Privacy Policy – Product name
GDPR/CCPA-shaped privacy policy skeleton
Cara menggunakan: App/site privacy policy skeleton. Fill every table cell honestly; "we do not sell personal data" is a CCPA-required statement when true. Lawyer review before publishing.
Pratinjau
Privacy Policy – Product name
Template only – not legal advice. Have a qualified lawyer review before publishing, especially for regulated markets (EU/CA/BR). Structure follows GDPR/CCPA disclosure conventions.
Effective date: YYYY-MM-DD · Last updated: YYYY-MM-DD
1. Who we are
Controller identity: legal name, contact, jurisdiction.
2. What we collect
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Account data | you provide | service delivery | contract |
| Usage data | automatic | improvement | legitimate interest / consent |
| Cookies | automatic | list purposes | consent where required |
State plainly what you do not collect – it is the most-read part.
3. How we use data
- Purpose one – linked to legal basis
- Purpose two
4. Storage & retention
- Where data lives (region, providers)
- How long kept, deletion schedule
5. Sharing
| Recipient | What | Why | Safeguard |
|---|---|---|---|
| Processor | data type | hosting | DPA |
| None other | – | – | – |
"We do not sell personal data." – required statement for CCPA.
6. Your rights
Depending on jurisdiction: access, rectification, erasure, portability, objection, withdrawal of consent, complaint to authority. How to exercise: [contact].
7. Cookies & tracking
- What is used, what each is for
- How to opt out
- Global Privacy Control (GPC) honored: yes/no
8. Security
Measures in general terms (never detail exploitable specifics).
9. Children
Age floor and policy.
10. International transfers
Mechanism if data crosses borders (SCCs, adequacy).
11. Changes
How users are notified of updates.
12. Contact
Privacy contact, DPO if applicable, supervisory authority note (EU).