River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Small Business Privacy Policy Template

Three documents and three sheets that classify every system touching customer data as a service provider or an undisclosed sale.

Free download  ·  No account needed

Processor Register

[Company], Inc. — every system, classified against the statute's own test

Service provider requires an actual contract restricting the vendor to your own purpose. Anything else, especially an ad platform, is a sale or a share.

SystemClassificationContract Restricts to Our Purpose?Disclosure Required

What a Yes/No questionnaire cannot show

Generic question"Do you share data with third parties?" answered once, for the whole business
Processor RegisterEach system checked against its own actual contract, one row at a time

Most undisclosed sales are not deliberate. They are an ad pixel nobody ever reclassified once it went live.

Every privacy policy generator online asks the same kind of question: do you use analytics, do you share data with third parties, yes or no. The answer becomes a paragraph, and the paragraph is only as accurate as the question was specific. California's own definition of a sale runs to communicating personal information to a third party for monetary or other valuable consideration, a test a generic Yes/No question was never built to apply system by system.

Fernbrook Home Goods, a fictional home goods brand, ran all eight systems touching customer data through Processor Register for the first time. Six sit on contracts keeping the vendor to Fernbrook's own purposes: the store platform, payments, email, SMS, support and fulfillment. Two do not: a Meta Pixel feeding Custom Audiences and a Google Ads remarketing tag, both trading customer data for better ad targeting rather than cash. The California Attorney General fined Sephora $1.2 million in 2022 for that exact arrangement: tracking pixels installed for free analytics and advertising benefits, no service-provider contract.

Two of eight systems, a quarter of Fernbrook's inventory, made its old privacy policy's blanket "we do not sell or share personal information" sentence false the day it was published. A verified access or deletion request carries its own deadline, 45 days from receipt, extendable once by 45 more if notice goes out inside the first window. Reviewing old support email turned up one request that had taken 74 days with no extension ever sent. This pack is the systems audit behind whatever the published policy is allowed to say.

Every sheet in the pack, filled in for one company

What actually touches customer data, how each system is classified, the policy language that follows, and every request against its deadline.

Data Inventory

Fernbrook Home Goods. 6 of 8 systems shown.

SystemVendorPersonal Data TouchedPurpose
Store platformShopifyName, address, email, order historyHosts the storefront and every order record
Payment processingShopify PaymentsCard token, billing addressAuthorizes and settles checkout
Email marketingKlaviyoEmail, purchase and browsing historyCampaign and abandoned-cart email
Customer supportGorgiasEmail, order history, message contentLive chat and ticketing
Ad retargetingMeta Pixel + Custom AudiencesHashed email/phone, device ID, page eventsMatches visitors to Meta accounts for ads
Ad remarketingGoogle Ads remarketing tagDevice ID, page and purchase eventsBuilds remarketing audiences

Eight systems total. The two flagged rows are the ones a "do you use analytics" checkbox usually misses as a sale.

Processor Register

Same eight systems, classified against the statute's own test. 5 of 8 rows shown.

SystemClassificationContract Restricts to Our Purpose?Disclosure
ShopifyService providerYesNamed, no opt-out needed
KlaviyoService providerYesNamed, no opt-out needed
GorgiasService providerYesNamed, no opt-out needed
Meta Pixel + Custom AudiencesSale or shareNoOpt-out required, incl. Global Privacy Control
Google Ads remarketing tagSale or shareNoOpt-out required, incl. Global Privacy Control

6 of 8 systems are service providers. The 2 that are not, a quarter of the inventory, is the same arrangement the California Attorney General fined Sephora $1.2 million for missing.

Privacy Policy, Section 3

Drafted from Processor Register, not from a blanket denial.

Service providers. Shopify, Shopify Payments, Klaviyo, Postscript, Gorgias and ShipStation each operate under a contract restricting them to our own purposes. This is not a sale or a share.
Sale or share. A Meta Pixel and Custom Audiences integration, and a Google Ads remarketing tag, each receive data used for their own ad targeting. You may opt out of both below, including through an automatic browser opt-out signal.

