Privacy Policy for Small Business: What to Include and a Ready-to-Copy Template
Published September 4, 2026
Yes, most small businesses need a privacy policy -- even a one-person operation with nothing more than a contact form and an email list. The moment your website or app collects any personal information from visitors, privacy laws in the United States, Europe, Canada, and elsewhere require you to disclose what you collect, why, and what you do with it. Skipping this step does not just risk fines; it can also get your site blocked by payment processors, ad networks, and app stores that mandate a published policy before they let you use their services.
This guide explains which laws apply to small businesses at different sizes, what your policy must cover, and the common data flows that small business owners overlook. At the bottom you will find a complete sample privacy policy you can copy and customize. If you want a policy generated from your specific data practices instead, you can build one for free with the generator.
Does a Small Business Need a Privacy Policy?
The short answer is yes if your business collects any personal information online. There is no small-business exemption in any major privacy law. A sole proprietor running a WordPress site with a newsletter signup is subject to the same disclosure requirements as a Fortune 500 company -- the only differences are the scale of data processing and, in some laws, the specific obligations that kick in at certain revenue or data-volume thresholds.
The practical trigger is simple: if your website has a contact form, an email opt-in, a booking widget, a payment checkout, analytics tracking, or advertising pixels, you are collecting personal information. That collection -- regardless of your headcount or revenue -- creates a legal obligation to publish a privacy policy explaining what you do with that data.
Beyond legal requirements, third-party services enforce their own mandates. Google Analytics, Google Ads, Meta advertising, Stripe, PayPal, Mailchimp, and dozens of other tools require a published privacy policy in their terms of service. Violating these terms can result in account suspension, which for many small businesses means losing their primary marketing or payment channel overnight.
Not sure which specific regulations cover your situation? A privacy law eligibility check based on your audience and platform can map your business to the relevant frameworks in under a minute.
Which Privacy Laws Apply to Small Businesses
Privacy laws do not exempt businesses based on size alone. Instead, they set thresholds around revenue, data volume, or the type of data collected. Understanding which laws apply to your business determines what your privacy policy must say.
United States: a patchwork of state laws
The US has no single federal privacy law covering all businesses. Instead, several state laws apply based on where your customers are located or where your business operates.
- California (CCPA/CPRA). Applies if your business has annual gross revenue over $25 million, buys or sells the personal information of 100,000 or more consumers or households, or derives 50% or more of revenue from selling personal data. Most very small businesses fall below these thresholds, but the moment you run retargeting ads that share data with ad networks, the "selling or sharing" definition may apply. California also has CalOPPA, which requires any website accessible to California residents to post a privacy policy -- with no revenue threshold at all.
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other state laws. These typically apply to businesses that process data of 100,000+ consumers or 25,000+ consumers combined with revenue from data sales. Small businesses with local customer bases often fall below these thresholds, but the laws still set the standard for best practices.
- FTC Act. The Federal Trade Commission can take enforcement action against any business that makes deceptive or unfair privacy claims -- including having no privacy policy while collecting data, or having a policy that does not match actual practices. There is no size exemption.
Europe (GDPR)
The GDPR applies to any business that processes personal data of individuals in the European Economic Area, regardless of where the business is located or how small it is. If a single EU resident fills out your contact form, the GDPR applies. There is no revenue threshold, no employee count minimum, and no small-business exemption. Your privacy policy must name your lawful basis for processing, explain data subject rights (access, correction, deletion, portability), and identify any cross-border data transfers.
Canada (PIPEDA)
PIPEDA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity. Sole proprietors and micro-businesses are covered. Your privacy policy must explain what information you collect, why, and how individuals can access or challenge their data. Quebec's Law 25 adds additional requirements including a privacy officer designation and consent management.
Brazil (LGPD)
The LGPD applies to any business processing personal data of individuals in Brazil, regardless of the business's size or location. Like the GDPR, it requires a legal basis for processing, transparency about data use, and individual rights including deletion and portability.
