Privacy Policy Generator
When to Use This Skill
- Launching a new website, app, or online store
- Adding email collection, payment processing, or analytics to a site
- Selling to EU customers (GDPR) or California residents (CCPA)
- Updating an outdated privacy policy after adding new tools or features
- Setting up a SaaS product or membership site
IMPORTANT: This skill generates starting-point privacy policies based on common practices. It is NOT legal advice. Always have a qualified attorney review the final policy before publishing.
Workflow
Step 1: Gather Business Details
Ask the user:
- What type of business? (e-commerce, SaaS, blog, service business, app)
- What data do you collect? (names, emails, payment info, browsing behavior, location)
- What tools process that data? (Stripe, Mailchimp, Google Analytics, Meta Pixel, etc.)
- Do you sell to EU customers? (triggers GDPR requirements)
- Do you sell to California residents? (triggers CCPA requirements)
- Do you sell or share data with third parties?
- What's your business name and website URL?
Minimum needed: questions 1, 2, and 3.
Step 2: Determine Required Sections
| Business Type |
Required Sections |
| All businesses |
Data collected, how it's used, how it's protected, contact info |
| E-commerce |
Payment processing, order data retention, shipping data sharing |
| SaaS / App |
Account data, usage analytics, data export/deletion |
| Email list / Blog |
Email collection, cookies, analytics, unsubscribe process |
| EU customers |
GDPR: legal basis, data rights, DPO contact, cross-border transfers |
| CA residents |
CCPA: right to know, right to delete, right to opt-out, non-discrimination |
Step 3: Draft the Policy
Write these sections in order:
- Introduction — Who you are, what this policy covers
- Information We Collect — Personal data, automatically collected data, third-party data
- How We Use Your Information — Specific purposes tied to specific data types
- How We Share Your Information — Third-party processors, legal requirements
- Cookies and Tracking — What cookies, what they do, how to opt out
- Data Retention — How long you keep data and why
- Your Rights — Access, correction, deletion, portability
- GDPR Rights (if applicable) — Legal basis, EU-specific rights, DPO contact
- CCPA Rights (if applicable) — CA-specific disclosures and opt-out
- Children's Privacy — COPPA compliance statement
- Security — How data is protected (general terms, not technical specifics)
- Changes to This Policy — How users are notified of updates
- Contact Information — How to reach you about privacy concerns
For each section, add a plain-language annotation in italics explaining what it means in simple terms.
Step 4: Review & Deliver
- Verify all third-party tools mentioned are covered in the sharing section
- Check that every data type collected has a stated purpose
- Confirm retention periods are specified
- Ensure contact method is included
- Add "Last Updated: [date]" at the top
- Remind the user to have an attorney review before publishing
Examples
Example 1: Shopify E-commerce Store
Business: Handmade jewelry store on Shopify
Data collected: Names, emails, shipping addresses, payment info, browsing behavior
Tools: Shopify, Stripe, Mailchimp, Google Analytics, Meta Pixel
EU customers: Yes | CA residents: Yes
Output (excerpt — Introduction + Information We Collect):
Privacy Policy
Last Updated: [Current Date]
1. Introduction
LunaStone Jewelry ("we," "us," or "our") operates lunastonejewelry.com. This Privacy Policy explains how we collect, use, and protect your personal information when you visit our website, make a purchase, or interact with us.
In plain language: This document tells you what information we collect about you, why we collect it, and what we do with it. We try to collect only what we need and keep it safe.
2. Information We Collect
Information you provide directly:
- Name and email address (when you create an account, place an order, or subscribe to our newsletter)
- Shipping and billing address (when you place an order)
- Payment information (credit card number, expiration date — processed securely by Stripe; we never store your full card number)
- Product reviews and messages (when you contact us or leave a review)
Information collected automatically:
- Browsing behavior on our site (pages visited, products viewed, time on page) via Google Analytics
- Device information (browser type, operating system, screen size)
- IP address and approximate location
- Cookies and tracking pixels (see Section 5)
In plain language: We collect what you type in (name, address, payment) plus some technical info about how you browse our site. We use Stripe for payments — we never see or store your full credit card number.
