Sell more with LaunchMyStore
LaunchMyStore Logo

Free legal template

Privacy policy generator

Answer a few questions about your store, get a privacy policy you can publish today. A starting template, not legal advice.

Your store

Privacy policy details

This is a template, not legal advice. Review it, adapt it to your business, and have a lawyer check it if you sell in regulated categories.

Privacy Policy

[Store name] · Effective September 7, 2026

1. Overview

This Privacy Policy describes how [Store name] ("we", "us" or "our") collects, uses and shares your personal information when you visit [website URL] (the "Site"), buy something from us, or otherwise communicate with us. It takes effect on September 7, 2026.

By using the Site you agree to the collection and use of information as described here. If you do not agree, please do not use the Site or place an order.

2. Information we collect

We collect the following types of personal information:

  • Device information: your browser type, IP address, time zone, approximate location, the pages or products you view, the site that referred you, and how you interact with the Site. We collect this automatically using cookies, log files and similar technologies.
  • Order information: your name, billing address, shipping address, email address, phone number and the items you buy. Payment card details are entered directly with our payment processor; we never see or store your full card number.
  • Account information: if you create an account, we store your name, email address, a hashed version of your password, your order history and any saved addresses.
  • Marketing preferences: whether you have signed up for our emails, which emails you open, and which links you click, so we can send you things you are more likely to want.
  • Customer support information: anything you send us when you contact us, including the contents of your messages and any attachments.

3. How we use your information

We use the information we collect to:

  • Fulfilling orders: processing your payment, arranging shipping, sending order confirmations and updates, and handling returns or refunds.
  • Communicating with you: answering your questions and telling you about changes to your order or to our policies.
  • Preventing fraud: screening orders for risk and protecting the Site, our customers and ourselves from abuse.
  • Improving the Site: understanding how visitors use the Site so we can fix problems and make it better.
  • Marketing: sending you product news, offers and abandoned-cart reminders when you have agreed to receive them. Every marketing email includes an unsubscribe link, and you can opt out at any time.
  • Legal compliance: keeping the records we are required to keep by tax, consumer-protection and other laws.

4. Cookies and analytics

A cookie is a small file stored on your device when you visit a site. We use cookies that are essential for the Site to work (for example, to keep items in your cart and to remember that you are logged in), and, where you allow it, cookies that help us understand and improve the Site.

Google Analytics: we use Google Analytics to understand how visitors find and use the Site. Google collects information such as the pages you visit, how long you stay and the device you use. You can read how Google uses this data at https://policies.google.com/privacy and opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.

You can control cookies through your browser settings, including blocking or deleting them. If you block essential cookies, parts of the Site, including checkout, may not work.

5. How we share your information

We share your personal information with third parties only where needed to run the store, and never sell it to data brokers:

  • Payment processors: Stripe process your payment on our behalf. They receive your card details and billing information directly and handle them under their own privacy policies (Stripe: https://stripe.com/privacy).
  • Shipping carriers: we share your name, address and phone number with the carriers who deliver your order so they can get it to you and contact you about the delivery.
  • Email service providers: the platform we use to send emails stores your email address and engagement data on our behalf.
  • Analytics and advertising partners: Google, as described in the cookies section above.
  • Service providers: the platform that hosts our store and other providers who help us run the business, all of whom may only use your information to provide their service to us.
  • Legal requirements: we may disclose information to comply with the law, respond to a lawful request, or protect our rights.
  • Business transfers: if we sell or merge the business, your information may be transferred to the new owner, who will be bound by this policy.

6. How long we keep your information

We keep order information for three years after your last order, unless a longer period is required by law, needed to resolve a dispute, or needed to enforce our agreements.

Account information is kept for as long as your account is open. You can ask us to delete your account at any time, after which we keep only the records we are legally required to keep.

Device and analytics information is kept in aggregated form that no longer identifies you.

7. Your rights under GDPR and UK GDPR

If you are in the European Economic Area, Switzerland or the United Kingdom, we process your personal information on the following legal bases: performance of our contract with you (to fulfil your order); our legitimate interests (to run and improve the Site and prevent fraud); your consent (for marketing and non-essential cookies); and compliance with our legal obligations.

You have the right to:

  • Access the personal information we hold about you and receive a copy of it.
  • Correct inaccurate or incomplete information.
  • Ask us to delete your information, where we have no overriding reason to keep it.
  • Restrict or object to our processing of your information.
  • Receive your information in a portable, machine-readable format.
  • Withdraw consent at any time where we rely on consent, without affecting processing that has already taken place.

