Table of Contents
- Why Agencies Face Different Risk Than Solo Stores
- Structuring Client Accounts: MCA vs. Individual Logins
- The Cross-Account Flags Nobody Warns You About
- Client Onboarding Compliance Checklist
- Standardizing Policy Pages Across Client Sites
- Monitoring Compliance at Scale
- When a Client Account Gets Suspended
- Protecting Your Agency: Contract Language
If you run a dropshipping agency, sourcing service, or freelance Google Shopping management business, you already know that managing one GMC account is hard enough. Managing ten, thirty, or a hundred client accounts introduces an entirely different category of risk โ one that most GMC guides never address because they're written for single-store owners.
This guide covers the specific compliance patterns agencies need to watch for, how to structure your account access to avoid triggering Google's abuse-detection systems, and how to build a repeatable onboarding process that catches problems before they become suspensions.
Why Agencies Face Different Risk Than Solo Stores
A single store owner manages one GMC account tied to one business, one domain, and one set of policies. An agency manages many accounts that may share infrastructure: the same payment processor, the same theme template, similar or identical policy page wording, the same shipping fulfillment partner, and sometimes the same physical warehouse or supplier.
Google's fraud and abuse detection is built to spot networks of related accounts โ because historically, networks of related accounts are how large-scale policy violation operations (fake stores, counterfeit rings, scam networks) have operated. An agency running legitimate dropshipping businesses for real clients can accidentally trip the same detection systems built to catch bad actors, simply because of shared infrastructure patterns.
Google doesn't distinguish between "an agency managing 20 legitimate independent client stores" and "one bad actor running 20 fake stores to evade suspension." Both patterns look identical from the outside: similar templates, similar policy language, and accounts logging in from the same IP or device fingerprints. Your job is to make sure your legitimate operation doesn't look like the latter.
Structuring Client Accounts: MCA vs. Individual Logins
Google Merchant Center supports a Multi-Client Account (MCA) structure, which lets an agency manage multiple sub-accounts under one parent umbrella. This is the correct way to manage client accounts โ not logging into each client's account separately with shared credentials.
| Structure | Pros | Cons |
|---|---|---|
| Multi-Client Account (MCA) | Centralized management, clean audit trail, Google-sanctioned structure, easier bulk reporting | Requires each client to grant MCA access; slightly more setup |
| Individual logins per client | Simple to set up initially | No centralized oversight, harder to spot patterns across accounts, higher risk if you reuse credentials |
| Shared login credentials | None | Violates Google's terms in most cases, no audit trail, single point of failure if compromised |
Set up an MCA under your agency's Google account, and have each client grant access from their own GMC account rather than sharing raw login credentials. This keeps a clean separation: each client's account remains legally and technically theirs, while you get centralized visibility and management.
The Cross-Account Flags Nobody Warns You About
Beyond account structure, there are specific patterns that increase scrutiny across a portfolio of client accounts:
- Identical policy page templates. If ten of your clients have return policies with the exact same wording (because you copy-pasted the same template), Google's systems can detect this pattern across domains. It's not automatically a violation, but it removes a trust signal โ unique, specific policy content signals a real, independently operating business.
- Same theme, same layout, same stock photos. Dropshipping stores built from the same Shopify theme with the same "About Us" stock photography across multiple client sites is a well-known red flag pattern that Google's Trust & Safety teams actively look for.
- Shared supplier/fulfillment info leaking into policy pages. If your return address or fulfillment contact details are identical across client stores (because they all drop-ship from the same supplier), and this leaks into the "Contact Us" or "Returns" page, it visibly links otherwise independent accounts.
- Sequential account creation. Many client accounts created in the same GMC batch, verified in short succession, from the same IP address, can trigger velocity-based fraud detection even when every account is legitimate.
- Same billing method across accounts. If you manage ad spend for clients using your own payment method linked to multiple accounts, keep documentation ready explaining the agency relationship โ Google's billing fraud systems sometimes flag shared payment methods across accounts as a potential abuse pattern.
Require every client to write their own About Us page and policy language in their own words, even if you provide a template as a starting point. Five minutes of client-specific detail (their actual founding story, their actual location, their actual return process) is worth more for compliance than a polished but generic template shared across accounts.
