How do I write a privacy policy for my Shopify store?
Last updated
Used in the opening line and every contact instruction.
Changes the rights section. Selling into several regions usually needs a section for each.
Tick every place a shopper hands you information.
Service providers, described by role rather than by name.
Two statements every notice should make.
Answer the questions on the left. Nothing is written, and nothing leaves this page, until you press the button.
- Business nameNeeded
- Contact emailNeeded
- Where your customers areNeeded
- Who takes paymentNeeded
- How long you keep dataNeeded
- Age statementNeeded
This is a starting template, not legal advice. Laws differ by country and change; have it reviewed.
What the notice has to cover
A Shopify privacy policy generator turns a few answers about what your store collects into a structured notice that tells shoppers what personal data you hold and why, so a boutique in Ireland that runs an email and SMS popup gets a sign-up and unsubscribe section plus the access, correction and complaint rights European shoppers expect.
A starting template, not legal advice. The wording is assembled from fixed clauses chosen by your answers; laws differ by country and change, so have the result reviewed before you publish it.
A privacy notice answers five questions a shopper is entitled to ask: what do you take, why, who else sees it, how long do you keep it, and how do I get it back. Each answer you give above maps to one of those.
- Personal data
- Anything that identifies a person or can be tied back to one: a name, a delivery address, an email, a phone number, an IP address, a device identifier. A cookie ID counts in Europe even without a name attached.
- Collection points
- Every place a shopper hands you something: checkout, account creation, a newsletter footer, a discount popup, a quiz, a contact form. Merchants usually remember checkout and forget the popup, which is often the busiest one.
- Consent at sign-up
- For marketing, the shopper opts in by submitting a form that says what they are joining. The notice records that this is how the list is built and links back from the form, so the promise and the explanation point at each other.
- Processors
- Outside services that handle personal data on your behalf: the carrier printing a label, the email platform sending a newsletter, the analytics service counting visits. You stay responsible for choosing them; the notice names them by role.
- Retention
- How long records stick around. Order records are usually kept for as long as tax rules demand; a subscriber address only until the person leaves the list. Saying nothing here reads as keeping everything forever.
- Data-subject rights
- What a shopper can ask of you: a copy, a correction, erasure, an objection. The wording shifts by region, which is why the generator asks where your customers are rather than where you are.
Nudgesmart is available on the Shopify App Store. Browse the template library or see what it costs.
Four stores, four different notices
Each row below was produced by the same function the generator runs. Notice how the rights paragraph changes with the region and how the section count grows once cookies or marketing sign-ups enter the picture.
| Store | Data points ticked | Sections | Rights paragraph opens with |
|---|---|---|---|
| Apparel shop in Ireland with an email and SMS popup | 4 of 5 | 12 | You can ask to see the personal information we hold about you, to have it corrected or deleted, to receive a copy in a portable format, and to object to or restrict how we use it. |
| Candle maker in Texas, orders only, no marketing list | 1 of 5 | 11 | Depending on the state you live in, you may have the right to know what personal information we hold about you, to have it corrected or deleted, and to opt out of its sale or its use for targeted advertising. |
| Supplement brand in Canada running ads and a welcome popup | 4 of 5 | 12 | You can ask to access the personal information we hold about you and to have it corrected. |
| Print shop in New Zealand with a footer sign-up form | 2 of 5 | 11 | You can ask for a copy of the personal information we hold about you and ask us to fix anything that is wrong. |
Where a privacy notice needs a human
It cannot see your apps
Every installed app that reads customer data is another processor. Reviews, loyalty, chat, upsell and analytics apps all qualify. The generator only knows the categories you ticked, so walk through your installed apps list and add anything it missed.
A cookie sentence is not a cookie banner
Describing cookies in the notice does nothing about when they fire. In much of Europe, analytics and advertising cookies need a yes before they load, and that is a consent tool on the storefront, not a paragraph on a policy page.
Regional wording is a starting point
Rights differ between the EU, the UK, individual US states, Canada, Australia and elsewhere, and they get amended. A store selling into several regions usually needs a section per region, drafted by someone who follows those changes.
The notice has to match what actually happens
If the notice says marketing stops on unsubscribe but your email platform keeps sending a flow, the notice is the evidence against you. Test the unsubscribe link and the deletion request yourself before publishing.
Privacy notice questions from store owners
Does Shopify already give me a privacy policy?
Shopify offers a policy template in the admin, and many stores publish it unchanged. It cannot know which popups, apps and messaging channels you run, so the parts about marketing sign-ups, cookies and retention are the ones most likely to be missing or wrong for your store.
Do I need to mention my email popup in the privacy policy?
If a popup or form asks for an email address, it is a collection point, and shoppers should be able to find out what happens to that address and how to leave the list. This generator always writes a sign-up section for that reason, and the form itself should link to the notice.
Does this take care of GDPR for me?
No, and no page can. European data protection law is about how you actually handle data, including consent for cookies, contracts with processors and answering requests on time. A notice is one visible piece of it. Use this draft as a starting point and have it reviewed.
Should I name the apps and services I use?
The draft describes them by role, which keeps it accurate when you switch providers. Some regions expect named recipients or a list available on request, so check what applies to the shoppers you sell to.
Is anything I type here stored?
No. The notice is assembled in your browser from your answers. Your business name and contact email never leave the page, are not put into a link, and are not sent to us.
Consent is given at the form, not on the policy page.
Nudgesmart email popups start from ready-made templates, grouped by industry and campaign type, so the consent line and the link to your notice go where the address is typed.