Legal

Privacy policy

Placeholder page

This is not a privacy policy. It is an outline of the sections a compliant policy needs. A real policy depends on where the business operates, where its customers are, and which third-party services process data. It should be reviewed by someone qualified before publication. Do not publish this page as-is.

Sections a completed policy needs

  • Who the data controller is — legal entity name and contact details
  • What personal data is collected, and at which points
  • Why it is collected and the lawful basis for processing
  • Cookies and similar tracking, including any analytics or advertising pixels
  • Third parties that receive data — payment processor, shipping carriers, email provider, hosting
  • How long data is retained
  • Customer rights and how to exercise them, including any applicable state or regional rights
  • Children’s data
  • Security measures
  • How changes to the policy are communicated
  • Complaint route

WordPress also generates a draft privacy policy under Settings → Privacy that lists the data WordPress and WooCommerce themselves collect. That draft is a useful starting point but is not sufficient on its own.