By platform

GDPR Policy Generator for Wix

Written for Wix Analytics, Wix Bookings and Stores, the App Market and the Wix cookie banner.

Generate your GDPR policy Read the GDPR policy guide

Wix bundles so much into one product that GDPR accountability becomes a question of which features you switched on. Bookings, Stores, Members, Chat and Automations are five processing activities under one login, and the records have to reflect that rather than describing "the website".

Wix sites collect more than their owners expect because so much of the platform is bundled. Wix Analytics runs by default, Wix Chat, Forms, Bookings, Stores, Members and Automations each collect their own data, and the App Market layers third-party tools on top - all under one login, which makes the boundaries invisible from the dashboard.

Wix acts as a processor for the data your site collects and as a controller for its own platform data. Its own cookies - XSRF-TOKEN, hs, svSession, smSession, bSession - are set on every site, and the analytics ones are not strictly necessary, which matters in the UK and EU.

Wix does supply a cookie banner and a consent policy manager, but the defaults are permissive and the banner does not automatically block third-party embeds added through the App Market or custom code. That gap is where most Wix compliance failures sit.

What a GDPR policy for a Wix site has to cover

How a Wix site actually moves personal data

Wix Analytics and visitor sessions

On by default, setting session identifiers on every visit. Under UK and EU rules that is non-essential storage requiring consent before it happens.

Wix Forms and contact collection

Every form builds a contact record in the Wix CRM, which then feeds automations and email marketing. The consent captured at form submission has to match what the automations later do.

Wix Bookings and appointment data

Names, contact details, appointment history and, for wellness and health businesses, information that is special category data requiring an Article 9 condition.

Wix Stores checkout

Order data, shipping details and payment hand-off to Wix Payments, Stripe or PayPal depending on configuration.

Wix Chat and inbox

Live chat transcripts are personal data, are retained in the inbox, and in the US are the specific fact pattern behind chat-interception class actions.

App Market and custom code embeds

Instagram feeds, review widgets, booking tools and analytics added through Settings → Custom Code each set their own cookies and are not covered by the Wix banner unless explicitly categorised.

Third parties the draft will ask you about

Wix.com Ltd · Wix Payments · Stripe · PayPal · Google Analytics 4 · Meta Pixel · Mailchimp · Wix Chat

The rules that apply

Wix Terms of Use

Site owners are responsible for their own legal pages and for complying with the laws that apply to their visitors.

Wix Data Processing Addendum

Wix acts as processor for the visitor data your site collects, which is the document your own privacy policy relies on when it names Wix as a recipient.

Wix cookie banner and consent policy

Available in the dashboard, but consent categories have to be mapped to what actually runs, and custom-code embeds are not gated automatically.

App Market third-party terms

Each installed app has its own controller relationship with your visitors and its own cookies.

Wix Payments and connected gateways

Payment data is handled by the gateway; the policy has to describe the hand-off rather than implying you hold card details.

What the generated GDPR policy contains

Publishing the document on Wix

  1. Create a dedicated page for each document

    Add a new page, paste the content, and set a clean URL such as /privacy-policy. Wix does not have a policies section, so these are ordinary pages.

  2. Link them from the site footer on every page

    Use the footer element rather than a single menu item, so the link is present site-wide including on landing pages.

  3. Turn on and configure the cookie banner

    Settings → Privacy and cookies. Map each category, and confirm the banner actually blocks the categories it claims to.

  4. Categorise every custom code embed

    Settings → Custom Code lets you assign a consent category. Anything left uncategorised loads regardless of consent.

  5. Link the privacy policy from every form

    Form fields collecting personal data should carry a link and, where you rely on consent, an unticked checkbox.

  6. Check the App Market list against your recipients

    Each installed app is a third party receiving visitor data.

Where this usually goes wrong

Relying on the auto-generated Wix policy text

Wix offers a fill-in template. It does not know which Wix products you enabled, which apps you installed, or where your visitors are - and it does not produce a cookie table.

Cookie banner enabled but not enforcing

Turning on the banner does not stop analytics or embeds from running. The consent categories have to be mapped, and custom-code embeds need explicit categorisation.

Custom code embeds firing pre-consent

Anything pasted into Settings → Custom Code loads according to the placement you chose, which by default is on every page load.

Bookings collecting health information without an Article 9 condition

Therapy, fitness, beauty and clinical bookings routinely collect special category data through the notes field.

Marketing automations running on form consent that was never asked for

A contact form is not consent to a newsletter. The Wix automation that adds them to a campaign needs its own basis.

Frequently asked questions

Does Wix give me a privacy policy?

Wix offers a template you fill in. It is a starting scaffold rather than a document tailored to the Wix products you have enabled, the apps you installed or the jurisdictions your visitors are in.

Where should the privacy policy go on a Wix site?

On its own page with a clean URL, linked from the site footer so it appears on every page, and linked again next to any form that collects personal data.

Does the Wix cookie banner make me compliant?

Only if it is configured to actually block non-essential categories before consent, and only if third-party embeds added through custom code are categorised. Enabling the banner alone changes nothing about what loads.

Do I need a policy for a small Wix business site with just a contact form?

Yes. A contact form collects personal data, which triggers the transparency obligation in the UK, EU and most other regimes. The document can be short, but it has to exist and be accurate.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator for Wix

Answer a short questionnaire and get a draft written for a Wix site. Free to start, no card required.

Generate your GDPR policy

Other documents a Wix site needs

Each one is written for the same context, not a generic template.

The same document, by platform

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.