Example set: April 2026

    15 Privacy Policy Examples
    From Companies You Know

    See how Apple, Google, Stripe, Shopify, and 11 other top companies write their privacy policies. Each example includes the actual language they use and analysis of why it works — so you can build a better policy for your own business.

    15 min read|15 real examples|6 industries covered
    PolicyForge Editorial Team|Legal guidance checked against primary sources
    Editorial contentUpdated August 2026
    Quick answer

    Quick answer

    A useful privacy policy explains who handles personal data, what is collected and why, the legal basis where relevant, recipients, retention, transfers, rights and choices, and how to contact the business. The exact disclosures depend on the laws, users, data, and services that apply, and the policy must match actual practices.

    Start with
    A current data map
    Core test
    Matches actual practices
    Review when
    Data uses, vendors, products, or laws change

    Legal guidance reviewed on August 11, 2026. Company policies change; check each linked example before relying on it. This guide is general information, not legal advice.

    Create your own

    Turn the examples into a privacy policy for your business

    Answer guided questions about your real data practices, then review and edit the draft before publishing. PolicyForge is free to start.

    • Guided questions
    • Editable draft
    • Free to start

    What Is a Privacy Policy?

    A privacy policy is a legal document that explains how your website or application collects, uses, stores, shares, and protects users' personal information. It serves as a transparency mechanism between your business and your users, building trust while fulfilling legal obligations.

    A website that collects personal data through contact forms, accounts, analytics, advertising, cookies, or other tools should assess which privacy notices are required by the laws and platform rules that apply. Business size alone does not answer the question.

    The best privacy policies do more than check a legal box. As you'll see in the examples below, companies like Apple, Google, and Stripe use their privacy policies as trust-building tools that reinforce their brand values and give users genuine control over their data.

    Why Do You Need a Privacy Policy?

    Legal Requirement

    The GDPR, CCPA, CalOPPA, PIPEDA, LGPD, and other laws can require privacy notices when their scope and thresholds are met. GDPR's highest fine tier can reach EUR 20 million or 4% of worldwide annual turnover.

    User Trust

    A clear, honest privacy policy helps people understand how their data is used and what choices they have. That transparency can support trust at sign-up, checkout, and other decision points.

    Platform Requirements

    App stores, advertising platforms, commerce providers, and other partners may require a privacy policy for relevant products or data uses. Check the current rule for each channel you use.

    Business Protection

    A policy that accurately describes your practices sets expectations, creates an accountable record, and can reduce ambiguity when users or regulators ask how data is handled.

    15 Privacy Policy Examples from Top Companies

    We analyzed the privacy policies of 15 industry-leading companies across technology, e-commerce, social media, SaaS, AI, and more. For each example, we highlight what they do exceptionally well and why it works — so you can apply the same principles to your own policy.

    Technology

    Apple

    Technology · Plain language with layered disclosure

    View policy

    "When you create an Apple Account, apply for commercial credit, purchase and/or activate a product or device, download a software update, register for a class at an Apple Store, connect to our services, contact us (including by social media), participate in an online survey, or otherwise interact with Apple, we may collect a variety of information."

    Why it works:

    Apple uses a layered approach: a short summary up front, then expandable sections for detail. This satisfies both casual readers and regulators. Their data minimization language ('we collect only what we need') reinforces their privacy-first brand positioning.

    Layered disclosure with expandable sections
    Clear data retention timelines
    Prominent opt-out mechanisms
    Available in 40+ languages

    Google

    Technology · Visual design with video explanations

    View policy

    "When you use our services, you trust us with your information. We understand this is a big responsibility and work hard to protect your information and put you in control. This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information."

    Why it works:

    Google leads with empathy ('you trust us') and immediately addresses the reader's concern. They embed explanatory videos and real-world examples throughout, making a complex policy accessible. Their 'Privacy Checkup' tool links directly from the policy, giving users immediate control.

