How to add a Privacy Policy URL for a Shopify or WooCommerce store
By Paul Cranmer, Founder · Last verified August 2026 · Shopify store · WooCommerce
Checkout and ads both ask for a privacy policy URL, and a homepage link is the usual wrong answer. Shopify merchants set privacy text under Settings → Policies (and often Customer privacy). WooCommerce stores usually publish a WordPress privacy page and link it in the footer. This page shows both paths, when Shopify’s built-in policy URL is enough, and when a hosted privacy policy URL helps for Google Merchant, Meta, or lead forms.
Who this is for
- Shopify store owners setting Privacy policy under Settings → Policies
- WooCommerce / WordPress shop owners who need a public privacy policy URL
- Merchants who will reuse the same HTTPS link in ads, Merchant Center, or forms
Not for
- Shopify App Partner listings (use the Shopify App privacy how-to)
- App Store or Chrome extension listings (free Mobile App / Extension path)
- A full cookie CMP install guide
What the platform requires
- Shopify: Settings → Policies includes Privacy policy. Public path is typically /policies/privacy-policy on your store domain.
- Shopify: Customer privacy settings can automate policy, cookie banner, and opt-out pages. Review what automation writes before you rely on it for ads.
- WooCommerce: Publish a Privacy Policy page (often via WordPress Settings → Privacy) and link it in the store footer and account flows.
- Ad platforms and many marketplaces expect a dedicated HTTPS privacy policy URL, not your shop homepage.
Get a live URL first
E-commerce Store and Website paths use our $9.99/yr hosted Privacy Policy URL. Generate a live HTTPS page that names your store and contact email, then either paste that URL into Shopify policy content as a clear link, use it as your WooCommerce privacy page destination, or keep Shopify’s built-in /policies/privacy-policy page and still host a canonical URL for ads. App Store Mobile App stays free.
Get store privacy URLStep-by-step: store privacy policy URL
- Shopify: open Settings → Policies. In Shopify admin, go to Settings → Policies. Open Privacy policy. Enter your policy text or start from Insert template, then edit it so it matches what you actually sell and which apps/pixels you use.
- Shopify: save and copy the public URL. Click Save. Your store privacy policy is usually available at https://YOUR-DOMAIN/policies/privacy-policy. Open it in a private browser window and confirm it loads without login.
- Shopify: footer and Customer privacy. Add Privacy policy to Content → Menus (footer). Optionally review Settings → Customer privacy for cookie banner and automated privacy updates so the policy stays aligned with store settings.
- WooCommerce: publish a Privacy Policy page. In WordPress, use Settings → Privacy to create or assign a Privacy Policy page, or publish a custom page. Name the shop, describe checkout and account data, and include a contact email for privacy requests.
- WooCommerce: link it in the storefront. Add the page to Appearance → Menus (footer) or your block theme footer. Confirm the URL is HTTPS and works logged out. Reuse that same URL anywhere ads or forms ask for a privacy policy URL.
- Reuse one canonical URL for ads and tools. Prefer one stable HTTPS privacy policy URL across the storefront footer, Shopify/Woo policy settings, Google Merchant, and Meta or Google lead forms. If you use a hosted URL outside the theme, link to it clearly from the store policy page so shoppers and reviewers land on the same document.
Field labels to look for
- Settings → Policies (Shopify)
- Written store policies including Privacy policy. Publishes under /policies/privacy-policy on your domain.
- Settings → Customer privacy (Shopify)
- Cookie banner, data sharing opt-out, and optional automated privacy policy updates.
- Settings → Privacy (WordPress / Woo)
- Assigns the official Privacy Policy page. Still add a footer link for shoppers.
Common reasons the form fails
- Leaving Shopify or WordPress template placeholders unpublished edits
- Using the shop homepage as the privacy policy URL in ads
- No footer link, so shoppers cannot find the policy at checkout time
- Policy that never mentions payments, shipping partners, or marketing pixels you use
- Confusing a Shopify App listing policy with the merchant storefront policy
Storefront vs Shopify App vs other policies
This how-to is for merchant storefronts (Shopify or WooCommerce) on the paid store/website path. Shopify App developers should use the Shopify App how-to. Refund and shipping policy URLs are separate store policies.
FAQ
Where do I set the privacy policy on Shopify?
Go to Settings → Policies, open Privacy policy, edit or insert a template, then Save. The public URL is usually /policies/privacy-policy on your store domain.
Do I need Shopify Customer privacy settings too?
Review them. They control cookie banners, opt-out pages, and optional automated privacy policy updates. Ads and tracking still need an accurate policy URL shoppers can open.
Can I use a hosted privacy policy URL instead of Shopify’s built-in page?
Yes. Many stores keep a short policy page or menu link that points to one hosted HTTPS URL so ads, Merchant Center, and the storefront stay in sync.
What about WooCommerce?
Publish a Privacy Policy page in WordPress, assign it under Settings → Privacy if you use that tool, link it in the footer, and use that HTTPS URL everywhere platforms ask.
Is the store homepage OK as a privacy policy URL?
No. Use a dedicated policy page URL. Reviewers and ad platforms expect a document about data practices, not your catalog.
Is this the same as a Shopify App privacy policy URL?
No. App listings use the Partner Dashboard field. This page is for the merchant storefront customers buy from.
Do I also need refund and shipping policy URLs?
Often yes for checkout and marketplaces. Shopify has separate policy entries for those. They are not a substitute for the privacy policy URL.
Is the e-commerce path free?
Store and website privacy URLs use the $9.99/yr hosted plan. App Store Mobile App URLs stay on the free path.