ToolNest

Ecommerce Privacy Policy Generator

An online store touches more personal data than almost any other small-business site, and the touchpoints are easy to undercount: analytics and ad cookies before the purchase, billing and shipping details during it, a payment processor holding the card data, a carrier receiving the address, and a marketing list receiving the follow-up. A store privacy policy that only describes "contact form data" is misdescribing its own checkout.

Generate the policy with the order, advertising and marketing boxes ticked, and read the sections below — they trace where data is created in a single order and flag the consent and retention points where ecommerce stores most often get into trouble.

Must be a mailbox you actually read.

Shown as 'last updated'. Fill it in when you publish.

What does your site do?
Adds the disclosures Google requires
Adds the analytics cookie clause
Adds consent and unsubscribe wording
Adds orders and payment-processor clauses
Adds registration-data wording
Adds legal bases and data rights
Adds California rights and opt-outs

Fill in: Site name, Site URL, Contact email — placeholders remain until you do.

A privacy policy alone does not satisfy the EU/UK consent requirement for personalized ads — a cookie consent banner must appear before ad scripts load. Pair this policy with a consent mechanism.

Under California law (CPRA), personalized advertising can count as "sharing". If you run ads for California visitors, add an opt-out link (for example "Your Privacy Choices") near the site footer, not only inside this policy.

Marketing email needs opt-in consent in the EU/UK and an unsubscribe option everywhere (CAN-SPAM). Make sure the signup form and email footer match what this policy promises.

PRIVACY POLICY



Last updated: [DATE]



This Privacy Policy explains how [SITE NAME] ("we", "us") collects, uses and protects information when you visit [SITE URL] (the "Site"). We collect only what the Site needs to work, and this page tells you exactly what that is, what we use it for, and what choices you have.



1. Information we collect

Information you give us:
  • Contact and support — if you email us or use a contact form, we receive the name, email address and contents of your message.
  • Newsletter — if you subscribe, we store your email address and send the updates you asked for. Every email carries an unsubscribe link.
  • Orders — if you buy something, we collect the billing name, email address, shipping address and order details. Payments run through our payment processor; we never receive or store your full card number.
  • Technical records — like most websites, we log your IP address, browser type, referring page, pages viewed and timestamps when you browse.

2. How we use information
We use the information above to operate, secure and troubleshoot the Site; respond to your messages; deliver purchases and handle refunds; understand how the Site is used and improve it; display the advertising that funds the Site; send the newsletter you asked for; comply with the law and prevent abuse.

We do not sell personal information to anyone, and we do not share it with third parties except the service providers listed in section 4, or where the law requires it. Note for California residents: personalized advertising can count as "sharing" for cross-context behavioural advertising under California law — section 3 explains how to opt out.

3. Cookies and similar technologies

Advertising — the Site is funded by advertising. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this Site or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this Site and/or other sites on the Internet. You may opt out of personalized advertising by visiting Google's Ads Settings (https://www.google.com/settings/ads), or opt out of a third-party vendor's use of cookies for personalized advertising at https://www.aboutads.info. Google's partner-site policies are described at https://policies.google.com/technologies/partner-sites.

Analytics — we use Google Analytics to understand aggregate usage of the Site. It sets cookies that distinguish visits from one another but do not identify you by name. You can opt out with Google's browser add-on at https://tools.google.com/dlpage/gaoptout or by blocking analytics cookies in your browser.

Essential cookies keep the Site working and remember preferences such as your settings. You can block or delete cookies in your browser at any time; parts of the Site may then stop working.

4. Third-party services
We share information only with the services that operate the Site: advertising partners (Google AdSense), Google Analytics, our payment processor, our email delivery provider. Each processes data under its own privacy policy. We do not otherwise disclose personal information except to comply with law, enforce our terms, or protect the rights and safety of the Site and its users.

5. Retention and security
We keep personal information only as long as the purposes above require, then delete or anonymize it. We protect it with reasonable technical and organisational measures. No method of transmission or storage is perfectly secure, so we cannot promise absolute security.

6. Your rights and choices
If you are in the EU or UK: we process personal data under these legal bases — consent (advertising and analytics cookies, the newsletter), contract (accounts and orders), and legitimate interests (security and site logs). You have the right to access, correct, erase, restrict and port your data, to object to processing, and to withdraw consent at any time; withdrawing consent does not affect earlier lawful processing. You can also complain to your local supervisory authority. Email [CONTACT EMAIL] to exercise any of these rights.

