Privacy Policy Generator for Squarespace
Written for Squarespace Analytics, Commerce, Scheduling and the cookie banner’s actual behaviour.
A Squarespace privacy policy needs to describe a bundle rather than a set of installed tools. Analytics, forms, commerce, scheduling and email campaigns are all Squarespace, but they are different processing purposes with different bases and different retention.
Squarespace bundles analytics, commerce, forms, scheduling and email marketing into one product, which means a site owner who never installed anything is still running several distinct processing operations. Squarespace Analytics is on by default and cannot be disabled, only supplemented.
The platform provides a cookie banner and a "restrict cookies until consent" option, but the behaviour depends on which region rules you select and whether third-party code blocks are categorised. Code injection and third-party blocks are not gated automatically.
Squarespace Scheduling (formerly Acuity) is the most sensitive part of the stack for many users, because appointment intake forms in wellness, therapy and beauty routinely collect health information.
What a privacy policy for a Squarespace site has to cover
Squarespace Inc. as processor, with the data processing addendum and sub-processor list referenced
Squarespace Analytics, which runs whether or not you use it
Form submissions and every destination they are forwarded to
Commerce orders and the payment hand-off to Stripe or PayPal
Scheduling intake data, with an Article 9 condition where health information is collected
How a Squarespace site actually moves personal data
Squarespace Analytics identifiers
Set on every visit, feeding the built-in reports. Non-essential under UK and EU rules, so consent should precede them.
Form block submissions
Stored in form submissions, emailed, or pushed to Google Sheets or an email marketing list depending on configuration - each destination a separate recipient.
Commerce orders and customer accounts
Billing and shipping data, order history and, where enabled, saved customer accounts.
Scheduling intake forms
Appointment details plus free-text intake answers, which in health, therapy and beauty contexts are special category data.
Squarespace Email Campaigns
Subscriber lists, open and click tracking, and the consent that authorised them.
Code injection and third-party blocks
Anything added through code injection loads on page render and is not covered by the banner unless explicitly handled.
Third parties the draft will ask you about
Squarespace Inc. · Stripe · PayPal · Squarespace Scheduling · Google Analytics 4 · Mailchimp · Zapier
The rules that apply
Squarespace Terms of Service and DPA
Squarespace processes visitor data on your behalf and publishes a data processing addendum and sub-processor list.
Squarespace Analytics
Always active on Squarespace sites, setting its own identifiers, which makes it a disclosure item whether or not you use the reports.
Cookies and visitor tracking settings
A configurable banner with regional rules, plus an option to restrict cookies until consent that has to be enabled deliberately.
Squarespace Commerce
Orders, customer accounts and payment hand-off to Stripe or PayPal.
Squarespace Scheduling
Appointment intake, reminders and client records, often including health data.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Publishing the document on Squarespace
Add each document as a page, then hide it from navigation
Keep the URL clean, and place the links in the footer instead of the main nav.
Link the privacy policy from checkout and forms
Commerce settings allow policy links at checkout; forms should carry a link where they collect personal data.
Enable cookie restriction and pick the right region rules
Then verify with a scan that analytics genuinely waits for consent.
Review code injection
Anything there needs categorising or removing.
Set Scheduling intake fields deliberately
Collect only what you need, and add an explicit consent statement where health information is involved.
Where this usually goes wrong
Assuming the banner blocks everything
Restricting cookies until consent covers Squarespace’s own cookies and some integrations, not arbitrary code injection.
Scheduling intake collecting health data with no Article 9 condition
The intake form is where this happens, and the privacy policy usually says nothing about it.
Form submissions duplicated to Sheets or Mailchimp undisclosed
Each destination is a recipient with its own retention.
No cookie table
Squarespace does not generate one, and a banner without a per-cookie disclosure fails the UK and EU test.
Marketing consent inferred from a contact form
A form submission is not a newsletter subscription unless it asked.
Frequently asked questions
Does Squarespace include a privacy policy?
No. It provides hosting, a cookie banner and its own data processing addendum. The policy content is yours, and it needs to describe the Squarespace features you have enabled.
Can I turn off Squarespace Analytics?
No - it is part of the platform. That is precisely why it belongs in your cookie and privacy disclosures rather than being treated as invisible infrastructure.
Where do I put the policy links on Squarespace?
In the footer so they appear site-wide, plus a link at checkout and next to any form that collects personal data.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for Squarespace
Answer a short questionnaire and get a draft written for a Squarespace site. Free to start, no card required.
Generate your privacy policyOther documents a Squarespace site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.