    Embedded video explanations
    Interactive privacy controls linked inline
    Real-world examples for each data type
    Regularly updated with change summaries

    Spotify

    Entertainment · Conversational tone with clear categories

    View policy

    "Personal data that we need to create your Spotify account and that enables you to use the Spotify Service. The type of data collected and used includes your profile name, email address, password, phone number, date of birth, gender, street address, country, and university/college (for Spotify Premium Student)."

    Why it works:

    Spotify organizes data collection by context (signing up, using the service, third-party connections) rather than legal categories. This makes it intuitive for users to understand exactly when and why their data is collected. Their tone is conversational without being informal.

    Organized by user action, not legal category
    Specific examples of collected data
    Clear distinction between required and optional data
    Dedicated section for music-specific data

    E-commerce & Finance

    Shopify

    E-commerce · Dual-audience policy for merchants and buyers

    View policy

    "We collect and use information about you, our merchants using Shopify to power your business, consumers who shop at a Shopify-powered business... We carefully analyze what types of information we need to provide our services, and we try to limit the information we collect to only what we really need."

    Why it works:

    Shopify addresses two distinct audiences (merchants and their customers) in one policy without confusion. Their clear categorization of collection methods (direct, third-party, automatic) follows GDPR Article 13/14 requirements precisely while remaining readable.

    Separate sections for merchants vs. shoppers
    Comprehensive cookie disclosure
    API and third-party integration transparency
    Data Processing Addendum linked for businesses

    Amazon

    E-commerce · Comprehensive coverage of complex ecosystem

    View policy

    "We collect your personal information in order to provide and continually improve our products and services. We use your personal information to take and handle orders, deliver products and services, process payments, and communicate with you about orders, products, services, and promotional offers."

    Why it works:

    Amazon's policy covers an enormously complex ecosystem (retail, AWS, Alexa, Prime Video, Kindle) in a single coherent document. They use a purpose-first structure: leading with WHY they collect data before WHAT they collect. Their examples are specific to each service.

    Covers 20+ services in one policy
    Purpose-first data collection disclosure
    Voice assistant data section (Alexa)
    Advertising preferences with opt-out links

    Stripe

    Financial Technology · Developer-friendly with technical precision

    View policy

    "Transaction Data refers to data collected or used by Stripe in relation to transactions you request. Some Transaction Data is Personal Data and may include: your name, email address, contact number, billing and shipping address, payment method information. We also collect information you choose to share with us through various channels, such as support tickets, emails, or social media."

    Why it works:

    Stripe's policy is technically precise — critical for a payments company processing billions. They categorize data into named types (Identity Data, Financial Data, Transaction Data) making it easy for developers integrating Stripe to understand exactly what data flows through their systems.

    Named data categories for technical clarity
    Sub-processor list publicly available
    GDPR, CCPA, and PCI DSS compliance in one document
    Developer-focused API data handling section

    Social & Communication

    Discord

    Social Platform · Youth-aware with age-gated disclosures

    View policy

    "When you create a Discord account, you can come up with a username and password, and provide a way of contacting you (such as an email address and/or phone number). We also collect any content that you upload to the service. For example, you may write messages or posts (including drafts), send voice messages, create custom emojis, or post other content."

    Why it works:

    Discord handles a uniquely challenging audience (many users under 18) with specific COPPA and age-gating disclosures. They clearly distinguish between data collected from teens vs. adults, and their parental controls section is prominently placed — not buried in fine print.

    Age-specific data handling (under 13, 13-17, 18+)
    Voice and video data transparency
    Bot and integration data disclosure
    Community server data vs. DM distinction

    LinkedIn

    Professional Network · Data portability emphasis with career context

    View policy

    "You create your LinkedIn profile (a complete profile helps you get the most from our Services). You have choices about the information on your profile, such as your education, work experience, skills, photo, city or area, endorsements, and optional verifications. Your profile is fully visible to all Members and customers of our Services."

    Why it works:

    LinkedIn contextualizes data collection within professional advancement — framing data sharing as enabling career opportunities rather than surveillance. Their policy prominently features data portability and download tools, exceeding GDPR minimum requirements.

