Privacy Policy Generator
A privacy policy that matches what your site really does — and the laws that apply.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Privacy Policy Generator
Every website or app that collects personal data needs a privacy policy — Indian law requires one from businesses that handle personal information (IT Act s.43A and the SPDI Rules 2011), Google requires one for AdSense and Analytics, and payment gateways ask for one before going live. Tick what your site actually collects — contact forms, accounts, newsletters, comments, orders and payments, analytics, ads, location, sensitive data, children’s data — name the services that receive data, and choose the laws that apply.
The generator writes a clear, plain-English policy with the sections those laws ask for: what is collected and why, cookies and advertising (with the disclosures Google AdSense and Google Analytics require), sharing, international transfers, retention, security, rights and contacts. Modules add the Grievance Officer India requires, a DPDP Act 2023 notice ready for May 2027, GDPR/UK GDPR legal bases and rights, the CCPA/CPRA categories table and CalOPPA Do-Not-Track wording, and a COPPA notice for children’s services. Copy it as HTML or Markdown, or download DOCX or text, with an effective date.
How to use it
- Enter your site’s name and address, who runs it, a privacy e-mail and the effective date.
- Tick what you collect and use — only what your site really does — and fill in the details that appear (analytics tool, ad network, payment providers).
- List the service providers that receive personal data (hosting, e-mail, delivery…), whether data leaves the users’ country, how long you keep each kind of data and your security measures.
- Choose the laws to cover and fill in the Grievance Officer (India), DPO or EU representative (GDPR) and request methods (California) as needed.
- Read the Checks, then copy the HTML into your privacy page (or download .html, .md, DOCX or text) and link to it from your footer and sign-up forms.
Examples
Contact form, accounts, newsletter, orders, Razorpay, GA4, AdSense · Cloudflare (US) · India + DPDP + GDPR
14 sections: the AdSense cookie statements and Ads Settings opt-out, the GA disclosure with Google’s partner-sites link, a Grievance Officer who resolves complaints within one month, a DPDP purpose table, GDPR legal bases and rights.
California ticked, personalised ads on
Adds the CCPA rights, a “categories collected in the last 12 months” table marking identifiers and browsing data as “shared”, and a check telling you to add a “Do Not Sell or Share” link or honour Global Privacy Control.
Children ticked, COPPA ticked, personalised ads on
Error until personalised ads are turned off (COPPA consent rules; DPDP Act s.9(3)); then adds the COPPA online notice — operator contact, what is collected, retention and parents’ rights.
Common uses
- A blog or small business site applying for Google AdSense or adding Google Analytics.
- An online shop that needs a privacy policy before its payment gateway goes live.
- An Indian business preparing its DPDP Act notice ahead of May 2027.
- A SaaS or app with users in the EU, the UK or California.
What Indian law requires today (IT Act s.43A, SPDI Rules 2011)
A body corporate that collects, stores or handles personal information must publish a privacy policy on its website covering its practices, the types of personal and sensitive personal data it collects (passwords, financial details, health and medical records, sexual orientation, biometrics — r.3), why, to whom it is disclosed, and its reasonable security practices (r.4). Sensitive data needs written consent before collection (r.5(1)). Users can review and correct their information and withdraw consent (r.5(6), (7)), and a Grievance Officer whose name and contact details are published must redress grievances within one month (r.5(9)). Sites with comments or user posts are intermediaries too: they publish their rules, privacy policy and user agreement, and the Grievance Officer acknowledges complaints within 24 hours and resolves them within 15 days (Intermediary Rules 2021, r.3).
The DPDP Act 2023 — from May 2027
The Digital Personal Data Protection Act’s duties for data fiduciaries — notice (s.5), consent (s.6), erasure (s.8(7)), children (s.9) and the rights of data principals (ss.11–14) — come into force eighteen months after 13 November 2025 (G.S.R. 843(E)), when s.43A of the IT Act is omitted. The DPDP Rules 2025 require a notice that can be understood on its own, with an itemised list of the personal data and the purposes, and the means to withdraw consent (as easily as it was given), exercise rights and complain to the Data Protection Board (r.3); the contact of a person who answers questions about processing (r.9); and a published grievance reply period of no more than 90 days (r.14(3)). A “child” is anyone under 18: processing needs verifiable parental consent, and tracking or targeted ads directed at children are not allowed (s.9).
GDPR, UK GDPR, California and children
- GDPR / UK GDPR (art. 13): who you are, each purpose and its legal basis, recipients, transfers outside the EEA/UK and their safeguards, retention, the rights to access, rectify, erase, restrict, object and port, the right to withdraw consent and to complain to a supervisory authority (in the UK, the ICO).
