Privacy Policy Guide: What to Include
The fastest way to understand what a privacy policy needs is to look at a real one — so we'll use the most-searched policy on the internet. When people look up the TikTok privacy policy, they're really asking the same thing every site owner asks: what does a policy actually disclose, and what does mine need to say? This guide answers both — the anatomy of a real policy, whether you're legally required to have one, exactly what to include, and the mistakes that turn a policy from protection into evidence.
Key takeaways
- Almost every website needs a privacy policy. There's no single US federal law requiring one, but CalOPPA, the CCPA, 20 state laws, and the terms of tools like Google and Meta together make it near-universal.
- A privacy policy discloses how you handle data — what you collect, why, who you share it with, and what rights people have. It's a disclosure, not a shield.
- TikTok's policy is a useful map of what a thorough policy includes: data collected automatically, biometric identifiers, location, third-party sharing, and rights — every category spelled out.
- A privacy policy is not the same as your terms of service. One governs data (and is legally required); the other is the contract for using your site.
- The biggest risk is the gap between what your policy says and what your site actually does — especially trackers firing before consent that the policy doesn't disclose. That mismatch is what regulators and plaintiffs enforce.
What this guide covers
What a privacy policy is — and its purpose
A privacy policy is a document that discloses how a website or app collects, uses, shares, and protects people's personal information. That's the whole definition: it's a public statement of your data practices. When people search for "privacy policy definition" or "the purpose of a privacy policy," that's the answer — it exists to tell people what happens to their data, in language they can find and understand.
Its purpose runs in two directions at once. For users, it's transparency — a way to see what they're agreeing to before they hand over an email address or let a site track them. For businesses, it's both a legal obligation and a set of representations you'll be held to. That second part is the one people underestimate: a privacy policy isn't a liability waiver that protects you by existing. It's closer to the opposite — a public record of promises you can be enforced against if your actual practices don't match. (We cover that dynamic in depth in is a privacy policy legally binding — the short version: yes, in the ways that count.)
Do you need a privacy policy?
This is the most common question — "do I need a privacy policy on my website," "does my website need one," "is it mandatory" — and the honest answer is: almost certainly yes. Here's why, precisely.
There is no single US federal law that requires every website to have a privacy policy. But you don't get to stop there, because a patchwork of laws and platform rules makes one effectively mandatory for almost everyone:
- CalOPPA (since 2004) requires any commercial website or online service that collects personally identifiable information from California residents to conspicuously post a privacy policy — and to state how it responds to Do-Not-Track signals. Since virtually any site is accessible in California, this reaches almost everyone.
- The CCPA/CPRA adds detailed requirements for businesses that meet its thresholds (roughly: $25M+ in revenue, data on 50,000+ California consumers, or 50%+ of revenue from selling data).
- Twenty US states now have comprehensive privacy laws with their own disclosure requirements, and more take effect each January.
- The GDPR requires an accurate privacy notice for anyone processing EU residents' data.
- The tools you use require it contractually. Even setting law aside — Google Analytics, Google Ads, Meta's pixel, the Apple App Store, and Google Play all require, in their own terms, that you post a privacy policy. If you run any of them, you've already agreed to have one.
So the practical test isn't "am I big enough to be regulated?" It's simpler: if your site collects any personal information — a contact form, an email signup, analytics, cookies, payment details, or account logins — you need a privacy policy. That covers essentially every real website.
Anatomy of a real policy: TikTok's privacy policy
Rather than describe a policy in the abstract, let's dissect a real one. TikTok's is ideal for this — it's the most-searched privacy policy anywhere, it's unusually thorough (because it discloses a lot), and it shows every major clause type in action. Whatever you think of the app, its policy is a clear map of what a comprehensive disclosure looks like.
Information you provide. The obvious stuff — your profile, content you post, messages, purchase info. Every policy starts here.
Information collected automatically. This is the large section: device and network data, usage patterns, and — notably — location. TikTok's 2026 policy expanded this to include precise, GPS-level location for users who enable it, where earlier language emphasized approximate location.
"Image and Audio Information" — including biometrics. Since 2021, TikTok's US policy has stated it may collect biometric identifiers, described in the policy as "faceprints and voiceprints." This is the clause that generated headlines — and litigation.
Inferences and off-app data. The 2026 policy explicitly describes building inferences about your interests by correlating your TikTok activity with data from third-party trackers, pixels, and partners — i.e. behavior beyond the app itself.
Sensitive categories. The updated policy lists sensitive personal information it may handle, including citizenship or immigration status — driven in part by US state laws that require companies to list the categories of data they may process.
Sharing, rights, and choices. Who data is shared with, and the controls and rights users have — the closing sections every policy needs.
Notice the pattern: TikTok's policy is long precisely because it discloses a lot. Every category of automatic collection, every sensitive data type, every sharing relationship has to be named. That's not padding — under laws like the CCPA, listing the categories you actually collect and share is the requirement. A short policy usually means either a very simple site or an incomplete one.
