Small Business Privacy Policy Template
Three documents and three sheets that classify every system touching customer data as a service provider or an undisclosed sale.
Free download · No account needed
Processor Register
[Company], Inc. — every system, classified against the statute's own test
Service provider requires an actual contract restricting the vendor to your own purpose. Anything else, especially an ad platform, is a sale or a share.
| System | Classification | Contract Restricts to Our Purpose? | Disclosure Required |
|---|---|---|---|
| — | — | — | — |
| — | — | — | — |
| — | — | — | — |
What a Yes/No questionnaire cannot show
| Generic question | "Do you share data with third parties?" answered once, for the whole business |
| Processor Register | Each system checked against its own actual contract, one row at a time |
Most undisclosed sales are not deliberate. They are an ad pixel nobody ever reclassified once it went live.
Every privacy policy generator online asks the same kind of question: do you use analytics, do you share data with third parties, yes or no. The answer becomes a paragraph, and the paragraph is only as accurate as the question was specific. California's own definition of a sale runs to communicating personal information to a third party for monetary or other valuable consideration, a test a generic Yes/No question was never built to apply system by system.
Fernbrook Home Goods, a fictional home goods brand, ran all eight systems touching customer data through Processor Register for the first time. Six sit on contracts keeping the vendor to Fernbrook's own purposes: the store platform, payments, email, SMS, support and fulfillment. Two do not: a Meta Pixel feeding Custom Audiences and a Google Ads remarketing tag, both trading customer data for better ad targeting rather than cash. The California Attorney General fined Sephora $1.2 million in 2022 for that exact arrangement: tracking pixels installed for free analytics and advertising benefits, no service-provider contract.
Two of eight systems, a quarter of Fernbrook's inventory, made its old privacy policy's blanket "we do not sell or share personal information" sentence false the day it was published. A verified access or deletion request carries its own deadline, 45 days from receipt, extendable once by 45 more if notice goes out inside the first window. Reviewing old support email turned up one request that had taken 74 days with no extension ever sent. This pack is the systems audit behind whatever the published policy is allowed to say.
What's in the pack
Data Inventory
Every system that actually touches customer data, by name, with what it collects, why, and how long it is kept.
Processor Register
Each system classified as a service provider or a sale under the same statutory test the Sephora enforcement action turned on, not a generic questionnaire.
Privacy Policy
Third-party disclosures drafted from the register, with any sale or share named specifically and given its own opt-out rather than folded into a blanket denial.
Data Handling Procedure
The internal process for adding a new system, reviewing vendor terms twice a year alongside every other recurring filing and renewal, and actually deleting data on schedule.
Breach Response Plan
Pre-drafted notification letters and the fastest applicable state deadline, worked out before an incident, not during one, alongside whatever cyber liability coverage is already in force.
Request Log
Every access, deletion and opt-out request logged against its real 45-day deadline, with the 90-day extension tracked separately.
How to use it
- 1
Open in River, or download it
Install the pack so the agent builds the inventory and the register from your own systems, or take the blank Word and CSV files away and fill them in yourself.
- 2
Name every system touching customer data
Not a Yes/No question about sharing in general: the store platform, payments, marketing tools, support, fulfillment, and any ad or analytics tag installed.
- 3
Classify each one against the statute's own test
A real contract restricting the vendor to your purpose makes it a service provider; anything else, especially an ad platform, is a sale or a share.
- 4
Draft the policy from what the register shows
Every sale or share named specifically with its own opt-out, so the published sentence matches every row rather than the easiest one to write.
Frequently asked questions
Is this template free?
Yes. Three documents and three sheets download as Word and CSV files with no signup and no credit card. "Edit with AI" is a separate, optional path for founders who want the agent to build the inventory from their own systems. The rest of the packs sit in the template library.
What format are the downloaded files?
Word documents (.docx) for the three policy and procedure documents, and CSV (.csv) for Data Inventory, Processor Register and Request Log, zipped together. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets, with nothing to convert.
What does 'Edit with AI' actually do?
It creates a free River account and installs this exact pack as a private workspace. The agent asks which systems actually touch customer data, checks each one's vendor terms, then classifies it as a service provider or a sale before drafting anything.
Does installing a Meta Pixel or Google Analytics really count as "selling" data?
It can, under the statute's own broad wording, whenever the platform keeps the data for its own ad targeting in exchange for a free or better service, cash or not. The California Attorney General fined Sephora $1.2 million in 2022 for exactly that arrangement, no service-provider contract in place.
If there is a breach, how fast do I have to notify people?
It depends on where your customers live, and there is no single US answer. Only 20 states set a fixed numeric deadline at all, 30 to 60 days; the other 31 use vague language like "without unreasonable delay". Build Breach Response Plan around the fastest deadline among the states you actually sell into, before an incident forces you to look it up.
How is this different from the terms of service pack's privacy policy?
The terms of service pack publishes a policy checked against refund and cancellation practice. This pack is the systems audit behind the data sections of any privacy policy: which specific vendor is a service provider, which is a sale, and the request log and breach plan neither one builds.
Do I still need a lawyer?
Yes, and this is not legal advice. What changes is what you hand them: a register showing exactly which system is a service provider and which is a sale, rather than a generic questionnaire neither of you has checked against what is actually installed on your site.
Find out which of your systems is actually a sale under the law
Download the blank pack as Word and CSV files, or open it in River and have your own systems classified against the same test the Sephora fine turned on.
Edit with AI