GDPR section (excerpt):
8. Your Rights Under GDPR (EU Customers)
If you are located in the European Economic Area, you have the following rights:
- Right to Access — Request a copy of all personal data we hold about you
- Right to Rectification — Ask us to correct inaccurate data
- Right to Erasure — Ask us to delete your data ("right to be forgotten")
- Right to Restrict Processing — Ask us to limit how we use your data
- Right to Data Portability — Receive your data in a machine-readable format
- Right to Object — Opt out of marketing communications at any time
Legal Basis for Processing:
- Contract performance (processing orders, shipping products)
- Legitimate interest (improving our website, fraud prevention)
- Consent (marketing emails, non-essential cookies)
To exercise any of these rights, email privacy@lunastonejewelry.com. We will respond within 30 days.
In plain language: If you're in the EU, you can ask us to show you what data we have, fix it, delete it, or send it to you in a file. Email us and we'll handle it within 30 days.
Example 2: SaaS Project Management App
Business: Cloud-based project management tool
Data collected: Names, emails, company info, project data, usage analytics
Tools: AWS hosting, Stripe billing, Intercom chat, Mixpanel analytics
Output (excerpt — Data Retention + Security):
6. Data Retention
| Data Type |
Retention Period |
Reason |
| Account information |
Duration of account + 30 days after deletion |
Service delivery and account recovery |
| Project data |
Duration of account + 30 days after deletion |
You can export all project data before deleting your account |
| Payment records |
7 years after transaction |
Tax and legal compliance |
| Usage analytics |
24 months (anonymized after 12 months) |
Product improvement |
| Support chat transcripts |
24 months |
Quality assurance and training |
In plain language: We keep your stuff while you use our product plus 30 days after you leave (in case you change your mind). Payment records stay longer because the law requires it. Analytics data gets anonymized after a year.
11. Security
We protect your data using:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Regular security audits and penetration testing
- Role-based access controls for our team
- SOC 2 Type II compliance (audit report available on request)
- Automated backups with geographic redundancy
No system is 100% secure. If we discover a data breach that affects your personal information, we will notify you within 72 hours as required by applicable law.
In plain language: We use industry-standard security to protect your data. If something goes wrong, we'll tell you within 72 hours.
Common Patterns by Business Type
| Business Type |
Key Considerations |
| E-commerce (Shopify, WooCommerce) |
Payment processors, shipping partners, abandoned cart tracking, review platforms |
| SaaS / Web App |
User-generated content ownership, API data access, sub-processors, data export |
| Blog / Content Site |
Cookies, analytics, email subscription, comment data, ad networks |
| Coaching / Services |
Intake forms, session recordings, scheduling tools, payment platforms |
| Membership / Course |
Student data, progress tracking, community platform data, certificate records |
Recovery & Fallbacks
- User doesn't know what tools they use: Ask them to check their website footer, admin dashboard, and email platform. Common stack: Google Analytics + Mailchimp + Stripe covers most small businesses.
- User operates internationally but doesn't know which laws apply: Default to including both GDPR and CCPA sections. It's better to over-comply than under-comply.
- User wants a "simple" one-page policy: Write the shortest compliant version, but warn that brevity should not come at the cost of required disclosures.
- Policy needs to cover an app + website: Write one combined policy that covers both, with sections clearly noting which applies to the app vs. website.
