These are starting-point structures, not finished legal documents — have an attorney review your actual policies before publishing them, especially the privacy policy, since accuracy about your specific data practices matters more than polish for that one. Never publish a privacy policy that describes data practices you don't actually follow; an inaccurate privacy policy is arguably worse than a vague one, since it creates its own separate compliance exposure (a policy that misrepresents your practices) on top of whatever underlying practice gap it's covering up.
Return and refund policy: sections to include
A return/refund policy is both a legal disclosure and a customer-facing trust document — buyers actively check it before purchasing, especially for higher-consideration items, so treat clarity as a conversion factor, not just a compliance checkbox.
- Return window — how many days after delivery (or purchase) a buyer has to initiate a return. Be specific about what the window is measured from (delivery date vs. order date) since this is a common point of buyer confusion and dispute.
- Condition requirements — unopened/unused, original packaging, tags attached, or whatever condition standard applies, and whether any categories are final-sale/non-returnable (commonly: personal care/hygiene items, custom/personalized products, perishables, digital goods, opened intimate apparel — but confirm what's appropriate and defensible for your specific catalog rather than copying a generic list uncritically).
- Who pays return shipping — you, the customer, or a hybrid (like free return shipping for a defective/wrong item, customer-paid for a change-of-mind return). Say this plainly, since ambiguity here generates a disproportionate share of customer service friction.
- Refund method and timing — original payment method vs. store credit, and a realistic timeframe for when a buyer should expect to see the refund reflected (accounting for your own processing time plus the payment processor's own posting time, which is often outside your direct control).
- Restocking fees, if you charge one — disclosed clearly and specifically, not buried, since an undisclosed restocking fee is a common source of chargeback and dispute risk.
- Exchanges — whether you offer a direct exchange path (different size/color) as distinct from a return-and-repurchase, and how that's handled operationally.
- Damaged/defective/wrong-item process — this should generally be more generous and more clearly explained than a standard change-of-mind return, since it's not the buyer's fault, and treating it identically to a standard return is a common source of avoidable customer dissatisfaction.
- How to initiate a return — a clear, specific process (a self-service portal link, an email address, a required RMA number) rather than vague language that leaves the buyer guessing what to actually do.
- International order handling, if relevant — customs, duties, and return shipping logistics for cross-border orders are often meaningfully different from domestic returns and worth their own explicit section if you ship internationally.
Privacy policy: sections to include
- What data you collect — be specific and complete: account/contact information, order and payment information (noting what your payment processor handles directly versus what you store), browsing/behavioral data via cookies and analytics tools, and anything collected through marketing sign-ups or loyalty programs.
- Why you collect it — order fulfillment, customer service, marketing (only where you have appropriate consent/basis for it), analytics, fraud prevention, and legal/compliance recordkeeping.
- Who you share it with — this needs to be specific and current, not generic: your payment processor, shipping carriers, email/SMS marketing platform, analytics and ad-pixel providers, and any other third-party tool with access to customer data. A generic "we may share data with third parties" without naming categories or examples is weaker than a specific, accurate list.
- Cookies and tracking — what categories of cookies/trackers you use (essential, analytics, advertising) and how a visitor can control or opt out of the non-essential ones (see GDPR and CCPA Basics for Ecommerce Sites).
- Data retention — roughly how long you keep different categories of data, even if only in general terms (e.g., "order records are retained for as long as needed for tax and accounting purposes").
- User rights and how to exercise them — access, correction, deletion, opt-out of sale/sharing, and a genuinely working contact method or process for making a request, not just a promise that rights exist.
- International data transfers, if relevant — if you're processing EU residents' data but your servers/vendors are outside the EU, this generally needs disclosure and an appropriate legal transfer mechanism.
- Children's privacy — a statement about whether your site is directed at or knowingly collects data from minors, and what your policy is if it isn't (most general ecommerce sites explicitly state they don't knowingly collect data from children below a certain age).
- Policy update process — how you'll notify users of material changes to the policy, and the effective date of the current version.
- Contact information — a real, monitored contact method for privacy-related questions or requests, not a dead-end address.
Sections most often missing from a bought/copied template
- A specific, accurate list of third-party tools/vendors — most generic templates use vague placeholder language here, but an accurate list matters both for genuine compliance and because you'll actually need to know this list when handling a data-subject request.
- A genuinely functioning process for exercising rights — plenty of templates promise rights that the business has no actual internal process to fulfill.
- Category-specific return exclusions that actually match your catalog (a generic template's exclusion list may not match what you actually sell).
- Clear return-shipping-cost ownership — many sellers leave this ambiguous in practice even when the policy document technically states something, causing repeated customer service disputes.
- A cookie-specific disclosure/consent mechanism distinct from the general privacy policy text, especially if you have any EU traffic.
How to use a template responsibly
- Start from a template structure (like the section lists above) to make sure you're not missing a category of disclosure, but write the actual content to reflect your real practices — don't leave placeholder or generic language that doesn't describe what you actually do.
- Have an attorney review the final policies, particularly the privacy policy, before publishing — the cost of a review is generally modest relative to the risk of an inaccurate or non-compliant policy, especially once you're collecting a meaningful amount of customer data.
- Revisit both policies whenever your actual practices change (a new marketing tool, a new international shipping destination, a new return-exclusion category) — an out-of-date policy that no longer matches practice is a liability in its own right.
- Link both policies clearly and consistently from your site footer and, for the return policy specifically, from the product page or checkout flow where a buyer is actually likely to look for it before purchasing.
Common mistakes
- Publishing a generic template's privacy policy without editing it to reflect your actual data practices.
- Leaving return-shipping-cost responsibility ambiguous, generating avoidable customer service disputes.
- Not naming actual categories of third-party vendors you share data with, using vague boilerplate instead.
- Never revisiting either policy after your practices (new tools, new markets, new product exclusions) change.
- Skipping attorney review entirely, especially for the privacy policy once you're collecting meaningful customer data.
FAQs
- Can I just copy a competitor's policy? No — beyond potential copyright issues with lifting their text directly, their policy describes their practices, not yours, and an inaccurate policy creates its own compliance exposure.
- Do I need a separate cookie policy from my privacy policy? Not necessarily as a fully separate document, but you do need clear, specific cookie disclosure and consent mechanics somewhere accessible — some sites fold it into the privacy policy, others give it a dedicated page or banner-linked document.
- How often should I update these policies? Whenever your actual practices change in a way the current policy doesn't reflect, and it's good practice to review both at least annually even without a known change, since vendor tools and legal requirements evolve.