TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. Squarespace Privacy Policy: How to Create and Add One (2026)
Tutorials

Squarespace Privacy Policy: How to Create and Add One (2026)

Learn how to create a Squarespace privacy policy, what it must include, and where to add it on your site. Covers GDPR, CCPA, and cookie requirements.

TermsBox Team|July 28, 202612 min read

If you run a website on Squarespace, you need a Squarespace privacy policy that accurately describes how your site collects and uses visitor data. Squarespace does not create this document for you: the platform's own privacy policy covers Squarespace as a company, not your individual site. This guide explains what your policy must contain, which laws apply, and exactly how to add the page to your Squarespace site. It is educational information rather than legal advice, so consult a qualified attorney for guidance specific to your business.

Why Your Squarespace Site Needs a Privacy Policy

A privacy policy is a legal document that discloses what personal data your website collects, why you collect it, who you share it with, and what rights visitors have over that data. If your Squarespace site has a contact form, uses analytics, or sells anything, it collects personal data and needs this document.

Several laws make a privacy policy legally required rather than optional:

  • General Data Protection Regulation (GDPR): Articles 13 and 14 require you to inform EU visitors about your data processing at the point of collection. The GDPR applies to any site with EU visitors, regardless of where you are based, and fines can reach 20 million EUR or 4% of global annual turnover under Article 83.
  • California Consumer Privacy Act (CCPA): Section 1798.130 requires covered businesses to publish a privacy policy describing consumer rights and data categories collected. Violations carry fines up to $2,500 per unintentional violation and $7,500 per intentional violation under Section 1798.155.
  • California Online Privacy Protection Act (CalOPPA): Requires any website collecting personal information from California residents to post a conspicuous privacy policy. This catches nearly every site with US traffic, including small portfolios and blogs.
  • PIPEDA (Canada), UK GDPR, and Australia's Privacy Act 1988: All impose similar transparency obligations if you serve visitors in those regions.

A common misconception is that Squarespace handles this for you because it hosts your site. It does not. Under GDPR terminology, you are the data controller for your visitors' data and Squarespace is your data processor. The controller carries the disclosure obligations, which is why every Squarespace site owner needs their own policy.

What Data Squarespace Collects on Your Behalf

Before writing a privacy policy for Squarespace, you need to know what your site actually collects. Squarespace sites gather more data out of the box than most owners realize.

Built-in Squarespace features that collect data

  • Squarespace Analytics: Enabled by default on every site. It logs IP addresses, browser and device details, referral sources, and on-site behavior using cookies.
  • Form and newsletter blocks: Store names, email addresses, and any other fields you add. Submissions are saved in your Squarespace dashboard and can sync to email marketing tools.
  • Commerce features: If you sell products or services, Squarespace processes names, shipping addresses, order history, and payment details through processors like Stripe and PayPal.
  • Member areas and customer accounts: Store login credentials, profile information, and content access history.
  • Scheduling (Acuity): Collects appointment details, contact information, and sometimes intake form responses or payment data.
  • Functional cookies: Squarespace sets cookies for shopping carts, session management, and site performance even before you add any third-party tools.

Third-party tools you may have added

Your policy must also cover integrations you connected yourself. Common examples on Squarespace sites include Google Analytics, the Meta (Facebook) pixel for ad tracking, Mailchimp for email marketing, embedded YouTube or Vimeo videos, and Google Maps blocks. Each of these sends visitor data to a third party and often sets its own cookies.

A practical way to build this inventory is to scan your live site rather than guess. An automated compliance scanner such as the one TermsBox provides detects the cookies, trackers, and third-party services actually running on your pages, which gives you an accurate basis for your disclosures.

What to Include in Your Squarespace Privacy Policy

Once you know what your site collects, your Squarespace privacy policy needs to disclose it clearly. A compliant policy covers the following sections:

