By platform

Privacy Policy Generator for Squarespace

Written for Squarespace Analytics, Commerce, Scheduling and the cookie banner’s actual behaviour.

Generate your privacy policy Read the privacy policy guide

A Squarespace privacy policy needs to describe a bundle rather than a set of installed tools. Analytics, forms, commerce, scheduling and email campaigns are all Squarespace, but they are different processing purposes with different bases and different retention.

Squarespace bundles analytics, commerce, forms, scheduling and email marketing into one product, which means a site owner who never installed anything is still running several distinct processing operations. Squarespace Analytics is on by default and cannot be disabled, only supplemented.

The platform provides a cookie banner and a "restrict cookies until consent" option, but the behaviour depends on which region rules you select and whether third-party code blocks are categorised. Code injection and third-party blocks are not gated automatically.

Squarespace Scheduling (formerly Acuity) is the most sensitive part of the stack for many users, because appointment intake forms in wellness, therapy and beauty routinely collect health information.

What a privacy policy for a Squarespace site has to cover

How a Squarespace site actually moves personal data

Squarespace Analytics identifiers

Set on every visit, feeding the built-in reports. Non-essential under UK and EU rules, so consent should precede them.

Form block submissions

Stored in form submissions, emailed, or pushed to Google Sheets or an email marketing list depending on configuration - each destination a separate recipient.

Commerce orders and customer accounts

Billing and shipping data, order history and, where enabled, saved customer accounts.

Scheduling intake forms

Appointment details plus free-text intake answers, which in health, therapy and beauty contexts are special category data.

Squarespace Email Campaigns

Subscriber lists, open and click tracking, and the consent that authorised them.

Code injection and third-party blocks

Anything added through code injection loads on page render and is not covered by the banner unless explicitly handled.

Third parties the draft will ask you about

Squarespace Inc. · Stripe · PayPal · Squarespace Scheduling · Google Analytics 4 · Mailchimp · Zapier

The rules that apply

Squarespace Terms of Service and DPA

Squarespace processes visitor data on your behalf and publishes a data processing addendum and sub-processor list.

Squarespace Analytics

Always active on Squarespace sites, setting its own identifiers, which makes it a disclosure item whether or not you use the reports.

Cookies and visitor tracking settings

A configurable banner with regional rules, plus an option to restrict cookies until consent that has to be enabled deliberately.

Squarespace Commerce

Orders, customer accounts and payment hand-off to Stripe or PayPal.

Squarespace Scheduling

Appointment intake, reminders and client records, often including health data.

What the generated privacy policy contains

Publishing the document on Squarespace

  1. Add each document as a page, then hide it from navigation

    Keep the URL clean, and place the links in the footer instead of the main nav.

  2. Link the privacy policy from checkout and forms

    Commerce settings allow policy links at checkout; forms should carry a link where they collect personal data.

  3. Enable cookie restriction and pick the right region rules

    Then verify with a scan that analytics genuinely waits for consent.

  4. Review code injection

    Anything there needs categorising or removing.

  5. Set Scheduling intake fields deliberately

    Collect only what you need, and add an explicit consent statement where health information is involved.

Where this usually goes wrong

Assuming the banner blocks everything

Restricting cookies until consent covers Squarespace’s own cookies and some integrations, not arbitrary code injection.

Scheduling intake collecting health data with no Article 9 condition

The intake form is where this happens, and the privacy policy usually says nothing about it.

Form submissions duplicated to Sheets or Mailchimp undisclosed

Each destination is a recipient with its own retention.

No cookie table

Squarespace does not generate one, and a banner without a per-cookie disclosure fails the UK and EU test.

Marketing consent inferred from a contact form

A form submission is not a newsletter subscription unless it asked.

Frequently asked questions

Does Squarespace include a privacy policy?

No. It provides hosting, a cookie banner and its own data processing addendum. The policy content is yours, and it needs to describe the Squarespace features you have enabled.

Can I turn off Squarespace Analytics?

No - it is part of the platform. That is precisely why it belongs in your cookie and privacy disclosures rather than being treated as invisible infrastructure.

Where do I put the policy links on Squarespace?

In the footer so they appear site-wide, plus a link at checkout and next to any form that collects personal data.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator for Squarespace

Answer a short questionnaire and get a draft written for a Squarespace site. Free to start, no card required.

Generate your privacy policy

Other documents a Squarespace site needs

Each one is written for the same context, not a generic template.

The same document, by platform

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.