Privacy Policy
Standard privacy policy — what data you collect, why, who you share with, user rights.
Live preview
PRIVACY POLICY
Effective Date: May 4, 2026
This Privacy Policy describes how Acme Inc. ("we", "us", "our") collects, uses, and shares information about you when you visit https://www.example.com (the "Site").
1. INFORMATION WE COLLECT
We collect the following categories of information:
(a) Information you provide directly: we do not require you to create an account; you can use the Site anonymously. If you contact us, we keep a record of your communications.
(b) Automatically collected data: when you visit the Site, we (or our service providers) automatically collect your IP address, browser type and version, operating system, referring URL, pages viewed, and time of visit. This is standard web-server logging and is used for security, analytics, and abuse prevention.
(c) Cookies: we use cookies and similar technologies as described in Section 4 below.
2. HOW WE USE INFORMATION
We use the information we collect to:
- Operate, maintain, and improve the Site;
- Respond to inquiries you send us;
- Detect and prevent fraud, abuse, and security incidents;
- Comply with applicable legal obligations;
- Understand how the Site is used in aggregate, so we can improve it;
- Communicate with you about updates, security alerts, and (if you opt in) news.
3. INFORMATION SHARING
We do not sell your personal information. We share information only:
- With service providers acting on our behalf (e.g., hosting, analytics, customer support, payment processing) under contractual confidentiality;
- When required by law (court order, subpoena, legal process);
- To protect the rights, safety, or property of Acme Inc. or others;
- In connection with a merger, acquisition, or asset sale (in which case the acquiring party will be bound by this Policy or a successor policy).
4. COOKIES AND TRACKING
We use the following types of cookies:
- Strictly necessary cookies: required for the Site to function (e.g., session management).
- Analytics cookies: help us understand how visitors interact with the Site (e.g., Google Analytics).
You can control cookies through your browser settings. Disabling some cookies may impair the Site's functionality.
5. DATA RETENTION
We retain personal information for as long as necessary to provide the services described in this Policy, and as required for legal, accounting, or reporting purposes (typically up to 7 years for financial records, less for marketing data).
6. YOUR RIGHTS
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you;
- Request correction or deletion of your personal information;
- Object to or restrict certain processing;
- Receive a copy of your data in a portable format;
- (For California residents under CCPA) Opt out of any sale of personal information; we do not sell personal information.
- (For EU/UK residents under GDPR) Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at privacy@example.com.
7. CHILDREN
The Site is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us and we will delete it.
8. SECURITY
We implement reasonable administrative, technical, and physical safeguards to protect personal information against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. CHANGES TO THIS POLICY
We may update this Policy from time to time. Material changes will be announced on the Site at least 30 days before they take effect.
10. CONTACT
For questions about this Policy or to exercise your rights, contact us at privacy@example.com or write to:
Acme Inc.
123 Main St, San Francisco, CA 94103About this template
A Privacy Policy is legally required for any website collecting personal data — and "personal data" includes things you might not realise you're collecting, like IP addresses for analytics. Even a static blog with Google Analytics is technically processing personal data under GDPR. Three regulations drive the content: GDPR (EU), CCPA (California), and COPPA (children under 13). The most-overlooked clause is Section 6 (Your Rights) — both GDPR and CCPA require you to clearly explain how users can request access, correction, or deletion of their data. Skipping this section is the most common reason for regulatory fines on small sites. The cookie section is also tightly regulated in the EU; you generally need a cookie banner with explicit consent for non-essential cookies (this template doesn't include the banner code, just the policy text).
When to use it
- ANY website that collects personal data — including basic analytics.
- Required by AdSense, Stripe, Apple App Store, Google Play, most B2B vendors.
- Legally required if you have ANY EU, UK, or California users.
- Update annually or whenever you add a new data-processing tool.
What to include
- What information you collect.
- How and why you use it.
- Who you share it with (service providers, ad partners, etc.).
- Cookies + tracking technologies.
- Data retention period.
- User rights (GDPR/CCPA): access, correct, delete, port.
- Children's information (COPPA).
- Security measures.
- How users can contact you about privacy.