This draft explains the structure required for the final privacy notice. It must be completed with the identity and contact details of the actual data controller before launch.
The live store may process account details, billing and delivery information, order history, customer communications, technical logs, consent choices and analytics identifiers according to the services enabled.
Typical purposes include processing orders, delivering purchases, customer support, fraud prevention, legal compliance, account administration, site security and - where valid consent or another lawful basis applies - analytics or marketing.
The final notice should identify relevant categories of processors such as hosting, WooCommerce extensions, payment providers, delivery carriers, email services, analytics tools and consent platforms.
Retention periods and UK data-protection rights must be documented for the live implementation, including how customers can make access, correction, deletion or objection requests where applicable.
See the Cookies Policy for the framework covering browser storage and consent controls.
Privacy requests should use the final privacy contact details supplied by the legal data controller.