I get asked this one a lot, usually from a client who saw a scary email about GDPR or read that some other business got fined for something website-related. I build custom websites for service businesses and I am not a lawyer, so take this as a plain-English starting point, not legal advice. But here is the honest answer based on what actually applies to a typical plumber, med spa, or restaurant site.
Does a Small Business Website Need a Privacy Policy?
For most small local service businesses, no federal law requires a privacy policy just for having a website. There is no single US law like Europe's GDPR that covers every business. What exists instead is a patchwork: a few state laws that only kick in above certain size or revenue thresholds, and a set of platform rules from Google and Meta that apply the moment you use their tools. In practice, most businesses end up needing a policy anyway because of that second category, not the first.
Which Laws Actually Require a Privacy Policy?
California's Consumer Privacy Act (CCPA), enforced by the California Attorney General's office, is the one people usually mean when they ask about this. It only applies to a business if it meets one of three thresholds: more than $25 million in annual gross revenue, buying or sharing the personal data of 100,000 or more consumers or households a year, or earning at least half its revenue from selling personal data. A five-page site for a local roofer or dentist almost never hits any of those numbers.
A handful of other states, including Virginia, Colorado, Connecticut, and Utah, have passed similar laws since 2023, and most use comparable size thresholds. Europe's GDPR is different: it is not about your business size, it is about whether you collect data from people in the EU. A Texas HVAC company with no EU customers and no reason to expect any is very unlikely to fall under it in practice, even though the rule technically applies based on whose data you collect, not where you are located.
The Federal Trade Commission enforces broader deceptive-practices rules that apply regardless of size: if you post a privacy policy and then do something different from what it says, that mismatch itself can be a violation. So the risk is not "must I have one," it is "don't lie in the one you post."
Do You Need One Even If the Law Doesn't Require It?
Almost certainly, yes, for a reason that has nothing to do with government regulation. If your site runs Google Analytics or Google Ads, Google's own terms of service require you to disclose your data collection practices in a privacy policy. Meta has the same requirement for businesses running Facebook or Instagram ad pixels. These are not optional add-ons for most service businesses chasing local leads, they are core marketing tools, which means the policy requirement comes along with them whether or not any privacy law technically applies to your revenue size.
There is also a plain trust factor. A customer who is about to hand over their name, phone number, and address through your contact form or booking widget is more comfortable doing it on a site that is upfront about what happens to that information next.
What Should a Small Business Privacy Policy Actually Say?
Keep it specific to what your site actually does. A good policy for a typical service-business site covers:
- What you collect automatically (IP address, browser type, pages visited, usually through your analytics tool)
- What visitors give you directly (name, email, phone, and message content through contact forms)
- What third-party tools touch that data (Google Analytics, an ad pixel, your hosting provider, an email or CRM tool)
- How you use it (responding to inquiries, improving the site, sending updates if they opt in)
- How a visitor can ask questions or request their data be deleted, with a real contact method
Skip the generic boilerplate that lists data practices you do not actually have, like selling data to third parties if you never do. A privacy policy that overstates what you collect just to sound thorough creates the exact mismatch the FTC cares about.
How Much Does It Cost to Get a Privacy Policy?
Pricing varies a lot depending on how much risk you are trying to cover.
| Option | Typical cost | Best for |
|---|---|---|
| Free generator tool | $0 | A simple contact-form-only site with no e-commerce or EU traffic |
| Paid template service | $50 to $200 one-time | A business that wants a more tailored document without hiring a lawyer |
| Attorney-drafted policy | $300 to $1,500+ | E-commerce, health data, or any business near a state law threshold |
For the vast majority of the plumbers, electricians, and roofers I build sites for, a solid free or low-cost template covers what the site actually does. If your business processes payments directly, stores health information, or is close to those CCPA-style revenue thresholds, that is when it is worth paying an attorney to look at it, the same way I would tell a client to get a lawyer for a lease instead of using a template.
Once you have a policy, publishing it costs nothing extra since it is just another page. On our $150/month plan, adding a privacy policy page does not use up any of your page allowance in a way that matters since it is a small, simple page, and on the $3,500 one-time plan it is a normal part of the build.
What Happens If You Don't Have One?
For most small businesses below the state law thresholds, nothing happens automatically, there is no privacy-policy police checking every local business site. The real exposure shows up in a few specific ways: a Google Ads or Analytics account can get flagged or suspended for missing a required disclosure, a customer complaint can turn into a bigger deal if you have nothing in writing about your data practices, and if your business ever grows past a state threshold, you want the habit already in place rather than scrambling to add it retroactively.
This is a smaller, quieter risk than something like ADA website accessibility lawsuits, which target small businesses directly and aggressively. A missing privacy policy is more likely to cost you a suspended ad account than a lawsuit, but it is still a loose end worth closing since it takes so little effort compared to the downside.
What Should You Do Next?
If you are running Google Ads, Google Analytics, or a Meta pixel, and most local service businesses are, add a privacy policy page this week. A free generator plus 20 minutes editing it to match what your site actually collects covers the large majority of cases. If you take online payments, handle health information, or you are already a large operation, spend the money on an attorney instead of trusting a template.
Either way, do not treat it as a set-and-forget page. Anytime you add a new booking tool, a live chat widget, or a new ad platform, take two minutes to make sure the policy still matches reality. That habit costs you almost nothing and it closes off the one part of this that regulators actually care about: saying one thing and doing another.