Privacy notice

What a privacy notice is for, and what it has to be honest about.

Most business owners think of a privacy policy as a formality bolted into the footer. It is better understood as a public description of what your website does with people's information, which means it has to be accurate.

A tracking plan from enquiry to CRMPhone calls, web forms and live chats all feed into one tagged event carrying the source, campaign and landing page, which is then written into the CRM alongside the enquiry, its owner and its outcome.EVERY ENQUIRY ARRIVES WITH ITS SOURCE ATTACHEDPHONE CALLWEB FORMLIVE CHATTAGGED EVENTSOURCECAMPAIGNLANDING PAGEYOUR CRMENQUIRYSOURCEOWNEROUTCOMEWITHOUT THIS, REPORTING IS GUESSING WHERE THE WORK CAME FROM.
A tracking plan from enquiry to CRM
In short

Why does my website need a privacy policy?

A privacy policy, often called a privacy notice, is the public statement of what personal information your site collects, why, who else receives it and what choices people have, and almost every business site collects more than its owner realises: contact form fields, analytics identifiers, advertising tags, chat widgets and call tracking all count.

Consumer privacy regimes such as California's expect that notice to exist and to be accurate, and advertising rules expect public statements a business makes, including the ones in a privacy notice, not to be misleading.

This page is a plain description of what such notices usually cover. What a business actually publishes should be reviewed by its own counsel before it goes live, because the obligations turn on facts this page cannot know.

Start here

You are collecting more than you think

The usual objection is that a small site collects nothing. That is almost never true, because collection is not limited to what somebody deliberately typed into a form.

A contact form collects a name, an email address and whatever else you asked for, plus the time and often the page it came from. An analytics tool assigns an identifier and records behaviour across a visit. An advertising tag reports back to a platform that a particular browser looked at a particular page, so that the platform can show that person something later.

Read the full breakdown: You are collecting more than you think3 more paragraphsHide the full breakdown: You are collecting more than you think

Then there is everything embedded. A chat widget, a booking system, a review carousel, an embedded map and a video player are each a connection to somebody else's servers, made on your visitor's behalf, from your site.

Call tracking deserves a specific mention because businesses often forget it entirely. A tracked number records that a call happened, from what number, at what length, and increasingly what was said. That is personal information and frequently the most sensitive you hold.

A privacy notice is where all of that gets described in language a normal person can read. Writing it is also the fastest way to discover what your site is actually doing, which is a genuinely useful exercise in itself.

Take an inventory

Where collection actually happens on a small business site

Work through this list against your own site before anyone writes a word of the notice. Describing what you do not actually do is its own problem.

  • Contact, booking and quote forms, including the fields you no longer use but never removed.
  • Newsletter sign-ups and anything that adds somebody to a mailing list.
  • Analytics, which typically sets an identifier and records pages, sources and actions.
  • Advertising and remarketing tags, which report activity back to an advertising platform.
  • Live chat and chatbot widgets, which usually store the transcript somewhere other than your own systems.
See the full checklist: Where collection actually happens on a small business site5 more itemsHide the full checklist: Where collection actually happens on a small business site
  • Call tracking numbers, including call recording if it is switched on.
  • Embedded third party content, such as maps, video players, review widgets and social feeds.
  • Appointment or patient portals, which often carry far more sensitive information than the rest of the site combined.
  • Server logs, which typically record addresses and requests whether or not anyone configured them to.
  • Anywhere a file is uploaded, because attachments frequently carry more than the person intended.

Once that list is written, the notice mostly writes itself, and you will usually find at least one thing on it that nobody remembers adding and nobody uses. Removing those is the cheapest privacy improvement available.

The collection point

The form is where most of it becomes real

The moment a visitor becomes an identifiable person is almost always the form or the phone call, which is why the fields you ask for are a privacy decision as well as a conversion one.

From a search to a booked jobA path running left to right: a search, then your page, then a branch into either a phone call or a form and chat, then a booked job. A faint branch drops away from the page to show the people who leave instead.FROM A SEARCH TO A BOOKED JOBSEARCHA QUERY WITH INTENTYOUR PAGEPROOF AND A NEXT STEPCALLFORM OR CHATBOOKEDTRACKED TO ITS SOURCELEAVESNOT EVERY CLICK CONVERTS.THE PAGE’S JOB IS TO LOSE FEWER OF THEM.EVERY STEP IS A PLACE TO LOSE SOMEONE, OR A PLACE TO MAKE IT EASIER.
A search, then your page, then a call or a form, then a booked job. The form is the point where an anonymous visitor becomes a record you hold.

Collect less and you have less to describe, less to protect and less to lose. A form that asks only what the first conversation needs converts better and reduces your obligations at the same time, which is an unusually clean alignment of interests.

Be careful about what a free text box invites. A field labelled tell us about your problem on a healthcare site will receive health information, and that changes what handling is appropriate. If that applies to you, it is a conversation for your counsel rather than a checklist item.

Settle the terms

Three documents people treat as one

These get merged into a single footer link constantly, and they answer different questions.

The documentWhat it describesWho it is mainly for
Privacy noticeWhat personal information you collect, why, who receives it and what choices people haveVisitors, customers and regulators
Terms of useThe rules for using your site and the relationship between you and a visitorYou, as a statement of the terms you operate under
Cookie or consent noticeWhat is stored on a device and what a person can accept or declineVisitors, at the moment of the choice
Vendor agreementsWhat your suppliers may do with data you pass to themYou and each supplier

Which of these you need, and what each must contain, depends on where you operate, what you collect and who your customers are. That is a question for a lawyer who knows your situation, not for a web page.

