Privacy Policy Generator for Etsy
Written for the Etsy seller: shared controllership, personalisation data, and the policies Etsy will not write for you.
An Etsy privacy policy is about what you do with buyer data after Etsy hands it to you - the spreadsheet, the mailing list, the print partner and the personalisation notes. Etsy’s own policy covers none of that, which is exactly why Etsy asks UK and EU sellers to publish their own.
Etsy sellers occupy an awkward position. Etsy is the controller for the marketplace itself, but the seller is an independent controller for the order data they receive and for anything they do with it afterwards - which is why Etsy requires sellers in the UK and EU to publish their own privacy policy in the shop’s policies section.
The data a handmade or personalised shop receives is unusually rich. Personalisation fields routinely contain names, dates, children’s names, memorial details and occasionally health references, all typed into a free-text box that was designed for engraving instructions.
Off-Etsy processing is where the seller’s own obligations bite. Downloading buyer addresses into a spreadsheet, adding them to a mailing list, or shipping through a separate label service are all processing the seller decides on, and none of it is covered by Etsy’s policy.
What a privacy policy for an Etsy shop has to cover
Your identity as the seller, with a contact route that is not only the Etsy message system
Order and address data received from Etsy, and how long you keep it off-platform
Personalisation and gift-message free text, including data about people who are not the buyer
Production and fulfilment partners such as print-on-demand services, named as recipients
Marketing: the separate consent, and how a buyer opts out
How an Etsy shop actually moves personal data
Order and address data from Etsy
Buyer name, shipping address and order details, received as an independent controller and retained by the seller under their own retention rules.
Personalisation and gift messages
Free-text fields containing recipient names, dates, memorial wording and sometimes health or religious references - none of which the seller asked for explicitly.
Messages between buyer and seller
Held on Etsy but frequently copied into email or notes, at which point the seller holds a second copy under their own control.
Off-platform mailing lists
Adding an Etsy buyer to a newsletter is a new purpose that Etsy’s policy does not cover and that usually needs consent.
Shipping and label services
Address data sent to Royal Mail, Evri, USPS or a label aggregator, each an independent recipient.
Custom order files
Photographs and artwork supplied by buyers for personalisation, which may contain images of identifiable people.
Third parties the draft will ask you about
Etsy, Inc. · Etsy Payments · PayPal · Royal Mail or USPS · Printful or Printify · Mailchimp · Canva
The rules that apply
Etsy Seller Policy
Sellers must comply with applicable data protection law and, in the UK and EU, publish their own privacy policy in the shop policies section.
Independent controller status
Etsy determines the marketplace processing; the seller determines what happens to order data afterwards. Both are controllers for their own decisions.
Personalisation free-text fields
Whatever a buyer types becomes personal data the seller holds, including data about third parties and occasionally special category data.
Distance selling rules
Fourteen-day cancellation in the UK and EU, with a permitted exclusion for genuinely personalised goods that has to be claimed correctly.
Marketplace tax reporting
Etsy reports seller income and identity data to tax authorities under marketplace reporting rules.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Publishing the document on Etsy
Paste it into Shop Manager → Settings → Policies
Etsy provides a privacy policy field for UK and EU sellers, plus fields for returns and exchanges.
Add the policy text to your shop’s About or FAQ section too
The policies tab is easy for buyers to miss.
Set a retention rule for personalisation data
Delete order spreadsheets and custom artwork once the return window and tax retention have passed.
Name your production and shipping partners
Print-on-demand and fulfilment services receive buyer data directly.
Separate marketing consent from purchase
Ask explicitly, outside the order flow, and keep the record.
Where this usually goes wrong
Assuming Etsy’s privacy policy covers the shop
It covers Etsy’s processing. Everything the seller does with order data afterwards is the seller’s own responsibility.
Adding buyers to a mailing list without consent
A purchase is not a newsletter subscription, and Etsy’s terms restrict marketing use of buyer data.
Keeping personalisation data indefinitely
Memorial and children’s details sitting in a spreadsheet years later have no remaining purpose.
Claiming the personalisation exemption too broadly
It applies to goods genuinely made to the customer’s specification, not to a stock item in a chosen colour.
Print-on-demand partners undisclosed
Printful, Printify and similar receive the buyer’s name and address directly and are recipients the policy should name.
Frequently asked questions
Do Etsy sellers need their own privacy policy?
In the UK and EU, yes - Etsy requires it in the shop policies section, and independently you are a controller for the order data you receive and everything you do with it off-platform.
Does Etsy’s privacy policy cover my shop?
Only Etsy’s own processing. Your spreadsheets, your mailing list, your shipping partners and your customer notes are yours.
Can I email Etsy buyers about new products?
Not on the strength of the purchase alone. Etsy restricts marketing use of buyer data, and UK and EU marketing rules need consent or a correctly-applied soft opt-in.
Do personalised items have to be refundable?
Genuinely personalised goods made to the customer’s specification can be excluded from the fourteen-day cancellation right, but the exclusion does not cover faulty goods or stock items in a chosen variant.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for Etsy
Answer a short questionnaire and get a draft written for an Etsy shop. Free to start, no card required.
Generate your privacy policyOther documents an Etsy shop needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.