Privacy Policy

A privacy policy written from what your site actually does - GDPR and CCPA sections included only where they apply.

100% free. Runs entirely in your browser - your files and data never leave your device and nothing is uploaded to any server.

Template, not legal advice. This produces a starting draft from standard clauses. It is not legal advice, and it cannot know everything your business does. Read every paragraph before you publish it - a policy that describes data collection you do not do is as much of a problem as one that omits collection you do.

Start from an example

Fills every answer with a worked example you can edit. Pick the one closest to your business.

0 of 5 details filled
Your business
GDPR expects a postal address, not just an email.
Who your visitors are

This decides whether the GDPR rights section, the California section, or both appear.

This decides which rights section is included. GDPR is the stricter of the two.
What your site actually does

Each of these adds or removes a section. Answer honestly - a policy claiming collection you do not do is as much of a problem as one that hides collection you do.

Who you share data with
Naming them is a GDPR requirement, and it is what makes a policy read as real rather than copied.

Privacy Policy

12 sections · 738 words · updates as you type

Privacy Policy

Last updated: 13 September 2026

Who we are

[Your business name] operates [your website] ("the site"). This policy explains what personal information we collect, why we collect it, and what you can do about it.

If you have any question about this policy, or about information we hold, contact us at [your contact email] or write to us at [your business address].

What we collect

We collect the following:

  • Usage data. Pages viewed, approximate location derived from your IP address, referring site, device type and browser. This is collected in aggregate to understand how the site is used.
  • Anything you send us. If you email us or use a contact form, we keep that correspondence so we can answer it.

We do not collect anything not listed here, and we do not sell personal information.

Why we collect it

  • To provide the site - so pages load, forms submit and the service works.
  • To understand what is used - so we can fix what is broken and improve what is not.

Under the UK GDPR and EU GDPR our lawful bases are: performance of a contract (running your account and taking payment), legitimate interests (keeping the site working and secure), legal obligation (financial records), and consent (marketing email and any non-essential cookies). Where we rely on consent you can withdraw it at any time.

Who we share it with

We share information with the service providers that run parts of this site for us - hosting, email delivery, and payment processing where relevant.

We require every provider to use the information only to deliver the service to us. We also disclose information where the law requires it, and if the business is sold, to the buyer as part of that sale.

Cookies

Analytics cookies tell us how the site is used, in aggregate.

Non-essential cookies are only set once you agree to them, and you can change or withdraw that choice at any time. You can also block or delete cookies in your browser settings.

How long we keep it

We keep personal information only as long as we need it:

  • Correspondence: kept while it is useful for support, then deleted.
  • Analytics: kept in aggregate; individual records expire according to our analytics provider settings.

Your rights

Under data protection law you have the right to ask us for a copy of the information we hold about you, to have it corrected, to have it deleted, to object to how we use it, to restrict our use of it, and to receive it in a portable format. Where we rely on your consent, you can withdraw that consent at any time.

To exercise any of these, email [your contact email]. We will respond within one month. If you are not satisfied with our response you can complain to your national data protection authority - in the UK that is the Information Commissioner's Office.

California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request a copy of it, to request deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information.

We do not sell personal information. To make a request, email [your contact email]. We will not treat you differently for exercising any of these rights.

Children

This site is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us at [your contact email] and we will delete it.

Security

We take reasonable technical and organisational measures to protect personal information, including encryption in transit and access controls on the systems that hold it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security - but if a breach affects your rights we will tell you and the relevant authority as the law requires.

International transfers

Some of our service providers are based outside the UK and the European Economic Area. Where personal information is transferred outside those areas, we rely on an adequacy decision or on standard contractual clauses approved for that purpose, so that your information keeps the same protection it has at home.

Changes to this policy

We may update this policy as the site changes or as the law does. The current version is always on this page, and the date below tells you when it last changed. If a change materially affects how we use your information, we will say so more prominently than a silent edit.

Generated from a template. Not legal advice - read it before you publish or sign it.

Other documents you can generate

Most sites need more than one. A privacy policy without terms, or terms without a refund policy, leaves the obvious gap.

Terms and ConditionsTerms of service built around what you actually sell - goods, subscription, downloads or services.Cookie PolicyA cookie policy with a real table - each cookie named, with its purpose and how long it lasts.Cookie Consent BannerGenerates a working consent banner - blocks tagged scripts until consent, Google Consent Mode v2, no dark patterns.Refund and Return PolicyA refund policy customers can follow and payment processors accept - windows, exclusions and statutory rights in plain words.Website DisclaimerA disclaimer that names the actual risk your site carries, plus affiliate and sponsorship disclosures.Accessibility StatementA WCAG accessibility statement that states what you actually meet, names known issues, and gives people a route to report problems.Non-Disclosure AgreementA mutual or one-way NDA with a real purpose clause, standard carve-outs and a defined term.Freelance ContractAn independent contractor agreement that pins down scope, revisions, IP ownership and what happens when payment is late.Data Processing AgreementA GDPR Article 28 processor agreement with the eight mandatory clauses and a filled-in processing schedule.W-9 FormFills a substitute Form W-9 in your browser - your TIN is never uploaded, stored or sent anywhere.1099-NEC Contractor SummaryPrepares a 1099-NEC recipient statement and a payer summary - with a straight answer about what you can and cannot print yourself.Shipping PolicyA shipping policy Shopify and Amazon sellers can publish - origin, times, tracking, duties and who pays.DSAR Form GeneratorA data-delete and access request page you can host - GDPR and CCPA wording, no upload, no signup.

