By platform

GDPR Policy Generator for WooCommerce

Written for Woo order data, gateway plugins, extension sprawl and self-hosted retention.

Generate your GDPR policy Read the GDPR policy guide

Self-hosting moves GDPR from a shared responsibility to a first-person one. The order database is on your server, so the security obligation, the retention decision and the 72-hour breach clock are all yours with no platform to escalate to.

WooCommerce inherits every WordPress consideration and adds a full commerce stack on top. Orders, customer accounts, addresses, tax records and payment tokens live in your own database rather than a platform’s - which means retention, encryption, backup handling and breach exposure are genuinely yours.

The extension model multiplies recipients quickly. Subscriptions, bookings, memberships, shipping calculators, tax services, review platforms and marketing integrations each add their own processing, and several transmit order data to their own cloud services.

Woo does provide account-erasure tooling and personal data export hooks that integrate with the WordPress privacy tools, plus settings controlling how long it keeps inactive accounts and order data. Those settings default to keeping everything indefinitely.

What a GDPR policy for a WooCommerce store has to cover

How a WooCommerce store actually moves personal data

Order and customer records in your database

Billing and shipping addresses, phone, email, order history and notes, held until you configure otherwise.

Payment tokens and gateway hand-off

Hosted fields keep card data out of your server; direct integrations do not. The policy has to reflect which model you actually use.

Subscriptions and stored payment methods

Recurring billing stores a token tied to a customer, which is a longer-lived relationship with its own disclosure and cancellation duties.

Shipping and tax integrations

Address data sent to carriers for rates and labels, and to tax services for calculation - each an independent recipient.

Abandoned cart and marketing extensions

Capturing a partially completed checkout and emailing about it is direct marketing based on data collected for a different purpose.

Backups containing the full order table

Every backup replicates customer records. Erasure has to reach the backup policy or it is not erasure.

Third parties the draft will ask you about

Stripe · PayPal · Klarna · Automattic (WooCommerce.com) · Royal Mail, DPD or your carrier · Avalara or TaxJar · Mailchimp for WooCommerce · your hosting provider

The rules that apply

WooCommerce data retention settings

Settings → Accounts & Privacy controls retention for inactive accounts, pending, failed and cancelled orders. Defaults keep everything.

Payment gateway plugins

Stripe, PayPal, Klarna and others handle card data. Which fields your server sees depends on whether the gateway is hosted, embedded or direct.

Tax and compliance services

Automated tax calculation transmits order and address data to a third-party service for every quote.

Self-hosted breach exposure

You hold the order database, so a compromise is your notifiable breach, not a platform’s.

Guest checkout and account creation

Different retention and different lawful bases apply depending on whether an account is created.

What the generated GDPR policy contains

Publishing and enforcing on WooCommerce

  1. Set the policy pages in WooCommerce settings

    Settings → Accounts & Privacy lets you link the privacy policy on the checkout and account registration pages.

  2. Configure retention for orders and inactive accounts

    Choose real periods and let Woo enforce them, rather than describing periods nobody applies.

  3. Add the terms checkbox at checkout

    Woo supports a mandatory terms acceptance checkbox, which is what makes your terms part of the contract.

  4. List your extensions

    Every extension that transmits order data is a recipient for the policy.

  5. Test personal data export and erasure

    Woo hooks into the WordPress tools; confirm what they return and what they leave behind.

  6. Document the backup and restore path

    Including how an erasure request is honoured against backups.

Where this usually goes wrong

Never configuring retention

Settings → Accounts & Privacy exists and is nearly always left at the defaults, which retain orders and inactive accounts forever.

Abandoned cart emails with no basis

The email was collected to complete an order. Using it for recovery marketing needs consent or a correctly-applied soft opt-in.

Extensions transmitting order data undisclosed

Review requests, loyalty programmes and analytics extensions each send order and customer data to a vendor.

No breach plan for a self-hosted database

You are the one who has to notify within 72 hours in the UK and EU. Platform-hosted merchants can lean on the platform; you cannot.

Card data touching the server unnecessarily

Direct integrations widen PCI scope considerably compared with hosted fields, and the policy should describe the model you actually run.

Frequently asked questions

Does WooCommerce store credit card details?

Not usually. With hosted or embedded gateway fields the card data goes straight to the provider and you store a token. Direct integrations are different, and they expand your PCI scope substantially.

How long should I keep WooCommerce orders?

Long enough for tax and contractual purposes - commonly six years in the UK - and no longer for the personal data that is not needed. Woo can enforce this automatically once configured.

Are abandoned cart emails legal?

They are direct marketing. In the UK and EU they need consent or the soft opt-in, which requires the address to have been collected in the course of a sale of similar goods with an opt-out offered at the time.

Who is responsible if my WooCommerce database is breached?

You are. Self-hosting means the controller and the operator are the same party, and the 72-hour notification obligation lands on you.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator for WooCommerce

Answer a short questionnaire and get a draft written for a WooCommerce store. Free to start, no card required.

Generate your GDPR policy

Other documents a WooCommerce store needs

Each one is written for the same context, not a generic template.

The same document, by platform

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.