Privacy Policy Generator for WooCommerce Stores

Enter your URL. We'll find the services collecting visitor data and generate the documents that disclose them.

Free scan and score. Privacy Policy, Terms and Cookie Policy for $19 one-time.

WooCommerce turns a WordPress site into a store, and the store adds a second layer of tracking on top of the WordPress plugins already present. WooCommerce sets cart, session and recently-viewed cookies for every shopper, and account registration stores names, addresses and order history. Payment gateways for Stripe and PayPal load their scripts on checkout and sometimes on every page, transmitting device fingerprints for fraud screening. WooCommerce's own usage tracking, when enabled, sends store data to Automattic.

Marketing extensions pile on. The official Google Listings and Ads extension installs Google Analytics and Google Ads conversion tags. Facebook for WooCommerce adds Meta Pixel and product catalog sync. Mailchimp for WooCommerce and Klaviyo capture email addresses at checkout and track browsing for abandoned-cart campaigns. reCAPTCHA protects login and checkout forms, and Jetpack or Cloudflare set cookies before the page renders.

A store policy needs to explain each of these, and the WooCommerce setup wizard does not write one for you. VerifiedPrivacy scans your storefront, lists the payment, analytics and marketing services actually loading, and generates a Privacy Policy, Terms of Service and Cookie Policy from a clause library, including refund terms and payment disclosures that match your answers. Enter your store URL below to see what your checkout stack is collecting.

Frequently asked questions

Does WooCommerce generate a privacy policy or terms?

WooCommerce adds suggested paragraphs to the WordPress privacy policy draft describing what WooCommerce core stores, but it does not cover your payment gateway, pixels or email extensions, and it produces no Terms of Service at all. VerifiedPrivacy scans the storefront, detects those services and generates all three documents from a clause library. Attorney review is recommended before you publish.

Do I need to mention Stripe or PayPal in my privacy policy?

Yes. Even though you never see card numbers, Stripe and PayPal receive your customers' payment and device data through your site, and their scripts may set cookies for fraud prevention. Most privacy frameworks treat them as recipients or processors that must be named. When the scan detects either gateway, the generated Privacy Policy includes its disclosure and links to the provider's own policy.

Should my Terms include a refund policy?

Card networks and payment processors generally expect published refund and cancellation terms, and buyers look for them before purchasing. The questionnaire asks whether you sell products and lets you choose no refunds, 14 days, 30 days or your own wording. The Terms of Service then includes a matching section alongside pricing, order acceptance and delivery terms.

Will the scan see extensions that only load at checkout?

The scan reads the homepage and checks the common policy URLs. Gateways and extensions that only inject scripts on the cart or checkout page may not appear. Compare the detected list with your active extensions, and when you complete the questionnaire, answer yes to selling and payments so the generated documents include payment and order disclosures even if a specific gateway was not detected.

Can I regenerate after switching payment gateways?

Yes. Your download link is permanent. Rescan the store from your public verification page after the change, then open the questionnaire from your download page and regenerate. The documents are rebuilt from your current answers and the latest detected services at no additional charge. Rescans are limited to one per domain per hour.

Other guides

Also: Terms of Service generator for woocommerce

VerifiedPrivacy generates documents from a clause library. It is not a law firm and does not provide legal advice. Have a licensed attorney review documents before use.