  1. Who you are: Your business name, location, and contact details, plus your data protection officer if you have one.
  2. What personal data you collect: Names, email addresses, IP addresses, payment details, analytics identifiers, and anything gathered by forms or commerce features.
  3. How you collect it: Directly through forms and purchases, and automatically through cookies, Squarespace Analytics, and embedded third-party tools.
  4. Why you process it: Your purposes and, for GDPR, the lawful basis for each under Article 6, such as consent, contract performance, or legitimate interests.
  5. Who you share it with: Squarespace as your hosting processor, payment processors, email marketing platforms, analytics providers, and advertising networks.
  6. International transfers: Squarespace is a US company, so EU and UK visitor data leaves the region. Disclose the safeguards used, such as Standard Contractual Clauses or the EU-US Data Privacy Framework.
  7. Retention periods: How long you keep form submissions, customer records, and analytics data.
  8. User rights: GDPR rights including access (Article 15), rectification (Article 16), erasure (Article 17), and data portability (Article 20), plus CCPA rights to know, delete, correct, and opt out of sale or sharing.
  9. Cookies: What cookies your site sets and how visitors can manage consent. Many sites keep the detail in a separate cookie policy and link it from the privacy policy.
  10. Children's data: State whether your site is directed at children. If it is, the Children's Online Privacy Protection Act (COPPA) imposes parental consent requirements for users under 13.
  11. Policy updates: How you notify visitors of changes and the date of the last revision.

Do not copy another site's policy. Disclosures that do not match your actual practices are worse than none, because they amount to a deceptive statement the FTC or a state attorney general can act on. Either draft each section against your real data inventory or use a privacy policy generator that builds the document from questions about your specific setup.

How to Add a Privacy Policy to Squarespace: Step by Step

Adding the finished policy to your site takes about ten minutes. Squarespace gives you two workable approaches: a native page or a link to an externally hosted policy.

Option 1: Create a native Squarespace page

  1. Open the Pages panel in your site dashboard.
  2. Add a blank page under the Not Linked section. This keeps the policy out of your main navigation while still publishing it at a public URL.
  3. Name the page "Privacy Policy" and set the URL slug to /privacy-policy. A predictable slug helps visitors and regulators find it.
  4. Paste your policy text into a text block. Use heading formatting for each section so the page is scannable, and check that no characters were mangled in the paste.
  5. Add a footer link. Edit your footer, add a link to the new page, and label it "Privacy Policy." The footer appears on every page, which satisfies the "conspicuous posting" standard in CalOPPA.
  6. Link it at data collection points. Add the link near contact forms, newsletter signup blocks, and in your checkout settings under Commerce, where Squarespace lets you require agreement to policies at purchase.
  7. Publish and test. Open your site in a private browser window, confirm the footer link works on desktop and mobile, and verify the page is readable.

Option 2: Link to a hosted policy

Instead of pasting text into a page, you can link your footer to a policy hosted elsewhere. Hosted documents have one significant advantage: when your data practices change, the hosted version updates without you re-pasting anything into Squarespace. TermsBox, for example, hosts generated policies at a clean URL and, on paid plans, keeps them aligned with what its scanner finds on your site. The footer link setup in Squarespace is identical, you just point the link at the external URL.

Whichever option you choose, keep the page indexable. Hiding your privacy policy from search engines undermines the transparency the law requires.

Squarespace Privacy Policy and Cookie Consent Work Together

A privacy policy alone does not make a Squarespace site compliant for EU and UK visitors. The ePrivacy Directive, in Article 5(3), requires informed consent before you store non-essential cookies on a visitor's device, and GDPR sets the standard that consent must be an active opt-in.

Squarespace includes a built-in cookie banner, but its default configuration is a notice-only banner that does not block cookies. To use it for EU traffic you need to change two settings:

  • Enable the opt-in banner so visitors get a real accept choice rather than a passive notice.
  • Activate the setting that disables Squarespace Analytics cookies until the visitor accepts, otherwise analytics cookies fire before consent and the banner is decorative.

The built-in banner also has real limits: it cannot block cookies set by custom code injections or many third-party embeds, and it offers limited consent granularity. If you run Google Analytics, ad pixels, or other injected scripts, a dedicated consent management platform that scans your site and blocks trackers until consent is the more defensible setup. For the full walkthrough of both routes, see the guide to Squarespace GDPR cookie banner setup.

Your privacy policy and your banner must tell the same story. If the policy says you use analytics and marketing cookies, the banner needs matching consent categories, and the policy should explain how visitors can withdraw consent later.

Common Squarespace Privacy Policy Mistakes

The same handful of problems appear on Squarespace sites over and over. Check your setup against this list:

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now
  • Relying on Squarespace's own privacy policy. Linking to squarespace.com's policy instead of publishing your own leaves your legal obligations completely unmet.
  • Copying a template without editing it. A policy that mentions services you do not use, or omits the Meta pixel you do use, misrepresents your practices.
  • Forgetting Squarespace Analytics. Because it is on by default, many owners disclose Google Analytics but never mention the platform's native tracking.
  • No footer link. A policy that exists only in the Not Linked section, with no visible link anywhere, fails the conspicuous posting requirement.
  • Ignoring commerce data. Sites that add a store later often never update the policy to cover order data, payment processors, and shipping partners.
  • Missing international transfer language. EU visitor data processed by a US platform needs a transfer disclosure, which generic US-focused templates usually lack.
  • A banner that contradicts the policy. Promising opt-in consent in the policy while running a notice-only banner is an inconsistency regulators specifically look for.

