It's actually not given to Google in a user identifiable way. I am not privy to the details, but an overview was presented at a crypto conference:
https://www.youtube.com/watch?v=ee7oRsDnNNc&t=10m1sIt looks to me like a form of homomorphic encryption where both the aggregate consumer transactions (people bought X at merchant M), and the aggregate Google ad information (people saw ad for X at merchant M) are encrypted and the set intersection is computed on the ciphertext revealing only the aggregate number of purchases, not the individuals.
Now granted, there could be a security hole in this scheme as with any crypto-protocol, so it does need peer review, but the design, as stated in that YouTube presentation, is not to reveal to Google personal purchasing information, nor reveal to merchants, personal profile information. No personal financial data or purchasing information is supposedly transmitted.
The problem with this kind of technology is that it is really difficult to explain to the public, and easily demagogued.