Constraints
- ALWAYS include the legal disclaimer — this is not legal advice
- NEVER claim compliance — say "designed to address requirements of" not "compliant with"
- List every third-party tool by name — don't hide behind "third-party services"
- Include a real contact method (email at minimum)
- Date every policy with "Last Updated"
- Use plain language annotations for every section
1---2name: privacy-policy3description: Writes GDPR and CCPA-compliant privacy policies for websites, apps, and online businesses with plain-language annotations explaining each section. Use when a user is launching a website, setting up e-commerce, collecting customer data, or needs to update an outdated privacy policy.4---56# Privacy Policy Generator78## When to Use This Skill910- Launching a new website, app, or online store11- Adding email collection, payment processing, or analytics to a site12- Selling to EU customers (GDPR) or California residents (CCPA)13- Updating an outdated privacy policy after adding new tools or features14- Setting up a SaaS product or membership site1516**IMPORTANT: This skill generates starting-point privacy policies based on common practices. It is NOT legal advice. Always have a qualified attorney review the final policy before publishing.**1718## Workflow1920### Step 1: Gather Business Details2122Ask the user:23241. What type of business? (e-commerce, SaaS, blog, service business, app)252. What data do you collect? (names, emails, payment info, browsing behavior, location)263. What tools process that data? (Stripe, Mailchimp, Google Analytics, Meta Pixel, etc.)274. Do you sell to EU customers? (triggers GDPR requirements)285. Do you sell to California residents? (triggers CCPA requirements)296. Do you sell or share data with third parties?307. What's your business name and website URL?3132**Minimum needed: questions 1, 2, and 3.**3334### Step 2: Determine Required Sections3536| Business Type | Required Sections |37|--------------|-------------------|38| All businesses | Data collected, how it's used, how it's protected, contact info |39| E-commerce | Payment processing, order data retention, shipping data sharing |40| SaaS / App | Account data, usage analytics, data export/deletion |41| Email list / Blog | Email collection, cookies, analytics, unsubscribe process |42| EU customers | GDPR: legal basis, data rights, DPO contact, cross-border transfers |43| CA residents | CCPA: right to know, right to delete, right to opt-out, non-discrimination |4445### Step 3: Draft the Policy4647Write these sections in order:48491. **Introduction** — Who you are, what this policy covers502. **Information We Collect** — Personal data, automatically collected data, third-party data513. **How We Use Your Information** — Specific purposes tied to specific data types524. **How We Share Your Information** — Third-party processors, legal requirements535. **Cookies and Tracking** — What cookies, what they do, how to opt out546. **Data Retention** — How long you keep data and why557. **Your Rights** — Access, correction, deletion, portability568. **GDPR Rights** (if applicable) — Legal basis, EU-specific rights, DPO contact579. **CCPA Rights** (if applicable) — CA-specific disclosures and opt-out5810. **Children's Privacy** — COPPA compliance statement5911. **Security** — How data is protected (general terms, not technical specifics)6012. **Changes to This Policy** — How users are notified of updates6113. **Contact Information** — How to reach you about privacy concerns6263For each section, add a **plain-language annotation** in italics explaining what it means in simple terms.6465### Step 4: Review & Deliver66671. Verify all third-party tools mentioned are covered in the sharing section682. Check that every data type collected has a stated purpose693. Confirm retention periods are specified704. Ensure contact method is included715. Add "Last Updated: [date]" at the top726. Remind the user to have an attorney review before publishing7374## Examples7576### Example 1: Shopify E-commerce Store7778**Business:** Handmade jewelry store on Shopify79**Data collected:** Names, emails, shipping addresses, payment info, browsing behavior80**Tools:** Shopify, Stripe, Mailchimp, Google Analytics, Meta Pixel81**EU customers:** Yes | **CA residents:** Yes8283**Output (excerpt — Introduction + Information We Collect):**8485> **Privacy Policy**86> Last Updated: [Current Date]87>88> **1. Introduction**89>90> LunaStone Jewelry ("we," "us," or "our") operates lunastonejewelry.com. This Privacy Policy explains how we collect, use, and protect your personal information when you visit our website, make a purchase, or interact with us.91>92> *In plain language: This document tells you what information we collect about you, why we collect it, and what we do with it. We try to collect only what we need and keep it safe.