Client Onboarding Compliance Checklist
Before you ever submit a new client's feed to GMC, run through this checklist:
๐ Pre-Launch Client Checklist
Domain is verified and claimed under the client's own GMC account, not a shared or agency-owned domain.
Business name matches across GMC, the website, business registration documents, and payment processor records.
Policy pages are client-specific โ not copy-pasted verbatim from another client or a generic template.
Contact information is real and client-owned โ a domain email address and, ideally, a real phone number, not a shared agency inbox.
Product images are unique or properly licensed โ not directly scraped from a competitor's listing or a supplier's marketing photos without rights.
Shipping timeframes are accurate to the actual supplier's fulfillment speed, not an optimistic guess.
Standardizing Policy Pages Across Client Sites
You can still use a repeatable process without creating identical content. Build a policy page framework โ the required sections and structure โ but require unique inputs for each client: their actual business name, their actual return window, their actual processing times, and a paragraph of unique founding story or product focus. This gives you efficiency without the red flag pattern of verbatim duplication.
Monitoring Compliance at Scale
With more than a handful of client accounts, manual monitoring becomes unsustainable. Build a recurring cadence:
- Weekly: Check the Account Health section of each MCA sub-account for new warnings or item disapprovals.
- Bi-weekly: Spot-check 5โ10 product landing pages per client for price mismatches, broken links, or feed sync issues.
- Monthly: Full policy page review โ confirm return policy, shipping policy, and contact info in GMC settings still match what's live on each client's site (clients change their sites without telling you).
Running each client account through our free GMC scan on a recurring basis is a fast way to catch drift before Google's own review catches it.
When a Client Account Gets Suspended
When (not if โ it will eventually happen) a client account gets suspended, resist the urge to appeal immediately. Follow the same discipline you'd want a solo store owner to follow: identify the specific policy cited, work through our suspension recovery checklist, fix every underlying issue, and only then submit the appeal โ ideally with documentation of the specific fixes made, since date-stamped documentation is more persuasive to Google's reviewers than a general assurance of compliance.
Critically, don't let one client's suspension trigger you to hastily "clean up" other client accounts in a way that looks coordinated โ spread out any bulk changes across accounts over several days rather than making identical edits to ten sites in one afternoon.
Protecting Your Agency: Contract Language
Because ultimate account ownership and compliance responsibility sits with the client (it's their business, their products, their legal obligations), your service agreements should be explicit about:
- Who owns the GMC account and Google Ads account (should always be the client, with agency access granted via MCA).
- The client's responsibility to provide accurate product, shipping, and policy information.
- Your agency's scope of responsibility: feed management, campaign optimization, and compliance monitoring โ but not liability for suspensions caused by client-provided misinformation.
This protects your agency's reputation and gives you a clear basis to require client cooperation when a compliance issue traces back to information they provided.
Frequently Asked Questions
Can I use one payment method to pay for Google Ads across all client accounts?
You can, but document the agency relationship clearly in your internal records and be prepared to explain it if Google's billing review flags the shared payment method. Where possible, prefer each client's own payment method linked via MCA billing permissions, since this creates a cleaner audit trail and reduces the chance of a billing-fraud flag cascading across unrelated client accounts.
How many client accounts can one agency safely manage under a single MCA?
There's no official hard cap, but the risk of cross-account pattern detection increases with scale, especially if clients share similar business models (e.g., an agency running fifty near-identical dropshipping stores in the same niche). Diversify onboarding timing, avoid templated content, and prioritize account-specific detail as your portfolio grows past a handful of accounts.
Should sub-agencies or freelancers working under my agency have their own logins?
Yes. Grant individual team members their own Google account access with appropriate MCA-level permissions rather than sharing a single login across your team. This keeps a clean activity log per user, which is valuable both for your own accountability and if Google ever asks about unusual account activity.
What happens if a client leaves and takes their GMC account with them?
Since the account should always be owned by the client under a proper MCA structure, this is a routine offboarding step: revoke your agency's MCA access to that sub-account. If you were managing the account fully in your own name โ a structure we recommend against โ the transfer process is more complex and worth avoiding for future clients.
Audit Every Client Account in Minutes
Run our free GMC scan across each client account to catch compliance issues before Google does โ no more surprise suspensions mid-campaign.
Run Free GMC Scan โ