Do you need a privacy policy on your website?
Updated August 12, 2026
The short answer: yes, you almost certainly need a privacy policy, and it is far less scary than it sounds. If your website has a contact form, an email signup, an order page, or a visitor counter like Google Analytics, it collects personal information. Once that is true, a California law that reaches most websites in the US says you must post a privacy policy, and the tools you plug in expect one too. The good news is that a privacy policy is one honest page, not a legal project.
Quick answer
- A privacy policy is a page that says what personal information your website collects, why, who else sees it, and how someone can contact you about it.
- If your website collects any personal information at all, even just names and emails from a contact form, you need one.
- California law requires any commercial website that collects personal information about California residents to post a privacy policy where visitors can find it (California Business and Professions Code section 22575). Anyone in California can visit your website, so in practice this reaches almost every website in the US.
- Tools require one too. Google's terms for Analytics say you must "have and abide by an appropriate Privacy Policy."
- The big laws you hear about mostly are not aimed at you. The CCPA only covers businesses over $25 million in yearly revenue, or ones handling personal information of 100,000 or more California residents or households, or ones making half their money selling it (California Attorney General, 2026).
- You can get an honest policy written in an afternoon with a generator or your website tool's template. It belongs in your footer.
This guide explains it all in plain words so you know what the page is, why it is asked of you, and how to get it done. For anything unusual about your situation, a lawyer gets the final word.
What is a privacy policy in plain words?
A privacy policy is a page on your website that tells visitors four things: what personal information you collect, why you collect it, who else gets to see it, and what a visitor can do about it.
Personal information means anything that points at a real person. A name typed into a contact form. An email address on your signup list. A shipping address at checkout. It also includes quieter things, like the way analytics tools note which pages someone visited.
That is the whole idea. It is not a contract, and it does not need legal-sounding language. The best privacy policies read like a shop owner explaining, in their own voice, what happens to the details a customer hands over.
Does your website even collect personal information?
Most first-timers assume the answer is no, because they are not running some big data operation. But look at what a normal small website actually does:
- A contact form collects names and email addresses. That is personal information.
- An email signup collects addresses on purpose, that is the whole point. If you are building a list, our guide on growing an email list from your website covers the sending rules that come with it.
- An online store or booking page collects names, addresses, and order details. The card numbers go to the payment company, but the order information is still yours. Our guide on how payments work on your website shows who holds what.
- Analytics tools like Google Analytics use cookies to count visitors and see which pages they read.
If even one of those is on your website, you collect personal information. A pure brochure website with no forms and no analytics is the rare case that collects almost nothing, and almost nobody leaves it that way for long.
Which laws say you need one?
The one that matters most for a small US website is a California law often called CalOPPA. It says the operator of any commercial website that collects personal information about California residents must post its privacy policy where visitors can find it (California Business and Professions Code section 22575). Your website does not have to be in California. Since anyone in California can open your website and type into your contact form, the practical effect is that nearly every US business website needs the page.
If people in Europe use your website, Europe's privacy law, the GDPR, also applies to businesses outside Europe that offer goods or services to people in the EU. Its transparency rules say you must tell people who you are, what you collect, why, and who else receives it, in clear and plain language. A plain honest privacy policy is exactly how websites do that.
And it is not only laws. The tools you plug in carry the same requirement in their terms. Google's terms of service for Analytics say you will "have and abide by an appropriate Privacy Policy" and disclose that you use Analytics. Email list tools and payment companies expect the same. So even before any regulator cared, the tools you sign up for on day one already ask for the page.
Do the big scary privacy laws apply to you?
Mostly no, and this is the part nobody tells first-timers.
The privacy laws that make headlines are aimed at companies far bigger than a new business getting online. California's CCPA, the one behind "do not sell my personal information" links, only covers for-profit businesses that clear at least one of three bars: over $25 million in yearly revenue, or buying, selling, or sharing the personal information of 100,000 or more California residents or households, or earning half their revenue from selling personal information (California Attorney General, 2026). A new website with a contact form is nowhere near any of those.
