How to Write a Privacy Policy, Step by Step
Five steps, in the order they actually matter. Do this yourself in about twenty minutes for a straightforward site, or use the generator and skip straight to step 5.
Last updated: August 2026
1. List what you actually collect
Before writing anything, go through your site and note every place it collects information: contact forms, email signups, checkout pages, comment sections. Also check what's collected automatically, most sites run analytics that logs visits even without a form. This list is the actual substance of your policy; everything else is structure around it.
2. Name your third-party services
List every tool that has access to any of that data: Google Analytics, an email marketing platform, a payment processor, an ad network. Each one gets its own line in your policy. Vague language like "third-party service providers" is weaker and less useful to a reader than naming the actual services.
3. Explain why you collect it
For each item on your list from step 1, write one sentence on why you collect it. "We collect your email address to send order confirmations" is specific and useful. "We may use your information for business purposes" isn't. This step is also where you'll notice if you're collecting something you don't have a real reason for, worth reconsidering whether you need it at all.
4. Add rights and contact info
If you have visitors in the EU, UK, or California, add a short section on their rights to access, correct, or delete their data. Then add a real, working way to reach you about privacy questions, this is the section people actually use, so it needs to be accurate.
5. Publish it somewhere findable
Link it from your site footer, and from anywhere you collect data directly (checkout, signup forms). A privacy policy that's technically published but impossible to find doesn't serve its purpose.
A note for WordPress and Shopify sites
WordPress has a built-in privacy policy page template under Settings, which gives you a reasonable starting structure, see how to add a privacy policy to WordPress for the specifics on finding it, customizing it, and where it needs to appear on your site. Shopify has its own free privacy policy generator built into the admin panel, and running a store adds its own considerations, accounts, checkout, payment processors, that a generic policy usually misses. See privacy policy for Shopify stores for the specifics. Either starting point still needs editing to reflect what your specific store or site actually does before you publish it.
Prefer to start from a document you can just edit, rather than working through these steps by hand? Here's a ready-made template.
Frequently asked questions
How long should this take?
For a straightforward site, working through these five steps yourself takes roughly twenty to thirty minutes. Using a generator that walks you through the same questions typically takes under five.
Do I need separate sections for GDPR and CCPA?
Not necessarily separate sections, but your rights section should cover both if you have visitors in either region, since the rights they grant (access, correction, deletion) overlap significantly even though the specific legal names differ.
What's the fastest way to skip straight to a finished policy?
Use the privacy statement generator. It walks through the same five steps as a short questionnaire and assembles the document as you answer.