Privacy Policy Generator for Online Stores

Answer a short form about your store and get a full privacy policy as HTML or plain text, ready to copy or download.

Privacy policy generator

Business details
Store platform
Data you collect
Payment providers
Analytics and ad pixels
Marketing
Laws and children
Updates as you change the form. Your answers are saved in this browser only.
This policy is a starting template, not legal advice. Privacy laws differ by country and state. Read the whole text, fix anything that does not match your store, and have a lawyer review it if you handle sensitive data.

In short

To create a privacy policy for your online store, fill in the form above: business details, platform, the data you collect, payment providers, analytics and ad pixels, email or SMS marketing, and whether GDPR or CCPA applies. The policy updates as you type. Copy or download it as HTML or plain text and publish it.

On this page
  1. How to use the privacy policy generator
  2. What the generated policy covers
  3. Does every website need a privacy policy?
  4. A worked example
  5. Why Merchant Center and payment providers expect a privacy policy
  6. Where to add the policy
  7. GDPR, CCPA and children's data
  8. Keeping the policy accurate
  9. Common mistakes
  10. Privacy of this tool
  11. Related tasks

Every online store collects personal data: names and addresses to ship orders, emails for receipts, and usually browsing data through analytics and ad pixels. A privacy policy tells customers what you collect, why, who you share it with and how they can exercise their rights. This tool writes one based on how your store actually works, naming the tools you use rather than filling the page with generic clauses.

Note: The generated policy is a starting template, not legal advice. Privacy laws differ by country and state and change over time. If you sell into regulated markets or handle sensitive data, have a lawyer review the final text.

How to use the privacy policy generator

  1. Enter your business details: store name, website URL, privacy contact email, country, postal address and the "last updated" date.
  2. Pick your platform: Shopify, WooCommerce or other. For other platforms, name your host or platform provider so the policy says who stores your data.
  3. Tick the data you collect: contact details, shipping and billing addresses, order history, payment details (through payment providers), customer accounts, device and usage data, support messages, and reviews or photos customers submit.
  4. Tick your payment providers: Shopify Payments, Stripe, PayPal, Apple Pay and Google Pay, or buy now, pay later providers.
  5. Select your tracking tools: Google Analytics, Meta Pixel, Google Ads conversion tracking, TikTok Pixel, Pinterest Tag and Microsoft Clarity. Each one gets its own description and opt-out link.
  6. Say whether you send marketing email or SMS, and optionally name your email platform, such as Klaviyo.
  7. Choose the laws that apply: GDPR and UK GDPR, CCPA/CPRA, international data transfers, and whether you knowingly collect data from children under 13.
  8. Set how long you keep records (3 to 10 years) and add an EU or UK representative if you appointed one.
  9. Review, then copy or download. Switch between the preview, HTML and plain text tabs, check the word count, and use Copy HTML or Download .html for your store.

Your answers are saved in this browser, so you can come back and regenerate the policy when your tools change.

What the generated policy covers

SectionWhat it explainsDriven by
Who we areBusiness name, address and how to contact you about privacyBusiness details
Information we collectThe categories of personal data and how you get themData collected
How we use your informationOrder fulfillment, customer service, fraud prevention, marketingData collected, marketing choices
Legal bases (EU and UK)Contract, legitimate interests, consent and legal obligationGDPR choice
Cookies, analytics and pixelsEach tool you use, who runs it, what it does and how to opt outTracking tool choices
Marketing messagesConsent, unsubscribing, SMS termsEmail and SMS choices
How we share your informationPlatform, payment processors, carriers, ad partnersPlatform, payment and pixel choices
Retention and securityHow long you keep data and how it is protectedRetention choice
International transfersWhere data is stored and the safeguards usedTransfer and GDPR choices
Your rights and choicesAccess, correction, deletion, opting out, how to make a requestGDPR and CCPA/CPRA choices
Children's privacyWhether you knowingly collect data from childrenChildren's data choice
Changes and contactHow you update the policy and where to send questionsBusiness details

Does every website need a privacy policy?

Any site that collects personal information, including an email signup form, a contact form, or analytics that record IP addresses, should have one, and an online store always does. The reasons stack up:

  • Laws. The EU and UK GDPR require clear privacy information for people in those regions. In the US, California's CCPA/CPRA applies to businesses with more than $26.625 million in annual revenue, or that buy, sell or share data on 100,000 or more California consumers or households, or earn half their revenue from selling or sharing data. California's older CalOPPA law requires any commercial website that collects personal information from California residents to post a privacy policy, regardless of size, and a growing list of other US states have their own privacy laws.
  • Tools. Google Analytics terms require a privacy policy that discloses your use of cookies, and Meta's business tools terms require clear notice when you use the Meta pixel.
  • Platforms. Google Merchant Center, Stripe and PayPal all look for visible policy pages when they review a store.

A worked example

A US Shopify store selling candles uses Shopify Payments and PayPal, Google Analytics and the Meta Pixel, sends Klaviyo emails and ships to the UK and EU. The right answers: platform Shopify; contact, address, order, payment and device data ticked; Google Analytics and Meta Pixel ticked; marketing email on with Klaviyo named; GDPR and UK GDPR on, because it sells to people there; CCPA off, because it is well under the thresholds; international transfers on; retention 5 years. The policy then names each tool with its opt-out link, lists the legal bases for EU and UK buyers, and explains transfers to the US. If the store adds a TikTok Pixel next month, tick it, regenerate and update the date.

