A US-focused privacy policy must satisfy California, federal sector rules, app store policies, and an expanding set of state comprehensive laws — even for companies incorporated outside the US.
CalOPPA — baseline for most sites
If you collect personally identifiable information from California residents through a commercial website, CalOPPA requires a conspicuous privacy policy describing practices.
That includes many sites with contact forms, analytics, or accounts — not only ecommerce.
CCPA/CPRA — California consumer rights
See CCPA requirements. Categories, purposes, sale/sharing, rights — essential for growing businesses with California users.
Other state laws
Virginia, Colorado, Connecticut, Texas, and others add similar consumer rights with varying thresholds. A well-structured master policy often addresses multiple states — counsel should confirm applicability.
See US data privacy laws tracker.
App stores and payments
Apple and Google require public privacy policy URLs. Stripe and PayPal expect linked legal pages during onboarding.
What to include (US-oriented master policy)
- Identity and contact
- Categories of PI collected
- Sources and purposes
- Sharing with third parties / subprocessors
- Retention
- State-specific rights (CA first, expand as needed)
- Security (high level)
- Children (if relevant)
- Changes and effective date
Generate
Privacy Policy Generator — Generated tier free on your domain.
Related: What is CCPA? · Privacy laws by country · Do I need a privacy policy?
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.