To exercise any of these rights, email us at [contact email]. We will respond within one month. You also have the right to lodge a complaint with your local data protection authority.

Because we and our service providers may be located outside your country, your information may be transferred across borders. Where we transfer information out of the EEA or UK, we rely on standard contractual clauses or another lawful transfer mechanism.

8. Your rights under California law (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use and disclose, and receive a copy of it.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information.
  • Not be discriminated against for exercising any of these rights.

We do not sell or share your personal information as those terms are defined under California law.

To exercise your rights, email [contact email]. We may need to verify your identity before responding. You can also authorise an agent to make a request on your behalf.

9. Security

We use reasonable technical and organisational measures to protect your personal information, including encryption in transit (HTTPS) and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Children

The Site is not intended for anyone under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us at [contact email] and we will delete it.

11. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or for legal reasons. The date at the top shows when it was last changed. If the changes are significant, we will let you know by email or with a notice on the Site.

12. Contact us

Questions about this policy or your personal information? Email us at [contact email].

[Store name], [your country or state].

Your store details stay in this browser so the other three policies are pre-filled. Nothing is uploaded.

Need a store for it?Try LaunchMyStore free
1

Answer a few questions

What you collect, which payment processors and marketing tools you use, and where you ship.

2

Get a formatted policy

Sections for data collected, cookies, third parties, retention and user rights, written in plain language.

3

Copy it onto your store

Paste the text into your Privacy Policy page. Update it whenever you add a new app or tool.

What a store privacy policy needs to cover

A privacy policy tells a visitor what you collect about them, why, and who else sees it. For an online store that means: personal data collected at checkout (name, address, email, phone), payment data (usually handled entirely by your payment processor, not stored by you), account data if customers can log in, and behavioral data from cookies and analytics.

It should also name the third parties involved. That is your payment gateway, your email marketing tool if you send newsletters or abandoned cart emails, your analytics provider, and any ad pixels you run for retargeting. State how long you keep data, and tell people how to ask you to delete or export theirs.

Keep the language plain. A policy nobody can read is a policy nobody trusts, and regulators increasingly expect plain language over legal boilerplate.

GDPR, UK GDPR and CCPA/CPRA basics

If you have customers in the EU or UK, GDPR and UK GDPR expect you to name your legal basis for processing data (usually contract, for an order, or consent, for marketing), list the third parties you share data with, and explain how someone requests access to or deletion of their data.

If you have customers in California, CCPA and its update CPRA expect you to disclose categories of personal information collected and sold or shared (including for ad targeting), and give residents a way to opt out of sale or sharing, often as a Do Not Sell or Share My Personal Information link. Other US states, including Virginia, Colorado and Connecticut, have similar laws with their own thresholds.

You do not need to be a large company for these to apply. If you sell to residents of these regions, cover the basics rather than skip them.

Where to put it

Link the policy in your store footer on every page, and again at checkout near the box where a customer agrees to your terms. If you send marketing email, link it in the footer of every campaign too, since that is where a regulator or an ISP will look first.

Frequently asked questions

Is this privacy policy generator free?
Yes. Answer the questions and copy the text with no signup.
Is the generated policy legal advice?
No. This is a starting template based on common ecommerce practice, not legal advice. Have a lawyer review it before you rely on it, especially if you operate in multiple countries or handle sensitive data.
Does it cover GDPR and CCPA?
It includes the common GDPR, UK GDPR and CCPA/CPRA sections: legal basis for processing, data sharing disclosures, retention, and how a user requests access, deletion or opt-out. You should still confirm it matches your actual data practices.
Do I need a privacy policy if I am a small store?
Yes. If you collect any personal data, which every checkout does, most jurisdictions and most payment processors and ad platforms require a published privacy policy regardless of your size.
Do I need to mention cookies separately?
Cookies are usually covered inside the privacy policy under a Cookies section rather than a separate document, unless you run a cookie consent banner, in which case link the two together.
What if I use apps that collect their own data?
List them. Payment processors, review apps, live chat and analytics tools each collect data under their own privacy policy, and yours should say which tools you use and link to theirs.
How often should I update my privacy policy?
Whenever you add or remove a tool that touches customer data: a new payment gateway, a new marketing platform, a new analytics tool. Review it at least once a year even if nothing changed.
Can I use this if I sell internationally?
Yes, the template covers the common US and EU/UK bases. If a specific country you sell into has stricter rules, such as Brazil's LGPD or Canada's PIPEDA, add a line for it or have a lawyer check.

Free 7-day trial

Start your free store trial today.

No credit card required. Every tool on this page keeps working whether or not you sign up.