GDPR Policy Generator for Wix
Written for Wix Analytics, Wix Bookings and Stores, the App Market and the Wix cookie banner.
Wix bundles so much into one product that GDPR accountability becomes a question of which features you switched on. Bookings, Stores, Members, Chat and Automations are five processing activities under one login, and the records have to reflect that rather than describing "the website".
Wix sites collect more than their owners expect because so much of the platform is bundled. Wix Analytics runs by default, Wix Chat, Forms, Bookings, Stores, Members and Automations each collect their own data, and the App Market layers third-party tools on top - all under one login, which makes the boundaries invisible from the dashboard.
Wix acts as a processor for the data your site collects and as a controller for its own platform data. Its own cookies - XSRF-TOKEN, hs, svSession, smSession, bSession - are set on every site, and the analytics ones are not strictly necessary, which matters in the UK and EU.
Wix does supply a cookie banner and a consent policy manager, but the defaults are permissive and the banner does not automatically block third-party embeds added through the App Market or custom code. That gap is where most Wix compliance failures sit.
What a GDPR policy for a Wix site has to cover
A processing record per enabled Wix product, not one entry for the whole site
The lawful basis for automations, which frequently act on data collected for a different purpose
Special category data collected through booking intake, with its Article 9 condition
The Wix data processing addendum, and App Market apps as separate processors
How a data subject request is fulfilled across the Wix CRM, the inbox and any connected apps
How a Wix site actually moves personal data
Wix Analytics and visitor sessions
On by default, setting session identifiers on every visit. Under UK and EU rules that is non-essential storage requiring consent before it happens.
Wix Forms and contact collection
Every form builds a contact record in the Wix CRM, which then feeds automations and email marketing. The consent captured at form submission has to match what the automations later do.
Wix Bookings and appointment data
Names, contact details, appointment history and, for wellness and health businesses, information that is special category data requiring an Article 9 condition.
Wix Stores checkout
Order data, shipping details and payment hand-off to Wix Payments, Stripe or PayPal depending on configuration.
Wix Chat and inbox
Live chat transcripts are personal data, are retained in the inbox, and in the US are the specific fact pattern behind chat-interception class actions.
App Market and custom code embeds
Instagram feeds, review widgets, booking tools and analytics added through Settings → Custom Code each set their own cookies and are not covered by the Wix banner unless explicitly categorised.
Third parties the draft will ask you about
Wix.com Ltd · Wix Payments · Stripe · PayPal · Google Analytics 4 · Meta Pixel · Mailchimp · Wix Chat
The rules that apply
Wix Terms of Use
Site owners are responsible for their own legal pages and for complying with the laws that apply to their visitors.
Wix Data Processing Addendum
Wix acts as processor for the visitor data your site collects, which is the document your own privacy policy relies on when it names Wix as a recipient.
Wix cookie banner and consent policy
Available in the dashboard, but consent categories have to be mapped to what actually runs, and custom-code embeds are not gated automatically.
App Market third-party terms
Each installed app has its own controller relationship with your visitors and its own cookies.
Wix Payments and connected gateways
Payment data is handled by the gateway; the policy has to describe the hand-off rather than implying you hold card details.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
Publishing the document on Wix
Create a dedicated page for each document
Add a new page, paste the content, and set a clean URL such as /privacy-policy. Wix does not have a policies section, so these are ordinary pages.
Link them from the site footer on every page
Use the footer element rather than a single menu item, so the link is present site-wide including on landing pages.
Turn on and configure the cookie banner
Settings → Privacy and cookies. Map each category, and confirm the banner actually blocks the categories it claims to.
Categorise every custom code embed
Settings → Custom Code lets you assign a consent category. Anything left uncategorised loads regardless of consent.
Link the privacy policy from every form
Form fields collecting personal data should carry a link and, where you rely on consent, an unticked checkbox.
Check the App Market list against your recipients
Each installed app is a third party receiving visitor data.
Where this usually goes wrong
Relying on the auto-generated Wix policy text
Wix offers a fill-in template. It does not know which Wix products you enabled, which apps you installed, or where your visitors are - and it does not produce a cookie table.
Cookie banner enabled but not enforcing
Turning on the banner does not stop analytics or embeds from running. The consent categories have to be mapped, and custom-code embeds need explicit categorisation.
Custom code embeds firing pre-consent
Anything pasted into Settings → Custom Code loads according to the placement you chose, which by default is on every page load.
Bookings collecting health information without an Article 9 condition
Therapy, fitness, beauty and clinical bookings routinely collect special category data through the notes field.
Marketing automations running on form consent that was never asked for
A contact form is not consent to a newsletter. The Wix automation that adds them to a campaign needs its own basis.
Frequently asked questions
Does Wix give me a privacy policy?
Wix offers a template you fill in. It is a starting scaffold rather than a document tailored to the Wix products you have enabled, the apps you installed or the jurisdictions your visitors are in.
Where should the privacy policy go on a Wix site?
On its own page with a clean URL, linked from the site footer so it appears on every page, and linked again next to any form that collects personal data.
Does the Wix cookie banner make me compliant?
Only if it is configured to actually block non-essential categories before consent, and only if third-party embeds added through custom code are categorised. Enabling the banner alone changes nothing about what loads.
Do I need a policy for a small Wix business site with just a contact form?
Yes. A contact form collects personal data, which triggers the transparency obligation in the UK, EU and most other regimes. The document can be short, but it has to exist and be accurate.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for Wix
Answer a short questionnaire and get a draft written for a Wix site. Free to start, no card required.
Generate your GDPR policyOther documents a Wix site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.