Business guide

US Privacy Policy Requirements

A US-focused privacy policy must satisfy California, federal sector rules, app store policies, and an expanding set of state comprehensive laws — even for companies incorporated outside the US.

CalOPPA — baseline for most sites

If you collect personally identifiable information from California residents through a commercial website, CalOPPA requires a conspicuous privacy policy describing practices.

That includes many sites with contact forms, analytics, or accounts — not only ecommerce.

CCPA/CPRA — California consumer rights

See CCPA requirements. Categories, purposes, sale/sharing, rights — essential for growing businesses with California users.

Other state laws

Virginia, Colorado, Connecticut, Texas, and others add similar consumer rights with varying thresholds. A well-structured master policy often addresses multiple states — counsel should confirm applicability.

See US data privacy laws tracker.

App stores and payments

Apple and Google require public privacy policy URLs. Stripe and PayPal expect linked legal pages during onboarding.

What to include (US-oriented master policy)

  • Identity and contact
  • Categories of PI collected
  • Sources and purposes
  • Sharing with third parties / subprocessors
  • Retention
  • State-specific rights (CA first, expand as needed)
  • Security (high level)
  • Children (if relevant)
  • Changes and effective date

Generate

Privacy Policy Generator — Generated tier free on your domain.

Related: What is CCPA? · Privacy laws by country · Do I need a privacy policy?

Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.

Publish with proof

Generate policies customers can verify

Use Clerica's free generator for privacy and terms, see your clarity rubric score, and upgrade to Certified when you want Verified directory placement and integrity monitoring.

Generate a policy free
← All guides