3 Things Your Privacy Policy Should Have

In my last post I discussed why I think virtually every small biz website should have a privacy policy. This time, I’d like to discuss three things every policy should have, which I commonly find to be missing.
First, a quick run-down of the basic purpose for a privacy policy is in order. Privacy policies basically fulfill two functions. They: 1) tell visitors what information you collect from them (whether the collection is overt, such as through an email opt-in, or covert, such as through tracking cookies); and 2) what you will and will not do with the information.
Now on to the three things every policy should have (but often don’t):
A Notice About Tracking Cookie Usage. If you use third-party analytics or ad serving, then it is virtually guaranteed that your site places tracking cookies on your visitors’ computers. If you have any sort of “sign-in” functionality to your site, chances are session cookies are also utilized keep users logged in, for security, or to make log-in easier. Your privacy policy should disclose your cookie usage, how information collected is used, and what cookies are controlled by third-parties. When appropriate, reference the privacy policies of these third-party cookie using providers so your visitors know what they do with information collected.
COPPA Notice. Whether or not your site is oriented toward collecting information from children under 13 years of age, you should be referencing the Children’s On-Line Privacy Protection Act (“COPPA”) in your privacy policy. On one hand, if … Read the rest >>>