Home / Shopify Privacy Policy Generator

Shopify Privacy Policy Generator

Preset for e-commerce: order and billing data, payment processors, marketing emails and ad pixels. Paste the result into Settings → Policies in your Shopify admin.

Free template, not legal advice. Replace every [bracketed] field, make sure it matches what you actually do, and get a lawyer's review for anything high-stakes. How clauses are sourced.

1 Quick start: what do you run?
2 Your details
3 Which laws should it cover?

Not sure? Check which laws apply to you.

4 What do you collect?
Platform
5 Services you use
6 A few specifics
+ Anything else

Only this description, your business name and chosen laws are sent to the AI. Check the draft carefully; it is a starting point, not legal advice.

Answers auto-save in this browser only.

Privacy Policy

[Bracketed] fields are placeholders · Template, not legal advice

Who we are

This Privacy Policy explains how [Business name] ("we", "us", "our") collects, uses and shares personal information when you use [Website or app name] (the "website"), available at [website URL]. For the purposes of the EU and UK General Data Protection Regulation, [Business name] is the controller of your personal data.

If you have any questions about this policy or your information, contact us:

  • Email: [contact email]
  • Postal address: [Business address]

Information we collect

Depending on how you use the website, we collect the following categories of personal information:

  • Contact details: name, email address, phone number.
  • Account login: username and password (stored hashed).
  • Purchase & billing: billing and shipping address, order history; card numbers are handled by our payment processor.
  • Usage data: pages or screens viewed, features used, clicks, referring page, time and date of visits.
  • Device & log data: IP address, browser type, operating system, device identifiers, crash logs.
  • Cookies & similar tech: cookies, local storage, pixels and SDK identifiers.
  • Support messages: the content of emails, chat and support requests you send us.
  • Marketing preferences: newsletter subscription status and email engagement (opens, clicks).

We collect this information directly from you (when you fill in a form, create an account, buy something or contact us), automatically from your device when you use the website, and from the service providers listed below.

How we use your information

  • To provide, operate and maintain the website.
  • To create and manage your account.
  • To process orders and payments, prevent fraud and send transaction receipts.
  • To answer your questions and provide customer support.
  • To understand how the website is used and improve it.
  • To send newsletters or marketing emails you have signed up for. You can unsubscribe at any time using the link in each email.
  • To show and measure advertising.
  • To keep the website secure and to comply with our legal obligations.

Legal bases for processing (EEA and UK visitors)

We rely on the following legal bases under Article 6 of the GDPR:

  • Contract: to provide the services you have asked for, such as your account or an order.
  • Legitimate interests: to run, secure and improve the website, where these interests are not overridden by your rights. [Describe each legitimate interest you rely on.]
  • Consent: for non-essential cookies, marketing emails and precise location. You can withdraw consent at any time without affecting processing that happened before.
  • Legal obligation: to keep records required by tax, accounting or other laws.

How we share information

We do not share your personal information except as described here. We share it with service providers who process it on our behalf and only as needed to provide their services:

  • Google Analytics, for website and app analytics (privacy policy: https://policies.google.com/privacy).
  • Meta Pixel, for advertising measurement and retargeting (privacy policy: https://www.facebook.com/privacy/policy/).
  • Stripe, for payment processing (privacy policy: https://stripe.com/privacy).
  • PayPal, for payment processing (privacy policy: https://www.paypal.com/us/legalhub/privacy-full).
  • Shopify, for online store hosting and checkout (privacy policy: https://www.shopify.com/legal/privacy).
  • Mailchimp, for email newsletters (privacy policy: https://www.intuit.com/privacy/statement/).

We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.

Cookies and tracking technologies

We and our partners use cookies and similar technologies on the website. Some third parties, such as analytics and advertising providers, may collect information about your online activities over time and across different websites when you use the website. See our Cookie Policy for details and for how to change your choices.