The takeaway for small businesses: even if you fall below the thresholds of newer US state laws, CalOPPA, the FTC Act, the GDPR (if you have any international visitors), and third-party service agreements still require a published privacy policy. Not having one is the riskier position regardless of your size.
Required Clauses in a Small Business Privacy Policy
A compliant privacy policy for a small business covers the same core sections as any business privacy policy. The difference is scope -- a small business typically has fewer data flows, but each one still needs disclosure.
- What personal information you collect. List every data type: names, email addresses, phone numbers, physical addresses, payment information, IP addresses, browser and device data, and any other identifiers. Be specific rather than vague. "We collect your name and email address when you submit our contact form" is useful. "We may collect certain information" is not.
- How you collect it. Distinguish between data the user provides directly (form submissions, account creation, purchases) and data collected automatically (cookies, analytics scripts, server logs).
- Why you collect it. Map each data type to a purpose: responding to inquiries, processing orders, sending marketing emails, improving website performance, running ad campaigns. If you cannot name a purpose, drop the collection.
- Who you share it with. Name the categories of third parties that receive customer data: payment processors (Stripe, PayPal, Square), email marketing platforms (Mailchimp, ConvertKit), analytics tools (Google Analytics), advertising networks (Google Ads, Meta), hosting providers, and any other service that processes data on your behalf.
- How long you keep it. Specify retention periods by data category. Contact form submissions might be kept for one year. Transaction records are typically retained for seven years for tax compliance. Marketing email addresses are kept until the subscriber unsubscribes.
- User rights. Under the GDPR: access, correction, deletion, portability, objection. Under the CCPA: knowledge, deletion, opt-out of sale/sharing. Under PIPEDA: access and challenge. List the rights that apply to your audience and provide a contact method for exercising them.
- Cookies and tracking. Describe the categories of cookies your site uses (essential, analytics, marketing), what each does, and how visitors can manage preferences. If you use a consent banner, mention it.
- Children's privacy. State whether your site is directed at children under 13 (COPPA) or 16 (GDPR). Most small business sites are not, but the disclaimer must be explicit.
- Contact information. Provide an email address or other method for privacy inquiries. GDPR-covered businesses should name a data protection contact.
- Policy updates. Explain how you notify users of changes -- typically by updating the "last modified" date and, for significant changes, by email or website notice.
Common Data Flows Small Businesses Miss
Small business owners often know they need to disclose contact form data and payment processing. But several common tools and integrations create data flows that are easy to overlook in a privacy policy.
- Contact forms and inquiry widgets. Every contact form submission sends a name, email, and message body to your email inbox or a CRM. If you use a third-party form tool like JotForm, Typeform, or Gravity Forms, that service also processes the data.
- Email marketing platforms. When someone joins your newsletter, their email address, signup timestamp, IP address, and often their location go to your email service provider. Most platforms also track open rates and click-through behavior, tying engagement data to individual subscribers.
- Payment processors. Stripe, Square, PayPal, and similar services collect card numbers, billing addresses, and transaction details. Even though the processor handles the sensitive card data, your privacy policy must disclose that financial information is collected during checkout and name the processor.
- Booking and scheduling tools. Calendly, Acuity, Square Appointments, and similar tools collect names, email addresses, phone numbers, and sometimes payment details. The booking platform stores this data independently of your website.
- Analytics and advertising. Google Analytics collects IP addresses, device identifiers, page views, and session data. Google Ads, Meta Pixel, and other advertising scripts track conversion events and browsing behavior for retargeting. Each of these creates a data-sharing relationship that must be disclosed.
- Social media plugins. Embedded Facebook Like buttons, Instagram feeds, Twitter share widgets, and YouTube embeds all set cookies and transmit visitor data back to the respective platforms, even if the visitor does not interact with the widget.
- Live chat and chatbots. Intercom, Drift, Tidio, and similar tools collect visitor names, email addresses, chat transcripts, and browsing behavior. Chat data is stored on the third-party platform's servers.
