PrivacyPolGen
Generate
privacy policyGDPRCCPAcompliancesmall business

Do I Need a Privacy Policy If I Don't Sell Anything?

· Reuben Richard Lancer

A common myth among indie developers, hobbyists, and non-profits is that “I don’t sell anything, so I don’t need a privacy policy.” It’s understandable — most privacy-policy advice is written for e-commerce stores processing credit cards. But whether you sell or not is almost irrelevant. What matters is whether you collect personal data.

The short answer: if your website or app collects any personal data from visitors, you need a privacy policy — even with $0 in sales. Here’s exactly when, and why.

What Counts as “Collecting Personal Data”?

You’re collecting personal data if your site or app does any of the following — and most do:

  • Contact forms (name + email)
  • Email newsletter signups (Mailchimp, ConvertKit, Substack)
  • Analytics cookies (Google Analytics, Plausible, Fathom)
  • Comment sections (WordPress, Disqus)
  • User accounts or logins
  • Embedded third-party content (YouTube, Google Maps, social feeds)
  • Payment info — only if you actually process payments

Notice that none of these require a sale. A free portfolio site with a “Contact me” form and a Google Analytics tag is collecting personal data from every visitor.

The Laws Don’t Care About Revenue

Major privacy laws are triggered by data collection and audience, not commerce:

  • GDPR (EU/EEA/UK): applies if any EU resident can reach your site. A free blog read by Europeans is in scope.
  • CCPA/CPRA (California): applies to for-profit businesses meeting revenue or data-volume thresholds — but many free sites still fall under CalOPPA, which requires a posted privacy policy for any commercial website collecting personally identifiable information.
  • COPPA (US): applies if you collect data from children under 13 — regardless of whether you charge.
  • PIPEDA (Canada), LGPD (Brazil), DPDP Act (India), PDPA (Singapore): all keyed to data handling, not sales.

The only websites that genuinely don’t need a privacy policy are those collecting no personal data at all — no forms, no analytics, no cookies, no accounts. For the vast majority of real-world sites, that’s not the case.

Real Examples of “Free” Sites That Still Need One

  • A photographer’s portfolio with a contact form + Google Analytics → needs a policy.
  • A church or ministry website with a prayer-request form → needs a policy.
  • A free open-source app with crash reporting (Firebase) → needs a policy.
  • A personal blog with newsletter signup → needs a policy.
  • A non-profit collecting donor emails → needs a policy.

The Cost of Skipping It

Beyond legal exposure (GDPR fines up to 4% of global revenue, CCPA penalties per violation), the practical risks hit free projects hardest:

  • Platform lockout: Google AdSense, the Apple App Store, and Google Play all require a privacy policy. No policy = no monetization later, even if you’re free today.
  • Lost trust: visitors increasingly check. A missing policy reads as “sketchy.”
  • Analytics/broken integrations: some tools won’t activate without a linked policy URL.

The Easy Fix

You don’t need a lawyer or a budget. Generate a free privacy policy with PrivacyPolGen — answer 5 questions, get a complete policy in under 60 seconds, no signup, nothing sent to a server. It covers GDPR, CCPA, and more out of the box.

Related articles

On this page
  1. What Counts as “Collecting Personal Data”?
  2. The Laws Don’t Care About Revenue
  3. Real Examples of “Free” Sites That Still Need One
  4. The Cost of Skipping It
  5. The Easy Fix