Typical contents

What these notices usually cover

Described generally, because the specifics depend on your business and your jurisdiction. Treat this as a conversation starter with your counsel rather than a template.

  • What categories of information are collected, described in plain terms rather than in legal abstraction.
  • How it is collected, separating what a person gives you from what is gathered automatically as they browse.
  • Why it is collected, tied to a real purpose rather than to a catch-all phrase about improving services.
  • Who else receives it, including the analytics, advertising, hosting, email and scheduling providers involved.
  • How long it is kept, and what happens to it afterwards.
See the full checklist: What these notices usually cover3 more itemsHide the full checklist: What these notices usually cover
  • What choices a person has, and specifically how they exercise them, including who to contact and what happens next.
  • How the business can be reached about privacy questions, with a route that is actually monitored.
  • How and where changes to the notice will be published, and the date of the current version.

Two things matter more than completeness. It has to be accurate, and it has to be readable. A notice copied from another business describes that business, and one written to be impenetrable fails the purpose it exists for.

Placement

A notice nobody can find has not been published

The notice needs a permanent, predictable route from every page, which in practice means the footer of the template rather than a single page linked from one place.

Hub and spoke internal linkingA three-level link map. The home page feeds three hubs, one for services, one for industries and one for locations, and each hub feeds two child pages. Dashed links run sideways between siblings, so no page is left without a route in or out.HOW THE PAGES HOLD EACH OTHER UPHOMESERVICE HUBWHAT YOU DOINDUSTRY HUBWHO YOU DO IT FORLOCATION HUBWHERE YOU DO ITGUIDEANSWERGUIDEANSWERCITY PAGECITY PAGEDOWN TO CHILDREN, AND BACK UPACROSS TO SIBLINGSNO PAGE IS LEFT AN ORPHAN.
A link map where every page has a route in and out, so nothing is left unreachable from the rest of the site.

Link it from the footer sitewide, from the point of collection on any form, and from any email that invites someone to share information. Somebody deciding whether to fill in your form should not have to go looking.

Keep it as an ordinary crawlable page, not a pop-up or a modal, and keep the link text plain. An accessible route to the notice is part of publishing it properly.

Common failures

The mistakes that cause real problems

Publishing a notice that describes a different business. Copied text routinely names services the business does not use and omits the ones it does, and an inaccurate public statement is worse than a short accurate one.

Leaving it to rot. Sites add a chat widget, a new booking tool or a remarketing tag and nobody revisits the notice. It should be reviewed whenever something new starts collecting data, not annually by habit.

Read the full breakdown: The mistakes that cause real problems4 more paragraphsHide the full breakdown: The mistakes that cause real problems

Consent theatre. A banner that records a refusal and then loads the tags anyway is a problem regardless of what the banner says, and it is straightforward for anyone technical to observe.

Forgetting the email side. If you send marketing email, the rules about what a commercial message must contain and how somebody opts out are separate from the privacy notice and equally binding.

Ignoring what your own staff do. Enquiries forwarded to personal inboxes, patient details in a spreadsheet, recordings kept indefinitely because nobody set a retention period. The notice describes the practice, so the practice has to be real.

Treating a generated document as the end of the task. A generated notice can be a reasonable starting point, but nothing generic knows what tools you run or what you promised a customer, and nothing generic is a substitute for a review by your own lawyer.

Want to know what your site is actually collecting

A free audit lists every third party tag, embed and tracker running on your pages, so your counsel has something factual to review.

Questions

Straight answers.

Does a small business website really need a privacy policy?

If your site collects any personal information, and nearly all do through forms, analytics or advertising tags, then a notice describing that collection is the normal expectation.

Whether one is legally required of you specifically depends on where you operate, who your customers are and what you collect. That question belongs to your lawyer, not to a web page.

Can I copy a privacy policy from another website?

It will describe that business rather than yours, which means your public statement about your own practices will be wrong in both directions: naming things you do not do and omitting things you do.

Start from your own inventory of what the site collects, then have counsel review the result.

Is a privacy policy the same as a cookie banner?

No. The notice describes your handling of personal information overall. A consent notice is the moment a visitor is asked to accept or decline what gets stored on their device.

They are related and they need to agree with each other, which is where inherited setups most often fall down.

How often should the notice be updated?

Whenever something changes what you collect or who receives it. Adding a chat widget, a booking tool, call recording or a new advertising platform all qualify.

Date the current version and say where changes will be published, so a reader can tell what they agreed to and when.

Does this cover marketing emails too?

Partly. The notice describes what you collect and why. The rules about commercial email, including what a message must contain and how somebody opts out, sit separately and apply to the sending itself.

If you run email campaigns, treat the two as a pair rather than assuming one covers the other.

Can you write my privacy policy for us?

We do not provide legal advice and we do not draft these. What we can do is give your lawyer an accurate technical inventory: every tag, embed, form and tracker the site runs, and where the data goes.

That inventory is usually the part that is missing, and it is the part that makes a review quick rather than speculative.

Next step

Talk to the team

A short call, a look at how the business currently shows up, and a straight answer on what we would do first.