Privacy Policy Generator for Wix
Written for Wix Analytics, Wix Bookings and Stores, the App Market and the Wix cookie banner.
A Wix privacy policy has to describe the Wix products you actually switched on. Bookings, Stores, Members, Chat, Forms and Automations each collect different data for different purposes, and a policy written for a brochure site will be wrong the moment you enable any of them.
Wix sites collect more than their owners expect because so much of the platform is bundled. Wix Analytics runs by default, Wix Chat, Forms, Bookings, Stores, Members and Automations each collect their own data, and the App Market layers third-party tools on top - all under one login, which makes the boundaries invisible from the dashboard.
Wix acts as a processor for the data your site collects and as a controller for its own platform data. Its own cookies - XSRF-TOKEN, hs, svSession, smSession, bSession - are set on every site, and the analytics ones are not strictly necessary, which matters in the UK and EU.
Wix does supply a cookie banner and a consent policy manager, but the defaults are permissive and the banner does not automatically block third-party embeds added through the App Market or custom code. That gap is where most Wix compliance failures sit.
What a privacy policy for a Wix site has to cover
Wix.com Ltd as processor, with the data processing addendum as the basis, plus the location of Wix infrastructure
Each enabled Wix product and the data it collects - Forms, Bookings, Stores, Members, Chat, Automations
App Market apps and custom-code embeds as separate recipients
Payment hand-off to Wix Payments, Stripe or PayPal, making clear you do not hold card numbers
Special category data collected through booking notes, where you operate in health, wellness or beauty
How a Wix site actually moves personal data
Wix Analytics and visitor sessions
On by default, setting session identifiers on every visit. Under UK and EU rules that is non-essential storage requiring consent before it happens.
Wix Forms and contact collection
Every form builds a contact record in the Wix CRM, which then feeds automations and email marketing. The consent captured at form submission has to match what the automations later do.
Wix Bookings and appointment data
Names, contact details, appointment history and, for wellness and health businesses, information that is special category data requiring an Article 9 condition.
Wix Stores checkout
Order data, shipping details and payment hand-off to Wix Payments, Stripe or PayPal depending on configuration.
Wix Chat and inbox
Live chat transcripts are personal data, are retained in the inbox, and in the US are the specific fact pattern behind chat-interception class actions.
App Market and custom code embeds
Instagram feeds, review widgets, booking tools and analytics added through Settings → Custom Code each set their own cookies and are not covered by the Wix banner unless explicitly categorised.
Third parties the draft will ask you about
Wix.com Ltd · Wix Payments · Stripe · PayPal · Google Analytics 4 · Meta Pixel · Mailchimp · Wix Chat
The rules that apply
Wix Terms of Use
Site owners are responsible for their own legal pages and for complying with the laws that apply to their visitors.
Wix Data Processing Addendum
Wix acts as processor for the visitor data your site collects, which is the document your own privacy policy relies on when it names Wix as a recipient.
Wix cookie banner and consent policy
Available in the dashboard, but consent categories have to be mapped to what actually runs, and custom-code embeds are not gated automatically.
App Market third-party terms
Each installed app has its own controller relationship with your visitors and its own cookies.
Wix Payments and connected gateways
Payment data is handled by the gateway; the policy has to describe the hand-off rather than implying you hold card details.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Publishing the document on Wix
Create a dedicated page for each document
Add a new page, paste the content, and set a clean URL such as /privacy-policy. Wix does not have a policies section, so these are ordinary pages.
Link them from the site footer on every page
Use the footer element rather than a single menu item, so the link is present site-wide including on landing pages.
Turn on and configure the cookie banner
Settings → Privacy and cookies. Map each category, and confirm the banner actually blocks the categories it claims to.
Categorise every custom code embed
Settings → Custom Code lets you assign a consent category. Anything left uncategorised loads regardless of consent.
Link the privacy policy from every form
Form fields collecting personal data should carry a link and, where you rely on consent, an unticked checkbox.
Check the App Market list against your recipients
Each installed app is a third party receiving visitor data.
Where this usually goes wrong
Relying on the auto-generated Wix policy text
Wix offers a fill-in template. It does not know which Wix products you enabled, which apps you installed, or where your visitors are - and it does not produce a cookie table.
Cookie banner enabled but not enforcing
Turning on the banner does not stop analytics or embeds from running. The consent categories have to be mapped, and custom-code embeds need explicit categorisation.
Custom code embeds firing pre-consent
Anything pasted into Settings → Custom Code loads according to the placement you chose, which by default is on every page load.
Bookings collecting health information without an Article 9 condition
Therapy, fitness, beauty and clinical bookings routinely collect special category data through the notes field.
Marketing automations running on form consent that was never asked for
A contact form is not consent to a newsletter. The Wix automation that adds them to a campaign needs its own basis.
Frequently asked questions
Does Wix give me a privacy policy?
Wix offers a template you fill in. It is a starting scaffold rather than a document tailored to the Wix products you have enabled, the apps you installed or the jurisdictions your visitors are in.
Where should the privacy policy go on a Wix site?
On its own page with a clean URL, linked from the site footer so it appears on every page, and linked again next to any form that collects personal data.
Does the Wix cookie banner make me compliant?
Only if it is configured to actually block non-essential categories before consent, and only if third-party embeds added through custom code are categorised. Enabling the banner alone changes nothing about what loads.
Do I need a policy for a small Wix business site with just a contact form?
Yes. A contact form collects personal data, which triggers the transparency obligation in the UK, EU and most other regimes. The document can be short, but it has to exist and be accurate.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for Wix
Answer a short questionnaire and get a draft written for a Wix site. Free to start, no card required.
Generate your privacy policyOther documents a Wix site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.