Answer a few questions and get a ready-to-use privacy policy and terms of service — required by Google, Apple and the law. Copy or download, no sign-up.
Templates for general guidance, not legal advice. Review before publishing.
An online shop processes considerably more personal data than a brochure site, and the policy has to account for all of it: names, delivery addresses, order history, payment references, and usually marketing preferences.
You must name the categories of recipient you share it with, which for a typical shop means your payment processor, your delivery carrier, your email platform and your hosting provider.
Almost every small shop uses Stripe, PayPal or Shopify Payments, which means card details go directly to the processor and never touch your systems. Your policy should say that plainly, because it is both true and reassuring, and because claiming to store cards you do not store creates obligations you have not met.
If you genuinely do store card details, you are in PCI DSS territory and need proper advice. Almost nobody running a small shop should be doing this, and if a developer has built something that does, question it.
Order records support tax obligations, so six years is the usual retention period for the transaction data itself. That is a legal obligation, not consent, and it means you cannot simply delete everything on request — a customer’s erasure right does not override your duty to keep accounting records.
Marketing data is different. If someone unsubscribes or asks to be removed, you must stop marketing to them and delete the marketing record, while keeping the order history you are obliged to hold.
Under PECR, you may email marketing to existing customers about similar products without fresh consent — the “soft opt-in” — provided you collected the address during a sale, offered an opt-out at that point, and offer one in every message.
That does not extend to people who only created an account, entered a competition or abandoned a basket without buying. Those need actual consent.
These are marketing. If the person never completed a purchase, the soft opt-in does not apply, so you need consent to send them. A great many shops run abandoned basket sequences without it.
You should say that you do not, if that is the case — most shops use a payment processor and card details never reach their systems. Only claim to store cards if you genuinely do, which brings PCI DSS obligations.
Six years is standard, because order records support tax obligations. That is a legal duty and it survives an erasure request for the transaction data itself.
Existing customers, about similar products, yes — the PECR soft opt-in — provided you gave an opt-out at the point of sale and in every message. Not people who never bought.
Yes. The person did not complete a purchase, so the soft opt-in does not apply.