    Professional context for all data collection
    Recruiter and advertiser data use separated
    Data download tool prominently linked
    InMail and messaging data handling clarified

    Slack

    Workplace Communication · Enterprise-grade with workspace admin transparency

    View policy

    "Customers or individuals granted access to a Workspace by a Customer ('Authorized Users') routinely submit Customer Data (such as messages, files or other content submitted through Services accounts) to Slack when using the Services. To create or update a Workspace account, you or our Customer (e.g. your employer) supply Slack with an email address, phone number, password, domain, and/or other account set up details."

    Why it works:

    Slack uniquely addresses the three-party relationship between Slack (provider), workspace admins (customers), and individual users (end users). They clearly explain what admins can see vs. what Slack can see, which is critical for enterprise trust.

    Three-party data relationship explained
    Admin vs. individual user visibility matrix
    Message retention and deletion policies
    SOC 2 and enterprise compliance references

    Productivity & SaaS

    Notion

    Productivity · Workspace content handling transparency

    View policy

    "We collect information about you when you use our services, including browsing our website, creating or logging into your Notion account, and when you otherwise engage with us. Service Data: When you use our Service, we collect and store content you create, upload, receive, or share using the Service."

    Why it works:

    Notion addresses the key concern for productivity tools: 'Do you read my documents?' Their policy explicitly states how workspace content is handled, whether it's used for AI training (it's not by default), and how shared pages affect data exposure.

    Explicit AI training data disclosure
    Workspace content vs. account data separation
    Shared page and public page data implications
    Third-party integration data flow transparency

    Zoom

    Video Communication · Meeting recording and AI features transparency

    View policy

    "We receive personal data from you when you use or interact with Zoom Products, including information you provide directly, information about how you use our Products, and information from third-party sources. Account Information: information associated with an account that licenses Zoom Products."

    Why it works:

    After their 2023 privacy controversy, Zoom rewrote their policy to explicitly address recording consent, AI companion data usage, and whether meeting content trains AI models. This transparency-after-crisis approach is now considered best-in-class for video platforms.

    Meeting recording consent requirements
    AI Companion data usage explicitly addressed
    Host vs. participant data distinctions
    End-to-end encryption scope clarified

    GitHub

    Developer Platform · Code and repository data handling

    View policy

    "We collect certain information when you open an account such as your GitHub handle, name, email address, password, payment information and transaction information. When you use our Services, we collect Personal Data included as part of the information you provide such as code, inputs, text, documents, images, or feedback."

    Why it works:

    GitHub addresses a unique concern: intellectual property in code repositories. They clearly distinguish between public repo data, private repo data, and Copilot AI training data. Their policy gives developers confidence that private code remains private.

    Public vs. private repository data handling
    Copilot AI training data opt-out
    Open source contribution data transparency
    Enterprise vs. individual account distinctions

    AI, Media & Travel

    OpenAI (ChatGPT)

    Artificial Intelligence · AI training data and conversation handling

    View policy

    "We collect personal information relating to you when you use our services, including information you provide, information we receive automatically from your use of our services, and information we receive from other sources. We use personal information to provide, analyze, and improve our Services."

    Why it works:

    OpenAI's policy is the gold standard for AI companies. They explicitly address whether conversations train models, how to opt out of training data use, and what happens when you delete conversations. Their API vs. consumer product distinction is critical for developers.

    Conversation data and AI training disclosure
    API data vs. ChatGPT consumer data separation
    30-day conversation deletion process
    Training data opt-out mechanism

    Netflix

    Streaming · Viewing history and recommendation transparency

    View policy

    "When you create your Netflix account, we collect your contact information (such as your email address) and authentication information for your login (such as a password). We collect your payment details, and other information to process your payments, including your payment history, billing address, and gift cards. We collect information about your interaction with the Netflix service (including playback events, such as play, pause, etc.), choices made when engaging with interactive titles."

