Generate ↓
Free · No sign-up · App-store ready

Free ecommerce privacy policy

Answer a few questions and get a ready-to-use privacy policy and terms of service — required by Google, Apple and the law. Copy or download, no sign-up.

Templates for general guidance, not legal advice. Review before publishing.

Privacy Policy
Terms of Service

Popular

Privacy policy for app storeFree privacy policy generator Terms of service templateGDPR privacy policyPrivacy policy for website
Recommended next step
Launching your site? Get hosting + a free domain.
You’ve got the legal pages — now put your site online with Hostinger’s fast, affordable hosting.
Get hosting with Hostinger →

What selling online adds

An online shop processes considerably more personal data than a brochure site, and the policy has to account for all of it: names, delivery addresses, order history, payment references, and usually marketing preferences.

You must name the categories of recipient you share it with, which for a typical shop means your payment processor, your delivery carrier, your email platform and your hosting provider.

You do not store card details — say so

Almost every small shop uses Stripe, PayPal or Shopify Payments, which means card details go directly to the processor and never touch your systems. Your policy should say that plainly, because it is both true and reassuring, and because claiming to store cards you do not store creates obligations you have not met.

If you genuinely do store card details, you are in PCI DSS territory and need proper advice. Almost nobody running a small shop should be doing this, and if a developer has built something that does, question it.

How long to keep orders

Order records support tax obligations, so six years is the usual retention period for the transaction data itself. That is a legal obligation, not consent, and it means you cannot simply delete everything on request — a customer’s erasure right does not override your duty to keep accounting records.

Marketing data is different. If someone unsubscribes or asks to be removed, you must stop marketing to them and delete the marketing record, while keeping the order history you are obliged to hold.

Marketing consent and the soft opt-in

Under PECR, you may email marketing to existing customers about similar products without fresh consent — the “soft opt-in” — provided you collected the address during a sale, offered an opt-out at that point, and offer one in every message.

That does not extend to people who only created an account, entered a competition or abandoned a basket without buying. Those need actual consent.

Abandoned basket emails

These are marketing. If the person never completed a purchase, the soft opt-in does not apply, so you need consent to send them. A great many shops run abandoned basket sequences without it.

Common questions

Do I need to say I store card details?

You should say that you do not, if that is the case — most shops use a payment processor and card details never reach their systems. Only claim to store cards if you genuinely do, which brings PCI DSS obligations.

How long should an online shop keep order data?

Six years is standard, because order records support tax obligations. That is a legal duty and it survives an erasure request for the transaction data itself.

Can I email customers marketing without consent?

Existing customers, about similar products, yes — the PECR soft opt-in — provided you gave an opt-out at the point of sale and in every message. Not people who never bought.

Do abandoned basket emails need consent?

Yes. The person did not complete a purchase, so the soft opt-in does not apply.