Every online store collects personal data: names and addresses to ship orders, emails for receipts, and usually browsing data through analytics and ad pixels. A privacy policy tells customers what you collect, why, who you share it with and how they can exercise their rights. This tool writes one based on how your store actually works, naming the tools you use rather than filling the page with generic clauses.
Note: The generated policy is a starting template, not legal advice. Privacy laws differ by country and state and change over time. If you sell into regulated markets or handle sensitive data, have a lawyer review the final text.
How to use the privacy policy generator
- Enter your business details: store name, website URL, privacy contact email, country, postal address and the "last updated" date.
- Pick your platform: Shopify, WooCommerce or other. For other platforms, name your host or platform provider so the policy says who stores your data.
- Tick the data you collect: contact details, shipping and billing addresses, order history, payment details (through payment providers), customer accounts, device and usage data, support messages, and reviews or photos customers submit.
- Tick your payment providers: Shopify Payments, Stripe, PayPal, Apple Pay and Google Pay, or buy now, pay later providers.
- Select your tracking tools: Google Analytics, Meta Pixel, Google Ads conversion tracking, TikTok Pixel, Pinterest Tag and Microsoft Clarity. Each one gets its own description and opt-out link.
- Say whether you send marketing email or SMS, and optionally name your email platform, such as Klaviyo.
- Choose the laws that apply: GDPR and UK GDPR, CCPA/CPRA, international data transfers, and whether you knowingly collect data from children under 13.
- Set how long you keep records (3 to 10 years) and add an EU or UK representative if you appointed one.
- Review, then copy or download. Switch between the preview, HTML and plain text tabs, check the word count, and use Copy HTML or Download .html for your store.
Your answers are saved in this browser, so you can come back and regenerate the policy when your tools change.
What the generated policy covers
| Section | What it explains | Driven by |
|---|---|---|
| Who we are | Business name, address and how to contact you about privacy | Business details |
| Information we collect | The categories of personal data and how you get them | Data collected |
| How we use your information | Order fulfillment, customer service, fraud prevention, marketing | Data collected, marketing choices |
| Legal bases (EU and UK) | Contract, legitimate interests, consent and legal obligation | GDPR choice |
| Cookies, analytics and pixels | Each tool you use, who runs it, what it does and how to opt out | Tracking tool choices |
| Marketing messages | Consent, unsubscribing, SMS terms | Email and SMS choices |
| How we share your information | Platform, payment processors, carriers, ad partners | Platform, payment and pixel choices |
| Retention and security | How long you keep data and how it is protected | Retention choice |
| International transfers | Where data is stored and the safeguards used | Transfer and GDPR choices |
| Your rights and choices | Access, correction, deletion, opting out, how to make a request | GDPR and CCPA/CPRA choices |
| Children's privacy | Whether you knowingly collect data from children | Children's data choice |
| Changes and contact | How you update the policy and where to send questions | Business details |
Does every website need a privacy policy?
Any site that collects personal information, including an email signup form, a contact form, or analytics that record IP addresses, should have one, and an online store always does. The reasons stack up:
- Laws. The EU and UK GDPR require clear privacy information for people in those regions. In the US, California's CCPA/CPRA applies to businesses with more than $26.625 million in annual revenue, or that buy, sell or share data on 100,000 or more California consumers or households, or earn half their revenue from selling or sharing data. California's older CalOPPA law requires any commercial website that collects personal information from California residents to post a privacy policy, regardless of size, and a growing list of other US states have their own privacy laws.
- Tools. Google Analytics terms require a privacy policy that discloses your use of cookies, and Meta's business tools terms require clear notice when you use the Meta pixel.
- Platforms. Google Merchant Center, Stripe and PayPal all look for visible policy pages when they review a store.
A worked example
A US Shopify store selling candles uses Shopify Payments and PayPal, Google Analytics and the Meta Pixel, sends Klaviyo emails and ships to the UK and EU. The right answers: platform Shopify; contact, address, order, payment and device data ticked; Google Analytics and Meta Pixel ticked; marketing email on with Klaviyo named; GDPR and UK GDPR on, because it sells to people there; CCPA off, because it is well under the thresholds; international transfers on; retention 5 years. The policy then names each tool with its opt-out link, lists the legal bases for EU and UK buyers, and explains transfers to the US. If the store adds a TikTok Pixel next month, tick it, regenerate and update the date.
Why Merchant Center and payment providers expect a privacy policy
Google Merchant Center reviews your website, not just your product feed. Its checkout requirements say to collect only the personal details needed to process an order, protect them with SSL, and never sell customer contact details. A store that collects data with no visible explanation of how it is used looks less trustworthy to reviewers, and missing policy pages are a common gap behind misrepresentation suspensions. Stripe's website checklist lists a privacy policy alongside refund, shipping and contact information.
Where to add the policy
Shopify
- In Shopify admin, go to Settings > Policies.
- Open Privacy policy, paste the HTML version and click Save.
- Shopify links your policies in the checkout footer automatically. Also add the policy to your store footer menu under Online Store > Navigation.
Shopify also offers automated privacy policy updates tied to its customer privacy settings. If you use that option, compare its text with this output instead of running two different policies.
WooCommerce and WordPress
- In WordPress, create a page called Privacy Policy and paste the HTML version (use the Custom HTML block or the code editor).
- Go to Settings > Privacy and select that page as your privacy policy page.
- In WooCommerce > Settings > Accounts and Privacy, check the privacy text shown at registration and checkout.
- Add the page to your footer menu so it is reachable from every page.
Other platforms
Create a page at a simple URL such as /privacy-policy, paste the HTML or plain text, and link it in the footer and next to every form that collects email addresses.
GDPR, CCPA and children's data
- GDPR applies when you offer goods to people in the EU, and the UK has its own equivalent. The policy must list the legal basis for each use of data and rights such as access, erasure and portability.
- CCPA/CPRA covers California residents, but only businesses that meet its thresholds. If you qualify, you need to explain rights to know, delete, correct and opt out of the sale or sharing of personal information, which includes some ad pixel use.
- Children's data: in the US, COPPA restricts collecting data from children under 13. Most stores state that they do not knowingly collect it, which is what the generator writes unless you tick the children's box.
Keeping the policy accurate
A privacy policy is only useful while it matches what your store really does. Review it whenever you install an app that collects customer data (reviews, loyalty, live chat), add or remove an ad pixel or email platform, start selling into a new country or state, or change who fulfills orders, for example a dropshipping supplier who receives customer addresses. Regenerate, compare with your live page, and update the "last updated" date.
Common mistakes
- Copying another store's policy. It will name their tools and partners, not yours.
- Forgetting new tools. Adding a TikTok pixel or a new email platform means updating the policy.
- Hiding the page. Link it in the footer on every page, not only at checkout.
- Using an unmonitored email. Privacy requests need a real reply, and GDPR gives you one month to answer.
- Claiming what you do not do. Do not say you never share data if you run ad pixels. The generator words pixel sharing honestly.
Privacy of this tool
The policy is written entirely in your browser. Your business details and answers are stored only in this browser so you can edit later, and nothing is sent to AM Jarvis.
Related tasks
Next, create your returns and shipping pages with the refund and shipping policy generator, and read how to set up Google Merchant Center on Shopify. If you run Google Shopping, the AM Jarvis GMC Scanner and Fixer checks a connected store for missing policy pages and contact information and can push fixes to the store.