← Back to blog
eCommerce

Privacy Policy for eCommerce: What WooCommerce & Online Stores Need

By DataShark · 27 June 2026 · 7 min read
?>

eCommerce websites collect significantly more personal data than a simple brochure site. Names, addresses, payment card data, order history, browsing behaviour, email addresses — each of these creates specific legal obligations under GDPR, UK GDPR, and CCPA. A generic Privacy Policy template is unlikely to cover everything your online store actually does.

Why eCommerce Privacy Policies are more complex

A standard business website might collect names and email addresses through a contact form. An eCommerce site typically collects:

Each category of data has its own legal basis, retention requirement, and disclosure obligation — all of which must be reflected in your Privacy Policy.

Legal basis for processing in eCommerce

Under EU GDPR and UK GDPR, every processing activity needs a lawful basis. For a typical online store:

You cannot rely on contract as the legal basis for sending marketing emails to customers. Even existing customers require consent (or in some limited cases, soft opt-in under PECR for UK businesses) before receiving marketing communications.

What WooCommerce stores specifically must disclose

WooCommerce processes substantial personal data by default. Your Privacy Policy must disclose:

WooCommerce data collection

WooCommerce stores customer names, email addresses, billing and shipping addresses, payment details (as tokenised references), order history, and customer notes. If you use WooCommerce's built-in account system, this also includes account login credentials.

Payment processors

Whether you use Stripe, PayPal, Klarna, Razorpay, or a different payment gateway, your Privacy Policy must name them as processors and explain that payment data is handled according to their own privacy policies and PCI DSS security standards. Your business should never store raw card numbers — this must be reflected in your policy.

Email marketing integrations

If you connect WooCommerce to Klaviyo, Mailchimp, Omnisend, or another email marketing tool, customer email addresses and purchase data are transferred to that platform. This transfer must be disclosed, along with the legal basis (typically consent for marketing, legitimate interests for transactional emails).

Analytics and advertising pixels

Google Analytics, Meta Pixel, Google Ads remarketing tags, and TikTok Pixel all collect browsing and purchase behaviour data. Each must be named in your Cookie Policy and Privacy Policy, with their specific purpose and cookie details.

Shipping and fulfilment

If you use a third-party fulfilment service or shipping provider (Royal Mail, DPD, FedEx, ShipBob), customer address and order data is shared with them. This sharing must be disclosed.

Returns and customer service

Returns processing involves collecting bank account details or card details for refunds. Customer service tools like Zendesk or Freshdesk receive customer communication data. Both require disclosure.

Data retention for online stores

eCommerce businesses often have competing retention requirements:

Your Privacy Policy must state these retention periods. Vague language like "we retain data as long as necessary" is not acceptable under GDPR — you need to specify actual periods or the criteria used to determine them.

Children's data and age verification

If your products might be purchased by or for children, you need to address this in your Privacy Policy. Under EU GDPR, processing data of children under 16 (under 13 in some member states) requires parental consent for consent-based processing. Under UK GDPR, the threshold is 13. Under CCPA, it's 16 (and 13 for the right of deletion).

If your store sells age-restricted products, you have additional obligations around age verification and the data collected in that process.

CCPA requirements for US eCommerce

US online stores face additional obligations under CCPA and state privacy laws:

What your eCommerce Privacy Policy must cover

  1. All categories of personal data collected (not just contact details)
  2. The lawful basis for each processing activity
  3. Every third-party processor — payment gateway, email platform, analytics, advertising, shipping
  4. International data transfers and the safeguards in place
  5. Data retention periods for each category
  6. Customer rights and how to exercise them
  7. Cookie usage and consent mechanism
  8. Children's data policy (if relevant)
  9. Security measures — encryption, tokenisation, access controls
  10. Contact details for privacy requests

DataShark generates a personalised Privacy Policy for your eCommerce site or WooCommerce store — naming your specific payment processor, email platform, analytics tools, and shipping providers. US and UK versions available from $14, EU version from €10.

Ready to generate your GDPR policy?

Answer a few questions about your business and get a personalised, legally-structured document in minutes.

Start free — from £29 →