    Why it works:

    Netflix addresses a uniquely sensitive topic: viewing habits. They explain how viewing history powers recommendations, who can see profile activity in shared accounts, and how they comply with the Video Privacy Protection Act (VPPA) — a US law specifically about viewing records.

    Video Privacy Protection Act (VPPA) compliance
    Profile-level data separation for shared accounts
    Recommendation algorithm data disclosure
    Download and offline viewing data handling

    Airbnb

    Travel & Hospitality · Two-sided marketplace with identity verification

    View policy

    "We collect personal information about you when you use the Airbnb Platform. Without it, we may not be able to provide all services requested. This information includes: Contact, Account, and Profile Information such as your name, phone number, postal address, email address, date of birth, and profile photo."

    Why it works:

    Airbnb handles a complex two-sided marketplace where hosts and guests share personal data with each other. Their policy clearly explains what information is shared between parties, how identity verification works, and what happens to property photos and reviews — addressing trust on both sides.

    Host-guest data sharing transparency
    Identity verification data handling
    Review and rating data policies
    Location data for property search vs. tracking

    Create your own

    Build the policy around your actual data practices

    Use the examples for structure and clarity, then create disclosures based on your own products, vendors, users, and data flows.

    • Business-specific inputs
    • Editable sections
    • Export when ready
    FREE RESOURCE

    Free Privacy Policy Compliance Checklist

    Get our 12-point checklist covering GDPR, CCPA, COPPA, and CalOPPA requirements — so you don't miss anything.

    • All required sections for each regulation
    • Data subject rights checklist
    • Third-party disclosure requirements
    • Cookie and tracking consent rules

    No spam. Unsubscribe anytime.

    How to Write a Privacy Policy

    Based on the patterns we see in the best examples above, here are six practical steps to writing a privacy policy that is accurate, useful, and easy to understand.

    1

    Audit Your Data Practices

    Before writing a single word, document every piece of personal data you collect. This includes form submissions, cookies, analytics tools, third-party integrations, and payment processors. Map the full lifecycle: collection, storage, usage, sharing, and deletion. Companies like Stripe excel because they categorize data into named types (Identity Data, Financial Data, Transaction Data).

    2

    Identify Your Legal Obligations

    Assess where the business is established, whom it targets, what data it processes, and whether legal thresholds are met. For example, GDPR can reach some non-EU businesses that offer goods or services to, or monitor, people in the EU; the CCPA applies only to covered businesses; and COPPA focuses on online services directed to children under 13 or with actual knowledge of collecting their data.

    3

    Structure for Readability

    Follow Apple's layered approach: provide a short summary first, then detailed sections. Use clear headings, short paragraphs, and plain language. Avoid legal jargon where possible. Google and Spotify show that conversational language builds more trust than formal legalese.

    4

    Cover the Disclosures That Apply

    Common topics include what data you collect, why and on what legal basis, how you use it, recipients, retention, transfers, user rights and choices, cookies, children's data where relevant, and how to contact you. The exact list depends on the laws and processing in scope.

    5

    Add Context-Specific Disclosures

    The best policies address industry-specific concerns. Zoom explains recording consent. OpenAI addresses AI training data. Discord handles age-gated content. Think about what YOUR users worry about and address it directly, as Notion does with their AI training data disclosure.

    6

    Make It Accessible and Maintainable

    Make the policy easy to find from persistent navigation and relevant collection points. Include a 'last updated' date, review it when practices change, and link directly to privacy controls such as data access or deletion tools where possible.

    Privacy Policy Requirements by Law

    Different jurisdictions impose different notice duties when their scope and thresholds are met. This overview highlights common topics; confirm the current requirements for your specific business.

