See how Apple, Google, Stripe, Shopify, and 11 other top companies write their privacy policies. Each example includes the actual language they use and analysis of why it works — so you can build a better policy for your own business.
A useful privacy policy explains who handles personal data, what is collected and why, the legal basis where relevant, recipients, retention, transfers, rights and choices, and how to contact the business. The exact disclosures depend on the laws, users, data, and services that apply, and the policy must match actual practices.
Legal guidance reviewed on August 11, 2026. Company policies change; check each linked example before relying on it. This guide is general information, not legal advice.
Create your own
Answer guided questions about your real data practices, then review and edit the draft before publishing. PolicyForge is free to start.
A privacy policy is a legal document that explains how your website or application collects, uses, stores, shares, and protects users' personal information. It serves as a transparency mechanism between your business and your users, building trust while fulfilling legal obligations.
A website that collects personal data through contact forms, accounts, analytics, advertising, cookies, or other tools should assess which privacy notices are required by the laws and platform rules that apply. Business size alone does not answer the question.
The best privacy policies do more than check a legal box. As you'll see in the examples below, companies like Apple, Google, and Stripe use their privacy policies as trust-building tools that reinforce their brand values and give users genuine control over their data.
The GDPR, CCPA, CalOPPA, PIPEDA, LGPD, and other laws can require privacy notices when their scope and thresholds are met. GDPR's highest fine tier can reach EUR 20 million or 4% of worldwide annual turnover.
A clear, honest privacy policy helps people understand how their data is used and what choices they have. That transparency can support trust at sign-up, checkout, and other decision points.
App stores, advertising platforms, commerce providers, and other partners may require a privacy policy for relevant products or data uses. Check the current rule for each channel you use.
A policy that accurately describes your practices sets expectations, creates an accountable record, and can reduce ambiguity when users or regulators ask how data is handled.
We analyzed the privacy policies of 15 industry-leading companies across technology, e-commerce, social media, SaaS, AI, and more. For each example, we highlight what they do exceptionally well and why it works — so you can apply the same principles to your own policy.
Technology · Plain language with layered disclosure
"When you create an Apple Account, apply for commercial credit, purchase and/or activate a product or device, download a software update, register for a class at an Apple Store, connect to our services, contact us (including by social media), participate in an online survey, or otherwise interact with Apple, we may collect a variety of information."
Why it works:
Apple uses a layered approach: a short summary up front, then expandable sections for detail. This satisfies both casual readers and regulators. Their data minimization language ('we collect only what we need') reinforces their privacy-first brand positioning.
Technology · Visual design with video explanations
"When you use our services, you trust us with your information. We understand this is a big responsibility and work hard to protect your information and put you in control. This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information."
Why it works:
Google leads with empathy ('you trust us') and immediately addresses the reader's concern. They embed explanatory videos and real-world examples throughout, making a complex policy accessible. Their 'Privacy Checkup' tool links directly from the policy, giving users immediate control.
Entertainment · Conversational tone with clear categories
"Personal data that we need to create your Spotify account and that enables you to use the Spotify Service. The type of data collected and used includes your profile name, email address, password, phone number, date of birth, gender, street address, country, and university/college (for Spotify Premium Student)."
Why it works:
Spotify organizes data collection by context (signing up, using the service, third-party connections) rather than legal categories. This makes it intuitive for users to understand exactly when and why their data is collected. Their tone is conversational without being informal.
E-commerce · Dual-audience policy for merchants and buyers
"We collect and use information about you, our merchants using Shopify to power your business, consumers who shop at a Shopify-powered business... We carefully analyze what types of information we need to provide our services, and we try to limit the information we collect to only what we really need."
Why it works:
Shopify addresses two distinct audiences (merchants and their customers) in one policy without confusion. Their clear categorization of collection methods (direct, third-party, automatic) follows GDPR Article 13/14 requirements precisely while remaining readable.
E-commerce · Comprehensive coverage of complex ecosystem
"We collect your personal information in order to provide and continually improve our products and services. We use your personal information to take and handle orders, deliver products and services, process payments, and communicate with you about orders, products, services, and promotional offers."
Why it works:
Amazon's policy covers an enormously complex ecosystem (retail, AWS, Alexa, Prime Video, Kindle) in a single coherent document. They use a purpose-first structure: leading with WHY they collect data before WHAT they collect. Their examples are specific to each service.