Why Merchant Center and payment providers expect a privacy policy

Google Merchant Center reviews your website, not just your product feed. Its checkout requirements say to collect only the personal details needed to process an order, protect them with SSL, and never sell customer contact details. A store that collects data with no visible explanation of how it is used looks less trustworthy to reviewers, and missing policy pages are a common gap behind misrepresentation suspensions. Stripe's website checklist lists a privacy policy alongside refund, shipping and contact information.

Where to add the policy

Shopify

  1. In Shopify admin, go to Settings > Policies.
  2. Open Privacy policy, paste the HTML version and click Save.
  3. Shopify links your policies in the checkout footer automatically. Also add the policy to your store footer menu under Online Store > Navigation.

Shopify also offers automated privacy policy updates tied to its customer privacy settings. If you use that option, compare its text with this output instead of running two different policies.

WooCommerce and WordPress

  1. In WordPress, create a page called Privacy Policy and paste the HTML version (use the Custom HTML block or the code editor).
  2. Go to Settings > Privacy and select that page as your privacy policy page.
  3. In WooCommerce > Settings > Accounts and Privacy, check the privacy text shown at registration and checkout.
  4. Add the page to your footer menu so it is reachable from every page.

Other platforms

Create a page at a simple URL such as /privacy-policy, paste the HTML or plain text, and link it in the footer and next to every form that collects email addresses.

GDPR, CCPA and children's data

  • GDPR applies when you offer goods to people in the EU, and the UK has its own equivalent. The policy must list the legal basis for each use of data and rights such as access, erasure and portability.
  • CCPA/CPRA covers California residents, but only businesses that meet its thresholds. If you qualify, you need to explain rights to know, delete, correct and opt out of the sale or sharing of personal information, which includes some ad pixel use.
  • Children's data: in the US, COPPA restricts collecting data from children under 13. Most stores state that they do not knowingly collect it, which is what the generator writes unless you tick the children's box.

Keeping the policy accurate

A privacy policy is only useful while it matches what your store really does. Review it whenever you install an app that collects customer data (reviews, loyalty, live chat), add or remove an ad pixel or email platform, start selling into a new country or state, or change who fulfills orders, for example a dropshipping supplier who receives customer addresses. Regenerate, compare with your live page, and update the "last updated" date.

Common mistakes

  • Copying another store's policy. It will name their tools and partners, not yours.
  • Forgetting new tools. Adding a TikTok pixel or a new email platform means updating the policy.
  • Hiding the page. Link it in the footer on every page, not only at checkout.
  • Using an unmonitored email. Privacy requests need a real reply, and GDPR gives you one month to answer.
  • Claiming what you do not do. Do not say you never share data if you run ad pixels. The generator words pixel sharing honestly.

Privacy of this tool

The policy is written entirely in your browser. Your business details and answers are stored only in this browser so you can edit later, and nothing is sent to AM Jarvis.

Next, create your returns and shipping pages with the refund and shipping policy generator, and read how to set up Google Merchant Center on Shopify. If you run Google Shopping, the AM Jarvis GMC Scanner and Fixer checks a connected store for missing policy pages and contact information and can push fixes to the store.

Frequently asked questions

Does an online store need a privacy policy?

Yes. Privacy laws such as GDPR and California's CalOPPA and CCPA require one in many cases, Google Analytics and the Meta pixel require you to disclose their use, and Google Merchant Center and payment providers like Stripe expect a visible policy. Any store that collects names, emails or addresses should publish one.

Do I need a privacy policy on my website if I do not sell anything?

If the site collects any personal data, such as a newsletter signup, a contact form, comments or analytics that log IP addresses, you should have one. California's CalOPPA requires commercial sites that collect personal information from California residents to post a policy, and GDPR applies to visitors in the EU and UK.

Is a generated privacy policy legally valid?

A generated policy is a template based on your answers, not legal advice. It covers the common sections most stores need, but it cannot know every law that applies to your business. Review it carefully, keep it accurate as your tools change, and have a lawyer check it if you handle sensitive data.

Where do I add a privacy policy in Shopify?

Go to Settings > Policies in Shopify admin, open Privacy policy, paste your text and save. Shopify links store policies in the checkout footer automatically. Add the policy to your footer menu under Online Store > Navigation so it is also reachable from every storefront page.

Does CCPA apply to my small store?

Probably not. In 2026 the CCPA applies to businesses with more than $26.625 million in annual revenue, or that buy, sell or share data on 100,000 or more California consumers or households, or earn half their revenue from selling or sharing data. Tick the CCPA box only if you meet one of these.

Do I need a privacy policy for Google Merchant Center?

Merchant Center reviews your site for trust signals, and its checkout guidance covers how you collect and protect personal data. A missing privacy policy is a common gap in stores that get flagged for misrepresentation, so publish one, link it in your footer and keep your contact details visible.

What should an ecommerce privacy policy include?

It should list what personal data you collect, how you use it, which cookies, analytics and ad pixels you run, who you share data with (platform, payments, shipping, ad partners), how long you keep it, what rights customers have, and how to contact you about privacy.

How often should I update my privacy policy?

Whenever your data practices change: a new pixel, email platform, app, fulfillment partner or market. Otherwise, review it at least once a year and update the "last updated" date. The generator remembers your answers in this browser, so an update takes a few minutes.