Privacy Policy Generator
Draft a privacy policy from what your site actually collects: forms, comments, analytics, cookies, orders and accounts, with GDPR and CCPA sections.
<!-- A starting point, not legal advice. Read every line and change what is not true of your site. -->
<h1>Privacy Policy</h1>
<p><em>Last updated: 2026-01-01</em></p>
<p>This policy explains what Acme Ltd collects when you use https://example.com, why, and what you can ask us to do about it.</p>
<h2>Who we are</h2>
<p>Acme Ltd operates https://example.com. You can reach us about anything in this policy at <a href="mailto:[email protected]">[email protected]</a>.</p>
<h2>What we collect and why</h2>
<h3>Contact forms</h3>
<p>When you send us a message we receive the name, email address and any other details you type into the form, together with the message itself. We use them to reply to you and to keep a record of the conversation. We do not use form submissions for marketing unless you ask us to.</p>
<h3>Comments</h3>
<p>When you leave a comment we store the comment, the name and email address you give, your IP address and your browser's user agent string. The IP address and user agent help us detect spam. Comments and their metadata may be checked by an automated spam detection service.</p>
<h3>Analytics</h3>
<p>We use Google Analytics to understand which pages people read and how they arrive. It collects information about your visit, which may include your approximate location, device and browser, and the pages you view. We use it in aggregate to decide what to write and what to fix.</p>
<h3>Cookies</h3>
<p>Cookies are small files stored by your browser. We use them to keep you signed in, to remember preferences, and, where you have agreed to it, for analytics. You can delete or block cookies in your browser settings; some parts of the site will stop working if you block the necessary ones.</p>
<h2>How long we keep it</h2>
<p>We keep contact details for 24 months after our last conversation with you, unless you ask us to remove them sooner. Comments and their metadata are kept indefinitely so that follow-up comments can be recognised and approved automatically.</p>
<h2>Who we share it with</h2>
<p>We do not sell your personal information. We share it only with the services we need to run the site, such as Google Analytics, and where the law requires us to.</p>
<h2>Your rights (UK and EU)</h2>
<p>If you are in the UK or the European Economic Area, you have the right to ask us for a copy of the personal data we hold about you, to have it corrected or deleted, to object to how we use it, and to ask us to restrict our use of it. You also have the right to receive the data you gave us in a portable form.</p>
<p>Ask by emailing <a href="mailto:[email protected]">[email protected]</a>. We will respond within one month. If you are unhappy with our response you can complain to the data protection authority in your country.</p>
<h2>Children</h2>
<p>This site is not aimed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has given us personal information, email us and we will delete it.</p>
<h2>Changes to this policy</h2>
<p>If this policy changes we will update the date at the top. Significant changes will be announced on the site.</p>
Output is valid and updates as you type.
Fix the highlighted fields to update the output.
Draft a privacy policy from what your site actually collects, rather than from a template that lists everything. It is a starting point for a lawyer or a careful read, not legal advice.
How to use
- Tick only what is true. A policy describing collection you do not do is as wrong as one that leaves out collection you do, and the second kind is what regulators act on.
- Name your actual providers. “A third-party analytics service” helps nobody; “Google Analytics” tells a visitor what to look up.
- Give a real, monitored email address. A subject access request under GDPR starts a one month clock whether or not anyone is reading that inbox.
- Say a retention period you will honour. “As long as necessary” is the phrase everyone writes and nobody can act on.
- Read every line before publishing. This is a draft based on what you ticked, and only you know whether it matches what your site does.
Example
The retention section is where most templates go vague:
<h2>How long we keep it</h2>
<p>We keep contact details for 24 months after our last conversation with you,
unless you ask us to remove them sooner. Order and payment records are kept for
as long as tax and accounting rules require, which is usually longer.</p>
A specific period is something you can build a deletion routine around. A vague one means the data is kept forever by default.
Pitfalls
- This is a draft, not legal advice. Privacy law is jurisdictional and changes; a lawyer in your country is the only way to be sure.
- GDPR applies based on where your visitors are, not where you are. A site in the United States with UK readers is in scope.
- A policy that does not match reality is worse than none: it is a documented statement you can be held to.
- Embedded content from other sites collects data as if the visitor had gone there. That belongs in the policy even though you wrote none of it.
- Cookie consent is a separate obligation in the UK and EU. A policy that mentions cookies does not replace asking before setting non-essential ones.
- Naming a processor means keeping the list current. Swapping analytics providers without updating the policy is a small, real inaccuracy.
- CCPA has revenue and volume thresholds. Including the section when it does not apply is harmless; assuming it applies instead of checking is not.
- WordPress has a built-in privacy policy draft under Settings, Privacy, which plugins add their own sections to. Check it before writing from scratch.
Compatibility
The output is plain HTML that pastes into the WordPress block editor, where it converts to blocks. It covers GDPR (UK and EU), CCPA (California) and the general disclosure expectations of most other regimes, but it is written in plain language rather than to any single statutory template. The tool runs entirely in your browser: nothing you type is uploaded.