MarketingPlaybook5 min readPublished September 26, 2026

Google Ads · Customer Match · first-party data · two columns you must not hash

Google Customer Match Now Matches on IP Address and Time

Customer Match lists can now carry an unhashed IP address and interaction time. The rules, the regions excluded, and who gains from adding the columns.

DA
Digital Applied Team
Research and practical guidance
New columns2
Regions excludedEEA · UK · CH

Google Ads Customer Match, the feature that turns an advertiser’s own customer list into an audience, now accepts two more pieces of data: the IP address of a customer’s device and the time they interacted with you. Trade press first reported the change on September 25. The rules below come from Google’s own help pages.

This matters most to advertisers who hold plenty of site or app activity but few email addresses. An IP address is something your server logs already record. It is also personal data in much of the world, which is why Google has switched the feature off for people in Europe, the UK and Switzerland.

Key takeaways
  1. 01
    Two new upload columns, both sent unhashed.“User IP address” and “User Engagement timestamp” go in as plain text, unlike email, phone and names.
  2. 02
    A timestamp needs an IP address.A row with a timestamp and nothing else triggers an error. An IP address can travel with or without personal fields.
  3. 03
    An IP sent alone matches the latest known user.Without a timestamp, Google defaults to whoever most recently used that address.
  4. 04
    Not available for the EEA, UK or Switzerland.Google’s Customer Match policy tells advertisers to exclude IP data for people in those regions.

01 — What changedTwo new columns, and neither is hashed

Until now, a Customer Match file carried contact details: email, phone, name, country and postcode, with the personal fields scrambled using the SHA-256 hashing standard before they reach Google. The new columns sit outside that scheme. Google’s upload guide asks for both as plain strings and says not to hash them.

Source: Google Ads Help, “Create a Customer Match list by uploading a data file”, read September 29, 2026.
ColumnHashedRule
Email, Phone, First Name, Last NameSHA-256Hash them yourself, or let Google Ads hash them on your computer before upload.
Country, ZipNoSent as plain text alongside the name fields.
User IP addressNoNew. IPv4 or IPv6 as a plain string, leading and trailing spaces trimmed. Can be sent with or without the personal fields.
User Engagement timestampNoNew. The time of the recorded interaction from that IP address. Rejected without an IP address in the same row.
Mobile Device IDNoUnchanged. Must be the only column in its file.

The details are in Google’s Customer Match upload guide. It describes the IP address as the one recorded when the customer interacted with you, and the timestamp as the time of that interaction. It also lists the earliest and the most recent recorded interaction as the two moments a timestamp can describe.

02 — The rulesThree rules that will fail an upload

  • No timestamp on its own. Google says a timestamp cannot be sent without an IP address, and a row with only a timestamp returns an error.
  • Header names must match exactly, in English. The same page uses two names for the time column: “User Engagement timestamp” in the column list and “User Interaction timestamp” in the combined-file template.
  • Do not hash the new fields. If your pipeline hashes every column by default, the IP and time columns will be unusable.
Test before you scale

Because the help page names the time column two ways, upload a small test file first and check that both new columns are recognised before you rebuild a production feed around either header. Google’s guide says a match rate appears only once at least 100 rows match unique users, so make the test file big enough to produce one.

Google also points new integrations away from the Google Ads API for this job. The same guide recommends Data Manager, in the interface or through its own API, as the path forward for Customer Match. If you maintain an API integration, our note on Google Ads API versions and sunset dates covers the deadline that arrives first.

03 — The limitsWhere IP matching does not apply

Google’s guide says IP matching is not supported for end users in the European Economic Area, the UK or Switzerland. Google’s Customer Match policy goes further: it tells advertisers to leave IP data for those regions out of uploads, be open about how the data was collected, and obtain whatever consent the law requires.

The general Customer Match rules still apply on top. The list must come from a first-party context, meaning people shared the data with you directly, and your privacy policy must say you share customer data with service providers. For a UK or European advertiser with a mixed audience, the practical job is filtering rows by the customer’s location before upload. Our Consent Mode v2 guide covers the consent side of that pipeline.

04 — The catchOne address, many people

An IP address often belongs to more than one person. A household shares one. So does an office, and mobile networks commonly put many phones behind the same address. Google’s rule for an IP sent without a time is to match whoever most recently used it, which may not be the customer on your list.

That is the reason to send the timestamp. It tells Google which moment you mean, so the match can point to the person using the address then. Google has not published how much either column lifts match rates, so treat any improvement as something to measure on your own lists, not assume.

Stronger case
Consumer sites with logged sessions
IP plus time

Checkout, sign-up or app sessions where you logged the address and the moment, for customers outside the excluded regions.

Test first
Weaker case
B2B lists from office traffic
IP only

Many staff share one office address, so an IP without a time is likely to match the most recent user, not your contact.

Low confidence
No effect
EEA, UK and Swiss customers
Excluded

Google does not support IP matching for these users. Remove their IP data before upload.

Filter out

05 — DecisionShould you add IP data to your lists?

Most customers outside Europe, sessions logged with time
Add both columns to a test list and compare its match rate with the email-only version.
Test now
Most customers already give an email address
Keep email as the main key. Add IP data only for rows without an email.
Fill gaps
Audience spans the UK, EU and elsewhere
Filter by customer location before upload so no excluded-region IP data is sent.
Filter first
B2B list built from office traffic
Skip IP-only rows. Shared office addresses make the match unreliable.
Hold

Match quality is where audience work quietly succeeds or fails. Our write-up of identity errors and campaign returns shows how much a bad match can cost, and our first-party data playbook covers collecting session data server-side in the first place.

06 — ConclusionThe IP column is useful only with a time and a region filter

What to do this week

Run one test list with IP address and time for customers outside Europe, and compare its match rate with your email-only list

The new columns can widen an audience for advertisers who log sessions but collect few emails. They can also match the wrong person on a shared address, and they must never carry data for European, UK or Swiss customers. If you want the upload pipeline, filtering and match-rate testing set up properly, our paid media team builds and audits Customer Match feeds.

Digital Applied

Better audiences start with cleaner customer data.

We build Customer Match feeds that filter by region, format each column correctly and measure match rates, so the audience you pay to reach is the one you meant.

Customer Match feedsRegion filteringMatch-rate tests
Your next project

Audience data that matches

  • →Upload pipelines checked column by column
  • →Excluded regions filtered before upload
  • →Test lists before production changes
Questions and answers

The questions we get about IP matching

No. Google's upload guide says to pass the IP address and the timestamp as plain, unhashed strings. Email, phone and name fields are still hashed with SHA-256.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading