web design

Does my website need a privacy policy and terms?

If your site has a form, analytics or cookies, it likely needs an accurate privacy policy. When the law requires one, what to include, and when to add terms.

You are building a new site, or finally reading the old one closely, and you reach the footer. You may find a link called Privacy Policy, maybe one called Terms, or nothing at all. If a policy exists, it may have come from a template years ago and mention cookies, rights requests or laws your business has never thought about. So, does my website need a privacy policy, and do you need terms and conditions too? The short answer is usually yes to the privacy policy, if your site collects anything about the people who visit it, and it depends on what you sell for the terms. The bigger risk is often not a missing page but a page that says things your site does not actually do. You can work out which one you are facing in an afternoon, without paying for legal work you do not need.

Key Takeaways

Collecting anything means a policy

A contact form, analytics, cookies, an email signup, checkout, chat or an embedded map or video all collect visitor information, and that is when a privacy policy becomes a real requirement.

California's rule has no size cutoff

CalOPPA reaches commercial sites that collect personal information from California residents, with no revenue or visitor threshold. The CCPA is separate and only applies above its thresholds.

Terms are a contract, not a privacy page

No general US law requires terms on a plain marketing site, but they matter when you sell, take bookings, run subscriptions, offer accounts or handle returns.

Accuracy beats wording

A generator is fine as a first draft; the policy still has to match the forms, tags, cookies and vendors your site really uses.

Does my website need a privacy policy if it only has a contact form?

In most real cases, yes. A contact or quote form collects a name, an email address, a phone number and whatever the visitor types into the message box. That is personal information, and a commercial site that collects it from people in California falls under California's online privacy law, whatever size the business is and wherever it is based.

Even a site with no form usually collects something. Analytics tools record visits, embedded maps and videos load content from other companies, and a chat widget or newsletter box sends data to its provider. If your site does any of those things, the practical answer to "does my website need a privacy policy" is yes, and it needs to be an accurate one.

A site with truly nothing on it (no form, no analytics, no cookies beyond what the page needs to load, no embeds) is a different case. That is rare for a business site, and it tends to stop being true the first time someone adds a signup box or a tracking tag. One note before going further: this is general information, not legal advice. If your business handles sensitive data, runs heavy advertising tracking or serves customers in other countries, a lawyer who knows your setup should review the final wording.

A small wooden box of blank index cards beside a closed notebook and a pencil on a pale oak desk.
Every form field is information someone handed you, and a policy explains what happens to it.

When does US law actually require a privacy policy?

No single federal law tells every website to post a privacy policy. What you have instead is a set of state laws with different reach, plus a federal regulator that holds you to whatever your policy says. The two California laws are the ones that catch small businesses most directly, and they work very differently from each other. The FTC sits on top of both.

What does California's CalOPPA require?

The California Online Privacy Protection Act, Business and Professions Code section 22575, applies to the operator of a commercial website or online service that collects personally identifiable information from California residents through the internet. It has no revenue threshold and no visitor count. A basic lead form can bring you within it. If you do business online, you cannot be sure no Californian will ever fill in your form, so this law is worth treating as the baseline wherever your business is based.

Under CalOPPA, the policy must be posted conspicuously and must:

  • Name the categories you collect: For example, names, email addresses, phone numbers.
  • Name who you share with: The categories of third parties that may receive that information.
  • Explain any review process: How a visitor can review and ask to change their information, if you offer that.
  • Explain how changes are announced: How you tell visitors about material changes to the policy.
  • Show an effective date: When the current version took effect.
  • Cover Do Not Track and outside tracking: How you respond to browser Do Not Track signals if you track visitors across sites, and whether other parties may collect information about visitors' activity across sites through yours.

When does the CCPA apply to a small business?

The California Consumer Privacy Act, as amended by the CPRA, is a larger law with a narrower reach. It applies to for-profit businesses doing business in California that meet at least one of three thresholds. If you meet one, you owe a notice at the point of collection and a fuller privacy policy. If you meet none, CCPA does not apply, but CalOPPA still can.