*93>94> **2. Information We Collect**95>96> **Information you provide directly:**97> - Name and email address (when you create an account, place an order, or subscribe to our newsletter)98> - Shipping and billing address (when you place an order)99> - Payment information (credit card number, expiration date — processed securely by Stripe; we never store your full card number)100> - Product reviews and messages (when you contact us or leave a review)101>102> **Information collected automatically:**103> - Browsing behavior on our site (pages visited, products viewed, time on page) via Google Analytics104> - Device information (browser type, operating system, screen size)105> - IP address and approximate location106> - Cookies and tracking pixels (see Section 5)107>108> *In plain language: We collect what you type in (name, address, payment) plus some technical info about how you browse our site. We use Stripe for payments — we never see or store your full credit card number.*109110**GDPR section (excerpt):**111112> **8. Your Rights Under GDPR (EU Customers)**113>114> If you are located in the European Economic Area, you have the following rights:115>116> - **Right to Access** — Request a copy of all personal data we hold about you117> - **Right to Rectification** — Ask us to correct inaccurate data118> - **Right to Erasure** — Ask us to delete your data ("right to be forgotten")119> - **Right to Restrict Processing** — Ask us to limit how we use your data120> - **Right to Data Portability** — Receive your data in a machine-readable format121> - **Right to Object** — Opt out of marketing communications at any time122>123> **Legal Basis for Processing:**124> - Contract performance (processing orders, shipping products)125> - Legitimate interest (improving our website, fraud prevention)126> - Consent (marketing emails, non-essential cookies)127>128> To exercise any of these rights, email privacy@lunastonejewelry.com. We will respond within 30 days.129>130> *In plain language: If you're in the EU, you can ask us to show you what data we have, fix it, delete it, or send it to you in a file. Email us and we'll handle it within 30 days.*131132### Example 2: SaaS Project Management App133134**Business:** Cloud-based project management tool135**Data collected:** Names, emails, company info, project data, usage analytics136**Tools:** AWS hosting, Stripe billing, Intercom chat, Mixpanel analytics137138**Output (excerpt — Data Retention + Security):**139140> **6. Data Retention**141>142> | Data Type | Retention Period | Reason |143> |-----------|-----------------|--------|144> | Account information | Duration of account + 30 days after deletion | Service delivery and account recovery |145> | Project data | Duration of account + 30 days after deletion | You can export all project data before deleting your account |146> | Payment records | 7 years after transaction | Tax and legal compliance |147> | Usage analytics | 24 months (anonymized after 12 months) | Product improvement |148> | Support chat transcripts | 24 months | Quality assurance and training |149>150> *In plain language: We keep your stuff while you use our product plus 30 days after you leave (in case you change your mind). Payment records stay longer because the law requires it. Analytics data gets anonymized after a year.*151>152> **11. Security**153>154> We protect your data using:155> - Encryption in transit (TLS 1.2+) and at rest (AES-256)156> - Regular security audits and penetration testing157> - Role-based access controls for our team158> - SOC 2 Type II compliance (audit report available on request)159> - Automated backups with geographic redundancy160>161> No system is 100% secure. If we discover a data breach that affects your personal information, we will notify you within 72 hours as required by applicable law.162>163> *In plain language: We use industry-standard security to protect your data. If something goes wrong, we'll tell you within 72 hours.*164165## Common Patterns by Business Type166167| Business Type | Key Considerations |168|--------------|-------------------|169| E-commerce (Shopify, WooCommerce) | Payment processors, shipping partners, abandoned cart tracking, review platforms |170| SaaS / Web App | User-generated content ownership, API data access, sub-processors, data export |171| Blog / Content Site | Cookies, analytics, email subscription, comment data, ad networks |172| Coaching / Services | Intake forms, session recordings, scheduling tools, payment platforms |173| Membership / Course | Student data, progress tracking, community platform data, certificate records |174175## Recovery & Fallbacks176177- **User doesn't know what tools they use:** Ask them to check their website footer, admin dashboard, and email platform. Common stack: Google Analytics + Mailchimp + Stripe covers most small businesses.178- **User operates internationally but doesn't know which laws apply:** Default to including both GDPR and CCPA sections. It's better to over-comply than under-comply.179- **User wants a "simple" one-page policy:** Write the shortest compliant version, but warn that brevity should not come at the cost of required disclosures.180- **Policy needs to cover an app + website:** Write one combined policy that covers both, with sections clearly noting which applies to the app vs. website.181182## Constraints183184- **ALWAYS include the legal disclaimer** — this is not legal advice185- **NEVER claim compliance** — say "designed to address requirements of" not "compliant with"186- List every third-party tool by name — don't hide behind "third-party services"187- Include a real contact method (email at minimum)188- Date every policy with "Last Updated"189- Use plain language annotations for every section