About this tool

Privacy Policy Generator builds a privacy policy from your answers to a short questionnaire. It is for anyone running a website, app or shop that collects a single piece of personal information - and an IP address in a server log already counts, and the right moment is before launch, and again whenever you add a tool that touches visitor data. A privacy policy is not one document with a region switch. GDPR requires you to state a lawful basis for each purpose and to name your processors; CCPA requires a "do not sell or share" route and a promise not to retaliate. A page that claims both without doing either is the common failure. Nothing irrelevant is included. A clause that does not apply to you is omitted, not padded - a document describing something you do not do is a problem in its own right. Everything runs in your browser. What you type is never uploaded, never stored, and gone when you close the tab - which matters here more than on most tools, because these documents carry company details, client names and sometimes tax identifiers.

How to use this tool

  1. Answer the questionsBusiness or website name. Website address. Contact email for privacy questions. Nothing you type leaves the browser.
  2. Watch it assembleClauses appear and disappear as you answer, so the document matches what you actually do rather than a generic template.
  3. Copy or downloadCopy the text, or download as PDF, Word or plain text. The Word version is the one to edit.

Key features

  • Says plainly what it is and is not, above the preview rather than in a footer.
  • Runs entirely in your browser. Nothing uploaded, nothing stored, no account.
  • Downloads as PDF, Word or plain text - the Word file is editable with no protection on it.
  • Free with no watermark, no email wall and no per-document limit.
  • Built from your answers, so clauses you do not need are left out rather than padded.

Common uses

  • Getting something in place before launch, and again whenever you add a tool that touches visitor data.
  • Preparing what a client, an app store or a payment processor has asked to see.
  • Anyone running a website, app or shop that collects a single piece of personal information - and an IP address in a server log already counts.
  • Giving a lawyer a draft to review rather than paying them to start from nothing.
  • Replacing a copied document that describes a different business.

Tips for better results

  • Keep a copy of each version with its date. When someone asks what your terms said last March, the answer needs to be a file rather than a memory.
  • Pair it with Cookie Policy. Publishing one without the other leaves the gap people notice first.
  • Read it before you publish it. It is a draft built from standard clauses, and you are the only person who knows whether every line is true of you.
  • Fill in the free-text fields rather than skipping them. The named lists - processors, exclusions, deliverables - are what make it read as yours rather than copied.

Mistakes to avoid

  • Copying a policy from a bigger site. You inherit their data practices on paper - the analytics they run, the payment processor they use, the children clause they need - and every line that is not true of you is a misrepresentation you published deliberately.
  • Leaving the placeholder text in. Anything in square brackets is a field you skipped, and readers spot them immediately.
  • Treating a generated draft as a reviewed one. This is a starting point, and where the stakes are real it is worth a professional reading it.
  • Hiding it. A document nobody can find does not do its job - it belongs in the footer of every page.

Frequently asked questions

Answer the questions on the left. The document builds as you type, and you can copy it, or download it as PDF, Word or plain text when it looks right.

No. It assembles a draft from standard clauses, and every page says so above the preview. Beyond regulators, the practical cost is commercial: Apple and Google both refuse app submissions without a reachable policy URL, Google Ads disapproves accounts, and payment processors ask for it during onboarding.

Yes - free, no signup, no email required and no watermark. It runs in your browser, which is why it costs nothing to provide.

Broadly, anyone running a website, app or shop that collects a single piece of personal information - and an IP address in a server log already counts. The best time to do it is before launch, and again whenever you add a tool that touches visitor data.

No. Everything happens on your device - nothing is sent to a server, nothing is stored, and closing the tab clears it.

Most people need Cookie Policy and Terms and Conditions as well. They cover the gaps this one does not.

Copying a policy from a bigger site. You inherit their data practices on paper - the analytics they run, the payment processor they use, the children clause they need - and every line that is not true of you is a misrepresentation you published deliberately.

People also search for

  • free privacy policy generator
  • privacy policy generator for small business
  • privacy policy generator template
  • privacy policy generator no signup
  • privacy policy generator uk
  • privacy policy generator
  • privacy policy generator usa

Related guides