Free Privacy Policy Generator (GDPR & CCPA Ready)

A privacy policy is a legal document that tells your users what data you collect, why you collect it, who you share it with, and what they can do about it. This generator produces a policy scoped to the data you actually collect — not a generic one that mentions cookies you don't set — and toggles on GDPR and CCPA disclosures if those apply to your users.

PRIVACY POLICY

Live document preview

Updates as you type

PRIVACY POLICY

Legal Disclaimer: This document is a general template and does not constitute legal advice. Consult a qualified attorney for advice specific to your situation and jurisdiction.

Effective Date: 2026-09-08

Website: [URL] · Operator: [Company]

1. Introduction

[Company] ("we", "us", "our") operates the website [URL] (the "Site"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have with respect to your data.

2. Information We Collect

We collect the following categories of personal information:

  • your name
  • your email address
  • cookies and device identifiers

3. How We Use Your Information

We use personal information to:

  • provide, operate and maintain the Site and our services;
  • respond to your enquiries and provide customer support;
  • process transactions and send related information such as confirmations and receipts;
  • send administrative information, including changes to our terms, conditions and policies;
  • improve the Site through analytics and usage measurement;
  • comply with legal obligations and enforce our terms.

4. Sharing With Third Parties

We share personal information with web analytics providers (e.g. Google Analytics) to the extent necessary for them to perform services on our behalf. These parties are bound by contractual confidentiality obligations and may only use the information for the purposes we specify.

5. Cookies and Tracking Technologies

We use cookies and similar technologies to remember your preferences, understand how you use the Site, and measure the effectiveness of our content. You can control cookies through your browser settings; disabling cookies may affect the functionality of the Site.

6. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When information is no longer needed, we securely delete or anonymise it.

7. Security

We implement commercially reasonable administrative, technical and physical safeguards to protect personal information against unauthorised access, alteration, disclosure or destruction. No method of transmission over the Internet is fully secure, and we cannot guarantee absolute security.

8. Your Rights Under GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights with respect to your personal data:

  • the right to access the personal information we hold about you;
  • the right to request correction of inaccurate or incomplete data;
  • the right to request erasure of your personal information;
  • the right to restrict or object to processing;
  • the right to data portability;
  • the right to withdraw consent at any time, where processing is based on consent;
  • the right to lodge a complaint with a supervisory authority.

9. Your Rights Under CCPA

If you are a California resident, you have the right to:

  • know what personal information we collect, use, disclose and sell;
  • request deletion of your personal information;
  • opt out of the sale of your personal information (we do not sell personal information as defined by the CCPA);
  • non-discrimination for exercising any of your CCPA rights.

10. Children's Privacy

The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on the Site with a new effective date.

12. Contact

To exercise any of your rights or ask questions about this Policy, contact us at [email].

Governed by the laws of California, USA.

Signed and Agreed

For [Company]
Authorised Signatory

Legal Disclaimer: This document is a general template and does not constitute legal advice. Consult a qualified attorney for advice specific to your situation and jurisdiction.

What the Privacy Policy Generator does

A privacy policy is a legal disclosure that tells users what personal data a website or app collects, why, who it is shared with, and what rights users have to access, correct or delete it.

Methodology and formula

Clause anatomy: Data Collected (by category) -> Legal Basis/Purpose of Processing -> Third-Party Sharing (processors, ad networks, subprocessors) -> Cookies and Tracking -> User Rights (access, rectification, deletion, portability) -> International Transfers -> Data Retention Period -> Contact/DPO Details -> Last Updated Date.

Worked example

Inputs
E-commerce site Lumen Home Goods, EU and California customers, collects name/email/shipping address/payment token via Stripe, uses Google Analytics, GDPR and CCPA toggles both enabled.
Result
9-section policy disclosing 4 data categories, 2 named subprocessors (Stripe, Google Analytics), GDPR lawful-basis statement for marketing consent, CCPA 'right to opt out of sale' notice with a Do Not Sell link, 24-month retention period.

Because Lumen has both EU and California customers, enabling both toggles produces one combined policy rather than two separate documents — the CCPA opt-out-of-sale notice and the GDPR consent basis coexist without contradicting each other.

When to use this tool

Publish a Privacy Policy on any site or app that collects personal data, alongside Terms and Conditions for the commercial rules. If you're contracting directly with a business client on data processing terms, a Service Agreement's confidentiality clause covers that relationship instead.

About the Privacy Policy Generator

The four questions your policy has to answer

What personal data you collect (names, emails, payment tokens, cookies, analytics identifiers, IP addresses), and why you collect each category. Who you share it with — payment processors, analytics vendors, ad networks, subprocessors, third-party integrations. How users can access, correct, export or delete their data. Every enforceable privacy framework in the world — GDPR, CCPA, LGPD, PIPEDA, India's DPDP Act — is a variation on those four questions.

GDPR applies whether you like it or not

If you have a single user in the EU or UK, GDPR applies regardless of where your business is registered. It requires a lawful basis for every category of processing, a clear opt-out for marketing that's single-click and not buried, the right to export and delete data on request, and disclosure of every third party that receives personal data. Enable the GDPR toggle and the generator inserts these obligations. Enforcement has moved past the "warning letter" phase — six-figure fines against small businesses are now routine.

CCPA and the wider US patchwork

The California Consumer Privacy Act gives Californians the right to know what data is collected, to delete it, and to opt out of the "sale" of personal information, which under CCPA's broad definition includes many ad-tech integrations. If you have California customers, enable the CCPA toggle. Virginia, Colorado, Connecticut, Utah and several other states have now passed similar laws close enough to CCPA that a CCPA-compliant policy usually covers them. The trend is clear, and the safer default for any US-facing business is to write for the strictest state.

Frequently asked questions

Do I need both the GDPR and CCPA sections enabled?

If you serve any EU or UK users, enable GDPR. If you serve any California users, or users in other US states with similar laws, enable CCPA. For most public websites, enable both — the combined policy is only marginally longer and future-proofs you against state-by-state expansion.

Where should the privacy policy be displayed?

Linked in the site footer, and prominently anywhere personal data is collected — signup, checkout, contact form, newsletter opt-in. GDPR, CCPA and most other frameworks require the policy to be easily accessible before data is collected, not just findable later.

How often should the policy be updated?

Any time a new data-processing tool is added — analytics, chat widget, ad pixel, third-party embed — and at minimum once a year. Keep the "last updated" date current, and for material changes, notify existing users the same way you'd notify them of a T&C change.

Do I need a cookie banner separately?

In the EU/UK, yes. The Privacy Policy discloses what cookies are set; the cookie banner captures active consent for non-essential cookies before they're set. The two are complementary, not interchangeable. Outside the EU/UK, a banner is best practice but usually not legally required.

Related Legal Tools

Other free tools in the legal & documents silo.