Documents / Website Policies

Website Privacy Policy

A clear, compliant privacy policy for your website or app — GDPR and CCPA sections included when you need them.

Time

⁨~7 min⁩

Questions

⁨17⁩

Steps

⁨3⁩

Export

⁨PDF · Word⁩

You will answer guided questions with a live preview, then export, share, or send for e-signature. Free during launch.

What we will cover

  1. 01

    Your Site

  2. 02

    Data You Collect

  3. 03

    Audience & Compliance

  4. 04

    Review and generate

    AI review, edits, export, and e-signature.

About this document

If your website or app collects anything about visitors — names, emails, payment details, analytics, cookies, IP addresses — you almost certainly need a privacy policy. GDPR requires notice for visitors in the EU, EEA, and UK regardless of where you are based; CCPA and CPRA impose disclosure and opt-out duties for California residents; and other US states have followed. The practical trigger arrives sooner than the legal one: Google, Apple, Meta, and Stripe all require a published policy as a condition of using their services.

The common mistake is pasting in a generic policy that describes practices you do not follow. A policy is a public statement of fact, and saying you do not share data with third parties while running analytics and ad pixels is the kind of inaccuracy regulators treat as a deceptive practice. List the categories you actually collect, name your processors, state your retention period, and update the document when your stack changes.

Common questions

Do I need a privacy policy for my website?+

In practice, yes, for almost any site that is not a static brochure page. GDPR, CCPA/CPRA, and a growing set of US state laws require notice once you handle personal data, and even a contact form or analytics script counts. Separately, app stores, ad networks, and payment processors require a live policy URL before they will approve you, so the requirement usually reaches you through a platform first.

Does GDPR apply to a US-based website?+

It can. GDPR reaches organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour, which includes analytics and advertising cookies on visitors located there. Simply being accessible from Europe is not usually enough on its own, but selling internationally or targeting EU users is. If you are unsure, including the GDPR rights section costs you nothing.

What happens if I do not have a privacy policy?+

The immediate consequences are commercial: app store rejection, ad account suspension, failed payment onboarding, and enterprise customers refusing to sign. The regulatory consequences follow from complaints and can include investigations and penalties under GDPR or state privacy laws. A policy that is inaccurate carries its own exposure, so update it when what you collect changes.

General information, not legal advice — laws vary by state and change over time.