# Create and Maintain a Website Privacy Policy

Publish a clear privacy policy that matches the information your organization collects, uses, shares, retains, and protects.

Reviewed 2026-09-04

## Publish a policy that matches your organization

Before publishing a site that collects visitor information, create a privacy policy for your organization. The policy should explain in plain language what information is collected, why it is collected, how it is used, who receives it, how long it is kept, and what choices visitors have.

Do not copy another organization's policy or promises. The [Workganic Privacy Policy](/privacy-policy/) describes Workganic's own website practices; it is not a substitute for the policy of a business using a Workganic marketing site.

This guide is an operational checklist, not legal advice. Privacy requirements vary by location, audience, industry, information type, and business practice. Have a qualified legal or compliance professional review the policy and any consent language before publication.

## Map actual information practices before writing

Review what happens on the website and what your organization does after a visitor responds. Account for:

- Information visitors enter in forms, appointment requests, messages, uploads, or other submissions.
- Ordinary website activity, cookies, analytics, advertising measurement, and similar technologies that are actually in use.
- Where information comes from and the purposes for which it is used.
- The categories of service providers or other organizations that receive information.
- How information is retained, corrected, deleted, protected, or transferred.
- Whether information is sold, shared for advertising, or used for another organization's own purposes.

Include off-site practices when they affect information collected through the website. A website policy is incomplete if it describes only the form and ignores what the organization does with the submission afterward.

## State sale and sharing practices accurately

Do not use a statement such as **We do not sell personal information** merely because it appears on another website. Use it only when your organization has confirmed that it is accurate for its actual practices and remains accurate as those practices change.

If your organization sells information or shares it in a way covered by an applicable privacy requirement, describe that practice clearly. Identify the relevant categories of information and recipients, explain the purpose, and provide any required choice or opt-out method. Legal meanings of "sell" and "share" can differ, so have qualified counsel confirm the wording.

## Cover the essential policy sections

A complete policy commonly addresses:

- The organization responsible for the website and how visitors can contact it.
- Categories of information collected and the sources of that information.
- Business purposes for collecting and using information.
- Categories of service providers and other recipients.
- Sale, sharing, advertising, and tracking practices, including visitor choices.
- Retention practices or the method used to determine retention.
- A practical description of safeguards without making guarantees.
- Visitor rights and how to submit a request, when applicable.
- Cookies and similar technologies, including any available controls.
- Children, sensitive information, or location-specific disclosures when applicable.
- The effective date, how changes are communicated, and the date of the latest revision.

Describe only practices the organization can verify and commitments it can honor. Avoid absolute promises such as "completely secure," "never shared," or "deleted immediately" unless they are accurate in every applicable situation.

## Build the policy in MKT

1. Open **Marketing**, choose **Website Builder**, and select the intended site.
2. Add a page titled **Privacy Policy** with a clear public path.
3. Use readable headings and text blocks for the reviewed policy sections.
4. Add a **Privacy Policy** link to the site footer and any other place where it should remain easy to find.
5. Place a clear privacy-policy link at or near forms that collect visitor information when appropriate for the form and applicable requirements.
6. Review page title, description, indexing choice, and link text in **SEO & Social**.
7. Select **Open Test Site** and verify the policy and every privacy link on desktop and mobile.

The link should open the policy without requiring a visitor to submit the form, create an account, or search the site.

## Match every form to the policy

For each public form, compare the visible fields and follow-up workflow with the policy. Confirm that:

- Every category of collected information is covered.
- The stated purposes match the actual follow-up.
- Consent or authorization language is separate and clear when needed.
- Advertising, measurement, communication, and sharing practices are described accurately.
- Visitors can reach the policy before submitting information.
- A synthetic submission reaches the intended Workganic destination.

Do not place real visitor or client information in the privacy policy, screenshots, examples, or test submissions.

## Understand the publishing boundary

Workganic's documentation and publishing checks help identify unsafe public content, but they do not certify the legal sufficiency of a tenant's privacy policy or continuously monitor whether an organization follows every statement it publishes. The site owner is responsible for confirming the policy's accuracy, obtaining appropriate review, honoring its commitments, and updating it when forms, tracking, advertising, recipients, retention, or business practices change.

## Publish and maintain the policy

Publish the privacy policy before publishing the collection experience it describes. Then open **Open Published Page** and verify the policy route, footer link, form links, revision date, desktop layout, and mobile layout.

Review the policy on a regular schedule and before launching a new form, audience, tracking tool, advertising use, recipient, or data practice. Record the review date and republish the updated policy when the public wording changes.

## Stop conditions

Stop before publishing if you cannot explain what information is collected, why it is used, who receives it, how long it is kept, whether it is sold or shared, or how visitors can exercise applicable choices. Also stop if the policy was copied from another organization, conflicts with a form or business practice, lacks appropriate review, or cannot be reached from the public site.
