If your website or mobile app uses Google Analytics, you definitely need to have a Privacy Policy.

This article breaks down this requirement both legally and from Google, and explains how you can comply. We've also put together a Sample Google Analytics Privacy Policy Template that you can use to help you write your own.

Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:

  1. At Step 1, select the Website option or App option or both.

    TermsFeed Privacy Policy Generator: Create Privacy Policy - Step 1

  2. Answer some questions about your website or app.

    TermsFeed Privacy Policy Generator: Answer questions about website - Step 2

  3. Answer some questions about your business.

    TermsFeed Privacy Policy Generator: Answer questions about business practices  - Step 3

  4. Enter the email address where you'd like the Privacy Policy delivered and click "Generate."

    TermsFeed Privacy Policy Generator: Enter your email address - Step 4

    You'll be able to instantly access and download your new Privacy Policy.



If You Use the Standard Features of Google Analytics

If You Use the Standard Features of Google Analytics

Google Analytics stores cookies on your users' PCs to keep track of usage data. This is enough to evoke the requirement of a Privacy Policy according to the EU Cookies Directive. The EU's GDPR also requires a Privacy Policy when usage data is collected, such as through cookies.

When you use Google Analytics, you can opt-in to getting access to analytics and usage data plus advertising features that allow you to create better marketing campaigns. The use of these features that include retargeting triggers the requirement to update your Privacy Policy to inform users about your usage of retargeting identifiers through Google's network.

In the Google Analytics Terms of Service agreement there's a requirement that users of Google Analytics must have a Privacy Policy agreement in place.

There are a few things you need to do if you take advantage of the standard features offered by Google Analytics. We'll review them now and show you how to implement them.

Disclose the Use of Google Analytics in Your Privacy Policy

The Privacy Policy must disclose that analytics is used, disclose how data is collected and processed, and provide notice of the use of cookies.

Here's the clause in the Terms of Service agreement that sets forth these requirements and provides suggestions for meeting them:

Google Analytics Terms of Service: Privacy clause

Your Privacy Policy should be easily accessible to visitors directly from your website or mobile app, such as in a footer link or mobile app "About" menu.

This makes it easy for users to locate and view your agreement whenever they want to.

Here's an example of how Upwork includes a link to its Privacy Policy and other legal agreements in its website footer:

Upwork website footer with Privacy Policy link highlighted: 2022

Because so many businesses place their legal agreement links in their website footer, people know to check there.

You can also include a pop-up or banner message, such as the one in the image below, that tells your users that cookies are in use. Include a link to your Privacy Policy (and Cookie Policy) in this pop-up or banner message to make sure relevant information is easily accessible:

Linden Lab cookies notice with active consent: Agree and Proceed

Include information about your use of Analytics cookies in your Privacy or Cookie Policy and make it clear that you're using Google Analytics to gain insights and improve the functionality of your website, or for marketing purposes.

Here's how Indeed.com does this in a clause in its Cookie Policy:

Indeed Cookie Policy: How we use cookies clause excerpt

Give users the ability to opt out of having cookies placed for the purposes of Google Analytics and let them know that they have this right.

There's an opt-out browser add-on from Google that helps make opting out incredibly easy and convenient for users. You can mention and link to this add-on in your Privacy Policy:

Screenshot of Google Analytics Opt-out Browser Add-on tool page

Disclose the Use of Remarketing Features in Your Privacy Policy

If you use the Google Analytics Remarketing Lists feature, you're required to agree to the Google Analytics Terms of Service. These Terms require you to have an informative Privacy Policy that discloses that Google Analytics Remarketing uses cookies to track users who visit your website or use your mobile app and display your ads to these users when they are on other websites.

Google Analytics Prerequisites to remarketing with requirement to agree to Analytics Terms of Service highlighted

While the exact language you should include isn't provided by Google, you should focus on being clear, concise, and informative.