Financial Technology · Developer-friendly with technical precision
"Transaction Data refers to data collected or used by Stripe in relation to transactions you request. Some Transaction Data is Personal Data and may include: your name, email address, contact number, billing and shipping address, payment method information. We also collect information you choose to share with us through various channels, such as support tickets, emails, or social media."
Why it works:
Stripe's policy is technically precise — critical for a payments company processing billions. They categorize data into named types (Identity Data, Financial Data, Transaction Data) making it easy for developers integrating Stripe to understand exactly what data flows through their systems.
Social Platform · Youth-aware with age-gated disclosures
"When you create a Discord account, you can come up with a username and password, and provide a way of contacting you (such as an email address and/or phone number). We also collect any content that you upload to the service. For example, you may write messages or posts (including drafts), send voice messages, create custom emojis, or post other content."
Why it works:
Discord handles a uniquely challenging audience (many users under 18) with specific COPPA and age-gating disclosures. They clearly distinguish between data collected from teens vs. adults, and their parental controls section is prominently placed — not buried in fine print.
Professional Network · Data portability emphasis with career context
"You create your LinkedIn profile (a complete profile helps you get the most from our Services). You have choices about the information on your profile, such as your education, work experience, skills, photo, city or area, endorsements, and optional verifications. Your profile is fully visible to all Members and customers of our Services."
Why it works:
LinkedIn contextualizes data collection within professional advancement — framing data sharing as enabling career opportunities rather than surveillance. Their policy prominently features data portability and download tools, exceeding GDPR minimum requirements.
Workplace Communication · Enterprise-grade with workspace admin transparency
"Customers or individuals granted access to a Workspace by a Customer ('Authorized Users') routinely submit Customer Data (such as messages, files or other content submitted through Services accounts) to Slack when using the Services. To create or update a Workspace account, you or our Customer (e.g. your employer) supply Slack with an email address, phone number, password, domain, and/or other account set up details."
Why it works:
Slack uniquely addresses the three-party relationship between Slack (provider), workspace admins (customers), and individual users (end users). They clearly explain what admins can see vs. what Slack can see, which is critical for enterprise trust.
Productivity · Workspace content handling transparency
"We collect information about you when you use our services, including browsing our website, creating or logging into your Notion account, and when you otherwise engage with us. Service Data: When you use our Service, we collect and store content you create, upload, receive, or share using the Service."
Why it works:
Notion addresses the key concern for productivity tools: 'Do you read my documents?' Their policy explicitly states how workspace content is handled, whether it's used for AI training (it's not by default), and how shared pages affect data exposure.
Video Communication · Meeting recording and AI features transparency
"We receive personal data from you when you use or interact with Zoom Products, including information you provide directly, information about how you use our Products, and information from third-party sources. Account Information: information associated with an account that licenses Zoom Products."
Why it works:
After their 2023 privacy controversy, Zoom rewrote their policy to explicitly address recording consent, AI companion data usage, and whether meeting content trains AI models. This transparency-after-crisis approach is now considered best-in-class for video platforms.
Developer Platform · Code and repository data handling
"We collect certain information when you open an account such as your GitHub handle, name, email address, password, payment information and transaction information. When you use our Services, we collect Personal Data included as part of the information you provide such as code, inputs, text, documents, images, or feedback."
Why it works:
GitHub addresses a unique concern: intellectual property in code repositories. They clearly distinguish between public repo data, private repo data, and Copilot AI training data. Their policy gives developers confidence that private code remains private.
Artificial Intelligence · AI training data and conversation handling
"We collect personal information relating to you when you use our services, including information you provide, information we receive automatically from your use of our services, and information we receive from other sources. We use personal information to provide, analyze, and improve our Services."
Why it works:
OpenAI's policy is the gold standard for AI companies. They explicitly address whether conversations train models, how to opt out of training data use, and what happens when you delete conversations. Their API vs. consumer product distinction is critical for developers.
Streaming · Viewing history and recommendation transparency
"When you create your Netflix account, we collect your contact information (such as your email address) and authentication information for your login (such as a password). We collect your payment details, and other information to process your payments, including your payment history, billing address, and gift cards. We collect information about your interaction with the Netflix service (including playback events, such as play, pause, etc.), choices made when engaging with interactive titles."
Why it works:
Netflix addresses a uniquely sensitive topic: viewing habits. They explain how viewing history powers recommendations, who can see profile activity in shared accounts, and how they comply with the Video Privacy Protection Act (VPPA) — a US law specifically about viewing records.
Travel & Hospitality · Two-sided marketplace with identity verification
"We collect personal information about you when you use the Airbnb Platform. Without it, we may not be able to provide all services requested. This information includes: Contact, Account, and Profile Information such as your name, phone number, postal address, email address, date of birth, and profile photo."
