By platform

Refund Policy Generator for WooCommerce

Written for Woo order data, gateway plugins, extension sprawl and self-hosted retention.

Generate your refund policy Read the refund policy guide

A WooCommerce refund policy has to match what the store can actually do: whether refunds are automatic through the gateway, whether partial refunds are supported, and how returns are initiated when there is no built-in returns portal.

WooCommerce inherits every WordPress consideration and adds a full commerce stack on top. Orders, customer accounts, addresses, tax records and payment tokens live in your own database rather than a platform’s - which means retention, encryption, backup handling and breach exposure are genuinely yours.

The extension model multiplies recipients quickly. Subscriptions, bookings, memberships, shipping calculators, tax services, review platforms and marketing integrations each add their own processing, and several transmit order data to their own cloud services.

Woo does provide account-erasure tooling and personal data export hooks that integrate with the WordPress privacy tools, plus settings controlling how long it keeps inactive accounts and order data. Those settings default to keeping everything indefinitely.

What a refund policy for a WooCommerce store has to cover

How a WooCommerce store actually moves personal data

Order and customer records in your database

Billing and shipping addresses, phone, email, order history and notes, held until you configure otherwise.

Payment tokens and gateway hand-off

Hosted fields keep card data out of your server; direct integrations do not. The policy has to reflect which model you actually use.

Subscriptions and stored payment methods

Recurring billing stores a token tied to a customer, which is a longer-lived relationship with its own disclosure and cancellation duties.

Shipping and tax integrations

Address data sent to carriers for rates and labels, and to tax services for calculation - each an independent recipient.

Abandoned cart and marketing extensions

Capturing a partially completed checkout and emailing about it is direct marketing based on data collected for a different purpose.

Backups containing the full order table

Every backup replicates customer records. Erasure has to reach the backup policy or it is not erasure.

Third parties the draft will ask you about

Stripe · PayPal · Klarna · Automattic (WooCommerce.com) · Royal Mail, DPD or your carrier · Avalara or TaxJar · Mailchimp for WooCommerce · your hosting provider

The rules that apply

WooCommerce data retention settings

Settings → Accounts & Privacy controls retention for inactive accounts, pending, failed and cancelled orders. Defaults keep everything.

Payment gateway plugins

Stripe, PayPal, Klarna and others handle card data. Which fields your server sees depends on whether the gateway is hosted, embedded or direct.

Tax and compliance services

Automated tax calculation transmits order and address data to a third-party service for every quote.

Self-hosted breach exposure

You hold the order database, so a compromise is your notifiable breach, not a platform’s.

Guest checkout and account creation

Different retention and different lawful bases apply depending on whether an account is created.

What the generated refund policy contains

Publishing and enforcing on WooCommerce

  1. Set the policy pages in WooCommerce settings

    Settings → Accounts & Privacy lets you link the privacy policy on the checkout and account registration pages.

  2. Configure retention for orders and inactive accounts

    Choose real periods and let Woo enforce them, rather than describing periods nobody applies.

  3. Add the terms checkbox at checkout

    Woo supports a mandatory terms acceptance checkbox, which is what makes your terms part of the contract.

  4. List your extensions

    Every extension that transmits order data is a recipient for the policy.

  5. Test personal data export and erasure

    Woo hooks into the WordPress tools; confirm what they return and what they leave behind.

  6. Document the backup and restore path

    Including how an erasure request is honoured against backups.

Where this usually goes wrong

Never configuring retention

Settings → Accounts & Privacy exists and is nearly always left at the defaults, which retain orders and inactive accounts forever.

Abandoned cart emails with no basis

The email was collected to complete an order. Using it for recovery marketing needs consent or a correctly-applied soft opt-in.

Extensions transmitting order data undisclosed

Review requests, loyalty programmes and analytics extensions each send order and customer data to a vendor.

No breach plan for a self-hosted database

You are the one who has to notify within 72 hours in the UK and EU. Platform-hosted merchants can lean on the platform; you cannot.

Card data touching the server unnecessarily

Direct integrations widen PCI scope considerably compared with hosted fields, and the policy should describe the model you actually run.

Frequently asked questions

Does WooCommerce store credit card details?

Not usually. With hosted or embedded gateway fields the card data goes straight to the provider and you store a token. Direct integrations are different, and they expand your PCI scope substantially.

How long should I keep WooCommerce orders?

Long enough for tax and contractual purposes - commonly six years in the UK - and no longer for the personal data that is not needed. Woo can enforce this automatically once configured.

Are abandoned cart emails legal?

They are direct marketing. In the UK and EU they need consent or the soft opt-in, which requires the address to have been collected in the course of a sale of similar goods with an opt-out offered at the time.

Who is responsible if my WooCommerce database is breached?

You are. Self-hosting means the controller and the operator are the same party, and the 72-hour notification obligation lands on you.

Can I run a no-refunds policy?

Not against statutory rights. In the UK and EU a consumer’s cancellation and faulty-goods rights apply regardless of what your policy says, and advertising "no refunds" is itself treated as a misleading practice.

Do digital products have to be refundable?

The cancellation right can be waived for digital content, but only if the customer gave express consent to immediate delivery and acknowledged losing the right. That acknowledgement has to be captured at checkout, not assumed.

How long do I have to issue a refund?

In the UK and EU, within 14 days of receiving the goods back or of the customer proving they returned them. Card scheme rules and marketplace policies often impose something tighter.

Refund Policy Generator for WooCommerce

Answer a short questionnaire and get a draft written for a WooCommerce store. Free to start, no card required.

Generate your refund policy

Other documents a WooCommerce store needs

Each one is written for the same context, not a generic template.

The same document, by platform

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.