All guides

Privacy Policy for Newsletters: Substack, Beehiiv, & ConvertKit Guide

Learn how to create a compliant privacy policy for Substack, Beehiiv, or ConvertKit. Our guide covers GDPR requirements, CCPA, and essential clauses for creators.

PolicyGenie Editorial·May 2026· 8 min read
Page last updated · May 2026

Introduction: Why Your Newsletter Needs a Privacy Policy

The newsletter boom is in full swing. Whether you are building an audience on Substack, scaling a paid membership on Beehiiv, or managing complex automation sequences on ConvertKit, one thing remains constant: you are collecting personal data.

The moment someone enters their email address into your signup form, you have entered the world of data privacy regulation. Many creators believe that because they are "just a writer" or a "small founder," they are exempt from the heavy-hitting laws like GDPR or CCPA. This is a dangerous misconception.

A privacy policy isn't just a legal "box to tick"—it is a foundational element of trust between you and your subscribers. In this guide, we will break down exactly how to draft a privacy policy for your newsletter, why platforms like Substack and Beehiiv don't automatically cover you, and the specific clauses you need to stay compliant.

Who Needs This? Identifying Your Responsibility

If you use any of the major Email Service Providers (ESPs), you need a custom privacy policy. Here is why the "platform defaults" are often insufficient:

1. Substack Creators

Substack provides a general privacy policy for the platform, but as a publication owner, you are often considered a "Data Controller" for your specific list. If you export your list or use third-party tracking pixels (like Meta or Google Analytics), Substack’s standard terms may not fully describe your specific data practices.

2. Beehiiv Power Users

Beehiiv is built for growth, offering advanced features like referral programs, ad networks, and 1-click surveys. Each of these features involves collecting different types of data (referral links, interests, demographic info). You must disclose how this data is used for advertising and attribution.

3. ConvertKit (Kit) Strategists

ConvertKit is often the choice for professional creators who sell digital products. If you are tagging users based on their behavior, tracking link clicks to build profiles, or integrating with platforms like Shopify or Teachable, your privacy policy needs to be significantly more robust than a simple blog.

The Rule of Thumb: If you collect an email address, name, or IP address from a resident of the EU, UK, California, or several other US states (like Virginia or Colorado), you are legally required to have a privacy policy.

The Legal Basis: GDPR, CCPA, and Beyond

To understand what goes into your document, you first need to understand the "Big Three" regulatory frameworks:

GDPR (General Data Protection Regulation)

The gold standard of privacy. If you have even one subscriber in the European Union, you must comply. GDPR requires:

  • Lawful Basis: You must have a reason to process data (usually "Consent" for newsletters).
  • Data Minimization: Only collect what you actually need.
  • The Right to be Forgotten: Subscribers must be able to request total deletion of their data.

CCPA/CPRA (California Consumer Privacy Act)

If you have California-based subscribers, these laws apply. They focus heavily on "selling" and "sharing" data. For Beehiiv users using the "Beehiiv Ad Network," this is particularly important because sharing your subscriber data for ad targeting can be viewed as "sharing" under California law.

CAN-SPAM and CASL

While these are primarily anti-spam laws (affecting how you send email), they also mandate that your privacy policy be easily accessible. They require a clear "Unsubscribe" link and a physical mailing address in every email.

What to Include: The Newsletter Privacy Policy Checklist

When drafting your policy for Substack, Beehiiv, or ConvertKit, ensure these sections are clearly defined.

1. Information Collection

Be specific. Don’t just say "we collect data." List the items:

  • Email address (obviously).
  • Name (if applicable).
  • IP address (captured by the platform for security/location).
  • Browser type and device info.

2. How the Data is Collected

Explain the "how." For newsletters, this is usually:

  • Directly from the user via the signup form.
  • Automatically via "cookies" and tracking pixels (tell them if you use the Beehiiv or Substack tracking features).

3. Purpose of Processing

Why do you want this data?

  • To deliver the newsletter.
  • To personalize content.
  • To manage your referral program (if using Beehiiv).
  • To send marketing offers for your own products (if using ConvertKit).

4. Third-Party Sharing (The "Processor" List)

You aren't just keeping the data on your laptop. You are sending it to third parties. You must name your ESP:

  • "We use Beehiiv to manage our email marketing list. You can view their privacy policy at [Link]."
  • "We use Stripe to process payments for premium subscriptions."

5. Cookies and Tracking Pixels

Most newsletters use "tracking pixels" to see who opened an email or clicked a link. You must disclose this. If you use a Meta Pixel or Google Analytics on your Substack custom domain, you need a specific section on how these "cookies" work and how users can opt-out.

6. Data Retention

How long do you keep the data? For most newsletters, the answer is: "Until you unsubscribe or ask us to delete it."