Why it works:
Airbnb handles a complex two-sided marketplace where hosts and guests share personal data with each other. Their policy clearly explains what information is shared between parties, how identity verification works, and what happens to property photos and reviews — addressing trust on both sides.
Create your own
Use the examples for structure and clarity, then create disclosures based on your own products, vendors, users, and data flows.
Get our 12-point checklist covering GDPR, CCPA, COPPA, and CalOPPA requirements — so you don't miss anything.
Based on the patterns we see in the best examples above, here are six practical steps to writing a privacy policy that is accurate, useful, and easy to understand.
Before writing a single word, document every piece of personal data you collect. This includes form submissions, cookies, analytics tools, third-party integrations, and payment processors. Map the full lifecycle: collection, storage, usage, sharing, and deletion. Companies like Stripe excel because they categorize data into named types (Identity Data, Financial Data, Transaction Data).
Assess where the business is established, whom it targets, what data it processes, and whether legal thresholds are met. For example, GDPR can reach some non-EU businesses that offer goods or services to, or monitor, people in the EU; the CCPA applies only to covered businesses; and COPPA focuses on online services directed to children under 13 or with actual knowledge of collecting their data.
Follow Apple's layered approach: provide a short summary first, then detailed sections. Use clear headings, short paragraphs, and plain language. Avoid legal jargon where possible. Google and Spotify show that conversational language builds more trust than formal legalese.
Common topics include what data you collect, why and on what legal basis, how you use it, recipients, retention, transfers, user rights and choices, cookies, children's data where relevant, and how to contact you. The exact list depends on the laws and processing in scope.
The best policies address industry-specific concerns. Zoom explains recording consent. OpenAI addresses AI training data. Discord handles age-gated content. Think about what YOUR users worry about and address it directly, as Notion does with their AI training data disclosure.
Make the policy easy to find from persistent navigation and relevant collection points. Include a 'last updated' date, review it when practices change, and link directly to privacy controls such as data access or deletion tools where possible.
Different jurisdictions impose different notice duties when their scope and thresholds are met. This overview highlights common topics; confirm the current requirements for your specific business.
A privacy policy should explain who handles personal data, what data is collected, why it is used, the legal basis where relevant, who receives it, how long it is kept, any international transfers, the rights and choices available to people, and how to contact the business. The exact disclosures depend on the laws and data practices that apply.
It depends on the business, users, data, and applicable law. GDPR, the CCPA, CalOPPA, COPPA, and other privacy laws can require notices or disclosures in defined circumstances. App stores, advertising platforms, payment providers, and other partners may also require a privacy policy even when a specific law does not apply.
Review it whenever your data practices, vendors, products, audience, or legal obligations change. A scheduled review can help catch stale language, but the important rule is to update the policy before or when a material practice changes and provide any notice required by the applicable law.
Use examples to study structure and plain-language techniques, not as a substitute for documenting your own practices. Another company's policy may describe different data, vendors, purposes, retention periods, and legal obligations. Copying it can therefore create inaccurate disclosures and may also raise intellectual-property concerns.
A privacy policy explains how personal data is collected, used, shared, retained, and protected, plus the rights and choices available to people. Terms of service govern use of a website or service, including matters such as acceptable use, intellectual property, payment, liability, and disputes. A business may need both, but they serve different purposes.
Business size alone does not decide the question. Check what personal data the site collects through forms, accounts, analytics, advertising, cookies, payments, or other tools; where users are located; and which laws and platform rules apply. Even a simple site can have disclosure obligations when it collects or shares personal data.
Make it easy to find, commonly through a persistent footer link, and place contextual links where people provide data or make privacy choices, such as sign-up, checkout, account settings, consent interfaces, and app-store listings. Applicable law or platform rules may prescribe additional placement or notice requirements.
The drafting time depends on the complexity of the business and the quality of its data inventory. A generator can produce a starting draft quickly, but the important work is verifying that every disclosure matches actual data flows, vendors, retention practices, user choices, and applicable requirements. Complex or high-risk processing may warrant professional review.
Generate a customized privacy policy in minutes
Download a free, editable privacy policy template
Understanding the EU's data protection regulation
California's consumer privacy rights explained
Create terms of service for your website or app
Create cookie disclosures for your website
Create your own
PolicyForge turns your answers into an editable starting draft. Verify the details against your real practices and get professional review where your risk or jurisdiction calls for it.