Create an editable WordPress privacy-policy draft with guided questions for plugins, forms, analytics, WooCommerce, cookies, GDPR, and CCPA/CPRA topics.
WordPress plugins can introduce forms, accounts, analytics, advertising, payments, comments, security logs, and third-party data flows. Inventory the active configuration rather than assuming WordPress core describes the whole site.
Here is what the most popular WordPress plugin categories collect from your visitors. All of this must be disclosed in your privacy policy.
Review: Verify form fields, IP logging, submissions, file uploads, storage, email delivery, and retention settings
Review: Verify events, identifiers, device data, search or referral fields, retention, advertising features, and consent settings
Review: Verify security logs, IP or device information, login events, comment screening, recipients, and retention
Review: Verify subscriber fields, preferences, message engagement, site tracking, audience sync, and deletion workflows
Review: Verify cookies, edge or server logs, IP and device data, CDN routing, recipients, and retention
Review: Verify identity fields, social profiles, comment content, IP logging, avatars, moderation, and publication settings
Running a WooCommerce store adds significant privacy obligations beyond a standard WordPress site. Here is what your policy must cover.
WooCommerce collects billing/shipping addresses, email, phone, payment details, and order history. Each must be disclosed with the legal basis for processing.
Every payment gateway (Stripe, PayPal, Square, Authorize.Net) has different data practices. Your privacy policy must reference each gateway's own privacy policy.
Registered customers have accounts with order history, saved addresses, and payment methods. You must disclose retention periods and allow data export/deletion.
Since WooCommerce 3.4, built-in GDPR tools support data export and erasure. Your privacy policy must document how customers can exercise these rights.
Build a WooCommerce-specific disclosure inventory
Guided questions cover checkout, accounts, payment gateways, orders, extensions, retention, and user-rights workflows. Verify each service against its first-party documentation.
Create a draft from the plugins and services you verify, then review it whenever the site's configuration changes.
No credit card required. Hosted and copy-paste publishing options available.
Three steps from a plugin inventory to a reviewed WordPress privacy-policy draft.
Inventory active plugins, themes, forms, comments, ecommerce, analytics, advertising, and third-party services. An MCP stack manifest can help, but you verify the final list.
PolicyForge uses the facts you provide to create an editable draft covering the selected services, WooCommerce topics, cookies, and relevant rights workflows.
Review the draft, publish it to a hosted URL or WordPress page, and revisit the inventory whenever plugins or data practices change. Native plugin automation remains on the roadmap.
Everything WordPress site owners need to know about privacy policies.
Plugins can change the site's data practices. Build a verified inventory, create a matching draft, and keep the published notice aligned. No credit card required.
Free to start • No credit card required