Keeping Your Squarespace Privacy Policy Current

A privacy policy is not a one-time task, because your Squarespace site changes over time. Each new block, integration, or feature can change what data you collect.

Update your policy when you:

  • Add or remove third-party tools such as Google Analytics, a Meta pixel, or an email marketing integration
  • Launch commerce features, member areas, or Acuity scheduling
  • Change payment processors or shipping partners
  • Start serving a new region with its own privacy law
  • Receive notice that a law you are subject to has changed, such as a new US state privacy act taking effect

A workable routine for a small site is a quarterly check: rescan your site for cookies and trackers, compare the results against your policy's disclosures, and revise the policy where they diverge. Date every revision and keep the "last updated" line visible at the top of the page. For material changes, such as starting to share data with an ad network, notify subscribers and customers directly rather than silently editing the page. If you want the monitoring automated, TermsBox's scanner watches for new trackers and flags when your documents no longer match your site.

If you are still deciding whether your specific site needs one at all, the answer is almost certainly yes, and the guide to whether you need a privacy policy walks through the edge cases.

Frequently Asked Questions

Does Squarespace provide a privacy policy for my website?

No. Squarespace's own privacy policy covers how Squarespace processes data as a company, not how your site processes visitor data. You are the data controller for your visitors, so you must create and publish your own privacy policy that reflects your specific data practices.

Where should I put my privacy policy on Squarespace?

Create it as a page in the Not Linked section of the Pages panel with the URL slug /privacy-policy, then link it in your site footer so it is reachable from every page. Also link it near any forms, newsletter signups, and the checkout if you sell products.

Is the built-in Squarespace cookie banner GDPR compliant?

Only if you configure it correctly. You must enable the opt-in setting for EU visitors and activate the option that blocks Squarespace analytics cookies until consent, because the default notice-only banner does not collect the active consent GDPR Article 6(1)(a) requires.

Do I need a privacy policy for a simple Squarespace portfolio site?

Yes, in almost every case. Even a basic portfolio site collects personal data through Squarespace Analytics, contact form submissions, and cookies. Laws like GDPR and CalOPPA apply based on who visits your site, not on how small or non-commercial it is.

Can I use a privacy policy generator for my Squarespace site?

Yes. A quality privacy policy generator asks about your actual data practices, such as forms, analytics, e-commerce, and marketing tools, and produces a policy covering GDPR, CCPA, and other laws. For most small businesses this is a practical and affordable alternative to custom legal drafting.

How often should I update my Squarespace privacy policy?

Update it whenever your data practices change, for example when you add a newsletter block, connect Google Analytics, install a Facebook pixel, or start selling products. Review it at least once a year and whenever new privacy laws take effect in regions you serve.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

Tutorials

Terms of Use for Wix: How to Create and Add Yours

Learn how to create terms of use for your Wix site, what clauses to include, and how Wix terms of use differ from the Wix Terms of Service you agreed to.

July 27, 202613 min read
Tutorials

WordPress Cookie Consent Plugin: The Complete Guide

Find the best WordPress cookie consent plugin for GDPR and ePrivacy compliance. Covers free and paid options, setup steps, and legal requirements.

April 4, 202612 min read
Tutorials

WordPress GDPR Plugin: The Complete Setup Guide

Find the best WordPress GDPR plugin for your site. This guide covers features to look for, setup steps, and how to achieve full GDPR compliance.

April 4, 202614 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • Why Your Squarespace Site Needs a Privacy Policy
  • What Data Squarespace Collects on Your Behalf
  • Built-in Squarespace features that collect data
  • Third-party tools you may have added
  • What to Include in Your Squarespace Privacy Policy
  • How to Add a Privacy Policy to Squarespace: Step by Step
  • Option 1: Create a native Squarespace page
  • Option 2: Link to a hosted policy
  • Squarespace Privacy Policy and Cookie Consent Work Together
  • Common Squarespace Privacy Policy Mistakes
  • Keeping Your Squarespace Privacy Policy Current
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.