Do I Need a Privacy Policy and a Cookie Banner on My Website?
General information, not legal advice. Privacy law varies by state and by where your visitors are, and if you handle sensitive data you want a lawyer.
That said, the practical answers for a normal small business site are clearer than the topic's reputation suggests.
The privacy policy: almost certainly yes
Owners assume this applies to companies with data operations. It does not.
If your site has any of these, you are collecting personal information:
- A contact form
- An email or text signup
- Google Analytics or any other analytics
- A Facebook pixel or advertising tag
- Online booking or payment
- A chat widget
That is essentially every website. A name and an email address is personal information, and the size of your business does not change what the data is.
Three separate pressures point the same way. State privacy laws generally require a posted policy when you collect personal information from residents. The tools themselves require it in their terms, so running Analytics or advertising pixels without a policy puts you in breach of those agreements. And a visitor who wants to know what you do with their number should be able to find out.
What it needs to say
Plain language, and it must be true of your site specifically.
- What you collect, including form fields, analytics data, and cookies
- Why you collect it
- Who else sees it, meaning the services you use
- How long you keep it
- How someone requests deletion or a copy
- A real contact method
- The date it was last updated
Do not copy someone else's. A borrowed policy usually lists collection you do not do and omits tools you do use. An inaccurate policy is worse than a simple one, because it is a written statement that does not match how your site behaves.
Generators are a reasonable starting point if you answer their questions honestly and then read the output. A five page site does not need eleven pages of policy.
The cookie banner: probably not that one
Here is where most small businesses copy the wrong thing.
The banner you picture, where nothing loads until you accept, comes from EU and UK law. It exists because those rules require consent before non-essential cookies are set. If you have meaningful European visitors, that framework may apply to you.
For a US local business serving a US market, the picture is different. Several state privacy laws focus on giving people a way to opt out of the sale or sharing of their personal information, which is a different mechanism from a consent wall. Some sites satisfy that with a clear link rather than a popup.
So the honest answer for most local businesses: you likely need disclosure and an opt-out path, not a European style consent gate.
And a practical note. Those banners cost you visitors. If you do not need one, adding it because it looks official is a self-inflicted wound on the first thing a stranger sees.
Where it gets more serious
Three situations where you should stop reading blogs and call a professional.
Health information. Anything touching patient data brings its own regime with real penalties.
Children under thirteen. Collecting information from children has specific federal rules and the penalties are not small.
Selling or sharing data with other companies. If any part of your model involves passing customer data to third parties, that is exactly what these laws were written about.
The realistic checklist
For a normal local business site:
- A privacy policy that accurately describes your site, linked in the footer on every page.
- A terms of use page if you sell or book online.
- An opt-out path appropriate to the state laws that reach your visitors.
- A cookie banner only if you genuinely have EU or UK visitors or your counsel tells you otherwise.
- A review whenever you add a tool. Adding a chat widget or a new pixel changes what you collect, which means the policy is now out of date.
That last one is the one everybody skips. A policy written in 2022 for a site that has gained three tools since is no longer accurate, and accuracy was the entire point.
Why this is worth an hour
Not fear. Two ordinary reasons.
Your advertising and analytics accounts require it, and account problems are a genuine nuisance to unwind.
And people read it. Not many, but the ones who do are frequently the cautious, high value customers deciding whether to hand you their information. A clear, human policy is a small trust signal in exactly the moment trust is being decided.
We include an accurate privacy policy, terms, and a footer that links them on every build, updated when the tools change. See website design, or send us your domain and we will tell you what your site is currently collecting and whether your policy actually matches it.
Common questions
Does a small business website need a privacy policy?
In almost every case, yes. If your site has a contact form, an email signup, analytics, or advertising pixels, you are collecting personal information, and state laws plus the terms of the tools themselves generally require you to disclose what you collect and why.
Do I need a privacy policy if I only have a contact form?
Yes. A contact form collects a name, an email and often a phone number, which is personal information. The size of the form does not change the obligation.
Do I need a cookie banner in the United States?
Usually not in the European style, where nothing loads until the visitor consents. That model comes from EU and UK law. Some US state privacy laws require a way to opt out of sale or sharing of personal information, which is a different mechanism from a consent wall.
Can I copy a privacy policy from another website?
It is a bad idea. A policy describes what your site specifically collects and which tools you use, so a copied one is usually inaccurate, and an inaccurate policy is worse than a plain one because it is a written statement that does not match reality.
Ready to turn your website into your hardest-working salesperson?
Professional, built around your business, and live in 5 days to 2 weeks.
Get My New Site Live