You are not allowed to copy

Privacy Policy Generate

Create a free privacy policy for your online business, website, or app. Comply with laws like the GDPR, CCPA, CalOPPA, PIPEDA, and more. One of the best privacy policy generators of 2023

Privacy Policy Uses

Privacy Policy Title

Privacy Policy Uses

What will this Privacy Policy be used for?
What is the URL address of your website?
Enter the URL of the website for which you are making this Privacy Policy.
What is the name of your mobile application?
Enter the full name of your mobile app.
User Information

User Location

Do you have users in the EU, UK, Switzerland, Iceland, Liechtenstein, or Norway?
Do you have users in Canada?
Do you have users in the United States?

California (USA) Users

Do you want your privacy policy to be California Consumer Privacy Act (CCPA) compliant?

Sale / Disclosure of Info

Please specify services that are used for selling or disclosing personal information:

Under CCPA, if you use non-essential tracking technologies to share a user's personal information to another entity for valuable consideration, this is considered "selling." If these trackers do not receive valuable compensation, then it is considered "disclosing."

Add your own
Specify the click redirect(s)

Example: Amazon affiliate link

Specify the social media plugin(s)

California Customer Records Personal Information

Personal information listed in the California Customer Records statute include:
  • Name
  • Signature
  • Social security number
  • Physical characteristics or description
  • Address
  • Telephone number
  • Passport number
  • Driver's license or state identification card number
  • Insurance policy number
  • Education or employment history
  • Bank account number, credit card, debit card number, or any other financial information
  • Medical and health insurance information
Have you collected or disclosed any personal information listed above in the last 12 months?
How long will you keep any of the personal information listed above?

Identifiers

Have you collected or disclosed personal identifiers in the last 12 months?

This is unique information that allows the identification of the person in question, such as an email address or social security number.

How long will you keep personal identifiers?

Characteristics

Have you collected or disclosed information related to a user's characteristics in the last 12 months?

This is information that describes a person or a feature that distinguishes a person, such as their gender or age.

How long will you keep a user's characteristics?

Consumer Data

Have you collected or disclosed information related to a user's purchasing history or tendencies in the last 12 months?

This is a record of what products or services a person has purchased or considered purchasing, consumption patterns, or even personal property.

How long will you keep consumer data?

Biometric Data

Have you collected or disclosed biometric information in the last 12 months?

This is information that can be used to digitally identify a person, such as the iPhone's fingerprint and facial recognition technology.

How long will you keep biometric information?

Internet Activity

Have you collected or disclosed information regarding a user's internet activity in the last 12 months?

This is any tracking or compiling of a person's online activity, for example, to personalize content or advertisements that you want the user to see.

How long will you keep biometric information?

Geolocation Data

Have you collected or disclosed information regarding a user's location in the last 12 months?

This is a person's physical location or movements through an Internet-connected device, such as a browser, computer, or mobile device.

How long will you keep geolocation data?

Sensory Data

Have you collected or disclosed audio, visual, thermal, electronic, or olfactory recordings/data in the last 12 months?

This is information that is recorded or detected by the senses, such as a recording of a person's conversation, or temperature detected by a thermal camera.

How long will you keep Sensory data?

Professional and Employment Data

Have you collected or disclosed professional- or employment-related information in the last 12 months?

This is information about a person's professional experience, such as work history or a job evaluation.

How long will you keep professional and employment data?

Education Information

Have you collected or disclosed student education records in the last 12 months?

These are records that are directly related to a student and maintained by an educational agency or institution, such as grades or class schedules.

How long will you keep professional and employment data?

Inferences

Do you create consumer profiles based on inferences or conclusions you make from user's personal information?
Have you disclosed the information about the inferences you made to a third party?
How long will you keep information about inferences?

Sensitive Personal Information Under the CCPA

Please select the sensitive personal information that you collect:

Skip this question if you do not collect any.

Have you disclosed sensitive personal information under the CCPA in the last 12 months?
How long will you keep the sensitive personal information?

Metrics

Do you process the personal information of 10 million or more California residents annually?

Under the CCPA, if your business processes the personal information of 10 million or more California residents annually, you are required to disclose metrics about data subject access requests form California residents for the previous calendar year. Please enter the URL where your metrics are disclosed.

