
- Upload exclusions before lookalikes. Excluding existing customers from acquisition campaigns is the cheapest performance win available and is rarely done.
- Build lookalikes from your best customers, not all of them. Seed from repeat buyers or the top decile by revenue. A seed list of everyone teaches the platform to find people like your worst customers too.
- Refresh lists on a schedule. A customer list uploaded once decays; match rates fall as addresses change.
- Implement server-side events with deduplication, and verify in the platform's own diagnostics that you are not double-counting.
- Keep a record of which list went to which platform, when, and under what consent. This is the document you will be asked for.
What to expect
Reported conversions will not match your shop's order count, and chasing that match is a trap. Platform attribution is modelled, window-based and self-serving by design. Use it to compare campaigns against each other, and use your own order data to decide whether advertising as a whole is working.
Sources and further reading (6)
- Google Ads Help — About consent mode
- Google — EU user consent policy
- Google Ads Help — About Customer Match
- Meta for Developers — Conversions API
- EDPB — Guidelines 01/2025 on pseudonymisation
- Directive 2002/58/EC (ePrivacy), Article 5(3) — storage and access on terminal equipment
Checked on 21 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
Build the audience once, use it where it belongs
Auralata builds ad audiences from the same WooCommerce data as your campaigns — repeat buyers, lapsed customers, top decile by revenue — and keeps the consent state attached, so a contact who refused advertising never ends up in an upload.