Short answer: Host your privacy policy on your own domain (for example yoursite.com/privacy) and link it from your website footer on every page, checkout and signup flows, account settings, and any app store listing URL fields. Regulators and platforms expect the link to be conspicuous — easy to find without hunting through nested menus.
This guide covers placement for websites, mobile apps, ecommerce, and Shopify — plus why verify badges work best when policies stay on your domain.
Why placement matters
A privacy policy nobody can find fails both users and regulators. CalOPPA requires a "conspicuous" link when you collect personally identifiable information from California residents. App store reviewers reject apps with broken or buried policy URLs. Enterprise buyers check footer links during vendor security reviews.
Placement is also a trust signal. Customers who cannot locate your policy assume you are hiding something — even when your disclosures are solid.
Website placement checklist
Required placements:
- Site footer — linked on every page; label it "Privacy Policy" (not "Legal" alone)
- Signup and registration — near the email/password fields or "Create account" button
- Checkout — before payment submission on ecommerce flows
- Contact and lead forms — near the submit button when you collect personal data
- Cookie or consent banners — link to policy when describing tracking (CMP is not Clerica's focus today; placement still applies if you use third-party banners)
Recommended placements:
- Account settings page
- Email footers for marketing messages (CAN-SPAM context)
- Help center or FAQ index
- Partner and API documentation when you share user data
Use a stable URL path (/privacy, /privacy-policy) and avoid PDF-only hosting — reviewers and customers expect HTML they can search and link to.
Mobile app placement
Apps need the policy in two places:
- Store listing — paste your public URL in App Store Connect and Google Play Console
- In-app — settings, about screen, or onboarding; the link must open in a browser or in-app web view
The URL should resolve to your domain, not a generator vendor subdomain. Store reviewers and users associate trust with your brand domain.
Shopify and ecommerce
Shopify requires a privacy policy link in your store policies section. Best practice:
- Publish the policy on your custom domain (
yourstore.com/policies/privacy-policyor/pages/privacy) - Add footer navigation from theme settings
- Link at checkout when Shopify Payments or third-party apps collect data
See do I need a privacy policy for Shopify? for store-specific triggers.
Hosting: your domain vs vendor subdomain
Many generators offer free hosting on vendor.com/yourbusiness/privacy. That works for checkbox compliance but weakens trust:
- Customers see a third-party URL in store listings
- SEO and branding accrue to the vendor, not you
- Verify badges and certification assume you control the live URL on your domain
Clerica Generated tier publishes on your domain with a nofollow stamp to a public verify page — no mandatory vendor credits link. Active Certified adds Verified directory placement and dofollow backlink while your policy stays at yoursite.com/privacy.
Linking verify badges and directory profiles
When you certify with Clerica, embed the verify badge near your footer policy link or in app settings. Customers can jump from your policy to clerica.io/stamp/verify/{policyId} to confirm disclosures match what you certified.
Your Verified directory profile at clerica.io/verified/{slug} links back to your site — another reason to keep canonical policy URLs on your domain.
Common mistakes
- PDF only — hard to update, bad for accessibility, fails some store checks
- Broken links after redesign — redirect old paths when you migrate CMS
- Generic "Legal" hub — users cannot tell privacy from terms; use explicit labels
- Policy only on contact page — not conspicuous on product or checkout pages
- Copy-paste URL from another company — wrong domain destroys trust instantly
After you publish
Update placement when you add analytics, AI features, new payment processors, or subprocessors. How often should I update my privacy policy? covers cadence. Clerica integrity scans compare your live URL to the certified snapshot — if you move the policy path without updating certification, drift detection may downgrade your badge until you fix it.
Related: Do I need a privacy policy on my website? · Do I need a privacy policy for my app? · Business FAQ · Privacy Policy Generator
Clerica is not a law firm and does not provide legal advice. This guide is educational.