A privacy policy is one of those documents that many stores have but rarely have written correctly. Copied from another site, generated without customisation, outdated after successive legal changes. Yet a privacy policy is the foundation of GDPR compliance. And its absence or incorrect formulation is the issue most frequently cited in data protection authority proceedings. A properly written privacy policy is not just a formal obligation – it is proof that your business takes customer data seriously. Data protection authorities in their reports consistently point out that the most common problem is not the absence of a privacy policy but its incorrect content.
Contents
Who needs a privacy policy?
Every entity that processes personal data. In practice, that means every WooCommerce store. Names, addresses, email addresses, phone numbers, IP addresses – all of these are personal data under GDPR. Even if you only use Google Analytics – you are processing your visitors' personal data.
What must a WooCommerce store privacy policy include?
- Identity of the data controller – full name, address, contact details. If you have appointed a Data Protection Officer, their details must also be included.
- Purposes and legal bases for processing – for each purpose separately: contract, consent, legitimate interest or legal obligation.
- Data retention periods – how long you keep customer, employee and subscriber data. Separately for each category.
- Data recipients – a list of entities you share data with: courier company, payment system, email platform, analytics tool. Vague references to partners are not sufficient.
- User rights – right of access, rectification, erasure, restriction of processing, data portability, objection and the right to lodge a complaint with the supervisory authority.
- Cookie information – if the privacy policy and cookie policy are a single document.
- Information about profiling and automated decision-making – if applicable.
WooCommerce and GDPR – where is customer data?
WooCommerce automatically collects and stores customer data: name, delivery address, email address and order history. Add to that integrations with payment systems (Stripe, PayPal) and courier companies (DHL, FedEx, UPS). Each of these is a data recipient that must be listed in your privacy policy.
If you use Google Analytics, Facebook Pixel or other remarketing tools – this must also be covered. Each tool means a separate point in the privacy policy.
Most common mistakes in WooCommerce privacy policies
- No information about the legal basis for processing.
- Vague references to partners instead of naming specific data recipients.
- No data retention periods.
- Missing or incomplete user rights.
- Document not updated after changes to technical infrastructure.
When must a privacy policy be updated?
Every time the circumstances of data processing change. You add a new analytics tool – update. You implement a new email system – update. Regulations change – update. A privacy policy is a living document, not a one-time form.
Something is coming – stay tuned
We are building a tool that takes care of your store's legal documentation automatically – tailored to your business, always up to date with the law. Stay tuned.

