Free tool · No signup

Free privacy policy generator

Answer three short questions about your store. Get a privacy policy you can copy straight onto your site.

  • Free forever
  • No signup
  • GDPR & US state law
  • Nothing uploaded

How to write a privacy policy.

Three questions, about a minute. The policy is written as you answer.

  1. Name your store

    Your business name, your website, an email customers can write to, and the country you are based in. That email is where data requests will arrive, so use one you read.

  2. Say what you collect

    Names, addresses, phone numbers, payment records, cookies. The common ones for a store are already selected. Turn off anything you do not collect, because a policy that claims more than you do is as wrong as one that claims less.

  3. Say who else handles it

    Your payment provider, your courier, your analytics, your email tool. The policy names them by category, so it stays true the day you switch from one to another.

  4. Read it, then publish it

    Copy the policy onto a page at yourstore.com/privacy, or download it as a PDF to file and send on. Link it from your footer and your checkout, and read it through first. It describes what you do, and only you know if it is right.

Jump back to the generator

Which law applies to you.

It follows your customers, not your office. Selling to someone in Berlin puts you inside the GDPR wherever you are.

  • UK & EU GDPR

    Any customer in the UK or the European Union.

    The strictest, and the easiest to fall under. You need a legal basis for every use of data, a policy written in plain language, and an answer to data requests within a month. It catches a one-person store shipping a single order into the EU.

  • US state privacy laws

    Customers in California, and a growing list of other states.

    The CCPA and its successors give people the right to know, delete and correct what you hold, and to opt out of their data being sold or shared for advertising. Thresholds vary by state, but the disclosure costs you nothing to make.

  • PIPEDA

    Customers in Canada.

    Requires meaningful consent, a stated purpose for collection, and access to what you hold on request. Complaints go to the Office of the Privacy Commissioner of Canada.

  • Everywhere else

    Every store, everywhere.

    Most countries now have a data protection law of their own, and app stores, payment providers and ad platforms all require a published policy before they will work with you. A missing policy is the most common reason a merchant account is refused.

What a privacy policy has to say.

Every privacy law asks for roughly the same things. The generator writes all of them; here is what each one is for.

  • Who you are

    Your business name and a way to reach you. Without it the rest of the document belongs to nobody, and a customer has nowhere to send a request.

  • What you collect

    Listed by category, not vaguely. “Your name, email and delivery address” is a disclosure; “certain information” is not.

  • Why you collect it

    A purpose for each category. If you cannot name a reason you need something, that is a sign to stop collecting it rather than a sign to write around it.

  • Who you share it with

    Your payment provider, courier, analytics and email tools. Named by category, so the policy does not go stale when you change supplier.

  • How long you keep it

    Order records usually have to be kept for years for tax. Analytics and marketing lists do not. Say which is which.

  • What rights people have

    A copy of their data, a correction, a deletion, and an unsubscribe. Plus the extra rights the GDPR and US state laws add, and the address to send the request to.

Before you publish it.

The generator writes the document. These six are yours, and none of them take long.

  • Read every line

    It was written from three answers. You know things about your store that three answers cannot carry, and the document is yours the moment you publish it.

  • Delete what you do not do

    If you do not run ads, do not keep the advertising paragraph. Claiming a practice you do not have is still an inaccurate policy.

  • Put it at a stable address

    yourstore.com/privacy, and leave it there. Payment providers, ad platforms and app stores all check that link, sometimes years later.

  • Link it from the footer and the checkout

    A policy nobody can find does not count as notice. The footer of every page and the checkout are the two places people look.

  • Check the email works

    Data requests arrive at the address in the policy, and the clock starts when they do. Send yourself one and make sure it lands.

  • Get advice if the data is sensitive

    Health, financial, biometric or children’s data raises the bar well past a template. So does selling data on. Talk to a lawyer in your country.

Privacy policy generator questions.

Is this privacy policy generator free?

Yes. It is free with no signup, no limit, and no watermark on what it produces. You own the policy it writes.

Is the generated privacy policy legally binding advice?

No. It is a template written from your answers and it is not legal advice. It covers what a normal online store does, in the language privacy laws expect. Read it before you publish it, and take advice from a lawyer if you handle health, financial or children’s data.

Does my online store actually need a privacy policy?

Almost certainly. If you take a name and an address to ship an order, you are processing personal data, and the GDPR, US state laws and most other privacy laws require you to say so. Payment providers, ad platforms and app stores also refuse accounts without a published policy.

Is the policy GDPR compliant?

It includes what the UK and EU GDPR require a policy to disclose: your identity, what you collect, your legal bases, who receives it, how long you keep it, international transfers, and the full list of rights. Compliance is about what you do as well as what you write, so the document is one part of it.

Does it cover the CCPA and other US state laws?

Yes. Select United States in the first step and the policy adds the right to know, delete and correct, the opt-out of sale or sharing, and the promise not to treat anyone differently for asking.

Where do I put the privacy policy on my store?

On its own page at a stable address such as yourstore.com/privacy, linked from the footer of every page and from the checkout. Keep the link working, because it gets checked long after you publish it.

Is anything I type sent to a server?

No. The policy is assembled in your browser from your answers. Nothing is uploaded, nothing is stored, and closing the tab clears it.

Can I edit the policy after I generate it?

Yes, and you should. Copy it into any editor and change whatever does not describe your store. You can also go back and change an answer, and the document rewrites itself as you do.

How often should I update my privacy policy?

Whenever what you do with data changes: a new analytics tool, a new email provider, a new country. Review it once a year even if nothing changed, and update the date at the top when you do.

Do I need a cookie banner as well?

If you use analytics or advertising cookies and have visitors in the UK or EU, yes. Consent for those has to be collected before the cookie is set, which a policy alone cannot do. Essential cookies that keep a basket working do not need one.

Policy done. Now the store.

Turn a Google Sheet into an online store with a free web address. No coding, and no commission on your orders.

0% Commissions  •  No Coding