- Review platforms. Google Reviews, Yelp, and Trustpilot collect reviewer names and sometimes email addresses. If you embed review widgets on your site, those platforms also track visitor behavior on your pages.
The rule of thumb: if a tool on your website sends data about a visitor to any server -- yours or a third party's -- it belongs in your privacy policy. Walking through your site's integrations before drafting the policy prevents gaps that could lead to non-compliance. For a deeper look at whether your website needs a policy at all and what triggers the requirement, see our guide on whether your website needs a privacy policy.
Sample Privacy Policy for a Small Business
Below is a complete privacy policy written for a fictional small business called "[Your Business Name]." It covers the data categories most small business websites handle -- contact forms, email marketing, payment processing, analytics, and advertising. Copy the entire block, replace the bracketed placeholders with your business details, and remove any sections that do not apply to your operations.
Privacy Policy for [Your Business Name]
Last updated: [Date]
1. Introduction
[Your Business Name] ("we," "us," or "our") operates the website [yourwebsite.com]. This privacy policy explains what personal information we collect from visitors and customers, why we collect it, who we share it with, how long we keep it, and what rights you have over your data.
2. Information We Collect
Information you provide directly:
- Name, email address, and phone number when you submit a contact form or inquiry
- Email address when you subscribe to our newsletter or mailing list
- Name, email, billing address, shipping address, and payment information when you make a purchase
- Name, email, and phone number when you book an appointment through our scheduling tool
- Any additional information you include in messages, reviews, or feedback
Information collected automatically:
- IP address, browser type, operating system, and device information
- Pages visited, time spent on pages, referring URLs, and click behavior
- Cookies and similar tracking technologies (see Section 6 below)
3. How We Use Your Information
- Respond to your inquiries and provide customer support
- Process orders, payments, and deliver products or services
- Send marketing emails and newsletters (only with your consent; you can unsubscribe at any time)
- Improve our website, products, and services through analytics
- Run advertising campaigns and measure their effectiveness
- Comply with legal obligations, including tax and accounting requirements
4. Third Parties We Share Data With
- Payment processor: [Stripe / PayPal / Square] receives your payment and billing information to process transactions securely.
- Email marketing: [Mailchimp / ConvertKit / other] receives your email address, name, and engagement data to deliver newsletters and marketing emails.
- Analytics: [Google Analytics / other] collects anonymized browsing data to help us understand how visitors use our website.
- Advertising: [Google Ads / Meta / other] receives conversion and browsing data to optimize ad campaigns and deliver relevant advertising.
- Hosting provider: [Your hosting provider] stores website data, including any information submitted through our site.
- Booking platform: [Calendly / Acuity / other] receives your name, email, and appointment details when you schedule a booking.
We do not sell your personal information to data brokers or unrelated third parties.
5. Data Retention
- Contact form submissions: retained for [1 year / your period] after the inquiry is resolved, then deleted.
- Transaction and order records: retained for [7 years] for tax, accounting, and legal compliance.
- Email marketing subscribers: retained until you unsubscribe. After unsubscribing, your email is moved to a suppression list to prevent accidental re-enrollment.
- Analytics data: retention depends on the tool. [Google Analytics retains user-level data for 14 months by default.]
- Cookies: session cookies expire when you close your browser. Persistent cookies expire after [12 months / your period].
6. Cookies and Tracking
Our website uses cookies and similar technologies for three purposes:
- Essential cookies: required for core website functionality such as shopping cart sessions and login persistence. These cannot be disabled without breaking the site.
- Analytics cookies: help us understand how visitors use the site by collecting anonymized usage data. We use [Google Analytics / other].
- Marketing cookies: used by advertising platforms to track conversions and deliver relevant ads. We use [Google Ads / Meta Pixel / other].
You can manage cookie preferences through your browser settings or through our cookie consent banner. Disabling non-essential cookies does not affect core website functionality.
