WooCommerce Privacy Policy Guide: GDPR & CCPA Compliance in 2026

By shopifypolicy Editorial Team · Last updated 2026-08-03 · 8 min read

Every WooCommerce store collects customer data. Names, addresses, emails, payment info. The GDPR (EU/UK) and CCPA (California) both say you have to tell people what you collect, what you do with it, who you share it with, and what rights they have. This guide covers what a WooCommerce privacy policy needs in 2026, which WooCommerce-specific data points to disclose, and how to publish it. You can also generate a compliant WooCommerce privacy policy for free.

Why WooCommerce stores need a privacy policy

WooCommerce runs on WordPress and powers over 5 million online stores. Every time a customer places an order, your store collects their name, shipping address, billing address, email, phone number, and payment info. On top of checkout, WooCommerce collects analytics data, IP addresses, and if you use them, customer accounts, marketing email lists, and product reviews.

Under the GDPR, any business processing the personal data of people in the EU or UK needs a publicly accessible privacy policy. It does not matter where the business is. A store in Buenos Aires selling to someone in Paris is covered. Under the CCPA (as amended by the CPRA), any for-profit business processing California residents’ data and meeting one of the thresholds, $25 million in annual revenue, data on 100,000+ consumers, or 50%+ revenue from selling data, is covered.

GDPR fines go up to €20 million or 4% of global annual turnover. CCPA penalties run up to $7,500 per intentional violation. Payment processors like Stripe and PayPal also require a visible privacy policy before they approve your merchant account.

What a WooCommerce privacy policy must include

A compliant privacy policy for a WooCommerce store needs these sections:

1. The data you collect

List every category of personal data your store collects:

  • Order data: name, shipping and billing address, email, phone number, payment info, order history, and any custom checkout fields.
  • Account data: if you offer customer accounts, their profile info, saved addresses, and order history.
  • Technical data: IP address, browser type, device info, approximate location, pages viewed, referral source.
  • Payment data: the payment instrument used and transaction identifiers, processed by WooCommerce Payments, Stripe, PayPal, or whichever gateways you use.
  • Marketing data: email engagement (opens, clicks) if you use Mailchimp, Klaviyo, or similar.
  • Review data: if customers submit product reviews, their name, email, and review content.

2. How you use the data

Explain the purpose for each data category. The GDPR requires a “lawful basis” for each processing activity:

  • Contract performance: fulfilling orders, processing payments, shipping.
  • Legal obligation: tax records, financial reporting.
  • Legitimate interests: fraud prevention, analytics, security.
  • Consent: marketing emails, product reviews, optional cookies.

3. Third-party processors

Name the third parties that process customer data on your behalf. For a typical WooCommerce store:

  • WooCommerce (Automattic): the platform itself, hosting and analytics.
  • Payment gateways: WooCommerce Payments, Stripe, PayPal, Square.
  • Shipping providers: ShipStation, Shippo, FedEx, UPS.
  • Email marketing: Mailchimp, Klaviyo, MailPoet.
  • Analytics: Google Analytics 4, Meta Pixel, TikTok Pixel.
  • Review plugins: Judge.me, Yotpo, WP Product Review.
  • Customer service: Gorgias, Zendesk, Crisp.

Each of these operates under its own terms and may transfer data outside the customer’s region. The GDPR says you have to disclose this.

4. WooCommerce-specific data points

WooCommerce has features that a generic privacy policy will miss. Your policy needs to cover:

  • WooCommerce Sessions: WooCommerce sets a session cookie (wp_woocommerce_session_) to store cart contents and user session data. This is personal data.
  • Order retention: WooCommerce stores order data indefinitely by default unless you configure automatic deletion. State how long you keep order data, usually 5 to 7 years for tax compliance.
  • Guest checkout: if you allow guest checkout, customer data is still collected and stored. Your policy should say how guest data is handled.
  • Customer accounts: if enabled, customers can create accounts with saved addresses and order history. Your policy must explain how they can close an account.
  • Product reviews: if reviews are enabled, customer names and emails are collected and shown publicly.
  • WooCommerce Payments: if you use WooCommerce Payments, Stripe processes payment data directly. Your store never sees the full card number. But you still have to name Stripe as a processor.

5. Cookies and tracking

WooCommerce sets several cookies by default:

CookiePurposeDuration
wp_woocommerce_session_Cart contents, user sessionSession
woocommerce_cart_hashCart hash for cachingSession
woocommerce_items_in_cartCart item countSession
woocommerce_snooze_suggestionsHides admin suggestions3 days

If you run Facebook or Google ads, the Meta Pixel and Google Ads tags set additional tracking cookies. Under the GDPR and the ePrivacy Directive, those require explicit consent.