Enter the URL that reports the metrics

Financial Incentives

Will you provide financial incentives to California residents in exchange for their personal information?

Inquiries

How can users contact you regarding CCPA-related questions?

Note: California residents have the right to request information about personal information that has been collected, disclosed, or sold. Under the CCPA, you must respond to their request within 45 days. You must also have an identity verification system in place.

Virginia (USA) Users

Do you want your privacy policy to be Virginia Consumer Data Protection Act (CDPA) compliant?

If your for-profit business collects the personal information of users located in Virginia (or may do so in the future), you may be required to comply with the CDPA. Check the FAQ on the right to see if you meet the requirements.

User Accounts

Can users create an account or register with your website or app?
How would you like to instruct users to update or delete their accounts?

Please select all that apply.

Add your own

User Age

Do you target users under the age of 18?
If you are located in the EU or UK and target users under the age of 16:

The GDPR requires that websites and apps obtain parental consent before processing any personal information.

If you are located in the US and target users under the age of 13:

The Children’s Online Privacy Protection Act (COPPA) has complicated requirements, and non-compliance can result in serious penalties. We suggest you consult with an attorney to ensure you understand you obligations.

Advanced Options (Not recommended for most users)

The majority of users do not need to change these settings. By interacting with this section, you understand that you should carefully review the resulting policy text and consult with a lawyer before making any changes.

EEA & UK Representative

Do you have an European Economic Area (EEA) and/or a UK representative?

EEA Representative

Who is your European Economic Area (EEA) representative?

You must fill out at least one contact method below.

Your EEA representative's email address
Your EEA representative's website URL for contact
Your EEA representative's phone number

EEA Representative Address

Country
Address line 1
Address line 2
City/Town
Province
Postal code
You may include a link, if you have multiple address contacts for your EEA representative:

UK Representative

Who is your European Economic Area (UK) representative?

You must fill out at least one contact method below.

Your UK representative's email address
Your UK representative's website URL for contact
Your UK representative's website URL for contact

UK Representative Address

Country
Address line 1
Address line 2
City/Town
Province
Postal code

International Transfers

Will you be transferring EU or UK user's personal information to anyone outside the EU or UK?
Where are your servers located (this includes server locations where you send personal information to)?
When you disclose personal information to third parties, in which countries are the third parties located?
Which set(s) of rules do you adhere to when transferring personal information internationally?

Check all that apply. You must adhere to at least one.

Can you provide a link to your company's Data Processing Agreement which contains Standard Contractual Clauses?
Please provide a link to your company's Data Processing Agreement which contains Standard Contractual Clauses.
Please provide a link to your binding corporate rules.

Privacy Shield

Do you currently adhere to Privacy Shield?

Please note that on July 16th, 2020, the Schrems II decision by the CJEU (Court of Justice of the European Union) invalidated the Privacy Shield Framework as a method for international transfer compliance.

Do you still plan to maintain Privacy Shield even if it's no longer an option for international transfer compliance?
Which Privacy Shield Framework are you registered to?
Please list any of your entities or subsidiaries that adhere to the Privacy Shield Principles.
Enter the URL address to your Privacy Shield listing
Which "independent recourse mechanism" do you offer for privacy-related complaints from EU, UK, and/or Swiss users?
Enter the name of your independent dispute resolution provider for the Privacy Shield program
Enter the dispute resolution website
Do you want to include any additional information about your Privacy Shield certification?
Additional Information
If you currently adhere to the Privacy Shield Framework, and do not plan to maintain Privacy Shield certification you must review and continue to abide by your obligations regarding any information you collected over the duration of your participation in the Privacy Shield program.
Collection Of Information

Personal Information Collected Directly

Please select the personal information you intend to collect directly from the user:

"Collect directly" means the user directly provides you with this information. For example, a user may give you their name and email address when signing up for an account on your site.

Add your own

Sensitive Personal Information Collected

Do you collect sensitive information?

If you are not sure, select "Yes" to see examples on sensitive information.

Please select the sensitive personal information you collect:

Generally, personal information categorized as sensitive must be treated with more care and caution.

Add your own
Sensitive categories of personal information must be treated with additional care because of the risk imposed on the data subject.

Personal Information from Social Media

Can users register for your website or app using Facebook, Google, or other social media accounts?

