eCommerce websites collect significantly more personal data than a simple brochure site. Names, addresses, payment card data, order history, browsing behaviour, email addresses — each of these creates specific legal obligations under GDPR, UK GDPR, and CCPA. A generic Privacy Policy template is unlikely to cover everything your online store actually does.
Why eCommerce Privacy Policies are more complex
A standard business website might collect names and email addresses through a contact form. An eCommerce site typically collects:
- Full name and billing/shipping address
- Email address and phone number
- Payment card data (or tokenised payment data via Stripe/PayPal)
- Order history and purchase behaviour
- IP address and device information
- Browsing and search history on your site
- Wishlist and saved item data
- Returns and complaints data
- Marketing preferences and email engagement data
Each category of data has its own legal basis, retention requirement, and disclosure obligation — all of which must be reflected in your Privacy Policy.
Legal basis for processing in eCommerce
Under EU GDPR and UK GDPR, every processing activity needs a lawful basis. For a typical online store:
- Contract (Article 6(1)(b)) — processing orders, shipping, managing returns, responding to customer service queries
- Legal obligation (Article 6(1)(c)) — retaining financial records for 6-7 years for tax/accounting purposes
- Legitimate interests (Article 6(1)(f)) — fraud prevention, security, improving your website
- Consent (Article 6(1)(a)) — marketing emails, advertising cookies, personalisation
What WooCommerce stores specifically must disclose
WooCommerce processes substantial personal data by default. Your Privacy Policy must disclose:
WooCommerce data collection
WooCommerce stores customer names, email addresses, billing and shipping addresses, payment details (as tokenised references), order history, and customer notes. If you use WooCommerce's built-in account system, this also includes account login credentials.
Payment processors
Whether you use Stripe, PayPal, Klarna, Razorpay, or a different payment gateway, your Privacy Policy must name them as processors and explain that payment data is handled according to their own privacy policies and PCI DSS security standards. Your business should never store raw card numbers — this must be reflected in your policy.
Email marketing integrations
If you connect WooCommerce to Klaviyo, Mailchimp, Omnisend, or another email marketing tool, customer email addresses and purchase data are transferred to that platform. This transfer must be disclosed, along with the legal basis (typically consent for marketing, legitimate interests for transactional emails).
Analytics and advertising pixels
Google Analytics, Meta Pixel, Google Ads remarketing tags, and TikTok Pixel all collect browsing and purchase behaviour data. Each must be named in your Cookie Policy and Privacy Policy, with their specific purpose and cookie details.
Shipping and fulfilment
If you use a third-party fulfilment service or shipping provider (Royal Mail, DPD, FedEx, ShipBob), customer address and order data is shared with them. This sharing must be disclosed.
Returns and customer service
Returns processing involves collecting bank account details or card details for refunds. Customer service tools like Zendesk or Freshdesk receive customer communication data. Both require disclosure.
Data retention for online stores
eCommerce businesses often have competing retention requirements:
- Order data — typically retained for 6-7 years for accounting and tax compliance
- Customer account data — retained while the account is active, plus a reasonable period after last activity
- Marketing consent records — retained for the duration of the marketing relationship
- Cookie consent records — retained for a reasonable period to demonstrate compliance
- CCTV footage (if applicable) — typically 30 days unless needed for an investigation
Your Privacy Policy must state these retention periods. Vague language like "we retain data as long as necessary" is not acceptable under GDPR — you need to specify actual periods or the criteria used to determine them.
Children's data and age verification
If your products might be purchased by or for children, you need to address this in your Privacy Policy. Under EU GDPR, processing data of children under 16 (under 13 in some member states) requires parental consent for consent-based processing. Under UK GDPR, the threshold is 13. Under CCPA, it's 16 (and 13 for the right of deletion).
If your store sells age-restricted products, you have additional obligations around age verification and the data collected in that process.
CCPA requirements for US eCommerce
US online stores face additional obligations under CCPA and state privacy laws:
- Disclose all categories of personal data collected and sold/shared
- Provide a "Do Not Sell or Share My Personal Information" link if you use advertising pixels
- Honour consumer requests to access, delete, or correct their data within 45 days
- Not discriminate against consumers who exercise their privacy rights
What your eCommerce Privacy Policy must cover
- All categories of personal data collected (not just contact details)
- The lawful basis for each processing activity
- Every third-party processor — payment gateway, email platform, analytics, advertising, shipping
- International data transfers and the safeguards in place
- Data retention periods for each category
- Customer rights and how to exercise them
- Cookie usage and consent mechanism
- Children's data policy (if relevant)
- Security measures — encryption, tokenisation, access controls
- Contact details for privacy requests
DataShark generates a personalised Privacy Policy for your eCommerce site or WooCommerce store — naming your specific payment processor, email platform, analytics tools, and shipping providers. US and UK versions available from $14, EU version from €10.
Ready to generate your GDPR policy?
Answer a few questions about your business and get a personalised, legally-structured document in minutes.
Start free — from £29 →