A privacy policy page is legally required especially if your website deals with payments and will also help your website stay compliant with privacy laws like GDPR and the ePrivacy Directive. This guide will walk you through how you can generate a custom privacy policy for Shopify in minutes.
To begin with, sign up on CookieYes and try it for free.
This guide consists of two sequential steps: generating a privacy policy for Shopify, and then adding that policy to your Shopify website.
After you sign up, you'll be directed to the installation screens, where you can install the cookie banner to help ensure GDPR-compliant use of cookies. If you'd rather create a privacy policy first, skip installation and proceed to the app dashboard instead.
Part 1. How to generate a privacy policy for Shopify
Step 1. Access the privacy policy generator
From your app’s homepage, click on Legal Policies and select Privacy Policy Generator.
Step 2. Language preferences
- Select the primary language
- Choose the default language of your privacy policy.
- Generate policy in multiple languages
- Select the additional languages you want to generate the privacy policy in. This feature is available only on Basic, Pro and Ultimate plans.
- Click Save draft to save your progress or Next to continue.
Step 3. Company details
Company details has two sections: Contact information and Business details.
In Contact information, provide the following details:
- Name – Enter either the company name or individual name.
- Website URL – Provide the website address.
- Email address – Enter the contact email.
- Contact URL – Add this if applicable.
- Full address – Provide the complete address.
Click Next to navigate to Business details.
Step 3b. Business details
In Business details, provide the following details.
Do you have users in EU/EEA?
Select Yes or No to indicate whether your website has users in the EU/EEA. Selecting Yes includes GDPR-specific clauses in your privacy policy.
Do you have users in California?
Select Yes or No to indicate whether your website has users in California. Selecting Yes displays follow-up questions that determine whether the CCPA/CalOPPA applies to your business. If you select No, no additional questions appear.
The follow-up questions below are available only on the Basic, Pro, and Ultimate plans.
Click Next to proceed to Step 4.
Step 4. Collection of data
Collection of data has two sections: Personal information and Additional information.
In Personal information, specify the types of personal or sensitive personal information you collect. Click Next to navigate to the Additional information section.
In Additional information, provide the following details:
- Specify whether you use cookies or other tracking technologies. If you select Yes, add a link to your cookie policy.
- Describe how you respond to Do Not Track requests.
- Specify whether you collect information about users below the age of 16.
- Select the legal bases for collecting the data.
- Specify whether you collect information about users below the age of 13.
- Specify whether you have a process that allows users to review and request changes to their information. If you select Yes, describe how users can review or update their data.
Click Next to proceed to Step 5.
Step 5. Use of data
In Use of data, select the options that describe how the information you collect is used. Click Next to continue.
Step 6. Disclosure of data
In Disclosure of data, provide details about the categories of users whose information is sold or shared, the request process for users to delete, correct, or access their information, sensitive information disclosures, and any third-party disclosures made in the past 12 months.
Disclosure of data appears only if you selected the relevant options in the Business details section of the Company Details page, so it may not be part of every user's setup.
Step 7. Data retention
In Data retention, specify how long the information you collect is retained. Click Next to continue.
Step 8. Miscellaneous disclosures
In Miscellaneous disclosures, provide details about cross-border data transfers (to non-adequate countries or regions outside the EU), automated data processing, your data protection officer's contact details, and your data controller or representative (if applicable). Click Next to continue.
Step 9. Preview and generate the privacy policy
You can now preview your privacy policy in multiple languages. Click Generate privacy policy to generate the policy. Click Add policy to site to see the methods for adding the privacy policy to your website.
Step 10. Copy your privacy policy code
Follow the below steps to copy your privacy policy code.
- Choose your preferred method for adding a privacy policy to your website:
- Option A: Code snippet: Keeps your privacy policy automatically updated.
- Option B: HTML format: Requires manual updates whenever the privacy policy changes.
- Select your preferred language.
- Click Copy code.
Part 2. How to add privacy policy into Shopify website
Step 1. Add a privacy policy page in Shopify
- Log in to your Shopify account.
- Go to Online Store > Pages.
- Click Add Page.
Step 2. Paste the privacy policy code into your Shopify website
- Provide a Title for the page.
- Paste your privacy policy into the Content field and click Save.
Step 3. Complete privacy policy generation
Return to CookieYes and click Complete generation. In the popup that opens, click Yes, I have installed.
Your privacy policy page will be live on your Shopify store. You can then link your privacy policy to your website footer.
Frequently asked questions
Do I need to add a privacy policy to my Shopify website?
Yes. You need a detailed privacy policy on your website to comply with regulations. Several privacy regulations across countries require websites to have a comprehensive privacy policy, including the GDPR in the EU and UK, CCPA in the US, PIPEDA in Canada, LGPD in Brazil and so on. Not only is a privacy policy a legal requirement, but it is also a best practice to build transparency and confidence in your site.
Where should a privacy policy go on a website?
Privacy policies are usually linked on a website’s footer and are accessible from every page of the website. You should also link your privacy policy on important touchpoints where you collect personal information such as sign up pages, checkout pages, forms, etc.