Every privacy law in force today, from GDPR to Quebec's Law 25 to the CCPA, requires roughly the same thing: tell people, in plain language, what you collect and what you do with it. This article walks through a privacy policy example section by section, so you can evaluate yours, and flags the traps that make generated policies worthless.
The structure of a solid privacy policy
- Who you are: legal name, address, and how to reach the person responsible for privacy.
- What you collect: account data, payment data, technical data (IP, device), cookies and trackers. Be specific; "various information" is not disclosure.
- Why you collect it: one purpose per category. Consent obtained for a stated purpose does not cover a different one.
- Who receives it: processors (hosting, payments, email), advertising partners if any, and authorities when the law requires.
- Where it goes: transfers outside your country or province, and the safeguards behind them.
- How long you keep it: retention periods or the criteria that set them.
- People's rights: access, correction, erasure, withdrawal of consent, portability, and how to exercise each.
- Cookies: the categories you use, and how to change one's choice at any time.
- Updates: the policy's date and how changes are announced.
A miniature example, annotated
Here is what the collection section of a small business policy can look like. Notice how each sentence commits to something specific and verifiable:
Example wording
"When you request a quote, we collect your name, email address and the details of your project, to prepare and follow up on the quote. When you browse the site, our analytics tool collects usage data only after you accept analytics cookies in the banner. We do not sell personal information, and we keep quote requests for 24 months."
You can read a full production document in our own privacy policy: a real example of a Law 25 and GDPR-aware policy, including the controller and processor distinction that consent platforms need.
About Wix and other generated policies
Site builders like Wix, Shopify and Squarespace offer privacy policy generators, and searches like "wix privacy policy" show how many owners rely on them. They are a starting point, with one structural weakness: the generator does not know your actual stack. If the template mentions tools you do not use, or omits the Meta Pixel you added last spring, the policy misrepresents your practices, which is worse than being vague. Whatever produces your first draft, reconcile it against the trackers really present on your site; a cookie scan gives you that list in minutes.
The mistakes that invalidate a policy
- Copying another site's policy, competitors' tool lists included.
- Publishing the policy but loading trackers before consent anyway: the policy describes a consent you never obtain.
- No date and no contact: two details regulators check immediately.
- Legalese nobody can read: Law 25 explicitly requires clear and simple language.
A policy is one half of the pair; the other is the terms and conditions that govern the use of your service. And Consorm is building a privacy policy generator that starts from your real tools rather than a generic template.