Free tool · Paperwork

Privacy policy generator

Nine questions about what your website actually does, and a policy written in plain language that says only those things. No clause appears unless you confirmed the practice behind it — and the document is yours to download without giving us an email address.

This appears in the document. Use one you actually read.

Today's date is fine.

months

Months. Your tax authority usually sets a floor — ask your accountant.

Tick only what your site genuinely does

Every tick adds real clauses. Every untick removes them. A policy claiming practices you do not have is worse than a short honest one.

Google Analytics, Plausible, Fathom, or your host's built-in stats.

Most analytics do. A purely static brochure site often does not.

A Google Map, a YouTube video, a reviews widget, a social feed.

Tutoring, childcare, kids' clubs. This changes the clause materially.

Your privacy policy

Generated from 1 practice you confirmed. No clause below describes anything you did not tick.

# Privacy Policy for [Your business name]

**Effective [date]**

This policy explains what personal information [Your business name] collects through [your website address], why we collect it, and what you can do about it. It describes only the things we actually do — practices we do not have are not listed.

## Who we are

[Your business name] operates [your website address] and is responsible for the information described here. You can reach us at [your contact email].

## What we collect

- **Contact details you send us.** When you fill in a form on this site, we receive whatever you type into it — typically your name, your email address or phone number, and your message.

## Why we use it

- To reply to you and carry out the work you asked about.
- To meet our legal and tax obligations.

We do not sell your personal information, and we do not share it for anyone else's advertising.

## Who else sees it

- Our hosting provider, which stores the site and its data.
- A professional adviser or a public authority, where the law requires it.

## Cookies

This site does not set cookies of its own.

## How long we keep it

We keep enquiry and customer records for about 24 months after our last contact with you, unless a longer period is required for tax or legal reasons. After that we delete them or strip out anything that identifies you.

## Your choices

- You can ask us what personal information we hold about you.
- You can ask us to correct anything that is wrong.
- You can ask us to delete it, unless we are required to keep it.

To do any of these, email [your contact email]. We will respond within a month.

Depending on where you live, you may have additional rights under local law — for example under the GDPR in the UK and EU, or under state privacy laws in the United States. Those rights apply whether or not they are listed here.

## Children

This site is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has sent us personal information, contact us at [your contact email] and we will delete it.

## Security

We take reasonable steps to protect the information we hold, including limiting who can access it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

## Changes

If we change this policy we will update the effective date at the top. Material changes will be flagged on the site.

## Contact

Questions about this policy: [your contact email]

---

*This document was generated from your own answers using the free Black Nile privacy policy generator. It is a starting point written in plain language, not legal advice. If you handle health information, financial data, children's data, or you operate across several jurisdictions, have a lawyer review it.*

What this cannot tell you

This is not legal advice and it is not a substitute for a lawyer. It is a plain-language starting point that describes ordinary small-business practices accurately, which is more than most template policies manage. It does not cover health information, financial services regulation, employee data, or the specific consent mechanics some jurisdictions require for advertising cookies. If you handle any of those, or you operate across several countries, get it reviewed. And read it before you publish it — a policy you have not read is a claim you cannot stand behind.

Reopens the generator with the same answers — handy for regenerating after you add a booking form.

A policy needs a page to live on.

Publish it as a page on your site and link it from the footer — that is where visitors and payment providers both look for it.

Build my site free
No sign-upNo email gateOnly true clauses

The short answer: A privacy policy should describe what your site actually does with people's information. Most generators produce the opposite: a maximalist template covering analytics, advertising cookies, third-party data sharing and account systems you have never had, on the theory that more coverage is safer. It is not safer — a policy claiming practices you do not have is a false statement about your business, and it is also unreadable, which defeats the point. This one adds a clause only when you confirm the practice, and it says so at the top of the document. Tick nothing and you get the shortest honest policy: a site that collects nothing beyond ordinary server logs.

This runs entirely in your browser. Nothing you type here is sent to us or to anyone else — there is no server call, no account, and no email required to see your result or take it away with you. There is a certain irony in a privacy policy generator that harvests your data. This one does not — the document is built in your browser.

How to generate your privacy policy

Nine questions, and the honest answer to each is the useful one.

  1. Fill in your business name, website, a contact email you actually read, and an effective date.
  2. Tick only the practices your site genuinely has. Untick anything you are unsure about — you can regenerate later.
  3. Name your analytics and payment providers if you use them; those appear in the document by name.
  4. Set how long you keep enquiry records. Your tax authority usually sets a floor — ask your accountant.
  5. Read the generated policy from top to bottom. A policy you have not read is a claim you cannot stand behind.
  6. Download it, publish it as a page, and link it from your footer.

Regenerate it when your site changes. Adding a booking form or turning on analytics changes what the policy should say, and a policy that describes last year's website is worse than no policy at all.

Why a shorter, true policy beats a longer, generic one

The instinct to cover everything is the wrong one.

The standard template covers every practice any website might have. The reasoning offered is that a broader document is safer, because you cannot be caught doing something it does not mention.

That gets it backwards in two ways. A privacy policy is a public statement about your business; claiming you share data with advertising partners when you do not is inaccurate, and inaccuracy is not a safe harbour. Regulators looking at a complaint compare what you said against what you do — in both directions.

It also destroys the document's actual purpose. Nobody reads a four-thousand-word policy covering practices that do not apply. A four-hundred-word policy describing exactly what your contact form does is one a customer might actually read, and a customer who reads it is a customer who trusts you slightly more.

There is a practical benefit too. When you know what your policy says, you can answer a customer's question about it without opening it. That is only possible when it is short enough to hold in your head.

What a typical small business website actually collects

Usually less than owners assume, and occasionally more.