- California: the CCPA/CPRA applies to businesses above US$25 million revenue (inflation-adjusted), or handling data of 100,000+ consumers or households, or earning half their revenue from selling or sharing it; the policy must explain the rights, give two request methods, and list the categories collected, sold or shared in the past 12 months (Civ. Code §1798.130(a)(5)). CalOPPA (Bus. & Prof. Code §22575) requires the effective date, how you notify changes and how you respond to Do Not Track signals.
- COPPA (16 CFR 312.4(d)): a service for children under 13 lists every operator’s contact details, what it collects from children and whether they can make it public, how it is used and disclosed, its retention policy, and parents’ rights — and needs verifiable parental consent before collecting.
Google AdSense and Google Analytics
AdSense publishers must disclose that third-party vendors, including Google, use cookies to serve ads based on a user’s prior visits, that Google’s advertising cookies let it and its partners serve ads based on visits to your and other sites, and how users can opt out of personalised advertising (Ads Settings, or aboutads.info). Google Analytics customers must disclose their use of Analytics and how it collects and processes data — linking to Google’s “How Google uses information from sites or apps that use our services” page is one way — and must not send Google personally identifiable information (GA Terms §7). Both disclosures are built in. For visitors in the EEA, UK and Switzerland, personalised AdSense ads also need a Google-certified consent tool.
Sources
- IT Act 2000 — s.43A; SPDI Rules 2011 — rr.3–6, 8; Intermediary Rules 2021 — r.3
- DPDP Act 2023 — ss.5–14, 44 and commencement (G.S.R. 843(E)); DPDP Rules 2025 — rr.3, 8, 9, 10, 14
- GDPR arts. 6, 8, 13, 14, 27, 37; ICO: what privacy information should we provide
- Cal. Civil Code §1798.130, §1798.135, §1798.140; Bus. & Prof. Code §22575
- COPPA Rule, 16 CFR 312.4
- AdSense: required content; Google Publisher Policies; Google Analytics Terms
Limitations
- A generic template, not legal advice. It cannot know what your site really does — check every statement, and have a lawyer review it if you handle sensitive data, children’s data or large volumes of data.
- It does not set up cookie banners, consent records, “Do Not Sell” links or Global Privacy Control — those are things your site must actually do.
- Laws outside India, the EU, the UK and the United States (California, COPPA) are not covered. The policy is in English.
- Review it at least once a year and whenever you add a new service — California requires an update at least every 12 months.
Privacy
Everything happens in your browser. Your site details are not uploaded or stored by MySmartCoPilot. If you tick Keep a draft in this browser, the form is saved in this browser’s local storage until you untick it.
Frequently asked questions
Is a privacy policy mandatory for a website in India?
Yes for a business (a “body corporate”, which includes firms and sole proprietorships in commercial or professional activity) that collects or handles personal information: rule 4 of the SPDI Rules 2011 requires a privacy policy published on its website, and rule 5(9) a Grievance Officer whose name and contact details are published. From May 2027 the DPDP Act requires a notice before collecting personal data on the basis of consent.
What must a privacy policy say for Google AdSense?
That third-party vendors, including Google, use cookies to serve ads based on prior visits to your site or other sites; that Google’s advertising cookies let it and its partners serve ads based on those visits; and how users can opt out of personalised advertising (Google’s Ads Settings or aboutads.info). The generator includes all three.
Do I need a separate DPDP Act notice?
From May 2027, when you rely on consent you must give a notice that can be understood on its own, listing the personal data and purposes, and how to withdraw consent, use your rights and complain to the Data Protection Board (DPDP Rules 2025, r.3). Tick the DPDP module to include it, and show it (or a short version) where you ask for consent.
Does the CCPA apply to my small website?
Usually not. It applies to for-profit businesses doing business in California with more than US$25 million annual revenue (inflation-adjusted), or that buy, sell or share data of 100,000+ consumers or households, or earn half their revenue from selling or sharing it. CalOPPA, which needs a much shorter set of disclosures, applies to any commercial site collecting personal data from Californians.
Can I copy someone else’s privacy policy?
No — besides copyright, it would describe their practices, not yours. A policy must match what your site actually collects and who it shares data with. Tick only what you do, and update it when that changes.
Where should I publish my privacy policy?
On its own page of your site, linked from every page (usually the footer), from sign-up and checkout forms, and — for apps — from the app store listing and inside the app. Copy the HTML from “Publish on your website”.