CalOPPA and CCPA side by side
QuestionCalOPPACCPA / CPRA
Who it coversOperators of commercial sites that collect personal information from California residentsFor-profit businesses doing business in California that meet a threshold
Size thresholdNoneOver $25 million in annual gross revenue, OR buying, selling or sharing information of 100,000 or more California consumers or households, OR 50% or more of revenue from selling California residents' information
What it asks forA conspicuously posted privacy policy with set disclosuresA notice at collection plus a fuller privacy policy, and a process for consumer requests
Could a one-location service business be covered?Yes, through a single contact formOnly if it crosses one of the thresholds
QuestionWho it covers
CalOPPAOperators of commercial sites that collect personal information from California residents
CCPA / CPRAFor-profit businesses doing business in California that meet a threshold
QuestionSize threshold
CalOPPANone
CCPA / CPRAOver $25 million in annual gross revenue, OR buying, selling or sharing information of 100,000 or more California consumers or households, OR 50% or more of revenue from selling California residents' information
QuestionWhat it asks for
CalOPPAA conspicuously posted privacy policy with set disclosures
CCPA / CPRAA notice at collection plus a fuller privacy policy, and a process for consumer requests
QuestionCould a one-location service business be covered?
CalOPPAYes, through a single contact form
CCPA / CPRAOnly if it crosses one of the thresholds

What role does the FTC play?

The FTC does not create a general rule that every website must have a policy. What it does is treat privacy promises as promises. Under Section 5 of the FTC Act, the agency can challenge an inaccurate privacy policy or privacy claim as deceptive, and its privacy and security guidance for businesses reflects a long record of enforcement on exactly that point. In February 2024 the FTC also warned that quietly changing your terms or privacy policy to allow broader use of people's data, through a retroactive update, can be unfair or deceptive. The lesson for a small site: whatever your policy says, your site has to do.

Other US states have passed their own broad privacy laws, and those generally have thresholds too. If you collect a lot of data or sell to customers in many states, check which ones apply with someone who follows them closely rather than assuming one page covers every state.

Does GDPR apply to a US business website?

Not automatically. Being viewable from Europe does not, on its own, bring a US site under European law. The rules below explain when it does, and what the UK and EU expect once they apply.

The EU GDPR reaches a business outside the EU, under Article 3(2), when its processing relates to offering goods or services to people in the EU (paid or free) or to monitoring their behavior in the EU. Signs that you are offering to EU customers include using EU languages or currencies, shipping to the EU, running ads aimed at EU countries or actively soliciting EU customers. A US site in English that happens to be reachable from Paris does not meet that test by itself.

If you do fall within it, Articles 13 and 14 list what your privacy information must include, and Article 12 requires it to be concise, transparent, easy to find and written in clear, plain language. The UK has its own version, the UK GDPR. The UK regulator, the ICO, tells small organizations that if they handle personal data they need to comply, and its guide on what goes in a privacy notice asks you to explain why you need the data, who you share it with and how long you keep it.

UK law also treats cookies separately. The ICO's cookie guidance says users must be told about cookies and their purpose, and must give consent for any that are not strictly necessary. A line in your privacy policy does not replace that consent. If you are unsure whether a US site needs a consent banner at all, our post on whether a US small business website needs a cookie banner covers that question on its own.

A folded paper map and a small brass compass resting on a stack of blank envelopes on a gray linen cloth.
European rules reach a US site when it offers to or monitors people there, not simply because it can be opened there.

What is the difference between a privacy policy and terms and conditions?

The two pages are often linked side by side in a footer, so it is easy to think of them as one document. They do different jobs and come from different areas of law. A privacy policy is about the visitor's information. Terms and conditions are about the deal between you and the person using your site.

What does a privacy policy do?

A privacy policy tells people how your business collects, uses, shares, keeps and protects their personal information, and how they can use any rights they have. It is required by data law when that law applies to you. Having a terms page does not create or replace that duty.

What do terms and conditions do?

Terms and conditions, also called terms of use or terms of service, are a proposed contract that governs how people use your site and buy from you. Typical subjects:

  • Purchases and payment: Prices, payment methods, what happens if a payment fails.
  • Returns, cancellations and refunds: What a customer can send back and when.
  • Accounts and user content: Who can sign up, what they may post, when you can close an account.
  • Acceptable use: What visitors must not do on the site.
  • Intellectual property: Who owns the content, photos and downloads.
  • Disclaimers and limits: Limits of liability and the extent of any warranties.
  • Disputes: How disagreements are handled and which state's law governs.

Are terms and conditions legally required?