Two more quick examples: Instagram and ChatGPT
TikTok isn't unique — the same anatomy shows up everywhere, with different emphasis. When people look up the Instagram privacy policy, they're actually reading Meta's policy, which covers data shared across Facebook, Instagram, and Messenger and is heavily oriented around ad targeting — a good example of how a policy must disclose data flowing between a company's own products. And the ChatGPT privacy policy (OpenAI's) illustrates a distinctly modern clause: it discloses that the prompts you type may be used to improve and train models unless you opt out — exactly the kind of "new data use" that any policy has to spell out plainly rather than bury. Different companies, same skeleton: what's collected, why, who it's shared with, and what you can control.
What to include: the 13-clause checklist
Here's the practical core of this guide — the sections nearly every privacy policy needs, synthesized from what the CCPA, CalOPPA, and GDPR actually require. Use it as a checklist against your own policy. (The exact wording and which apply depend on your business and where your users are — this is a map, not legal drafting.)
There's one idea worth picturing before the checklist becomes a to-do list, because it's what all of this is really about — the relationship between what your policy says and what your site does:
Does your policy match what your site actually does?
Clause 6 — cookies and trackers — is where most policies quietly go wrong, because tools get added and the policy doesn't catch up. Run a free scan to see every tracker firing on your site before consent, so your policy describes reality. About 10 seconds, no account.
Scan your site free →Privacy policy vs terms of service — they're not the same
A huge number of people search for these together — "terms of service and privacy policy," "terms and conditions and privacy policy" — and often assume they're one document, or interchangeable. They're not. They do genuinely different jobs, and mixing them up is a common mistake.
Privacy Policy
Discloses how you handle personal information. It's a legally required disclosure.
- What data you collect & why
- Who you share it with
- User rights over their data
- Mandated by privacy laws
Terms of Service (T&C)
The contract governing use of your site or app. Also called Terms & Conditions or a user agreement.
- Rules for using the service
- Liability & disclaimers
- Intellectual property & disputes
- Advisable, not always mandated
The clearest way to hold the distinction: your privacy policy is about the user's data, and privacy law generally requires it. Your terms of service is about the user's conduct — a contract you set — and while strongly advisable, it isn't mandated the same way. Many sites present them together at signup ("I agree to the Terms and Privacy Policy"), and that's fine — but they remain two separate documents doing two separate jobs. Bundling them into one file, or copying a competitor's, is where sites get into trouble.
Where to put your privacy policy (and the "URL" question)
A policy nobody can find doesn't do its job — and "conspicuously posted" is an actual legal requirement, not a suggestion. People also search "what is a privacy policy URL," usually because a platform (Meta, Google, an app store) is asking for one. Here's the practical placement:
- In your footer, site-wide. The near-universal convention: a "Privacy Policy" link in the footer of every page. This is the first place regulators, users, and platforms look.
- At every point you collect data. Link it near signup forms, checkout, and account creation — anywhere someone hands over personal information.
- At consent. Reference it in your cookie banner and any "I agree" checkbox, so acceptance is informed.
- The "privacy policy URL" is simply the web address where your policy lives — e.g.
yoursite.com/privacy. When Facebook Ads, an app store, or an analytics tool asks for your "privacy policy URL," that dedicated page is what they want. Give the policy its own stable URL rather than burying it in a PDF or a pop-up.
Mistakes that get sites fined
Regulators don't usually penalize the absence of a policy so much as the gap between what a policy says and what a site does. These are the specific mistakes that have drawn enforcement — worth checking your own policy against:
- Copy-paste boilerplate. A template describing a generic company makes promises about someone else's practices — and you're held to them as if they were yours. Businesses have been fined for policies that described data practices they didn't actually follow (and for practices they followed but didn't disclose).
- Overpromising deletion. "Your data is deleted on request" sounds good until backups, legal retention, and third-party copies make it untrue. Promising deletion you can't fully deliver is a deceptive practice.
- Burying the opt-out. Both the CCPA and GDPR expect rights and opt-outs to be easy to find. Making people click through multiple pages to opt out has been cited in enforcement.
- Omitting data sources. Policies often describe website collection but forget mobile-app data, offline collection, IoT, or data bought from brokers. If you collect it, disclose it.
- The tracker mismatch. The most common and most dangerous: your policy implies trackers wait for consent (or doesn't mention them), while ad and analytics pixels actually fire the moment the page loads. That gap is exactly what US wiretapping (CIPA) litigation targets — with statutory damages of $5,000 per violation under California Penal Code §637.2 — and what the FTC treats as a deceptive practice.
Quick notes by business type
The 13-clause core applies to everyone, but a few business types have specific angles people search for:
| Type of site | What to pay extra attention to |
|---|---|
| Ecommerce / online store | Payment data, shipping/address info, order history, and the many third-party tools (analytics, ads, reviews, chat) a store typically runs — each is a disclosure. |
| SaaS | Distinguish account/customer data from end-user data your customers put in; cover sub-processors and data location. B2B buyers will read this closely. |
| Blog / blogger | Even a simple blog usually runs analytics, comments, an email list, and ad networks — all of which collect data and require disclosure. "It's just a blog" doesn't exempt you. |
| Small business / local | A contact form and Google Analytics are enough to need a policy. The bar is "do you collect any personal data," and you almost certainly do. |
The honest way to build one that holds up
Pulling it together: a privacy policy that actually protects you has two properties — it's complete (covers the 13 clauses that apply to you) and it's true (describes what your site really does). Completeness you can get from a good generator or a lawyer. Truth is the harder part, because it depends on knowing what your site is actually doing — especially which trackers are firing and when.