  • Contact form submissions. Whatever the visitor types — a name, a phone number, a message. This is the main thing most local business sites collect, and often the only thing.
  • Analytics, if you turned it on. Which pages were viewed, roughly where the visit came from, what device was used. Many owners are unsure whether they have this; check whether you ever set it up.
  • Payment details, handled elsewhere. If you take payment, the processor handles the card and tells you only whether it worked. You almost certainly do not store card numbers, and your policy should say so plainly.
  • Embedded content. A Google Map, a video, a review widget. These load from someone else's servers, which means that provider can see the visit and may set cookies you do not control. Easy to forget, and worth disclosing.
  • Ordinary server logs. Every web host keeps these. They are unremarkable, and a policy that mentions nothing else should still acknowledge them.

The list of things a small brochure site does NOT do is longer and more interesting: no accounts, no profiling, no data sales, no advertising networks, no cross-site tracking. Saying that explicitly is a genuine trust signal, and it is only available to you if the policy is honest.

Do you actually need a privacy policy?

The honest answer is yes, for reasons beyond the legal one.

If your website collects any personal information at all — and a contact form counts — then privacy law in most jurisdictions expects you to tell people what you do with it. That includes the GDPR in the UK and EU, several US state laws, and equivalent regimes elsewhere. The specifics vary; the general expectation does not.

Beyond the law, there are practical requirements. Payment processors and app platforms generally require a published policy. Advertising platforms require one before they will run your ads. And a visitor who is deciding whether to type their phone number into your form has a reasonable question about where it goes.

The threshold for needing one is much lower than owners assume. A one-page site with nothing but a contact form is in scope. A site with no forms at all is arguably not, but its host still keeps logs, and a two-sentence policy saying so costs nothing.

Where the policy goes, and what to do next

Publishing it is the part people leave for later and then never do.

Put it on its own page and link it from the footer of every page on your site. That is where visitors look, where payment processors check, and where advertising platforms expect to find it.

Link it next to your contact form as well, in small text. It costs nothing and it answers the question the visitor is silently asking at exactly the moment they are asking it.

Then diarise a review. Every time you change what your site does — add a booking form, turn on analytics, start a newsletter — the policy needs regenerating and the effective date updating. Six-monthly is a reasonable rhythm even when nothing has changed, because things change without being noticed.

FAQ

Questions, answered

The things owners ask before they trust a number like this.

Do I need a privacy policy for my small business website?

If your site collects any personal information — and a contact form does — then yes, in most jurisdictions. Beyond the legal requirement, payment processors and advertising platforms generally require one before they will work with you, and visitors deciding whether to type their phone number into your form have a reasonable question about where it goes. The threshold is lower than most owners assume: a one-page site with a single contact form is in scope.

Is a free privacy policy generator good enough?

For an ordinary small business website with a contact form, some analytics and perhaps a payment processor — usually yes, provided the document actually describes what you do. Where free generators go wrong is producing a maximalist template covering practices you do not have, which is inaccurate rather than safe. If you handle health data, financial data, children's data, or operate across multiple jurisdictions, have a lawyer review it.

What should a privacy policy include?

Who you are and how to contact you; what personal information you collect and how; why you use it; who else sees it and why; whether you use cookies; how long you keep things; what rights the visitor has and how to exercise them; and how to reach you with a question. That is the structure this generator produces. Everything else is either jurisdiction-specific detail or padding.

Do I need a cookie banner as well?

It depends on what cookies you set and where your visitors are. If your site sets only essential cookies, generally no. If you run analytics or advertising cookies and have visitors in the UK or EU, the rules there expect consent before non-essential cookies are set — which requires a mechanism, not just a policy paragraph. Several US states have their own requirements. A policy alone does not satisfy a consent requirement, and this generator does not produce a banner.

How long should I keep customer enquiry data?

As long as you need it for the purpose you collected it, plus whatever your tax authority requires for records of actual transactions — commonly several years. For enquiries that never became customers, a much shorter period is appropriate; twelve to twenty-four months is a common and defensible choice. The principle in most privacy regimes is that you should not keep personal data indefinitely just in case. Ask your accountant for the floor on transaction records.

Does my privacy policy need to mention Google Analytics?

Yes, if you use it. Analytics collects information about your visitors and sends it to a third party, which is exactly the kind of thing a policy exists to disclose. Name the provider rather than saying 'analytics services' — a visitor who wants to understand what happens to their data needs to know whose systems it goes into. The generator adds the clause and the provider name when you tick the box.

Can I copy another business's privacy policy?

Technically it is their copyrighted text, and practically it describes their practices rather than yours. A copied policy will claim things you do not do and omit things you do, which is the specific failure this generator is designed to avoid. It is also a strange document to have published without reading. Generating one from your own answers takes five minutes and produces something you can actually stand behind.

What if I do not collect any data at all?

Tick nothing and the generator produces the shortest honest policy: a site with no forms, no analytics and no accounts, whose host keeps ordinary technical logs as all web hosts do. That is a perfectly valid policy and quite a lot of small brochure sites should have exactly it. Saying plainly that you collect nothing is a genuine trust signal, and it is only available to businesses whose policies are honest.

How often should I update my privacy policy?

Whenever what your site does changes — a new booking form, analytics turned on, a newsletter started, a payment provider added. Update the effective date each time, and flag material changes on the site. Even with no changes, a six-monthly look is worth it, because things get added to websites without anyone thinking about the policy. Regenerating here takes two minutes.

More free tools

Others that pair with this one

Every one runs in your browser, free, with no sign-up.

See every free tool

Related

Where to go next

The reading that turns this result into a decision.

Now it needs a page to live on.

Publish your policy as a real page and link it from the footer — that is where visitors and payment processors both look. Free to build and publish.