No general US website law requires every ordinary marketing site to publish terms. They become important once your site handles transactions or ongoing relationships: an online store, bookings, subscriptions, user accounts, downloads, community posts, or any purchase where the customer should see the rules before they commit. Separate rules can also require specific disclosures, for example consumer protection, auto-renewal and payment rules, or the FTC's guidance on advertising and marketing online. One limit worth knowing: putting something on a page called "terms" does not make an unenforceable clause binding.

If your site is a brochure with a contact form, the privacy policy is the page that matters most. If it sells or takes bookings, you likely need both, and the terms belong where the customer commits, not only in the footer.

Is a privacy policy generator or copied template enough?

A generator can be a perfectly reasonable place to start, especially for a simple site with one form and one analytics tool. The problem is not where the words came from. The problem is when the words do not match the site.

A copied or generated policy can:

  • Promise no sharing while Google Analytics, a Meta Pixel, a CRM, a YouTube embed, a map, a chat widget, a payment processor or a newsletter provider receives visitor data.
  • List rights or an opt-out your business has no way to honor.
  • Name laws you have never set up any process to follow.
  • Mention features you do not have, such as accounts, a mobile app or a loyalty program, which reads as unprofessional to anyone who notices.

Because the FTC treats a privacy policy as a set of promises, a mismatch is a real risk, not only an embarrassment. Even the UK regulator, which offers its own privacy notice generator for small businesses, says the organization using it stays responsible for compliance, and notes that the tool does not cover some complex processing. Use a generator's output as a draft, then check every sentence against what your site does.

A thin stack of blank paper held with a binder clip beside a red pencil and a closed laptop on a walnut table.
A template is a draft until each line has been checked against what the site really does.

What should a website privacy policy say?

Once you know what your site collects, the policy follows from it. The FTC, California law and the ICO's guidance point to the same core contents. Your policy should cover each of these in clear language:

What a website privacy policy should cover
SectionWhat to writeWhere it comes from
What you collectCategories of personal information, by collection point (forms, checkout, analytics, chat)CalOPPA, ICO guidance
Why you collect itThe purpose of each kind of collectionICO guidance, GDPR Article 13
Who receives itCategories of third parties and vendorsCalOPPA, GDPR Article 13
How long you keep itYour retention approachICO guidance
Cookies and trackingWhich are necessary, and which are analytics, advertising, preference or embedded third-party servicesICO cookie guidance, CalOPPA tracking disclosures
Choices and rightsHow visitors can review, correct or object, where applicableCalOPPA, CCPA, GDPR
How to contact youA working contact method for privacy questionsICO guidance
Changes and dateHow you announce changes, and the effective dateCalOPPA
SectionWhat you collect
What to writeCategories of personal information, by collection point (forms, checkout, analytics, chat)
Where it comes fromCalOPPA, ICO guidance
SectionWhy you collect it
What to writeThe purpose of each kind of collection
Where it comes fromICO guidance, GDPR Article 13
SectionWho receives it
What to writeCategories of third parties and vendors
Where it comes fromCalOPPA, GDPR Article 13
SectionHow long you keep it
What to writeYour retention approach
Where it comes fromICO guidance
SectionCookies and tracking
What to writeWhich are necessary, and which are analytics, advertising, preference or embedded third-party services
Where it comes fromICO cookie guidance, CalOPPA tracking disclosures
SectionChoices and rights
What to writeHow visitors can review, correct or object, where applicable
Where it comes fromCalOPPA, CCPA, GDPR
SectionHow to contact you
What to writeA working contact method for privacy questions
Where it comes fromICO guidance
SectionChanges and date
What to writeHow you announce changes, and the effective date
Where it comes fromCalOPPA

If CCPA applies to you, add the notice at collection and link it to the policy. If GDPR or UK GDPR applies, the lawful basis for each use belongs in there too. Where the law calls for a notice at the moment of collection, a single footer link may not be enough on its own; a short line next to the form pointing to the policy helps close that gap.

How can you check your own site in about fifteen minutes?

You do not need a lawyer to find out what your site collects. You need a list. This check is an inventory, not a legal ruling, but it gives you (and anyone who later reviews your policy) the facts to work from. The ICO's advice on common data protection topics uses the example of a builder's enquiry form: collect only what the enquiry needs, keep it secure and make the privacy notice easy to find.

A fifteen-minute privacy check

  1. 1

    Step 1

    Open your site in a private browser window and list every place a visitor can type something: contact, quote, booking, job application, account, checkout, newsletter, chat, reviews, uploads and text-message consent.