7. Your Physical Address

Many creators forget this. Legally, you must provide a physical address (a P.O. Box is usually fine) to comply with the CAN-SPAM Act.

Common Mistakes Creators Make

Using a "Generator" for a Different Business Model

Don't use a privacy policy template designed for a "Mobile App" if you are a Substack writer. The data flows are completely different. A mobile app might request camera access; a newsletter never will. Using irrelevant clauses makes you look unprofessional and can confuse regulators.

Forgetting the "Sale of Data" Clause

If you are on Beehiiv and you participate in their Ad Network, you might technically be "sharing" data for cross-contextual behavioral advertising. Under CCPA, you must provide a way for users to opt-out of this specifically.

Hiding the Policy

Don't hide your policy behind three menus. It should be:

  • Linked in the footer of your newsletter website.
  • Linked on the "Welcome" or "About" page.
  • Linked near the "Subscribe" button if possible.

Failing to Update When Switching Platforms

If you migrate from Substack to ConvertKit, your privacy policy must change. You are moving from a platform where data ownership is shared/simplified to one where you have much more control and responsibility. The "Third-Party Processors" section must be updated immediately.

Platforms Specific Tips

For Substack Users

Substack's simplicity is its strength, but it's also a trap. Since you don't "own" the infrastructure, you must disclose that Substack Inc. is the data processor. If you have a custom domain (e.g., mail.yourbrand.com), you have even more responsibility to show that you control the user experience.

For Beehiiv Users

Pay close attention to the Referral Program. If a user refers a friend, you are collecting the friend's email address via the user. Your policy should mention that you collect information provided by users about third parties for the purpose of the referral program.

For ConvertKit (Kit) Users

ConvertKit is often used for "Segmentation." If you are tagging users as "High Value" or "Interested in Course A" based on their link clicks, this is technically "Profiling." GDPR requires you to disclose that you use automated decision-making or profiling to tailor the experience.

Real-World Example: The "Newsletter Flow"

Imagine a subscriber named Sarah.

  1. Direct Collection: Sarah sees your "Growth Hacks" newsletter on Beehiiv and enters her email.
  2. Automated Collection: Beehiiv logs Sarah’s IP address to determine she is in London.
  3. Third-Party Transfer: Beehiiv sends Sarah’s data to their servers (AWS).
  4. Behavioral Tracking: Sarah opens your first email. A tiny, invisible 1x1 pixel pings your Beehiiv dashboard to say "Open."
  5. Direct Marketing: Because Sarah clicked a link about "SEO," you use ConvertKit tags to send her an offer for your SEO course two days later.

Your privacy policy must cover every one of these 5 steps. If it only says "We collect your email," you are missing 80% of the story.

FAQ: Privacy Policies for Newsletters

1. Do I really need a policy if I have 0 revenue?

Yes. Privacy laws (especially GDPR) are about data protection, not revenue. If you collect a single email address from a person in a regulated jurisdiction, the law applies.

2. Can I just link to Substack's privacy policy?

No. Substack's policy covers their relationship with the user. You need a policy that covers your relationship with the subscriber, including what you do with the list if you export it or how you use it to sell your own products.

3. What is a "Data Processing Agreement" (DPA)?

This is an agreement between you and your ESP (Substack/Beehiiv/ConvertKit). Most of these platforms include a DPA in their Terms of Service. You should reference this in your policy to show that your "Processors" are also compliant.

4. How often should I update my policy?

At least once a year, or whenever you change your "Tech Stack." If you add a new analytics tool (like Fathom or plausible) or start using a new sponsor network, update the policy.

5. Does a "Link in Bio" need a privacy policy?

If your Linktree or Bio.site has an email signup form that feeds directly into your newsletter, yes. You should link to your privacy policy right below that signup box.

Conclusion: Building Trust Through Transparency

A privacy policy is more than just a legal shield; it’s a signal to your readers that you value them. In an era of data breaches and spam, being transparent about how you handle an email address can actually increase your conversion rates. People are more likely to subscribe when they know exactly what will happen to their data.

Don't let the complexity of GDPR or CCPA stop you from building your audience. By using a structured approach and selecting the right tools, you can stay compliant without needing a law degree.

Take Action Today

  1. Audit your stack: List every tool that touches your subscriber emails (ESP, Analytics, Payment Processors).
  2. Check your links: Ensure your "Unsubscribe" and "Privacy Policy" links are live and working.
  3. Generate a custom policy: Don't copy-paste a generic document. Use a tool that understands the specific needs of newsletter creators.

Ready to protect your newsletter? Use the PolicyGenie Privacy Policy Generator to create a professional, compliant policy for Substack, Beehiiv, or ConvertKit in less than 5 minutes. It’s free to start and built for creators like you.

Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.

Get the next guide in your inbox

One compliance deep-dive per month. No spam, ever.

Compliance updates, monthly.

One email a month. No spam. Unsubscribe anytime.