Skip to main content
Small Business

The Legal Pages Your Website Needs

The Legal Pages Your Website Needs

Most small business websites have a privacy policy that was copied from another small business website, which had copied it from a third. It mentions a mailing address in a country the business does not operate in, promises a data-retention period nobody measures, and describes an analytics product that was removed two years ago.

It is worse than nothing, because it is a set of written commitments the business cannot meet.

Three pages, and what each is for

  • Privacy policy. What personal information you collect, why, who else sees it, and what rights the visitor has. This is the one with statutory force behind it in the UK, the EU and a growing list of other places.
  • Terms of service. The rules of using your site and buying from you: orders, bookings, payments, refunds, cancellations, liability. This is the one that protects you rather than the visitor.
  • Cookie information. What is set, by whom, and how to change your mind, sitting behind whatever consent banner you show.

Small sites sometimes fold the third into the first, which is fine, as long as what it says matches what the banner actually does.

The policy has to describe your site, not a website

This is the whole problem with a copied policy, and the test is simple: read your privacy policy and count the things in it you cannot point to.

What you collect depends on which parts of your site are switched on, and that changes as you grow.

  • A contact form collects a name, an email, a message.
  • A newsletter signup collects an email and a consent record.
  • A shop adds order and delivery details, and a payment processor that handles the card, which you never see.
  • Appointments add the service, date, time and the contact details for the booking.
  • Hire or rental adds the item, the dates and the driver or hirer details.
  • Blog comments add whatever the commenter typed and the name they gave.

A privacy policy assembled from what the site actually does, next to a copied one describing features the business does not have

Every one of those is a different sentence in the policy, and a policy that lists all of them when your site only has a contact form is inaccurate in the direction that makes you look careless.

Starter privacy and terms pages can be generated from your business details and the features you have actually enabled, which is a better starting point than a template from a search result because it begins from what your site does. It is still a starting point. The business name, contact address and governing jurisdiction have to be yours, and anything specific to how you trade has to be written by you or checked by someone qualified.

Terms: the five clauses that get used

Most terms of service go unread until something goes wrong, and then only five parts matter:

  • What you are actually selling, and when the contract is formed. For a shop, is it when the order is placed or when it is dispatched.
  • Payment, including deposits, and what happens if a payment fails.
  • Cancellations and refunds. The clause quoted back at you most often. It should match what you actually do, and it should match what your booking page says, because a mismatch is decided against whoever wrote the terms.
  • Delivery or fulfilment timescales, phrased as estimates unless you can guarantee them.
  • Liability, in language a court in your jurisdiction recognises.

A clinic has a different version of this to a car hire firm and both are different again from a shop. If you have a cancellation policy on your booking page, and you should, the terms need to agree with it word for word. The reasoning behind writing one is in the clinic cancellation and no-show policy piece, and it generalises.

Cookies, and the banner that lies

A consent banner is only meaningful if the scripts it governs actually wait for consent. The common failure is a banner that appears while analytics and advertising tags have already loaded, which is a worse position than having no banner at all: you have documented that consent was required and then not honoured it.

So the order is: work out what actually loads, decide what genuinely needs consent, make the banner control it, then describe it. Getting that sequence right is the whole subject of cookie consent basics.

Letting people ask what you hold

Under the GDPR and the UK equivalent, a person can ask what personal data you hold about them, ask for a copy, and ask you to delete it. For most small businesses these requests are rare and the obligation is real.

The practical answer is a single route in: a page or a form where the request arrives somewhere you will see it, linked from the privacy policy, so a request cannot be missed in a personal inbox. How that works here is described in customer data requests.

Where they go and how they stay true

Put all three in the footer, on every page, with plain names. "Privacy Policy", not "Legal". They are also the pages a payment processor looks for when approving an account, which is a practical reason to have them up before you start selling rather than after.

Then set a reminder to reread them once a year and every time you switch on something new. Adding a shop to a site whose privacy policy has never mentioned orders is the single most common way these pages become wrong. Adding pages themselves is covered in pages and menus, and the business details that feed the policy live in business details.

This is a practical guide to what these pages have to cover, not legal advice. If you handle health data, children's data or anything high risk, get the policy reviewed by someone qualified in your jurisdiction.

FAQ

Do I need a privacy policy if I only have a contact form?

Yes. A contact form collects personal data, and the obligation attaches to collecting it, not to how much you collect. The policy will be short, which is fine.

Can I copy a privacy policy from another site?

It is the most common approach and the worst one, because the policy then describes a different business. Start from something generated from your own details and features, then edit it to match what you really do.

What is the difference between terms and a privacy policy?

The privacy policy is about personal data and mostly protects the visitor. The terms are about the deal and mostly protect you. They are separate documents with different legal bases and should not be merged.

If you set anything beyond what is strictly necessary to run the site, in the UK and EU you generally do, and it has to actually gate those scripts. If you set nothing but a session cookie, a line in the privacy policy may be enough.

How often should I update them?

Once a year as a habit, and immediately whenever you enable a new capability, take a new kind of payment, or start using a new third-party service.

Share:
Website building tips & guides

The Webkio team builds website, booking and online shop software for small businesses. The guides here come from what we watch owners actually struggle with: taking bookings without adding staff, being found by people nearby, getting paid without friction, and keeping a site working long after launch day.

Ready to build your own? Browse free website templates, or see plans & pricing.