That's the gap most policies fall into: they're written once, describe the site as it was that day, and then drift as tools get added through a tag manager or a plugin update. The fix is to build the policy from your site's real behavior, and keep an eye on that behavior over time.
Frequently asked questions
What does the TikTok privacy policy include?
TikTok's US privacy policy discloses information you provide (profile, content, messages), information collected automatically (device, usage, and location — expanded to precise GPS location in its 2026 update), an "Image and Audio Information" section covering biometric identifiers it describes as "faceprints and voiceprints," inferences built by correlating your activity with third-party trackers, sensitive categories it may handle (including citizenship or immigration status), and sections on sharing, rights, and choices. It's a thorough example of what a comprehensive policy looks like — long precisely because it discloses a lot. TikTok has also faced enforcement, including a $5.7M FTC COPPA fine (2019) and a $92M biometric-privacy class settlement, resolved without admitting wrongdoing.
Do I need a privacy policy on my website?
Almost certainly yes. There's no single US federal law requiring one for all sites, but CalOPPA requires any commercial site collecting personal information from California residents to post one — which reaches nearly every website — and the CCPA, twenty state privacy laws, and the GDPR add further requirements. On top of the law, the tools most sites use (Google Analytics, Google Ads, Meta's pixel, the Apple App Store, Google Play) contractually require you to have a privacy policy. If your site collects any personal data — a contact form, email signup, analytics, or cookies — you need one.
What is the difference between a privacy policy and terms of service?
They do different jobs. A privacy policy discloses how you handle users' personal data — what you collect, why, who you share it with, and users' rights — and is generally required by privacy law. Terms of service (also called terms and conditions or a user agreement) is the contract governing how people may use your site or app, covering rules, liability, intellectual property, and disputes; it's strongly advisable but not mandated the same way. They're separate documents, even when presented together at signup, and shouldn't be combined into one.
What is a privacy policy URL?
It's simply the web address where your privacy policy lives — for example, yoursite.com/privacy. When platforms like Facebook Ads, the Apple App Store, Google Play, or an analytics tool ask for your "privacy policy URL," they want a link to a dedicated, publicly accessible page containing your policy. Give your policy its own stable URL as a real web page rather than a PDF-only file or a one-time pop-up, so it's persistent, crawlable, and easy for users to return to.
What must a privacy policy include?
At minimum: who you are and how to contact you; what personal data you collect and how; why you collect it (and, under the GDPR, the legal basis); who you share it with; your use of cookies and trackers; how long you retain data; users' rights and how to exercise them; international transfer safeguards; children's-data handling; security measures; how you notify of changes; and a "last updated" date. If the CCPA applies, add the categories collected and sold or shared in the past 12 months, two methods to submit requests, and a "Do Not Sell or Share My Personal Information" link. The guiding rule is to describe what your site actually does — not a generic template.
Can I copy another website's privacy policy?
You shouldn't. A copied policy describes a different company's data practices, and you'll be held to the promises in it as if they were about your site — a mismatch regulators treat as a deceptive practice, and businesses have been fined for exactly this. Beyond the legal risk, it's likely to miss things your site actually does and include things it doesn't. Build your policy from your own real data practices, whether through a generator that uses your actual site data or with legal help, and keep it accurate as your site changes.
The bottom line
A privacy policy is a disclosure of how you handle people's data — and for almost every website, it's effectively required, through CalOPPA, the CCPA, state laws, and the terms of the tools you already use. The TikTok privacy policy is a useful map of what a thorough one contains: every category of data collected, every sharing relationship, every user right, spelled out.
Get the 13 clauses that apply to you in place, keep it separate from your terms of service, and post it at a real, findable URL. But the part that actually determines whether your policy protects you or exposes you isn't the drafting — it's whether it's true. The gap between what a policy says and what a site does, especially around trackers firing before consent, is what regulators and plaintiffs enforce.
So build the policy from what your site really does, and keep the two aligned as things change. A true policy is an asset; an inaccurate one is a signed record of the gap.
Build a policy that matches your real site
See exactly what your site collects and fires before consent — then generate a privacy policy from that real data, so your disclosures describe reality. Start with a free scan in about 10 seconds.
Scan your site free →Information, not legal advice. This guide explains privacy-policy requirements for general educational purposes and does not create an attorney–client relationship. Privacy laws vary by jurisdiction and change frequently, and which requirements apply depends on your business and where your users are. Company examples (including TikTok) reflect publicly reported facts and settlements resolved without admissions of wrongdoing. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; actual exposure varies by case. ConsentPixel — Privacy · Verified is not a law firm, and having a privacy policy does not by itself make a website compliant with any law — consult qualified counsel for your situation.