Personal Information Collected Automatically (Derivative Data)

Will you be collecting any derivative data from your users?

If you use tracking and analytics services such as Google Analytics, you are likely collecting derivative data.

Please select each category of derivative data that you intend to collect:
Do you want to add your own category?

Personal Information from Applications

The following questions pertain to your application(s).

Will you be requesting access to your user's geolocations?
Will you be requesting access to features on your user's mobile devices?

Features may include contacts, calendars, bluetooth, etc.

Which features will you be requesting access to?

Please select all that apply.

Add your own
Will you be collecting any information regarding your user's mobile devices?
Will you be sending push notifications to your users?
Does your mobile app have an “offer wall”?

Personal Information from Other Sources

Are you collecting personal information about your users from other sources?
Under the EU GDPR and the UK GDPR, when you obtain personal information indirectly (e.g., public records, internet, email lists), you must:
(1) Notify the individuals that you have their information, and provide them with a privacy notice (do this as soon as possible, as the legal deadline for notice is one month after you obtain the individual's information).
(2) Notify the individuals immediately upon using their personal information or sharing that information with another party.
Under Canadian privacy law, you can only use personal information you obtained from other sources for data mapping if you have the user's consent. For example, data mapping includes using data from other sources to update your records and enhance your ability to provide relevant marketing, offers, and services.
Use of Information

EU/UK Legal Bases for Processing

What are legal bases for processing a user’s personal information?

When it is necessary to process a user's personal information you must have a reason, known as a legal basis. Legal bases can vary under different privacy laws.

Under the EU and UK's GDPR, you need a valid reason to use personal information — this is called a "lawful basis." There are six lawful bases for processing under the GDPR: Consent, Performance of a Contract, Legitimate Interests, Legal Obligation, Vital Interests, or Public Tasks.

In addition to needing lawful basis, you must also notify your users about why you use their personal information (Article 13).

Will my privacy policy list legal bases under the GDPR?

By default, your privacy policy will list five of the most common legal bases that apply to most companies: (1) Consent (2) Performance of a Contract (3) Legitimate Interests (4) Legal Obligation (5) Vital Interests. We will not list the sixth legal basis, "Public Tasks," as it will not apply to the majority of termsgo customers. Please reach out to termsgo customer service if you would like to add it to your privacy policy.

Legal Basis: Provision of Services / Performance of a Contract

Do you use personal information to provide your Services or fulfill contractual obligations with your users?
When providing your Services or fulfilling contractual obligations with your users, in what ways do you need to use their personal information?
Do you want to add other ways you use the personal information?

Please enter why you are using the user's personal information and a short description for that use.

Legal Basis: Legitimate Interests

Are there any other important reasons you use your user's information?

Select "Yes" to see examples of other important reasons.

When you cannot rely on any other legal bases to use your user's information, and the use of information is important to you and fair to your users, then you are likely able to rely on the legal basis called "legitimate interest." When you rely on legitimate interests to use information about your users, you must list the reason you use the information AND why it is important that you do so. Below are examples of commonly applicable uses and their reasons (in italics). However, in most cases you will also need to use the "add your own" for any uses and reasons that are unique to your business.

Do you want to add your own important reason to use your user's information?

Please enter the reason for using the information, a short description of the reason, and what your legitimate interest is for that reason.

Use of Information

How will you use the information you collect?

Please select all that apply.

Do you want to add other ways you use the information you collect?

Marketing and Promotional Communications

Do you send marketing or promotional communications to your users?

If yes, make sure you have selected "To send marketing and promotional communications" as a reason for using your user's personal information (on previous page).

How can users unsubscribe to these marketing and promotional communications?
Add your own
Disclosure of Information

Third Parties

Do you disclose or users' personal information to third parties?

If you use third-party services like Google Analytics, you are disclosing information.

Do you disclose or sell/share users' personal information to third parties?

If you use third-party services like Google Analytics, you are disclosing information.

How do you want to list the third parties that you disclose information with?

Disclosure to Third Parties

Which third parties do you disclose users' personal information to?

The most common categories of third-party services are listed below. Select all that apply.

Add your own

Sell to Third Parties

Which third parties do you sell users' personal information to?

Select all that apply.

Add your own

Share to Third Parties

Which third parties do you share users' personal information with?

Select all that apply.

