Write store policies & pages · Generators · Free tool for merchants

How do I write a privacy policy for my Shopify store?

Last updated

Your business

Used in the opening line and every contact instruction.

Changes the rights section. Selling into several regions usually needs a section for each.

What you collect

Tick every place a shopper hands you information.

Is payment taken by your store platform checkout?
Who else sees it

Service providers, described by role rather than by name.

Keeping and children

Two statements every notice should make.

Not directed at children
Your draft

Answer the questions on the left. Nothing is written, and nothing leaves this page, until you press the button.

  • Business nameNeeded
  • Contact emailNeeded
  • Where your customers areNeeded
  • Who takes paymentNeeded
  • How long you keep dataNeeded
  • Age statementNeeded

This is a starting template, not legal advice. Laws differ by country and change; have it reviewed.

What the notice has to cover

A Shopify privacy policy generator turns a few answers about what your store collects into a structured notice that tells shoppers what personal data you hold and why, so a boutique in Ireland that runs an email and SMS popup gets a sign-up and unsubscribe section plus the access, correction and complaint rights European shoppers expect.

A starting template, not legal advice. The wording is assembled from fixed clauses chosen by your answers; laws differ by country and change, so have the result reviewed before you publish it.

A privacy notice answers five questions a shopper is entitled to ask: what do you take, why, who else sees it, how long do you keep it, and how do I get it back. Each answer you give above maps to one of those.

Personal data
Anything that identifies a person or can be tied back to one: a name, a delivery address, an email, a phone number, an IP address, a device identifier. A cookie ID counts in Europe even without a name attached.
Collection points
Every place a shopper hands you something: checkout, account creation, a newsletter footer, a discount popup, a quiz, a contact form. Merchants usually remember checkout and forget the popup, which is often the busiest one.
Consent at sign-up
For marketing, the shopper opts in by submitting a form that says what they are joining. The notice records that this is how the list is built and links back from the form, so the promise and the explanation point at each other.
Processors
Outside services that handle personal data on your behalf: the carrier printing a label, the email platform sending a newsletter, the analytics service counting visits. You stay responsible for choosing them; the notice names them by role.
Retention
How long records stick around. Order records are usually kept for as long as tax rules demand; a subscriber address only until the person leaves the list. Saying nothing here reads as keeping everything forever.
Data-subject rights
What a shopper can ask of you: a copy, a correction, erasure, an objection. The wording shifts by region, which is why the generator asks where your customers are rather than where you are.

Nudgesmart is available on the Shopify App Store. Browse the template library or see what it costs.

Four stores, four different notices

Each row below was produced by the same function the generator runs. Notice how the rights paragraph changes with the region and how the section count grows once cookies or marketing sign-ups enter the picture.

Worked examples: four stores, what each collects, how many sections its notice gets and how its rights paragraph opens
StoreData points tickedSectionsRights paragraph opens with
Apparel shop in Ireland with an email and SMS popup4 of 512You can ask to see the personal information we hold about you, to have it corrected or deleted, to receive a copy in a portable format, and to object to or restrict how we use it.
Candle maker in Texas, orders only, no marketing list1 of 511Depending on the state you live in, you may have the right to know what personal information we hold about you, to have it corrected or deleted, and to opt out of its sale or its use for targeted advertising.
Supplement brand in Canada running ads and a welcome popup4 of 512You can ask to access the personal information we hold about you and to have it corrected.
Print shop in New Zealand with a footer sign-up form2 of 511You can ask for a copy of the personal information we hold about you and ask us to fix anything that is wrong.
The Texas candle maker has no marketing list, yet the sign-up section still appears in a conditional form: the day that store adds a newsletter popup, the notice already describes it. The Canadian row is the only one with advertising cookies, so it is the only one telling shoppers that some laws treat ad cookies as sharing.

Where a privacy notice needs a human

It cannot see your apps

Every installed app that reads customer data is another processor. Reviews, loyalty, chat, upsell and analytics apps all qualify. The generator only knows the categories you ticked, so walk through your installed apps list and add anything it missed.

A cookie sentence is not a cookie banner

Describing cookies in the notice does nothing about when they fire. In much of Europe, analytics and advertising cookies need a yes before they load, and that is a consent tool on the storefront, not a paragraph on a policy page.

Regional wording is a starting point

Rights differ between the EU, the UK, individual US states, Canada, Australia and elsewhere, and they get amended. A store selling into several regions usually needs a section per region, drafted by someone who follows those changes.

The notice has to match what actually happens

If the notice says marketing stops on unsubscribe but your email platform keeps sending a flow, the notice is the evidence against you. Test the unsubscribe link and the deletion request yourself before publishing.

Privacy notice questions from store owners

Does Shopify already give me a privacy policy?

Shopify offers a policy template in the admin, and many stores publish it unchanged. It cannot know which popups, apps and messaging channels you run, so the parts about marketing sign-ups, cookies and retention are the ones most likely to be missing or wrong for your store.

Do I need to mention my email popup in the privacy policy?

If a popup or form asks for an email address, it is a collection point, and shoppers should be able to find out what happens to that address and how to leave the list. This generator always writes a sign-up section for that reason, and the form itself should link to the notice.

Does this take care of GDPR for me?

No, and no page can. European data protection law is about how you actually handle data, including consent for cookies, contracts with processors and answering requests on time. A notice is one visible piece of it. Use this draft as a starting point and have it reviewed.

Should I name the apps and services I use?

The draft describes them by role, which keeps it accurate when you switch providers. Some regions expect named recipients or a list available on request, so check what applies to the shoppers you sell to.

Is anything I type here stored?

No. The notice is assembled in your browser from your answers. Your business name and contact email never leave the page, are not put into a link, and are not sent to us.

Get started

Consent is given at the form, not on the policy page.

Nudgesmart email popups start from ready-made templates, grouped by industry and campaign type, so the consent line and the link to your notice go where the address is typed.