Do Etsy Sellers Need a Privacy Policy? (2026 Guide)
Yes — Etsy sellers in the US, EU, UK, Canada, and Australia are legally required to publish a privacy policy. Here is what to include, where to put it, and how to do it for free.
The short answer
Yes — if you run an Etsy shop, you are legally required to publish a privacy policy in almost every country Etsy operates in. That includes the United States (under state laws like the CCPA in California, VCDPA in Virginia, and the new Texas and Florida acts), the entire European Union and UK (under GDPR and UK GDPR), Canada (PIPEDA), Australia (Privacy Act 1988), and a growing list of others.
Etsy's own Seller Policy reinforces this. Section 6 of Etsy's Seller Policy states sellers are independently responsible for complying with applicable privacy laws and for the data they collect from buyers — Etsy will not write a policy for you.
This guide walks through what your privacy policy actually needs to cover, where to publish it on Etsy, and how to generate one for free in under two minutes.
Why Etsy sellers are personally on the hook
A lot of new sellers assume Etsy's platform-wide privacy policy covers them. It doesn't. Etsy's policy only covers what Etsy does with buyer data. The moment you collect anything yourself — a buyer's email through a Message, a shipping address you save in a spreadsheet, an email signup for a newsletter, an off-Etsy custom-order form — you become a separate data controller under GDPR, CCPA, and similar regimes.
That means:
- You need your own privacy policy.
- You must give buyers a lawful way to contact you about their data.
- You must honor requests to access, delete, or correct their data.
- You can be personally fined for violations, not Etsy.
Under GDPR, fines can reach €20 million or 4% of annual turnover — whichever is higher. California's CCPA caps civil penalties at $7,500 per intentional violation. For small sellers, the realistic risk isn't a regulator at your door — it's a buyer complaint to Etsy that gets your shop suspended, or a "data subject access request" you don't know how to handle.
What your Etsy privacy policy must include
A compliant policy for an Etsy shop should cover, at minimum:
- Who you are. The legal name (or trading name) of your shop, your country, and a contact email a buyer can actually reach you on.
- What data you collect. Names, shipping addresses, email addresses, order history, message contents, payment confirmations from Etsy (note: Etsy handles the actual card data — you never see it).
- Why you collect it. Fulfilling orders, providing customer support, sending shipping updates, responding to messages, marketing (if you do email marketing).
- Who you share it with. Shipping carriers (USPS, Royal Mail, DHL, etc.), printing partners if you do print-on-demand (Printful, Printify, Gelato), email marketing platforms if you use them (Mailchimp, ConvertKit), accounting software.
- How long you keep it. Most Etsy sellers default to 7 years for order records (matches tax retention requirements in most countries) and "until unsubscribe" for marketing lists.
- Buyer rights. Right to access their data, right to delete, right to correct, right to data portability (GDPR), right to opt-out of "sale" of personal info (CCPA — even if you don't technically sell data, you must mention this).
- International transfers. If you ship internationally, name the regions and the legal basis (Standard Contractual Clauses for EU→US, etc.).
- Cookies and tracking. Only relevant if you also run your own off-Etsy website or use tracking pixels. For Etsy-only shops, this section is short.
- Last updated date. Required under most privacy laws.
- How to contact you about privacy. An email like
privacy@yourshop.comor your standard contact email.
A generated policy from PolicyGenie automatically handles all of these and toggles in the right jurisdiction clauses based on where you and your buyers are.
Where to publish it on Etsy
Etsy gives sellers two places to publish a privacy policy:
1. Your Shop Policies tab
Go to Shop Manager → Settings → Policies → Privacy. Paste your generated policy directly into the field. Etsy will display it to any buyer who clicks "Shop policies" on your storefront. This is the bare minimum and is what Etsy's Seller Policy expects.
2. Your shop's "About" or "Announcement" section (optional)
Include a one-line link if you keep your full policy on an external website (recommended for sellers who also operate an off-Etsy site). Example: "Read our full privacy policy at yourshop.com/privacy."
3. In every marketing email (mandatory if you email buyers)
If you collect emails from buyers (with their consent — important) and send them marketing, every email must include a link to your privacy policy and an unsubscribe link. This is a CAN-SPAM, GDPR, and CASL requirement.
What happens if you don't have one?
Three realistic outcomes for Etsy sellers without a privacy policy:
- Buyer complaint → shop review. A buyer files a complaint about their data. Etsy's Trust & Safety team reviews your shop. Without a policy, you're in breach of Etsy's Seller Policy and risk suspension.
- Regulator inquiry (low probability, high impact). Regulators in the EU and California occasionally sweep small sellers, especially after a buyer complaint. The first letter is usually a request to produce your policy and your records of processing.
- Lost sales. Buyers from Europe and California increasingly check for a privacy policy before making purchases from unknown shops. A missing policy is a trust signal — a bad one.
How to create your Etsy privacy policy for free (2 minutes)
- Open the free privacy policy generator.
- Toggle "Etsy" as your platform and select your country and the countries you ship to.
- Answer 12 short questions (shop name, email, what services/integrations you use).
- Download the PDF and the DOCX, copy the plain-text version, and paste it into Shop Manager → Settings → Policies → Privacy.
- Save. Re-review every 12 months or any time you change tools (add Mailchimp, switch to Printful, etc.).
That's it. You're compliant, your shop policies are complete, and you have a downloadable record in case Etsy or a buyer ever asks.
Common Etsy privacy policy mistakes
- Copying another shop's policy. Other sellers' policies are written for their tools, their countries, and their integrations. Copying creates inaccurate disclosures, which is itself a violation.
- Using a US-only policy when you ship to the EU. If you ship to the EU or UK even once, you fall under GDPR and the policy must reflect that.
- Skipping the "data sharing" section. Almost every Etsy seller shares data with carriers and (often) print-on-demand or fulfilment partners. Not disclosing those partners is a common GDPR violation.
- Listing tools you don't use. "Just in case" lists hurt you — under GDPR you can only collect/share data for stated, specific purposes.
- Never updating the "last updated" date. A policy dated 2021 signals to regulators that you haven't reviewed your data practices. Update at least annually.
Final checklist
- Privacy policy generated and customized to your shop
- Pasted into Shop Manager → Settings → Policies → Privacy
- Privacy contact email reachable
- Date updated within the last 12 months
- Marketing emails include policy link and unsubscribe
- Off-Etsy website (if any) hosts the same policy at
/privacy
If you tick all six, you're ahead of 80% of Etsy sellers — and you've done it in less time than it takes to list a new product.
Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.
Get the next guide in your inbox
One compliance deep-dive per month. No spam, ever.