  2. 2

    Step 2

    Open your tag manager or your platform's integrations page and list every tool: analytics, ad pixels, heatmaps, CRM, email, payments, maps, video, social feeds and chat.

  3. 3

    Step 3

    List the cookies or similar storage the site sets, and mark each as necessary, analytics, preference or advertising.

  4. 4

    Step 4

    Read your privacy policy beside those lists and mark every sentence that is wrong, every vendor it does not mention, every promise you cannot keep and every tool you no longer use.

  5. 5

    Step 5

    Confirm the policy shows an effective date and that the link is easy to find on every page and next to your forms.

What you do next depends on what the check turns up. A stale policy on a simple site is a small writing job. Undisclosed tracking tools take more: remove the ones you do not need, then describe and configure the rest. A form that asks for more than you use is a quick fix; cut the extra fields. Missing terms for an online store is a bigger business decision about returns, payment and subscriptions, and that is where a lawyer earns their fee.

It also helps to know what not to worry about. A small US brochure site does not need a sprawling terms document, a full CCPA program or GDPR compliance simply because anyone in the world can load it. The first job is accuracy: know what the site collects and who receives it, and say so clearly.

A ring of small brass keys laid beside a closed wooden drawer box on a white shelf.
Knowing each tool and vendor on your site is the first step to a policy you can stand behind.

Check your privacy policy knowledge

Pick an answer to begin.

1. A small Texas business collects names and emails through a contact form. A visitor from California fills it in. Which law is most likely to require a privacy policy?

2. What is the main job of terms and conditions?

3. When is a generated privacy policy risky?

Frequently Asked Questions About does my website need a privacy policy

Do I need a privacy policy if my website only has a contact form?

Very likely. A commercial site that collects personal information from California residents falls under CalOPPA, which has no size threshold, and a contact form collects names and contact details.

Is a privacy policy the same as terms and conditions?

No. A privacy policy explains how you handle personal information. Terms and conditions set the rules for using your site and buying from you.

Does the CCPA apply to every small business?

No. It applies to for-profit businesses doing business in California that meet one of three thresholds: over $25 million in annual revenue, 100,000 or more California consumers' or households' information bought, sold or shared, or 50% or more of revenue from selling it.

Does GDPR apply to my US website?

Only if your processing relates to offering goods or services to people in the EU, or monitoring their behavior there. Being reachable from Europe is not enough on its own.

Can I use a free privacy policy generator?

Yes, as a starting draft. Check every sentence against the forms, tools, cookies and vendors your site actually uses before you publish it.

Do I need terms and conditions if I sell online?

In practice, yes. No general US law requires terms on every site, but a store, booking system or subscription needs clear rules on payment, returns and cancellations that customers see before they commit.

Moving Forward

If your site collects anything about visitors, it should carry a privacy policy, and that policy should describe what the site really does. California's CalOPPA sets the bar for any commercial site that collects Californians' information, the CCPA only applies above its thresholds, and GDPR reaches a US business only when it offers to or monitors people in Europe. Terms and conditions are a separate contract that matters once you sell, take bookings or offer accounts.

Once your policy matches your forms, tools and vendors, you can answer a customer's question about their data in one sentence, and each new tool added to the site becomes a quick policy update instead of a hidden gap.

If the check above turns up tools you cannot identify or promises you cannot keep, Web Leveling can help. Our web design work includes an inventory of every form, tag, cookie and embed on your site, removal of what you do not need, and clean setup of the notices and consent controls you and your counsel approve. We do not sell a one-size "compliant" policy, and legal wording stays with you and your lawyer. We work with small and medium businesses across the country and overseas. Tell us what your site collects today, and we will help you make the pages match it.

Terms

Privacy policy words in this post

Tap a term to see what it means.

Privacy policy. A page that explains how a business collects, uses, shares, keeps and protects personal information.

Terms and conditions. A proposed contract that sets the rules for using a site and buying from the business, also called terms of use or terms of service.

CalOPPA. California's Online Privacy Protection Act, which requires a posted privacy policy from commercial sites that collect personal information from California residents.

CCPA. The California Consumer Privacy Act, amended by the CPRA, which applies to for-profit businesses in California that meet one of three thresholds.

Notice at collection. A short notice given at the point where information is collected, required under the CCPA for covered businesses.

GDPR. The EU's General Data Protection Regulation; the UK has its own version, the UK GDPR.

Strictly necessary cookie. A cookie the site needs to work, which UK rules exempt from consent.