Cookie Policy Generator for Squarespace
Written for Squarespace Analytics, Commerce, Scheduling and the cookie banner’s actual behaviour.
Squarespace sets its own analytics and session cookies on every site, and the banner’s blocking behaviour depends on settings most owners never open. The cookie policy should describe the configuration you actually chose.
Squarespace bundles analytics, commerce, forms, scheduling and email marketing into one product, which means a site owner who never installed anything is still running several distinct processing operations. Squarespace Analytics is on by default and cannot be disabled, only supplemented.
The platform provides a cookie banner and a "restrict cookies until consent" option, but the behaviour depends on which region rules you select and whether third-party code blocks are categorised. Code injection and third-party blocks are not gated automatically.
Squarespace Scheduling (formerly Acuity) is the most sensitive part of the stack for many users, because appointment intake forms in wellness, therapy and beauty routinely collect health information.
What a cookie policy for a Squarespace site has to cover
Squarespace platform and analytics cookies, categorised
Commerce and Scheduling cookies where those features are enabled
Third-party cookies from code injection and embedded blocks
Which region rules the banner applies and what it restricts before consent
How a visitor changes their choice
How a Squarespace site actually moves personal data
Squarespace Analytics identifiers
Set on every visit, feeding the built-in reports. Non-essential under UK and EU rules, so consent should precede them.
Form block submissions
Stored in form submissions, emailed, or pushed to Google Sheets or an email marketing list depending on configuration - each destination a separate recipient.
Commerce orders and customer accounts
Billing and shipping data, order history and, where enabled, saved customer accounts.
Scheduling intake forms
Appointment details plus free-text intake answers, which in health, therapy and beauty contexts are special category data.
Squarespace Email Campaigns
Subscriber lists, open and click tracking, and the consent that authorised them.
Code injection and third-party blocks
Anything added through code injection loads on page render and is not covered by the banner unless explicitly handled.
Third parties the draft will ask you about
Squarespace Inc. · Stripe · PayPal · Squarespace Scheduling · Google Analytics 4 · Mailchimp · Zapier
The rules that apply
Squarespace Terms of Service and DPA
Squarespace processes visitor data on your behalf and publishes a data processing addendum and sub-processor list.
Squarespace Analytics
Always active on Squarespace sites, setting its own identifiers, which makes it a disclosure item whether or not you use the reports.
Cookies and visitor tracking settings
A configurable banner with regional rules, plus an option to restrict cookies until consent that has to be enabled deliberately.
Squarespace Commerce
Orders, customer accounts and payment hand-off to Stripe or PayPal.
Squarespace Scheduling
Appointment intake, reminders and client records, often including health data.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Publishing the document on Squarespace
Add each document as a page, then hide it from navigation
Keep the URL clean, and place the links in the footer instead of the main nav.
Link the privacy policy from checkout and forms
Commerce settings allow policy links at checkout; forms should carry a link where they collect personal data.
Enable cookie restriction and pick the right region rules
Then verify with a scan that analytics genuinely waits for consent.
Review code injection
Anything there needs categorising or removing.
Set Scheduling intake fields deliberately
Collect only what you need, and add an explicit consent statement where health information is involved.
Where this usually goes wrong
Assuming the banner blocks everything
Restricting cookies until consent covers Squarespace’s own cookies and some integrations, not arbitrary code injection.
Scheduling intake collecting health data with no Article 9 condition
The intake form is where this happens, and the privacy policy usually says nothing about it.
Form submissions duplicated to Sheets or Mailchimp undisclosed
Each destination is a recipient with its own retention.
No cookie table
Squarespace does not generate one, and a banner without a per-cookie disclosure fails the UK and EU test.
Marketing consent inferred from a contact form
A form submission is not a newsletter subscription unless it asked.
Frequently asked questions
Does Squarespace include a privacy policy?
No. It provides hosting, a cookie banner and its own data processing addendum. The policy content is yours, and it needs to describe the Squarespace features you have enabled.
Can I turn off Squarespace Analytics?
No - it is part of the platform. That is precisely why it belongs in your cookie and privacy disclosures rather than being treated as invisible infrastructure.
Where do I put the policy links on Squarespace?
In the footer so they appear site-wide, plus a link at checkout and next to any form that collects personal data.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for Squarespace
Answer a short questionnaire and get a draft written for a Squarespace site. Free to start, no card required.
Generate your cookie policyOther documents a Squarespace site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.