// Blog / Guide

How to write a privacy policy for your small business website

Share

Almost every small business website has a "Privacy Policy" link in the footer, and a surprising number of them point to something copied from another company, half-true, and never read. A privacy policy is not decoration and it is not a formality. It is a public promise about how you handle people's personal information, and in Canada it is effectively required. This guide explains, in plain language, what one is, what actually belongs in it, and the parts small businesses most often get wrong. It is general guidance, not legal advice.

What a privacy policy actually is

A privacy policy is a plain statement to your customers and website visitors that says: here is what personal information we collect, why we collect it, what we do with it, who we share it with, and what choices you have. "Personal information" is broader than most people think. It includes names, email addresses, phone numbers, billing details, and also things like IP addresses and the data your analytics tools quietly gather. If your website has a contact form, takes bookings, sells anything, or runs analytics, you are collecting personal information and you owe visitors an honest account of it.

Do you actually need one?

For a Canadian small business, the practical answer is yes. Federal privacy law (PIPEDA) and provincial laws such as Quebec's Law 25 expect any organization handling personal information to be transparent about it, and being transparent means publishing a policy people can read. On top of the law, the platforms you rely on require one anyway: Google, Meta, Apple's App Store, payment processors, and email marketing tools all ask for a privacy policy URL as a condition of using them. So even setting the law aside, you likely cannot run the business without one.

What actually goes in it

A good small business privacy policy is thorough but readable. The sections that matter:

  • Who you are. Your business name and a real way to reach you about privacy (an email address is fine).
  • What you collect. Be specific: contact-form details, booking or order information, payment details (usually handled by your processor, not stored by you), and automatically-collected data like IP address and analytics.
  • Why you collect it. Tie each type to a purpose: to answer enquiries, fulfil orders, send a newsletter someone asked for, improve the site. If you would not say the reason out loud to a customer, do not do it.
  • Who you share it with. Name the categories of third parties: your email host, payment processor, analytics provider, booking tool, CRM. You do not need every vendor's name, but be honest that data goes to service providers.
  • How long you keep it and how it is protected. A short, truthful statement that you keep information only as long as needed and take reasonable steps to protect it.
  • What choices people have. How someone can access, correct, or ask you to delete their information, and how to unsubscribe from marketing.
  • Cookies and tracking. Covered below, because it is the part most policies skip.
  • Changes and contact. That you may update the policy, and where to send a question or complaint.

The cookies and analytics part everyone misses

The single most common gap is the tracking a site does without anyone thinking about it. If you run Google Analytics, a Meta or LinkedIn pixel, a chat widget, embedded videos, or ad retargeting, those tools set cookies and send visitor data to third parties. Your policy needs to say so, in plain terms, and if you serve visitors in regions that require it you may also need a cookie banner that lets people decline non-essential tracking. The honest test is simple: list every third-party script your site loads, and make sure the policy accounts for what each one collects. Most small business owners are surprised by how long that list is.

Common mistakes to avoid

  • Copy-pasting someone else's. A borrowed policy describes a different business's data practices, which means yours is inaccurate the moment you publish it. An inaccurate policy is worse than a short honest one, because it is a promise you are already breaking.
  • Promising things you do not do. "We never share your data with anyone" is almost always false the instant you use an email host or payment processor. Say what is actually true.
  • Writing it once and never touching it. When you add a new tool, a chat widget, or a marketing pixel, the policy is out of date. Revisit it whenever your stack changes.
  • Burying or hiding it. The policy should be linked in your footer and easy to find, not something a visitor has to hunt for.

When to get a lawyer involved

Plenty of small businesses can write an honest, workable first policy themselves using the structure above, and doing so is far better than a copied one. But get a privacy lawyer involved when the stakes rise: if you handle sensitive information (health, financial, information about children), operate in Quebec under Law 25, sell to customers in other countries with their own rules, or process personal data at any real scale. The cost of proper advice is small next to the cost of a complaint or a breach involving data you mishandled. A privacy policy is one visible piece of a larger practice, which is what a full privacy management program is really about.

Want a privacy policy that matches what your business actually does?

Talk to us

Related