Add your own

Disclosure to Third Parties

Which third-party services do you disclose users' personal information to?

The most common third-party services have been organized by their purposes below. Use the dropdown menu to select all that apply. If you cannot find a third-party service on the list, you can manually add it under the appropriate purpose. If you use a third-party service for a purpose that isn’t listed here, you can add that purpose and the third-party service using the field at the bottom.

Advertising, Direct Marketing, & Lead Generation

ex. Bing Ads, Chitika, Google AdSense.

Affiliate Marketing Programs

ex. Amazon Affiliation, eBay Partner Network, iTunes Affiliation.

Allow Users to Connect to Their Third-Party Accounts

ex. Facebook account, Google account, Instagram account.

Cloud Computing Services

ex. Microsoft Azure, Google Cloud Platform

Communicate & Chat with Users

ex. Customerly, Facebook Customer Chat, LiveChat.

Content Optimization

ex. Google Site Search, TripAdvisor widget, YouTube video embed.

Data Backup & Security

ex. Dropbox Backup, Google Drive Backup, Vaultpress.

Functionality & Infrastructure Optimization

ex. Cloud Firestore, Firebase Legacy, termsgo.io.

Invoicing & Billing

ex. Apple Pay, PayPal, Stripe.

Retargeting Platforms

ex. AdRoll, Facebook Custom Audience, Google Ads Remarketing.

Social Media Sharing & Advertising

ex. Facebook advertising, Google+ social plugins, Reddit plugins.

User Account Registration & Authentication

ex. Facebook Login, GitHub OAuth, Google Sign-In.

User Commenting & Forums

ex. Disqus, Facebook Comments, Muut.

Web & Mobile Analytics

ex. Crazy Egg, Google Analytics, Heap Analytics.

Website Hosting

ex. Shopify, Tumblr, WordPress.com.

Website Performance Monitoring

ex. Crashlytics, Firebase Crash Reporting, Sentry.

Website Testing

ex. Google Play Console, Optimizely, TestFlight.

Other
Do you have data processing agreements in place with your third-party service providers?

If a third-party service provider is processing your EU or UK users' personal information, they need to provide you with a data processing agreement in order for you to comply with the GDPR. This agreement can usually be found in the third-party service provider's terms of service, or they may have a separate data processing agreement. Ask your third-party service providers for their data processing agreements if you're unable to locate them.

This step is crucial for GDPR and CCPA compliance and we suggest that you contact your third-party service providers and ask them to sign a Data Processing Agreement with you.
By default, termsgo includes language about sharing personal information in the case of ‘Business Transfers’, meaning when your business needs to share personal information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of your business to another company. Please note, some laws, require more than just including this language in your privacy policy and may contain provisions that should be followed in these circumstances. If you are not sure about such obligations please consult with an attorney.

Online Payments

Does your website/app accept payments online?

Can a user make purchases or complete a payment on your website/app?

Paste a link to your payment vendor's privacy policies:

Copy and paste their privacy policy URL below

Do you want to include additional details?

Online Posting

Can users upload or post content on your website?

This includes comments, articles, photos, audio, videos, user profile images, etc.

Interactions with Other Users

When users interact, can they see other user's personal information?

Third-Party Advertisers

Does your website or app contain advertisements from third parties that are not affiliated with you?

Business Affiliates

Will you disclose any of your user's personal information to business affiliates?

Business affiliates include your parent company, subsidiaries, and joint venture partners.

Business Partners

Will you disclose any collected information to business partners?

Security Measures

Do you have appropriate security measures in place that protect your users’ personal information?

If "Yes," termsgo will include a general clause about security measures in your privacy policy.

Please ensure that you are keeping personal information safe. We recommend consulting with an information security expert and and updating your policy once you are confident you can protect your users’ privacy.

Retention of Information

Do you want to specify how long will you keep the information that you've collected from your users?
How long will you keep the information that you've collected from your users?
Use Of Tracking Technologies

Tracking Technologies

Which of the following does your website or app use or plan to use?

Cookie Policy

Do you already have a cookie policy?
Would you like us to embed the link to your cookie policy into your privacy policy?

We highly recommend you link your cookie policy within your privacy policy.

