Terms of service and privacy policy: what your website needs

If your website collects any personal information (a contact form, a newsletter sign-up, analytics cookies, online orders), you almost certainly need a privacy policy, and in many countries it’s a legal requirement. Terms of service are different. They’re usually not required by law, but they’re your contract with users, and if you sell online, run subscriptions or host user content, you should have them. A plain brochure site with no forms and no tracking can get away with very little. Few sites are really that plain.

Two documents, two different jobs

They sit next to each other in the footer, so people treat them as a pair. They aren’t. A privacy policy is a disclosure: it tells visitors what personal data you collect, why, who you share it with, and what rights they have. Terms of service are a contract: they set the rules for using your site or buying from you, and they protect you when something goes wrong.

Side-by-side comparison. The privacy policy is a disclosure covering what data you collect, why, who you share it with, how long you keep it and visitors’ rights, and is often required by law. Terms of service are a contract covering site rules, prices and refunds, content ownership, liability limits and governing law, and are usually optional but useful.
One tells visitors what you do with their data; the other sets the rules of the deal.

When a privacy policy is required

What matters is where your visitors are, not only where you’re based. A design studio in Austin with clients in Dublin has to think about EU law whether it likes it or not.

There’s also a practical reason. Payment processors, app stores and advertising platforms generally require a privacy policy before you can use them. Even where no law forces one on you, a platform probably will.

What your privacy policy should say

It should describe what you actually do. Obvious, yes. But the most common problem we see is a policy copied from another site that promises things the business doesn’t do, or leaves out things it does, like running an ad pixel or sending newsletters through a US email platform.

Behind the scenes, any vendor that handles personal data for you should be covered by a data processing agreement. Big providers usually build one into their terms. Check that it’s there.

Cookies are their own problem

In the EU and UK, you generally need consent before setting non-essential cookies such as advertising trackers. A banner that says “by using this site you accept cookies” doesn’t meet that standard. Visitors need a real choice, rejecting should be as easy as accepting, and trackers shouldn’t load until someone says yes. Strictly necessary cookies, like a shopping cart or login session, don’t need consent. The UK has started loosening the rules for some low-risk analytics cookies, so check current guidance there. US rules are generally lighter on cookies, though several state laws let people opt out of targeted advertising.

What terms of service should cover

Terms are where you protect yourself. A brochure site needs only a short set of website terms. If you sell products, run subscriptions or let users upload content, they deserve real attention.

Consumer law sets limits

If you sell to consumers, your terms can’t take away their statutory rights. In the EU and UK, consumers buying online generally get a 14-day cancellation right for most goods and many services, with exceptions for things like made-to-order items, perishable goods and digital content they’ve chosen to access straight away. Terms that try to exclude liability for death or personal injury caused by negligence won’t work there either. Several US states have tightened their rules on subscription renewals and cancellation, too.

The US is more accepting of mandatory arbitration clauses and class action waivers in consumer terms, as long as they’re presented fairly. The same clauses in EU consumer terms are often unenforceable.

Make sure users actually agree

Terms tucked behind a footer link (sometimes called “browsewrap”) are hard to enforce, because nobody clicked anything. Courts are much more willing to enforce terms when the user took a clear step, such as ticking a box or clicking a button next to a visible line like “By creating an account you agree to our Terms”.

  1. Put the link right next to the sign-up or checkout button.
  2. Require a click or tick that clearly signals agreement.
  3. Record who accepted which version, and when.
  4. When you change the terms, tell existing users, and for significant changes get fresh agreement.

Where to start

List everything your site actually does with data: every form, plugin, pixel and third-party tool. Then write or update the privacy policy to match, fix your cookie banner if you have EU or UK visitors, and decide whether you need full terms or a short website-use notice. Generators are fine for a first draft, but read the output line by line. A policy claiming you don’t share data with advertisers, on a site running an ad pixel, is worse than a short, accurate one.

Put a reminder in the calendar to review both documents once a year, and look at them again whenever you add a tool that touches visitor data.

This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.