Privacy Policy Generator for WordPress
Written for the plugin stack - because on WordPress, the plugins are the data flows.
On WordPress the privacy policy is a description of your plugin stack. Core collects comment metadata and a login cookie; everything else that touches personal data was installed by someone, and the accuracy of the document depends entirely on whether that list is complete.
WordPress core collects very little: comment author details, a login cookie, and whatever the theme adds. Everything else comes from plugins, and a typical business site runs between fifteen and forty of them. Contact forms, analytics, SEO tools, caching, backups, security, membership, e-commerce and email marketing each collect, store or transmit personal data.
That makes the plugin list the single most important input to a WordPress privacy policy. WordPress core has built-in privacy tooling - a suggested policy text assembled from plugins that implement the privacy API, plus personal data export and erase tools - but only some plugins participate, so the suggested text is always incomplete.
Self-hosting adds a layer most site owners forget: your host processes personal data too, server logs record IP addresses, and backups replicate everything including data a user has asked you to delete.
What a privacy policy for a WordPress site has to cover
Comment author data including IP address and user agent, which core stores by default
Each plugin that collects or transmits personal data, named with its purpose
Hosting provider and server log retention, including IP addresses
Backups and staging environments as locations where personal data persists
Gravatar or other remote avatar services, if enabled
How a WordPress site actually moves personal data
Contact form submissions
Contact Form 7, WPForms and Gravity Forms may email submissions, store them in the database, or both - and each has its own retention setting that defaults to keeping everything.
Comment metadata
WordPress stores the commenter’s IP address and user agent alongside the comment, which many site owners do not realise and few disclose.
Analytics and SEO plugins
Analytics plugins inject tracking, and some SEO plugins phone home with usage telemetry. Both belong in the disclosure.
Security plugins and firewall logs
Wordfence, Sucuri and similar log IP addresses and login attempts, retain them, and often send data to a vendor cloud.
Backups and staging copies
Full-database backups replicate personal data to another location, and a deletion request has to reach them or your erasure is incomplete.
Gravatar and remote avatars
Enabled by default, sending a hash of the commenter’s email address to Automattic on every page view that shows an avatar.
Third parties the draft will ask you about
Automattic (Jetpack, Gravatar) · WooCommerce · Stripe · PayPal · Mailchimp · Wordfence · Cloudflare · UpdraftPlus · Google Analytics 4 · your hosting provider
The rules that apply
WordPress privacy tools
Settings → Privacy assembles suggested policy text from participating plugins, and Tools → Export/Erase Personal Data handles subject requests for core and participating plugins.
Plugin-by-plugin obligations
Each plugin that transmits data off-site introduces a new recipient and usually a new processor agreement to obtain.
Hosting and server logs
Your host is a processor. Access logs containing IP addresses are personal data with their own retention question.
WooCommerce and payment gateways
Order, customer and payment data, with gateway plugins handing card details to the provider.
Comment and user data
Core stores comment author name, email, IP address and user agent, and sets a cookie if the consent checkbox is ticked.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Publishing the document on WordPress
Create the page and set it as the privacy policy page
Settings → Privacy lets you designate it, which makes core link it from the login and registration screens.
Export your plugin list first
It is the raw material for the recipients and cookies sections. Note which ones transmit data off-site.
Configure form and comment retention
Set a real period in each form plugin and decide how long comment metadata is kept.
Decide on Gravatar
Disable it, or disclose it. Discussion settings control whether avatars render at all.
Test the export and erase tools
Tools → Export Personal Data and Erase Personal Data. Confirm what they actually return, and document what they miss.
Add the policy links to the footer widget or menu
So they appear site-wide rather than only where the theme happens to place them.
Where this usually goes wrong
Publishing the suggested privacy text unedited
Settings → Privacy generates suggested content with instructional placeholders. Sites publish it verbatim, brackets included.
Undisclosed plugin data flows
Only plugins that implement the WordPress privacy API contribute to the suggested text. The others - often the ones sending the most data - are silent.
Gravatar left on without disclosure
It transmits an email hash to a third party for every avatar rendered.
Erasure requests that miss backups and caches
A deletion that leaves the record in nightly backups and a CDN cache is not a deletion.
No processor agreement with the host
Hosting is processing. The contract needs Article 28 terms if you serve UK or EU visitors.
Comment IP logging with no retention rule
Stored indefinitely by default, with no purpose after the spam check is done.
Frequently asked questions
Does WordPress generate a privacy policy for me?
It generates suggested text assembled from core and from plugins that implement the privacy API. It is a scaffold with placeholders and it is silent about every plugin that does not participate.
Do I need to list every plugin in my privacy policy?
Not every plugin, but every plugin that collects personal data or sends it somewhere. A caching plugin that stays local is different from an analytics plugin that transmits to a vendor.
Does WordPress store IP addresses?
Yes - comment author IP addresses and user agents are stored by default, and most security plugins log far more. Both are personal data.
What about my hosting provider?
They are a processor. You need appropriate contractual terms with them, and your policy should disclose hosting as a category of recipient including where the servers are.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for WordPress
Answer a short questionnaire and get a draft written for a WordPress site. Free to start, no card required.
Generate your privacy policyOther documents a WordPress site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.