Privacy Policy Generator for e-commerce
Written for checkout data, payment hand-offs, marketing consent and cross-border selling.
An e-commerce privacy policy has to survive being read by someone mid-checkout, which means the disclosures that matter most - what happens to their card details, whether they will be emailed afterwards, who gets their address - need to be findable rather than buried.
An online store collects more categories of personal data than almost any other small business, and it collects them at the highest-stakes moment: checkout. Name, address, phone, email, order contents, payment token, device identifiers and behavioural history all arrive in one flow, feeding a dozen downstream systems.
The marketing layer is where most stores go wrong. Abandoned cart emails, review requests, loyalty programmes and retargeting all reuse data collected to fulfil an order. Each of those is a distinct purpose, and in the UK and EU each needs its own basis - which is usually consent or the narrowly-defined soft opt-in, not the contract basis that covers the order itself.
Selling across borders multiplies everything. Every market adds a consumer law, a cancellation regime and a set of disclosure duties, and shipping internationally means transmitting customer data to carriers and customs authorities in each destination.
What a privacy policy for an online store has to cover
Checkout fields, why each is collected, and the basis for each purpose
Payment hand-off: which provider sees card data and what you retain
Marketing: the separate basis, the consent record, and how to opt out
Carriers, customs and any 3PL receiving address data, including cross-border transfers
Retention split between transaction records and marketing profiles
How an online store actually moves personal data
Checkout data
Collected under contract, but the fields you add beyond what fulfilment needs - date of birth, gender, marketing preferences - are on a different footing.
Payment tokens and fraud scoring
The gateway processes card data as its own controller for fraud prevention, which is a hand-off, not a straightforward sub-processing.
Abandoned cart capture
An email address entered but never used to complete an order. Using it is direct marketing, and whether the soft opt-in applies is genuinely debatable because no sale happened.
Retargeting and lookalike audiences
Uploading customer lists to ad platforms for matching or audience building is a disclosure to a third party and, in California, likely sharing.
Reviews and post-purchase requests
Review platforms receive customer name, email and order data, and typically publish part of it.
Cross-border shipping and customs
Address and contents data transmitted to carriers, customs brokers and destination authorities.
Third parties the draft will ask you about
Stripe · PayPal · Klarna · Klaviyo or Mailchimp · Trustpilot or Judge.me · Meta and Google Ads · DPD, Royal Mail or your carrier · Gorgias or Zendesk
The rules that apply
Distance selling and cancellation rules
Fourteen days in the UK and EU, seven in Brazil, none federally in the US - the same store faces different obligations per market.
Marketing consent and the soft opt-in
Post-purchase marketing is permitted only where the address was collected in a sale of similar goods with an opt-out offered at the time and in every message.
Cookie and tracking consent
Retargeting pixels, analytics and personalisation all require consent in the UK and EU before they fire.
Payment card handling
Using a hosted gateway keeps card data off your systems, but the policy has to describe the hand-off accurately rather than implying you store nothing at all.
Consumer information duties
Total price, delivery costs, return costs, complaint routes and trader identity, disclosed before the order is placed.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
The e-commerce document set
Map the checkout field by field
For each field: why it is collected, the basis, where it goes and how long it is kept.
Separate order processing from marketing
Different purposes, different bases, different retention. The consent record for marketing has to be independent.
Scan the storefront for pre-consent tags
Retargeting pixels are the usual finding.
Write the refund policy against every market you ship to
Statutory rights first, then your own terms.
Document the payment hand-off
Which provider, which fields they see, and what you retain.
Set retention for orders and for marketing profiles separately
Tax retention is not a reason to keep a behavioural profile.
Where this usually goes wrong
Abandoned cart emails without a basis
Where no purchase completed, the soft opt-in argument is weak. Consent captured at the point of email entry is the defensible route.
Pre-ticked marketing checkboxes
Invalid consent in the UK and EU, and it taints the whole list rather than just the individual record.
Customer list uploads to ad platforms undisclosed
It is a disclosure to a third party and in several US states a sale or share requiring an opt-out.
Retargeting pixels firing before consent
The most common UK and EU failure on e-commerce sites, and the one a cookie scan finds in seconds.
A returns policy that contradicts statutory rights
Final sale rules that override cancellation rights are unenforceable and, in several markets, independently actionable.
Order data retained forever
Tax records justify a period for the transaction data, not for marketing profiles and behavioural history attached to it.
Frequently asked questions
Do I need a privacy policy for a small online shop?
Yes. Taking an order always involves personal data, which triggers transparency obligations in every major market, and payment providers and marketplaces require a published policy as a condition of service.
Can I email customers after they buy?
In the UK and EU, only under the soft opt-in: your own similar products, to someone who bought from you, with an opt-out offered at collection and in every message. Otherwise you need consent.
Are abandoned cart emails allowed?
They are direct marketing, and where no purchase completed the soft opt-in is difficult to rely on. Capturing explicit consent at the point of email entry is the safer route.
Do I need a cookie banner for an online shop?
If you serve the UK or EU and run analytics, retargeting or personalisation - which nearly every store does - then yes, and it needs to block those tags until consent.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for e-commerce
Answer a short questionnaire and get a draft written for an online store. Free to start, no card required.
Generate your privacy policyOther documents an online store needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.