If you are a California resident: you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its "sale" or "sharing" for cross-context behavioural advertising. We do not sell personal information for money. To exercise any right, email [CONTACT EMAIL]; we will verify your request and respond within the time the law allows, and we will never discriminate against you for exercising these rights.

Everyone else: email [CONTACT EMAIL] and we will help with the equivalent requests.

7. Children
The Site is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has given us personal information, email [CONTACT EMAIL] and we will delete it.

8. Changes to this policy
We will post any changes on this page and update the "last updated" date. Significant changes will be flagged more prominently.

9. Contact
Questions about this policy: [CONTACT EMAIL] — or write to us through the contact page on [SITE URL].

This generator writes the policy, not your compliance. Only tick what is genuinely true — a policy describing data practices you don't have is worse than no policy. Set the date when you publish it.

Starting values are set for a typical online stores scenario — change any field to match yours. Need the plain version? Privacy Policy Generator.

The data trail of one order

Every step of a purchase creates personal data held by someone different. The policy needs to describe all of it, because regulators and payment processors both treat an incomplete description as a red flag.

Where data is created, and who holds it
StepData createdWho holds it
Customer browsesAnalytics events, advertising cookies, IP addressYou + analytics and ad vendors
Checkout beginsBilling name, email, shipping address, order contentsYou (and your platform)
Payment runsCard details, transaction recordPayment processor only — you never store the full number
Order shipsShipping address, trackingYou + the carrier
Follow-up marketingEmail address, purchase historyYou + your email platform
The payment row matters most: your policy should say plainly that card data goes to the processor and is not stored by you — that sentence satisfies both users and PCI-DSS expectations.

Marketing consent is where stores get fined

The purchase is a transaction; the marketing list is a separate consent. Treating the first as permission for the second is the single most common EU enforcement finding against small stores.

  • Pre-ticked newsletter boxes at checkout are invalid under the GDPR — consent must be an unticked, optional box with its own purpose statement.
  • An order confirmation email is transactional; a "you might also like" blast is marketing. EU customers need to have opted in before the second category is sent.
  • Abandoned-cart emails are marketing too. They are allowed where consent exists, and in the US they must carry a working unsubscribe under CAN-SPAM.
  • Ad retargeting pixels can amount to "sharing" for cross-context behavioural advertising under California's CPRA — honour opt-outs and the Global Privacy Control signal, and say so in the policy.
  • Consent records need to be kept: who consented, when, to what wording. That record is your defence when a complaint arrives.

Retention: how long stores keep what

  • Order records: keep for your tax and accounting law — commonly six to seven years — and say that is the reason. It is the longest legitimate retention in the store.
  • Marketing lists: until unsubscribe, then delete rather than flag-and-hold unless the law of your market requires a suppression list.
  • Abandoned carts and checkout analytics: months, not years; match your analytics tool's retention setting and state it.
  • Customer support threads: a reasonable service period, then purge or anonymise.
  • The one-sentence rule for the policy: state a period or a criterion ("as long as needed for the purpose above"), never "indefinitely".

Frequently asked questions

What personal data does an online store collect?
More than the checkout: analytics and advertising cookies from the browsing session, contact and billing details from the order, shipping details passed to a carrier, card details held by the payment processor, and the email address behind any marketing list. A compliant policy names each of those and who holds the data at each step.
Do I need a privacy policy if I only sell a few products?
Yes, once you take orders. The volume is irrelevant; taking payment and shipping to a named individual is personal-data processing under every major regime, and your payment processor and ad networks will require a policy regardless.
Who is responsible for the data — me or my platform?
Both, in different roles. The platform (Shopify, WooCommerce host, marketplace) processes data to run the infrastructure; you decide the purposes — marketing, analytics, retention — which makes you the controller of your store's data under GDPR terms. Your policy describes your decisions; the platform's own policy covers its role.
Do I have to name my payment processor in the policy?
You must disclose that payments are handled by a third party and that you do not store full card details. Naming the processor in the third-party services section is the cleaner practice — users recognise the name, and it pre-empts the most common checkout privacy question.
Are abandoned-cart emails allowed?
With consent, yes. In the EU they are marketing like any other and require opt-in; in the US they must carry unsubscribe and sender identification under CAN-SPAM. What is not allowed anywhere is treating a half-filled cart as implied permission — the email follows from the consent, not from the cart.
Do ad pixels count as selling data under CCPA?
Advertising pixels that enable cross-context behavioural advertising count as "sharing" under the CPRA even though no money changes hands, and the opt-out right applies. The practical response is an honour-the-GPC stance and a "Your Privacy Choices" link, both of which the generated policy supports when the California and advertising boxes are ticked.