Effective date: [DATE]
Business/entity: [LEGAL NAME]
Contact: [PRIVACY EMAIL]
Address: [ADDRESS]
1. Scope
This policy should describe how the actual business handles personal information when someone visits the site, requests the free checklist, purchases a product, contacts support, or otherwise interacts with the business.
2. Information to document
- Contact information such as name and email.
- Transaction information received from the checkout provider.
- Communications and support records.
- Website usage, device, and event data from consented tools.
- Consent choices and technical security or delivery logs.
3. Purposes and legal bases
List every actual purpose, its data, retention, recipients, and applicable legal basis. Do not assume one legal basis works everywhere. Obtain professional advice.
4. Providers and transfers
Name the actual hosting, checkout, payment, email, analytics, consent, support, and delivery providers. Document international transfer mechanisms where required.
5. Retention
Set real retention periods or criteria for transaction records, support, marketing, consent logs, and technical logs.
6. Choices and rights
Explain unsubscribe controls and how eligible people can request access, correction, deletion, restriction, objection, portability, or withdrawal. Rights vary by location.
7. Security
Describe reasonable safeguards without guaranteeing absolute security or claiming controls that are not maintained.
8. Changes and contact
Explain how material changes are communicated and provide the verified privacy contact.
Before publishing
Replace every bracketed field, inventory real vendors, align the banner and tags, verify the request workflow, set retention, and obtain legal review.