Would you like us to embed the link to your cookie policy into your privacy policy?
termsgo’s Cookie Policy Generator can help you create a customizable cookie policy for your website, ecommerce site, SaaS, online marketplace, or iOS mobile app. Go to your dashboard to start generating your own Cookie Policy right now.
A cookie policy is required for you to use cookie-enabled Maps APIs. Do you already have a Cookie Policy?
Would you like us to embed the link to your cookie policy into your privacy policy?
Please enter the URL of your cookie policy.
A cookie policy is required for you to use cookie-enabled Maps APIs. Google Maps Platform APIs terms of service require websites and applications using cookie-enabled maps to have a cookie policy. termsgo’s Cookie Policy Generator can help you create a customizable cookie policy for your website, ecommerce site, SaaS, online marketplace, or iOS mobile app. Go to your dashboard to start generating your own Cookie Policy right now.

Google Maps APIs

Google Maps Platform API Terms of Service requires websites and applications using any Google Maps Platform APIs to have a Terms of Use. The Terms of Use: (1) must be publicly available, and (2) you must explicitly state in your Terms of Use that by using your application, users are bound by Google's Terms of Service. If you do not have a Terms of Use that meets these requirements, you should not use Google Maps Platform APIs.
Does your Maps Platform API Implementation enable you or any party to gain access to information about users of the Maps Platform APIs?
Please list all the information you will be collecting:
Will you obtain or cache the user's location?
Do you want to specify how long you will cache the user's location?
Number of months
A cookie policy is required for you to use cookie-enabled Maps APIs. Do you already have a Cookie Policy?
Would you like us to embed the link to your cookie policy into your privacy policy?
Please enter the URL of your cookie policy.
A cookie policy is required for you to use cookie-enabled Maps APIs. Google Maps Platform APIs terms of service require websites and applications using cookie-enabled maps to have a cookie policy. termsgo’s Cookie Policy Generator can help you create a customizable cookie policy for your website, ecommerce site, SaaS, online marketplace, or iOS mobile app. Go to your dashboard to start generating your own Cookie Policy right now.

Google Maps APIs

Google Maps Platform API Terms of Service requires websites and applications using any Google Maps Platform APIs to have a Terms of Use. The Terms of Use: (1) must be publicly available, and (2) you must explicitly state in your Terms of Use that by using your application, users are bound by Google's Terms of Service. If you do not have a Terms of Use that meets these requirements, you should not use Google Maps Platform APIs.
Does your Maps Platform API Implementation enable you or any party to gain access to information about users of the Maps Platform APIs?
Please list all the information you will be collecting:
Will you obtain or cache the user's location?
Do you want to specify how long you will cache the user's location?
Number of months
User Rights

Data Protection Officer (DPO)

Have you, or will you, appoint a data protection officer (DPO)?

A data protection officer (DPO) oversees the company's compliance with US, EU and/or UK privacy laws. If you are targeting EU or UK users, you may be required to have a DPO. If you only target US users, we still highly recommend having a DPO or another individual responsible for all privacy issues at your company.

What is the DPO's name?
What is the DPO's email?
DPO's phone number
Does the data protection officer have the same physical address as the company?

DPO Address

Country
Address line 1
Address line 2
City / town
ZIP code / postal code
What is the email address users should contact in case they have questions about your policy?

Please enter the email address of the person responsible for your privacy notice.

Data Subject Access Request

Do you provide a service that allows users to send a request to view/edit/delete their personal information stored on your website and/or app?

This type of service could be an online request form, contact form, or a dedicated email address.

Please enter the URL to access this service
Please provide an email address for privacy-related inquiries, (e.g., data subject access requests or questions related to this Privacy Policy)
Users may request access to their personal information:
Final Details

Company

Full legal name of company

Include corporate ending if applicable: Inc., LLC, etc.

Are you doing business under a short form or trade name (also known as a DBA)?
What is the short form or trade name of your company?
Email

Include your company email address or your personal email address.

Phone numbe

Include your office phone number or your personal phone number.

Fax numbe

Corporate Address

Country
Address line 1

Provide the address where your company is registered or located.

Address line 2
City / town
ZIP code / postal code

Version Date

What is the effective date for this Privacy Policy?

The effective date on your Privacy Policy informs your users of when your Privacy Policy was originally published or last updated. When you make an update to your Privacy Policy that requires notifying your users, make sure the effective date is the same date you indicated in your notice communications.