# Privacy Policy – Product name

> **Template only – not legal advice.** Have a qualified lawyer review
> before publishing, especially for regulated markets (EU/CA/BR).
> Structure follows GDPR/CCPA disclosure conventions.

**Effective date**: YYYY-MM-DD · **Last updated**: YYYY-MM-DD

## 1. Who we are

Controller identity: legal name, contact, jurisdiction.

## 2. What we collect

| Data | Source | Purpose | Legal basis |
|------|--------|---------|-------------|
| Account data | you provide | service delivery | contract |
| Usage data | automatic | improvement | legitimate interest / consent |
| Cookies | automatic | list purposes | consent where required |

State plainly what you do **not** collect – it is the most-read part.

## 3. How we use data

- Purpose one – linked to legal basis
- Purpose two

## 4. Storage & retention

- Where data lives (region, providers)
- How long kept, deletion schedule

## 5. Sharing

| Recipient | What | Why | Safeguard |
|-----------|------|-----|-----------|
| Processor | data type | hosting | DPA |
| None other | – | – | – |

"We do not sell personal data." – required statement for CCPA.

## 6. Your rights

Depending on jurisdiction: access, rectification, erasure, portability,
objection, withdrawal of consent, complaint to authority. How to
exercise: [contact].

## 7. Cookies & tracking

- What is used, what each is for
- How to opt out
- Global Privacy Control (GPC) honored: yes/no

## 8. Security

Measures in general terms (never detail exploitable specifics).

## 9. Children

Age floor and policy.

## 10. International transfers

Mechanism if data crosses borders (SCCs, adequacy).

## 11. Changes

How users are notified of updates.

## 12. Contact

Privacy contact, DPO if applicable, supervisory authority note (EU).
