Google Analytics collects IP addresses, device data, and usage events — your privacy policy must disclose it and align with your consent setup.
What to disclose
- That you use analytics or platform SDKs
- Categories of data collected (device IDs, usage events, crash logs)
- Purposes (analytics, product improvement, ads if applicable)
- Whether data is shared with Google/Apple or third-party SDK vendors
- Retention and opt-out where applicable
- How users contact you about data questions
Consent and CMP
Google Analytics may require consent in EU/UK and opt-out considerations in California depending on configuration. Cookie consent/CMP is not Clerica's focus today — configure GA/consent mode separately; ensure policy text matches live behavior.
App-specific notes
Link policy in website footer; disclose GA4 or Universal Analytics version you deploy.
Steps
- Inventory GA properties, tags, and linked Google Ads if any
- Generate policy with Privacy Policy Generator
- Publish on your domain — not only vendor hosted URL
- Update when changing analytics vendor or consent mode
Related: How to write a privacy policy · Do I need an app privacy policy? · US privacy requirements
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.