A privacy policy that describes your actual site
A privacy policy is a description of what your site collects and why. Most small business policies are copied templates describing a company that gathers far more than the owner ever has.
A privacy policy is a description of what your site collects and why. Most small business policies are copied templates describing a company that gathers far more than the owner ever has.
Short answer
A privacy policy tells visitors what you collect, why, who else sees it, and how long you keep it. For most small business sites the honest answer is short. A copied template that lists data you never gather is a written claim about your business that is not true. Nothing here is legal advice.
It answers four questions. What do you collect. Why do you collect it. Who else gets to see it. How long do you keep it.
A visitor deciding whether to fill in your form wants those answers in under a minute. So does anybody reviewing your site for a client or a partner.
Everything else on the page is detail hung off those four. If your policy does not answer them plainly, it is not doing its job.
There is a fifth question worth answering while you are there: what happens if somebody asks you to delete it. A policy that describes collection and never mentions deletion is only half the story.
Templates are written to cover every case. They mention advertising networks, profiling, data sold to partners and transfers overseas.
Most small sites do none of that. So the policy describes a business the owner does not run, and it is the only written statement about data on the whole site.
If somebody ever asks what you do with their details, your own policy is the first thing they will read. It should match the truth.
It also fails the only test that matters in practice. Somebody reading it before filling in your form is trying to work out whether you are careful, and a page describing an advertising network you do not run answers that badly.
Less than people assume. Whatever your contact form asks for. Server logs of page requests. An analytics tag if you added one.
That is often the whole list. No accounts, no payments on the site, no tracking network, no profiles.
Write that list down first, then write the policy from the list. Working in that order keeps you honest and takes an hour rather than a day.
Embedded things count. A map, a video player, a booking widget, a chat box. Each one usually loads from another company and can see that a visitor arrived.
So does an email list tool, and any form that posts to a service rather than to your own site.
List them by name. A visitor cannot judge what they have agreed to if the page never mentions the third parties involved.
This is the question most policies skip and most readers care about. An enquiry sitting in an inbox for nine years is a real answer, just not a good one.
Pick a period you can actually keep to. Say what happens at the end of it. Then set a reminder and do it.
Short retention is easier to honor, easier to explain, and means less to lose if anything ever goes wrong.
Pick a period you can keep to and then actually keep to it, which is covered in form data and how long to keep it.
In the footer of every page, beside your terms. Write it in plain words rather than legal drafting, because the reader is a customer and not a court.
Date it, and change the date when you change the policy. An undated page tells a reader nothing about whether it still describes you.
Pages here are written from a conversation about your business, and your policy publishes exactly as you gave it. We do not rewrite it for you.
We will not draft your policy or tell you that a template makes you safe. Nothing here is legal advice, and rules differ by state and by what you collect.
What we will do is keep the page structural, readable and easy to find, and check it before anything publishes like every other page.
If you collect more than the simple list above, that is the point to get a professional to look at it.
The dividing line is simple enough to state: we handle how the page is built, reached and read. What it says about your business is yours, because only you know what your business actually does.
You are still collecting personal details, so a short honest page is sensible. Whether you are required to have one depends on your situation, and that is a question for a lawyer.
As a starting structure, yes. Then cut everything that does not describe you. The editing is the part that makes it useful.
No. A banner asks for consent to a narrow thing. The policy explains the whole picture, including the data your form collects.
Whenever you add a tool that touches visitor data, and once a year otherwise. Most policies drift out of date because a widget was added and nobody told the page.
15-day free trial. Card required. Cancel before day 15 and you pay nothing.