Terms of service and privacy policy: what your website needs
If your website collects any personal information (a contact form, a newsletter sign-up, analytics cookies, online orders), you almost certainly need a privacy policy, and in many countries it’s a legal requirement. Terms of service are different. They’re usually not required by law, but they’re your contract with users, and if you sell online, run subscriptions or host user content, you should have them. A plain brochure site with no forms and no tracking can get away with very little. Few sites are really that plain.
Two documents, two different jobs
They sit next to each other in the footer, so people treat them as a pair. They aren’t. A privacy policy is a disclosure: it tells visitors what personal data you collect, why, who you share it with, and what rights they have. Terms of service are a contract: they set the rules for using your site or buying from you, and they protect you when something goes wrong.
When a privacy policy is required
What matters is where your visitors are, not only where you’re based. A design studio in Austin with clients in Dublin has to think about EU law whether it likes it or not.
- In the EU and UK, the GDPR (and the UK’s version of it) requires you to give people clear information when you collect their personal data. On a website, that information lives in a privacy notice. Business size doesn’t matter.
- In the US, there’s no single federal privacy law for most businesses. California requires commercial websites that collect personal information from California residents to post a privacy policy, and a growing number of states have broader privacy laws that apply above revenue or data-volume thresholds. Separate federal rules cover areas such as children’s data and health information.
- In Canada, federal privacy law requires organizations to be open about how they handle personal information in commercial activity, and Quebec has its own, stricter regime.
- In Australia, the Privacy Act requires covered businesses to have a privacy policy. As of 2025, many small businesses with annual turnover of AUD 3 million or less are exempt, though there are exceptions (health service providers, for one) and reforms are being worked through.
- In the UAE, the federal data protection law sets transparency duties, and financial free zones such as DIFC and ADGM run their own data protection regimes.
There’s also a practical reason. Payment processors, app stores and advertising platforms generally require a privacy policy before you can use them. Even where no law forces one on you, a platform probably will.
What your privacy policy should say
It should describe what you actually do. Obvious, yes. But the most common problem we see is a policy copied from another site that promises things the business doesn’t do, or leaves out things it does, like running an ad pixel or sending newsletters through a US email platform.
- Who you are and how to contact you (plus a data protection officer or EU or UK representative, if you’re required to have one).
- What you collect: form entries, accounts, orders, cookies, analytics, data from third parties.
- Why you use it and, in the EU and UK, your legal basis for each purpose, such as consent, contract or legitimate interests.
- Who you share it with: hosting, payments, email, analytics and advertising providers.
- Transfers abroad, if data leaves the EU or UK.
- How long you keep each type of data.
- People’s rights (access, deletion, correction, and opting out of sale or sharing in the US states that grant it) and how to exercise them.
- The date of the last update.
Behind the scenes, any vendor that handles personal data for you should be covered by a data processing agreement. Big providers usually build one into their terms. Check that it’s there.
Cookies are their own problem
In the EU and UK, you generally need consent before setting non-essential cookies such as advertising trackers. A banner that says “by using this site you accept cookies” doesn’t meet that standard. Visitors need a real choice, rejecting should be as easy as accepting, and trackers shouldn’t load until someone says yes. Strictly necessary cookies, like a shopping cart or login session, don’t need consent. The UK has started loosening the rules for some low-risk analytics cookies, so check current guidance there. US rules are generally lighter on cookies, though several state laws let people opt out of targeted advertising.
What terms of service should cover
Terms are where you protect yourself. A brochure site needs only a short set of website terms. If you sell products, run subscriptions or let users upload content, they deserve real attention.
- What you offer, prices, payment and refunds.
- For subscriptions: the billing cycle, auto-renewal and how to cancel.
- Acceptable use: what users mustn’t do.
- Who owns content, and the license you need to host what users upload.
- A warranty disclaimer and a limitation of liability, as far as local law allows.
- When you can suspend or close accounts.
- Governing law and where disputes get heard.
- How you’ll tell users about changes.
Consumer law sets limits
If you sell to consumers, your terms can’t take away their statutory rights. In the EU and UK, consumers buying online generally get a 14-day cancellation right for most goods and many services, with exceptions for things like made-to-order items, perishable goods and digital content they’ve chosen to access straight away. Terms that try to exclude liability for death or personal injury caused by negligence won’t work there either. Several US states have tightened their rules on subscription renewals and cancellation, too.
The US is more accepting of mandatory arbitration clauses and class action waivers in consumer terms, as long as they’re presented fairly. The same clauses in EU consumer terms are often unenforceable.
Make sure users actually agree
Terms tucked behind a footer link (sometimes called “browsewrap”) are hard to enforce, because nobody clicked anything. Courts are much more willing to enforce terms when the user took a clear step, such as ticking a box or clicking a button next to a visible line like “By creating an account you agree to our Terms”.
- Put the link right next to the sign-up or checkout button.
- Require a click or tick that clearly signals agreement.
- Record who accepted which version, and when.
- When you change the terms, tell existing users, and for significant changes get fresh agreement.
Where to start
List everything your site actually does with data: every form, plugin, pixel and third-party tool. Then write or update the privacy policy to match, fix your cookie banner if you have EU or UK visitors, and decide whether you need full terms or a short website-use notice. Generators are fine for a first draft, but read the output line by line. A policy claiming you don’t share data with advertisers, on a site running an ad pixel, is worse than a short, accurate one.
Put a reminder in the calendar to review both documents once a year, and look at them again whenever you add a tool that touches visitor data.
This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.