Do I Need a Privacy Policy If I Don't Sell Anything?
A common myth among indie developers, hobbyists, and non-profits is that “I don’t sell anything, so I don’t need a privacy policy.” It’s understandable — most privacy-policy advice is written for e-commerce stores processing credit cards. But whether you sell or not is almost irrelevant. What matters is whether you collect personal data.
The short answer: if your website or app collects any personal data from visitors, you need a privacy policy — even with $0 in sales. Here’s exactly when, and why.
What Counts as “Collecting Personal Data”?
You’re collecting personal data if your site or app does any of the following — and most do:
- Contact forms (name + email)
- Email newsletter signups (Mailchimp, ConvertKit, Substack)
- Analytics cookies (Google Analytics, Plausible, Fathom)
- Comment sections (WordPress, Disqus)
- User accounts or logins
- Embedded third-party content (YouTube, Google Maps, social feeds)
- Payment info — only if you actually process payments
Notice that none of these require a sale. A free portfolio site with a “Contact me” form and a Google Analytics tag is collecting personal data from every visitor.
The Laws Don’t Care About Revenue
Major privacy laws are triggered by data collection and audience, not commerce:
- GDPR (EU/EEA/UK): applies if any EU resident can reach your site. A free blog read by Europeans is in scope.
- CCPA/CPRA (California): applies to for-profit businesses meeting revenue or data-volume thresholds — but many free sites still fall under CalOPPA, which requires a posted privacy policy for any commercial website collecting personally identifiable information.
- COPPA (US): applies if you collect data from children under 13 — regardless of whether you charge.
- PIPEDA (Canada), LGPD (Brazil), DPDP Act (India), PDPA (Singapore): all keyed to data handling, not sales.
The only websites that genuinely don’t need a privacy policy are those collecting no personal data at all — no forms, no analytics, no cookies, no accounts. For the vast majority of real-world sites, that’s not the case.
Real Examples of “Free” Sites That Still Need One
- A photographer’s portfolio with a contact form + Google Analytics → needs a policy.
- A church or ministry website with a prayer-request form → needs a policy.
- A free open-source app with crash reporting (Firebase) → needs a policy.
- A personal blog with newsletter signup → needs a policy.
- A non-profit collecting donor emails → needs a policy.
The Cost of Skipping It
Beyond legal exposure (GDPR fines up to 4% of global revenue, CCPA penalties per violation), the practical risks hit free projects hardest:
- Platform lockout: Google AdSense, the Apple App Store, and Google Play all require a privacy policy. No policy = no monetization later, even if you’re free today.
- Lost trust: visitors increasingly check. A missing policy reads as “sketchy.”
- Analytics/broken integrations: some tools won’t activate without a linked policy URL.
The Easy Fix
You don’t need a lawyer or a budget. Generate a free privacy policy with PrivacyPolGen — answer 5 questions, get a complete policy in under 60 seconds, no signup, nothing sent to a server. It covers GDPR, CCPA, and more out of the box.
- Running a store instead? See our guide to a privacy policy for Shopify.
- Not sure which laws apply? Our GDPR vs CCPA breakdown explains the differences.
- Need the companion document too? Generate a Terms & Conditions policy as well.
Related articles
Privacy Policy for WordPress Sites: Complete Guide 2026
Every WordPress site that collects data needs a privacy policy. Learn what WordPress requires, the plugins that collect data, and how to add a compliant policy in minutes.
GDPR Privacy Policy Template: Free Guide + Generator Tips
Complete GDPR privacy policy template with generator tips. Learn how to create compliant policies that protect users while being user-friendly.
GDPR vs CCPA: Key Differences Every Website Owner Should Know
Understand the key differences between GDPR and CCPA — scope, user rights, penalties, and compliance requirements for your website or business.