6. Data retention

State how long you keep each category of data:

  • Order data: 5 to 7 years (tax law requirement in most jurisdictions).
  • Marketing data: until the customer unsubscribes.
  • Customer accounts: until the customer requests deletion.
  • Analytics data: 14 to 26 months (configurable in Google Analytics).

7. Customer rights

The GDPR gives EU/UK customers the right to access, rectify, erase, restrict, port, and object to processing. The CCPA gives California consumers the right to know, delete, opt out of sale/sharing, and not be discriminated against for exercising those rights. Your policy has to list these rights and explain how a customer can use them, usually by emailing a contact address.

8. Data security

Describe the technical measures you take: SSL/TLS encryption, PCI-DSS compliance (via your payment processor), access controls, secure password policies, WordPress security practices.

9. International transfers

If you serve customers outside your own country, their data may be processed in countries with different data protection standards. The GDPR requires you to disclose this and name the safeguard: Standard Contractual Clauses, adequacy decisions, or binding corporate rules.

How to add a privacy policy to WooCommerce

WooCommerce includes built-in pages for policies. Here is how to publish yours:

  1. Generate your policy. Use the free WooCommerce policy generator to create a privacy policy tailored to WooCommerce.
  2. Copy the generated HTML. Click Copy on the Privacy Policy tab.
  3. In WordPress admin, go to Pages, then Privacy Policy. WordPress includes a default Privacy Policy page. Replace the placeholder content with your generated policy.
  4. Link the policy in your footer and checkout. Go to Appearance, Customize, Footer and add a link to your Privacy Policy page. WooCommerce can also display policy links at checkout if configured.
  5. Configure the WooCommerce privacy page. Go to WooCommerce, Settings, Advanced, Page setup and select your Privacy Policy page. This makes WooCommerce link to it from checkout and order emails.
  6. Set up a cookie consent banner. If you serve EU/UK customers, you need one. WordPress plugins like CookieYes or Complianz handle this.

GDPR vs CCPA: what changes for WooCommerce?

AspectGDPR (EU/UK)CCPA/CPRA (California)
Who is coveredAny business processing EU/UK dataFor-profit businesses meeting thresholds
Consent modelOpt-in: explicit consent before non-essential cookiesOpt-out: consumers can refuse sale/sharing
Cookie bannerRequired for all non-essential cookiesRequired only if you sell/share data
Right to deleteCustomer can request erasureCustomer can request deletion
Max fine€20M or 4% of global turnover$7,500 per intentional violation

Most WooCommerce stores need to satisfy both. One privacy policy that covers both GDPR and CCPA is the simplest way to do it.

Common WooCommerce privacy policy mistakes

  1. Using WordPress’s default policy without editing it. WordPress ships a placeholder. It is a starting point, not a finished document.
  2. Not naming WooCommerce-specific cookies. WooCommerce sets session and cart cookies. They have to be in your cookie section.
  3. Forgetting to list plugins as processors. Every WooCommerce plugin that processes customer data, payment gateways, shipping calculators, email tools, should be named in your third-party processors section.
  4. Not disclosing guest checkout data retention. Guest customers’ data is still stored. Your policy has to say so.
  5. No cookie consent banner. If you serve EU/UK customers and run analytics or ads without a consent banner, you are violating the ePrivacy Directive.

Frequently asked questions

Does WooCommerce include a privacy policy by default?
WordPress includes a Privacy Policy page template, but it is generic and not tailored to WooCommerce. You need to customize it with WooCommerce-specific data points, or generate one.

Do I need a privacy policy if I only sell domestically?
Yes. If anyone from the EU, UK, or California can access your store, you are covered by GDPR and CCPA. On the internet, “domestic only” rarely holds up.

Where should the privacy policy link appear?
In your footer (visible on every page) and at checkout. WooCommerce can automatically link policies from the checkout page if you configure it under WooCommerce, Settings, Advanced, Page setup.

Is a cookie consent banner required for WooCommerce?
If you serve EU/UK customers and use any non-essential cookies (analytics, ads, marketing), yes. Use a plugin like CookieYes or Complianz.

Can I use the same privacy policy for WooCommerce and Shopify?
No. Each platform collects data differently and sets different cookies. Use a platform-specific generator: WooCommerce or Shopify.


Need a compliant privacy policy for your WooCommerce store? Generate one for free, no login required. Or read our Shopify privacy policy guide for comparison.