    GDPR

    European Union
    • Legal basis for each processing activity
    • Data Protection Officer contact (if applicable)
    • Data subject rights (access, rectification, erasure, portability)
    • Cross-border transfer mechanisms
    • Data retention periods
    • Right to lodge complaint with supervisory authority
    Penalty: Up to 4% of annual global turnover or EUR 20MLearn more →

    CCPA / CPRA

    California, USA
    • Categories of personal information collected
    • Purpose for each category
    • Right to know, delete, and opt-out of sale
    • Do Not Sell My Personal Information link
    • Financial incentive disclosures
    • Updated at least once every 12 months
    Penalty: Up to $7,500 per intentional violationLearn more →

    PIPEDA

    Canada
    • Consent for data collection and use
    • Purpose limitation principle
    • Access and correction rights
    • Accountability with designated privacy officer
    • Safeguards appropriate to sensitivity
    • Breach notification to Privacy Commissioner
    Penalty: Up to CAD $100,000 per violationLearn more →

    CalOPPA

    California, USA
    • Conspicuous posting on website
    • Categories of PII collected
    • Third parties with whom you share data
    • Process for user to review and request changes
    • Effective date clearly stated
    • Do Not Track signal disclosure
    Penalty: Up to $2,500 per violation after 30-day cureLearn more →

    COPPA

    USA (Children under 13)
    • Verifiable parental consent before collection
    • Direct notice to parents about data practices
    • Parents' right to review and delete child's data
    • No conditioning participation on data collection
    • Data security and retention limits
    • Operator contact information
    Penalty: Up to $50,120 per violationLearn more →

    EU AI Act

    European Union
    • AI system transparency disclosures
    • Automated decision-making explanations
    • High-risk AI system documentation
    • Human oversight mechanisms
    • Data governance requirements
    • Conformity assessment documentation
    Penalty: Up to EUR 35M or 7% of global turnoverLearn more →

    Privacy Policy FAQ

    What should a privacy policy include?

    A privacy policy should explain who handles personal data, what data is collected, why it is used, the legal basis where relevant, who receives it, how long it is kept, any international transfers, the rights and choices available to people, and how to contact the business. The exact disclosures depend on the laws and data practices that apply.

    Is a privacy policy legally required?

    It depends on the business, users, data, and applicable law. GDPR, the CCPA, CalOPPA, COPPA, and other privacy laws can require notices or disclosures in defined circumstances. App stores, advertising platforms, payment providers, and other partners may also require a privacy policy even when a specific law does not apply.

    How often should I update my privacy policy?

    Review it whenever your data practices, vendors, products, audience, or legal obligations change. A scheduled review can help catch stale language, but the important rule is to update the policy before or when a material practice changes and provide any notice required by the applicable law.

    Can I copy another company's privacy policy?

    Use examples to study structure and plain-language techniques, not as a substitute for documenting your own practices. Another company's policy may describe different data, vendors, purposes, retention periods, and legal obligations. Copying it can therefore create inaccurate disclosures and may also raise intellectual-property concerns.

    What's the difference between a privacy policy and terms of service?

    A privacy policy explains how personal data is collected, used, shared, retained, and protected, plus the rights and choices available to people. Terms of service govern use of a website or service, including matters such as acceptable use, intellectual property, payment, liability, and disputes. A business may need both, but they serve different purposes.

    Do I need a privacy policy for a small business website?

    Business size alone does not decide the question. Check what personal data the site collects through forms, accounts, analytics, advertising, cookies, payments, or other tools; where users are located; and which laws and platform rules apply. Even a simple site can have disclosure obligations when it collects or shares personal data.

    Where should I display my privacy policy?

    Make it easy to find, commonly through a persistent footer link, and place contextual links where people provide data or make privacy choices, such as sign-up, checkout, account settings, consent interfaces, and app-store listings. Applicable law or platform rules may prescribe additional placement or notice requirements.

    How long does it take to write a privacy policy?

    The drafting time depends on the complexity of the business and the quality of its data inventory. A generator can produce a starting draft quickly, but the important work is verifying that every disclosure matches actual data flows, vendors, retention practices, user choices, and applicable requirements. Complex or high-risk processing may warrant professional review.

    Related Resources

    Create your own

    Draft a privacy policy that reflects how your business works

    PolicyForge turns your answers into an editable starting draft. Verify the details against your real practices and get professional review where your risk or jurisdiction calls for it.

    • No credit card required
    • Guided setup
    • Editable output