There are several other names for this policy — privacy statement, privacy declaration or sometimes, just privacy. Their purpose remains the same: to inform users about their private data use.
- Notify users about private data collection and usage
- Give users a choice in opting out of data collection
- Give users access to the collected data or contest its accuracy
- Assure users that their data is secure
All of this helps assure users that their private data won’t be sold to third parties or put to malicious use.
Before you write the policy, it’s important that you understand your own requirements, local regulations, and industry
Here are a few things you must do before getting started.
1. Understand local regulations
Although you have significant operational freedom as an
This will depend on three things:
- How your business is incorporated
- What kind of products you’re selling
- What state/jurisdiction your business is based out of.
Some jurisdictions and product categories (such as food supplements) have higher regulatory requirements than others.
You can find these regulations by Googling your state/country/county name/product +
Note that as the home of Silicon Valley, California is considered a leader in privacy laws. Most states and even countries look to California for direction when framing their own laws. Reviewing California’s privacy laws (CalOPPA) is a good idea when you’re starting out.
2. Understand your own data needs
What are you going to use customer data for? How are you going to store this data? Are there any proprietary data storage or analysis systems customers should know about?
- Email addresses and passwords (registering for the site)
- Names, addresses and phone numbers (placing orders)
- Credit card and other payment data (paying for orders)
- Data collection and user tracking via cookies
You’ll need to mention clearly how you collect and store this data. In case the data only passes through your site (i.e. you don’t store it), like credit card information, you need to mention this as well.
It’s also important that you meet your country or state’s requirements about data collection. Some countries like the UK require clear declarations if you’re going to track usage via cookies.
Here are some
- Personal Information Protection and Electronic Documents Act (Canada)
- Data Protection Directive (EU)
- Data Protection Act of 1998 (UK)
3. Research industry norms
Unless you are operating in a very obscure industry, you’ll likely have tons of competitors running their own profitable
Of course, these stores would have their own privacy policies as well. You can usually find them in the site’s footer.
Before you write your own policy, research a few competitors. Don’t borrow their exact policies but take note of the following:
- How the policy is written
- What information they’ve included in the policy, what they’ve omitted
- How they’ve handled data collection and disclosure
- Do they give users a way to opt out of data collection?
You’ll often notice a few patterns. Consider these your industry norms. Try to follow them when writing your own policy.
Here are a few things to follow when you’re doing this:
1. Make a list of everything you need to include
Start by making a list of everything you need to include in the policy. Again, this will depend on your regulatory requirements, industry norms and data needs.
- What personally identifiable information you’re collecting
- What personally identifiable information you’re sharing with third parties (such as email addresses or credit card data)
- The process by which users can request changes to any collected data
- The process by which you can notify users about any change to the policy
- What measures you’ve taken to protect data (such as using SSL)
Note that much of this is required by law.
Besides the above, you’ll also want to include the following:
- How you’ll treat reviews posted by users (and any personal data included in those reviews)
- Whether there is a minimum age for users to view the site (might be required for stores selling sensitive products)
- Whether you store sensitive payment information, and if yes, where and how
2. Write your policy
To make the process easier, use a quality template to create the basic structure. You can reframe it in your own words.
Of course, you’ll need to customize the template to fit your business. If the template doesn’t cover any specific regulation you need to follow (based on your jurisdiction/product), add sections as necessary.
Keep a few things in mind when writing the policy:
- Make the policy easy to read. It shouldn’t read like a blog post, but there is no reason to pepper it with legalese either. Make it formal without being too complex for average readers.
- Keep the policy brief. It can be tempting to include everything under the sun in the policy, but that will just make it harder to read. If you need to include a lot of information, consider adding a summary at the top to make it more
- Include contact information. Give users phone numbers, email addresses and physical addresses where they can get in touch for clarification or redressal.
- Include a date when the policy was last updated.
It’s also a good idea to include a link to the policy anywhere you’re collecting private information such as a newsletter or
This tells customers that you collect data responsibly, increasing trust.
To write your own policy, you’ll need to first understand industry norms and regulations. You’ll then want to frame all of this in a
Finally, make the policy easily visible to anyone who lands on your site. This will help underscore that you take privacy issues seriously.