Do Not Track and opt-out preference signals

We treat a Global Privacy Control (GPC) signal from your browser as a valid request to opt out of the sale or sharing of your personal information for that browser. There is no common industry standard for older "Do Not Track" (DNT) browser signals, and we [do / do not] respond to them. [Confirm how your site actually behaves.]

California privacy rights (CCPA / CPRA)

This section applies to California residents. In the preceding 12 months we have collected the following categories of personal information, as defined in the California Consumer Privacy Act:

Category (CCPA)ExamplesDisclosed for a business purpose to
Identifiersname, email address, phone numberService providers listed above
Identifiers; account log-in credentials (sensitive personal information)username and password (stored hashed)Service providers listed above
Commercial informationbilling and shipping address, order history; card numbers are handled by our payment processorService providers listed above
Internet or other electronic network activitypages or screens viewed, features used, clicks, referring page, time and date of visitsService providers listed above
Identifiers; internet or network activityIP address, browser type, operating system, device identifiers, crash logsService providers listed above
Internet or other electronic network activitycookies, local storage, pixels and SDK identifiersService providers listed above
Identifiers; electronic informationthe content of emails, chat and support requests you send usService providers listed above
Internet or other electronic network activity; inferencesnewsletter subscription status and email engagement (opens, clicks)Service providers listed above

We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA.

You have the right to:

  • Know what personal information we have collected about you, including the categories, sources, purposes and the categories of third parties we disclose it to, and to receive a copy of specific pieces of information.
  • Delete personal information we collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information.
  • Limit the use of sensitive personal information, where we use it for purposes beyond those allowed by the regulations.
  • Not receive discriminatory treatment for exercising any of these rights.

To make a request, email [contact email]. We will verify your request by matching information you give us with information we hold. You may use an authorised agent to make a request on your behalf; we may ask for proof of the agent's authority.

We keep each category of personal information only as long as described under "How long we keep information".

Your rights under the GDPR (EEA and UK)

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing, including processing based on legitimate interests and direct marketing;
  • receive your data in a portable format;
  • withdraw consent at any time, where we rely on consent.

To exercise these rights, contact [contact email]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or where you believe an infringement occurred.

International transfers: our service providers may process data outside your country, including in the United States. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses. [Confirm the transfer mechanism for each provider.]

Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. [Edit if you do.]

Reviewing and changing your information

You can review and update the information in your account at any time from your account settings, or ask us to do it for you by email.

How long we keep information

We keep personal information as long as your account is active, and afterwards only as long as we need it for the purposes above or to meet legal, tax or accounting obligations.

How we protect information

We use reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

The website is not directed to children under 13 (or under the age of digital consent in your country, which is between 13 and 16 in the EU), and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the "Effective date" below, and if the changes are significant we will notify you by email or by a notice on the website before they take effect.

Effective date

This Privacy Policy is effective as of [Effective date].

14 left · View document ↓

Adding it to Shopify

In your Shopify admin go to Settings → Policies, paste the policy into the Privacy policy field and save. Shopify adds the page to your store and you can link it in your footer menu. Do the same with your refund and shipping policies.

Stores that run the Meta Pixel or Google Ads remarketing may be "sharing" personal information for cross-context behavioural advertising under the CCPA. If you are covered by the CCPA, answer "yes" to selling or sharing and add a "Do Not Sell or Share My Personal Information" link.

Frequently asked questions

Doesn't Shopify provide a privacy policy?

Shopify offers a basic template in its admin, but it can't know which apps, pixels and email tools you use. Your policy has to describe your store's actual practices.

Is it really free? Do I need an account?

Yes, and no. Every generator is free with no sign-up, watermark or paywall. Your answers stay in your browser; they are never sent to our server unless you use the optional AI clause writer or policy checker.

Is a generated policy legal advice?

No. PolicyForge produces a starting template from your answers. It cannot know every detail of your business or every law that applies to you. Read the whole document, replace every [bracketed] placeholder, make sure it describes what you actually do, and have a lawyer review it if you handle sensitive data, sell to children, or operate at scale.

Related generators