Two situations do deserve extra care. If your website is aimed at children, a federal law called COPPA sets strict rules about collecting information from anyone under the age of 13 (15 U.S. Code section 6501), and that is worth a conversation with a lawyer before you build. And if you actively sell to customers in Europe, the GDPR asks more of you than a US-only website, so read up as you grow.
For everyone else, the honest summary is: the law that applies to you mostly asks you to post one truthful page. The giant fines you have read about belong to a different weight class.
What does your privacy policy need to say?
California's law spells out the core list, and it maps neatly onto plain English:
- What you collect. The kinds of personal information your website gathers, like names, email addresses, and order details.
- Who else sees it. The other companies your information flows through, like your email list tool, your payment company, and Google Analytics.
- How people can ask about their information. If you offer a way to review or change it, say how that works, and give a contact.
- How you announce changes. One line saying you will update this page when something changes.
- The date. When the policy took effect or was last updated.
Write it to match what your website actually does today, not what it might do someday. A short true page beats a long borrowed one every time. When you add a new tool later, add a line for it.
How do you actually get one written?
You do not write it from a blank page, and you do not need to hire anyone for a normal small website.
- List what your website collects. Walk through your own pages: forms, signup boxes, checkout, analytics. Write down each one and which company is behind it.
- Use a generator or your website tool's template. Privacy policy generators ask you plain questions about that list and produce the page. Many website builders include one. Answer honestly, and read the result once to check it matches reality.
- Put it on its own page and link it from the footer. The footer link is where every visitor, tool, and regulator expects to find it. Our guide on what pages a website needs shows where it sits among the rest.
- Note the date and move on. Come back only when your website starts collecting something new.
That is the whole task. It sits nicely in the same afternoon as the rest of your getting-online paperwork, and if a store is part of your plan, our guide on licenses and sales tax for selling online covers that side in the same plain way.
Sorting out the legal page for a website you have not built yet?
Describe your business in your own words, and Expert Built turns your description into the detailed prompt an AI website builder needs. The website comes out built around what you actually do, with the pages a real business needs, instead of the generic one everyone else gets.
Get startedWhen should you ask a real lawyer?
Most small websites never need to. A few situations are worth the hour: your website is aimed at children, you handle health or money information beyond a normal checkout, you sell into Europe at real volume, or you simply want certainty because your industry is regulated. A short consultation early is cheap compared with untangling a problem later.
For everyone else, the path is short. Your website collects a little personal information, the law asks you to say so plainly, and one honest page in your footer answers it. Write the page, link it, and get back to the part only you can do: the business the website exists for.
Frequently asked questions
- Can you copy a privacy policy from another website?
- That is a shortcut worth skipping. A privacy policy describes what that business collects and does with information, not what yours does. Copying one means publishing promises that are not true for your website, which is worse than having a short honest policy of your own. The text may also belong to whoever wrote it. Privacy policy generators and the templates inside website tools ask you plain questions and turn your answers into a policy that matches what you actually do, and that usually takes minutes.
- What happens if your website has no privacy policy?
- Usually nothing dramatic happens on day one, which is why so many people put it off. Under California's law, an operator who is notified gets 30 days to post a policy before they are considered out of line. Tools can be stricter, since their terms require you to have one from the start. The honest picture: the fix takes an afternoon, the risk grows as your website collects more, and the easiest time to do it is before your website goes online.
- Is a privacy policy the same as terms and conditions?
- No, they do different jobs. A privacy policy explains what personal information you collect and what you do with it, and it is the page laws and tools expect you to have. Terms and conditions are your house rules, things like payment terms, refunds, and what visitors may not do, and a simple website can often wait on them. If you run an online store, adding terms early is sensible because they set expectations about orders and refunds. Start with the privacy policy either way.
- Do you need one of those cookie pop-up banners too?
- The banner is a separate thing from the policy. Cookie banners come from European rules that say a website should ask before running cookies that are not needed for the website to work, like tracking cookies, for visitors in Europe. Your privacy policy is needed whether or not you show a banner. Many website tools and analytics tools can add a banner for you, so if your visitors include people in Europe, turn that option on rather than building anything yourself.