7. Your Privacy Rights
If you are in the European Economic Area or United Kingdom (GDPR): You have the right to access, correct, delete, restrict processing of, and request portability of your personal data. You also have the right to object to processing and to withdraw consent at any time.
If you are in California (CCPA/CPRA): You have the right to know what personal information we collect, request its deletion, and opt out of the sale or sharing of your personal information. We do not sell personal information.
If you are in Canada (PIPEDA): You have the right to access your personal information held by us and to challenge its accuracy.
To exercise any of these rights, contact us at [your-email@example.com]. We will respond within 30 days.
8. Children's Privacy
Our website and services are not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at [your-email@example.com].
9. Changes to This Policy
We may update this privacy policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you by email or by posting a notice on our website.
10. Contact Us
If you have questions about this privacy policy or how we handle your data, contact us at:
[your-email@example.com]
[Your Business Name]
[Your Address (optional)]
This template covers the most common small business data flows. If your business handles specialized data -- health records, financial advisory information, or children's data -- add dedicated disclosure sections for those categories. For a policy tailored to your exact setup instead of editing a template, generate one for free with the privacy policy builder.
Frequently Asked Questions
Do small businesses need a privacy policy?
Yes. Any business that collects personal information through a website, app, or online service needs a privacy policy. There is no small-business exemption in any major privacy law. Even if your business falls below the thresholds of laws like the CCPA, CalOPPA and the FTC Act still apply to any website accessible to US consumers, and the GDPR applies if any EU resident can reach your site.
What happens if a small business does not have a privacy policy?
Operating without a privacy policy when you collect personal data exposes your business to regulatory fines, FTC enforcement actions for deceptive practices, and potential lawsuits from consumers. Beyond legal risk, many third-party services -- including Google Analytics, Stripe, PayPal, and advertising platforms -- require a published privacy policy in their terms of service and can suspend your account for non-compliance.
How much does a privacy policy cost for a small business?
Costs range from free to several thousand dollars depending on the approach. A privacy policy generator can produce a compliant policy at no cost. A lawyer-drafted policy typically costs $500 to $3,000 or more depending on the complexity of your data practices and the jurisdictions you need to cover. For most small businesses with straightforward data flows, a generator or customized template provides adequate coverage.
What is the difference between a privacy policy and a terms of service?
A privacy policy explains how you collect, use, store, and share personal information. A terms of service (or terms and conditions) governs the rules for using your website or service -- things like acceptable use, intellectual property, liability limitations, and dispute resolution. They serve different legal purposes and are typically published as separate documents, though both are commonly linked in a website footer.
Does a small business privacy policy need to mention cookies?
Yes, if your website uses cookies or similar tracking technologies. Under the GDPR and ePrivacy Directive, you must disclose non-essential cookies and obtain consent before setting them. Under the CCPA, if cookies transmit data to advertising networks, you must provide an opt-out mechanism. Your privacy policy should list the categories of cookies you use and explain how visitors can manage their preferences.
Can I write my own privacy policy for my small business?
You can, but accuracy matters more than authorship. A self-written policy must correctly identify every data type you collect, every third party that receives it, and the specific rights granted under each applicable privacy law. Missing a data flow or misstating a legal right can create compliance gaps. Using a privacy policy generator or a detailed template like the one above reduces the risk of omissions.
How often should a small business update its privacy policy?
Update your privacy policy whenever your data practices change -- for example, when you add a new analytics tool, switch payment processors, start running advertising pixels, or expand to serve customers in a new jurisdiction. At minimum, review the policy once a year to confirm it still reflects your actual practices. Each update should change the "last modified" date at the top of the document.
Where should I display my small business privacy policy?
Place a link to your privacy policy in your website footer so it is accessible from every page. Additionally, link to it near any data collection point: contact forms, newsletter signup boxes, checkout pages, and account registration forms. If you run a mobile app, include a link in the app settings or about section and in your app store listing.