Legal
Privacy policy
Placeholder page
This is not a privacy policy. It is an outline of the sections a compliant policy needs. A real policy depends on where the business operates, where its customers are, and which third-party services process data. It should be reviewed by someone qualified before publication. Do not publish this page as-is.
Sections a completed policy needs
- Who the data controller is — legal entity name and contact details
- What personal data is collected, and at which points
- Why it is collected and the lawful basis for processing
- Cookies and similar tracking, including any analytics or advertising pixels
- Third parties that receive data — payment processor, shipping carriers, email provider, hosting
- How long data is retained
- Customer rights and how to exercise them, including any applicable state or regional rights
- Children’s data
- Security measures
- How changes to the policy are communicated
- Complaint route
WordPress also generates a draft privacy policy under Settings → Privacy that lists the data WordPress and WooCommerce themselves collect. That draft is a useful starting point but is not sufficient on its own.