The generator-built version of this section read "we do not sell or share your personal information," full stop. It was inaccurate for two of eight systems the day it went live.

Request Log

6 requests logged. One found on retroactive review, from before this log existed.

TypeReceivedDue (45 days)CompletedStatus
Deletion03 Nov18 Dec22 JanExtended to 90 days, notice sent in time
Access14 Sep29 Oct20 OctOn time
Opt-out01 DecImmediate03 DecMeta and Google suppressed
Deletion02 Jun17 Jul15 Aug74 days, no extension ever sent

The bottom row predates this log: handled by email, no due date ever calculated, closed 29 days past a deadline nobody knew it had.

What's in the pack

01

Data Inventory

Every system that actually touches customer data, by name, with what it collects, why, and how long it is kept.

02

Processor Register

Each system classified as a service provider or a sale under the same statutory test the Sephora enforcement action turned on, not a generic questionnaire.

03

Privacy Policy

Third-party disclosures drafted from the register, with any sale or share named specifically and given its own opt-out rather than folded into a blanket denial.

04

Data Handling Procedure

The internal process for adding a new system, reviewing vendor terms twice a year alongside every other recurring filing and renewal, and actually deleting data on schedule.

05

Breach Response Plan

Pre-drafted notification letters and the fastest applicable state deadline, worked out before an incident, not during one, alongside whatever cyber liability coverage is already in force.

06

Request Log

Every access, deletion and opt-out request logged against its real 45-day deadline, with the 90-day extension tracked separately.

How to use it

  1. 1

    Open in River, or download it

    Install the pack so the agent builds the inventory and the register from your own systems, or take the blank Word and CSV files away and fill them in yourself.

  2. 2

    Name every system touching customer data

    Not a Yes/No question about sharing in general: the store platform, payments, marketing tools, support, fulfillment, and any ad or analytics tag installed.

  3. 3

    Classify each one against the statute's own test

    A real contract restricting the vendor to your purpose makes it a service provider; anything else, especially an ad platform, is a sale or a share.

  4. 4

    Draft the policy from what the register shows

    Every sale or share named specifically with its own opt-out, so the published sentence matches every row rather than the easiest one to write.

Frequently asked questions

Is this template free?

Yes. Three documents and three sheets download as Word and CSV files with no signup and no credit card. "Edit with AI" is a separate, optional path for founders who want the agent to build the inventory from their own systems. The rest of the packs sit in the template library.

What format are the downloaded files?

Word documents (.docx) for the three policy and procedure documents, and CSV (.csv) for Data Inventory, Processor Register and Request Log, zipped together. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets, with nothing to convert.

What does 'Edit with AI' actually do?

It creates a free River account and installs this exact pack as a private workspace. The agent asks which systems actually touch customer data, checks each one's vendor terms, then classifies it as a service provider or a sale before drafting anything.

Does installing a Meta Pixel or Google Analytics really count as "selling" data?

It can, under the statute's own broad wording, whenever the platform keeps the data for its own ad targeting in exchange for a free or better service, cash or not. The California Attorney General fined Sephora $1.2 million in 2022 for exactly that arrangement, no service-provider contract in place.

If there is a breach, how fast do I have to notify people?

It depends on where your customers live, and there is no single US answer. Only 20 states set a fixed numeric deadline at all, 30 to 60 days; the other 31 use vague language like "without unreasonable delay". Build Breach Response Plan around the fastest deadline among the states you actually sell into, before an incident forces you to look it up.

How is this different from the terms of service pack's privacy policy?

The terms of service pack publishes a policy checked against refund and cancellation practice. This pack is the systems audit behind the data sections of any privacy policy: which specific vendor is a service provider, which is a sale, and the request log and breach plan neither one builds.

Do I still need a lawyer?

Yes, and this is not legal advice. What changes is what you hand them: a register showing exactly which system is a service provider and which is a sale, rather than a generic questionnaire neither of you has checked against what is actually installed on your site.

Find out which of your systems is actually a sale under the law

Download the blank pack as Word and CSV files, or open it in River and have your own systems classified against the same test the Sephora fine turned on.

Edit with AI