It must describe what your business actually collects, why, where it goes and how somebody can ask about it. A copied policy is wrong by definition, because it describes another business.

Why a copied one fails

A privacy policy is a statement about what your business does with information.

Which means it cannot be borrowed, because another business does different things with different information using different tools.

A copied policy is not merely generic. It is inaccurate, and its inaccuracy is the thing it was supposed to prevent.

The common evidence: a policy naming a company that is not yours, tools you have never used, or a jurisdiction you do not operate in.

This is a general description rather than legal advice, and a policy that matters is worth having checked by somebody qualified.

What a small trade site actually collects

Usually less than people assume, and listing it is the whole first step.

Enquiry form submissions: a name, an email address, a phone number, and whatever somebody typed.

Analytics data about visits, which is generally not identifying but is collected.

Cookies set by the site or by anything embedded in it.

Emails and phone messages, which are records held about people.

And anything a booking or payment tool handles, if one exists.

What the policy has to say

The third is the one most often missing. An enquiry form frequently sends data through a form service, an email provider and possibly a CRM, none of which the policy mentions.

A worked example

A business whose privacy policy had been copied from another site during a rebuild.

It named a different company throughout, referred to a mailing list they did not operate, and described a jurisdiction that was not theirs.

It also failed to mention the form service their enquiries actually went through, which was the only third party involved.

Rewriting it took about an hour: listing what the site collected, checking where each item went, and writing it in plain sentences.

The result was shorter than what it replaced and described the business.

The hour was mostly spent establishing where the form data actually went, which nobody had previously known.

Finding out where the data goes

The part that takes the time and is worth doing regardless of the policy.

Submit your own enquiry form and follow it: which service processes it, where the email lands, whether a copy goes anywhere else.

Check what is embedded in your pages: analytics, fonts, maps, video, chat tools, social widgets, each of which may set cookies or send data.

List them. That list is most of the policy and it is also a useful thing to know for its own sake.

Businesses are frequently surprised by how many third parties a modest website involves.

The Canadian position, briefly

Worth knowing in outline and confirming properly for your situation.

Federal privacy legislation applies to personal information collected in the course of commercial activity, with some provinces having their own comparable legislation that applies instead for businesses operating within them.

The general obligations are consistent in shape: be clear about what you collect and why, collect only what you need, keep it secure, and let people ask what you hold.

Which is what the policy above describes, and it is also just reasonable practice.

The specifics of which legislation applies to your business depend on where you operate and what you do, and are worth checking rather than assuming.

Retention, honestly

The question most policies answer vaguely and most businesses have never considered.

Enquiries sit in an inbox indefinitely, which means personal information is being kept for years by default rather than by decision.

A policy saying data is kept only as long as necessary is true of almost nobody, since nothing is ever deleted.

The honest options are stating a period and actually applying it, or describing what you genuinely do.

For a small business, deciding to clear enquiries older than a stated period is a real improvement and makes the policy accurate at the same time.

Cookies and the banner question

A related decision worth taking deliberately.

A site running analytics is setting cookies, which the policy should say.

Whether a consent banner is required depends on your jurisdiction and your visitors, and the requirements differ considerably between Canada and elsewhere.

A banner that appears and does nothing, blocking the page while setting the cookies regardless, satisfies nobody and irritates everybody.

If you add one, it should genuinely control what loads, which is more work than adding a notice and is the point of having it.

Keeping it current

The part that decides whether the policy stays accurate, since sites change.

Adding a chat widget, a booking tool, a map or a new analytics property changes what the site collects.

Which makes the policy inaccurate from that day, without anybody deciding anything.

The practical habit is checking the policy whenever anything is added to the site, which is rarely and takes minutes.

Dating it makes that visible, both to you and to anybody reading it.

A policy dated three years ago on a site that has changed twice since is telling the reader something accurate about how closely it has been maintained.

The counter-case

Where a very short policy is sufficient.

A site with no forms, no analytics and nothing embedded, which collects essentially nothing, where a few sentences saying so is honest and adequate.

That describes fewer sites than people think, since most have analytics and a form.

What is never sufficient is no policy at all on a site collecting enquiries, since that is personal information being collected with no statement about it.

And what is never adequate is a policy describing somebody else's business, however long it is.

Writing yours

  1. Submit your own form and follow the data.
  2. List everything embedded in your pages.
  3. Write what each item is and why.
  4. Give a real contact for questions.
  5. Date it and link it from the footer.
  6. Have it checked if anything is unusual.

The first two are the actual work and the rest is writing down what you found, which is why an hour is a realistic estimate for most small business sites.

The analytics side of this is covered in installing analytics without breaking privacy rules.


Frequently asked questions

Why can a policy not be copied?

Because it is a statement about what your business does with information, and another business does different things with different tools. A copied one is inaccurate.

What does a small trade site collect?

Enquiry form submissions, analytics data about visits, cookies set by the site or anything embedded, emails and phone messages, and anything a booking tool handles.

What must the policy say?

What is collected, why, where it goes including third parties, how long it is kept, how somebody can ask what you hold, and a real contact.

What is most often missing?

Where the data goes. An enquiry form frequently passes through a form service, an email provider and possibly a CRM, none of which get mentioned.

How do I find out?

Submit your own form and follow it, then list everything embedded in your pages: analytics, fonts, maps, video, chat and social widgets.

Do I need a cookie banner?

It depends on your jurisdiction and visitors. A banner that blocks the page while setting the cookies anyway satisfies nobody; if you add one it should genuinely control what loads.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Privacy policy naming a company that is not yours?

Submit your own form and follow where the data goes. That hour is most of the rewrite.

Start a Conversation