Does My Small Business Website Need a Privacy Policy?

If your website has a contact form, a "get a quote" box, a newsletter signup, or anything else that asks a visitor for a name or email, you are collecting personal information whether you think of it that way or not. The honest answer to "do I need a privacy policy" is almost always yes - and the good news is that writing one well doesn't require a law degree, just an accurate description of what your site actually does.

What a privacy policy actually is

A privacy policy is a page on your website that plainly states what personal information you collect, why you collect it, who else sees it, and how a visitor can ask you to delete or correct it. It is not a formality tucked in the footer to satisfy a lawyer - it is the one place a visitor can check before deciding whether to trust you with their name, email, or phone number. A short, accurate policy is also one of the cheapest trust signals a small business can put on its site, right alongside a working "Contact us" page and real photos of real work.

A lot of owners assume this only matters for big companies with data to sell. It doesn't. A one-person landscaping business with a "request a free estimate" form is collecting the exact category of information the laws below are written to protect - name, email, sometimes an address or phone number - just at a smaller scale.

Do you actually need one?

In practice, close to every US small business website does, for three overlapping reasons:

1California's CCPA/CPRA, and the ~20-state landscape behind it

California's privacy law was the first, and roughly twenty other states have since passed their own comprehensive privacy laws with broadly similar disclosure requirements. Most have a revenue or user-count threshold meant to exempt the smallest businesses - but a visitor from California, Colorado, Virginia, or any of the other covered states can land on any public website, regardless of where the business is based. That is the part most "am I too small for this" calculations miss.

2The EU's GDPR, if you get any EU visitors

If your site is purely local - a plumber who only serves one metro area - GDPR is unlikely to reach you in practice. But any US business that runs national or online-facing marketing, sells a downloadable product, or simply gets occasional international search traffic should assume some EU visitors will land on the site, and GDPR's disclosure requirements are stricter than any single US state's.

3The tools you already use often require it

Stripe, most email marketing platforms, and several ad networks require a linked privacy policy before they will fully activate your account - not because they enforce privacy law themselves, but because they don't want the liability of powering a checkout or a mailing list with no disclosure behind it. If you take payments or send marketing email, there's a decent chance one of your own vendors already expects you to have one.

This is general information to help you understand the landscape, not legal advice for your specific business. State and international privacy law changes regularly and thresholds vary by revenue, user count, and industry - if your business handles anything more sensitive than a name and email (health information, financial data, anything aimed at children), talk to an attorney licensed in your state rather than relying on a blog post, including this one.

What a policy actually needs to say

A privacy policy does not need to be long to be complete. It needs to honestly answer six questions:

Cookies and tracking: do you need a banner too?

A privacy policy and a cookie consent banner are two different things, and conflating them is one of the most common mistakes. A banner asking for consent is only required if your site actually sets non-essential cookies or runs third-party tracking - most commonly Google Analytics, a Meta or ad pixel, embedded video, or a chat widget. If your site sets no cookies and loads no third-party trackers, there is nothing to get consent for, and no banner is required or useful.

Check what your own site actually loads before assuming either way. Plenty of small business sites run a privacy-friendly, cookieless analytics tool (or none at all) and genuinely need no banner; plenty of others have a Facebook pixel bolted on from an old marketing campaign nobody remembers approving, and that one does need disclosure and, depending on the law that applies, consent before it fires.

Mistakes that make a policy worse than none at all

A 3-minute self-check on your own site

  1. Does a privacy policy page exist at all, and is it linked from your site's footer on every page - not just the homepage?
  2. Read it against what your site actually does: does it name every form, every third-party tool (payment processor, email platform, analytics), and every category of information you really collect?
  3. Open your browser's dev tools (or a free cookie-scanner tool) and check what cookies your homepage actually sets before anyone clicks anything. If it's genuinely none, you don't need a consent banner - just say so plainly in the policy.

How we handled it on our own site

We wrote our own privacy policy in plain language rather than legal boilerplate, because it's short enough to actually be true: we don't use Google Analytics, Meta Pixel, or any third-party ad or tracking script anywhere on BitwiseDesigns, so we don't show a cookie banner either - there's nothing to get consent for. What we do collect (the website and email you give us for a free audit, or your correspondence if you email us) is named plainly, along with every vendor that touches it. It's the same standard we'd point a client to: say what you actually do, nothing more and nothing less.

Frequently asked questions

Does a small business website legally need a privacy policy?

In almost every practical case, yes. If your site collects any personal information, a growing list of US state laws plus the EU's GDPR for any EU visitors require disclosing what you collect and why. Some have revenue or user-count thresholds, but since any visitor from any state or country can land on your site, writing an honest policy regardless of the exact threshold is the safe default.

What happens if my website doesn't have one?

For most small businesses, nothing happens immediately - regulators go after large-scale violators first. But some ad platforms and payment processors require a policy before approving your account, and if a state's threshold ever does apply to you, having none at all is the hardest position to defend.

Do I need a cookie consent banner too?

Only if your site actually sets non-essential cookies or trackers, most commonly analytics or an ad pixel. If your site sets no cookies and runs no third-party tracking, there's nothing to get consent for, so no banner is required.

Can I just write my own privacy policy?

Yes, for a simple site that only collects a name and email through a contact form, honest language you write yourself is often clearer than a copy-pasted template - as long as it's accurate. For anything more complex, an attorney familiar with your state is worth the cost.

A privacy policy is legal text, not a speed or SEO fix

Getting the policy right protects you legally, but it doesn't touch the things that actually cost you visitors and search ranking - slow load times, broken links, missing alt text, weak SEO basics. Our free audit checks those with Google's own tooling and emails you a plain-English report of exactly what's wrong. If something needs fixing, it is a flat $149 for your fixable speed/image/SEO/broken-link issue, or $299 for everything, with before-and-after proof once it's done.

Want a full read on your site's health, not just privacy?

Enter your site and email and we'll run the full speed, SEO, accessibility, and security audit with Google's own tooling and email you the report within the hour - free.