A privacy policy is a statement placed in an easily visible place on a website informing users about how the website deals with users' personal information. Privacy policies generally explain whether and how users' information will be shared with third parties, including parent companies or subsidiaries. It frequently explains whether and how the website uses cookies.
Privacy policies let people know what you will do with information that they provide when registering with your website, as well as information that gets logged while they browse. A privacy policy allows users to find out what you do with their private information and enables them to adapt their conduct accordingly. Beyond that, a privacy policy will help you avoid liability under a complex array of state and federal laws dealing with users' private information.
A well-crafted privacy policy should include the following items (although the particular items included may depend upon the nature of your website):
Another important aspect of a privacy policy is what it says about minors. If your site targets or knowingly collects information from children under age thirteen, it must comply with the Children’s Online Privacy Protection Act. For more information about how to comply with the Children's Online Privacy Protection Act, please see COPPA.org's compliance page. If you do not plan to collect information from minors, you should consider adding a statement to your privacy policy saying:
This website's content is intended for adults and we will not knowingly collect personal information from children under 13 years of age. If you are a parent or legal guardian of a child under age 13 who you believe has submitted personal information to this site, please contact us immediately.
There are also rules about collecting medical information and information about criminal records. Unless it is important to the purpose of your website, you should not gather this type of information. If you plan to gather this type of information, you should consult a lawyer about your data collection strategy.
You can find good examples of privacy policies on the following sites: MinnPost.com, HuffingtonPost.com, Ars Technica, and CMLP.
It is common to see the following statement in website privacy policies: "[Name of website] will not collect any personal information about you except when you specifically and knowingly provide such information." While this kind of statement may sound reassuring for your users, it is not true in most cases. When a user visits a website, he or she provides personal information to the website operator simply by virtue of browsing, reading, and downloading material. This information includes IP address, user configuration settings, and what website referred the user to the site, among other things. It is better to tell users that this type of information is being collected automatically on standard web server access logs.