Here's a checklist of what to include in your agreement:

  • Let users know that you use remarketing and that this will advertise your company or website across other websites that users visit.
  • Let users know that Google and other third-party vendors will show your ads on websites that users visit after visiting your website.
  • Let users know that your ads will be shown on other websites because the user visited your website in the past.
  • Let users know how they can opt out of this remarketing campaign through the Google Ad Settings page.

Here's a clause from NextRoll's Privacy Notice that's a great example of how to let users know all of this information:

NextRoll Privacy Notice: Cookies and related technologies clause excerpt

Another clause in the Privacy Notice addresses how users can opt out of or adjust targeted ads and the use of their personal data:

NextRoll Privacy Notice: Your choices and opting-out of interest-based advertising and analytics clause excerpt

NextRoll provides an AdChoices feature where a user can adjust advertising preferences quickly and easily. It's linked in the website footer:

NextRoll website footer with AdChoices link highlighted

Users who click on the link are taken to a screen where they are given the ability to adjust individual ad remarketing settings. Consent can be revoked or granted for all advertising and analytics cookies with one click, or individually adjusted:

Screenshot of AdRoll

If you use NextRoll, AdWords, or a different remarketing tool, you can add a link on your website to a page or module like this. Having something like this one is a great way to allow your users to choose which cookies they wish to allow and opt out of behavioral ads if they want to.

If You Use the Advertising Features of Google Analytics

If You Use the Advertising Features of Google Analytics

If you choose to enable remarketing or any of the Google Analytics Advertising features, Google requires that you notify your visitors by disclosing the following 3 main points in your Privacy Policy, as stated in the Policy Requirements from Google:

Google

Google Analytics Advertising tools lets you take the usage data and information you obtain from Google Analytics and use it for advertising purposes. Remarketing, also known as retargeting, is a widely used and incredibly popular function of Google Analytics.


Google Analytics Advertising Features

Which Google Analytics Advertising Features have you implemented? In your Privacy Policy, include a list of all features and links to more information about each of the features you have implemented for your website so that users can be aware of them.

For example, if you use Google AdWords for remarketing purposes, declare this and consider including links to both Google's Remarketing website, as well as the general Google Privacy Policy as it applies to AdWords usage.

Disclose the use of cookies and identifiers

Disclose that you and third-party vendors use first-party cookies (such as the Google Analytics cookie) or other first-party identifiers, and third-party cookies (such as Google advertising cookies) or other third-party identifiers together. Do this through a Cookies Policy or at least a cookies clause in your Privacy Policy.

You need to let users know that you use third-parties for advertising and how these third-parties may use cookies.

If your business is based in the EU or you sell to EU customers, there are additional requirements you must meet in order to satisfy the EU Cookies Directive because all remarketing service are based on cookies usage.

Visitors to your website or mobile app must give informed, specific, and voluntary consent to have cookies placed on their devices before any cookies are placed.

The most common way that this requirement is satisfied is through the use of pop-up banners that appear prominently on a web page the first time a user visits a website. The banner informs a user about the use of cookies and requires some sort of active action from the user to give consent.

In this example from the BBC, a user must click the "Continue" button before cookies can be used. The notification box clearly states that by clicking the "Continue" button, the user is consenting to BBC's use of cookies:

BBC Notification: Cookies on website

How visitors can opt out

How visitors can opt out of the Google Analytics Advertising Features you use, including through Ads Settings, Ad Settings for mobile apps, or any other available means (for example, the NAI's consumer opt-out).

Google has its own available opt-out tool for Google Analytics that they encourage you to linking to, as noted earlier in this article. Linking to it is a great way to satisfy the requirement that users must be informed on how to opt-out.

If you're developing a mobile app and not a website, your Privacy Policy should be accessible from within the app.

Dropbox accomplishes this by putting a "Legal and Privacy" section in its "Settings" tab that links to its Privacy Policy.

Highlight Legal & Privacy Item in Dropbox iOS App

Here's an example from The Sierra Trading Post's Privacy Policy that discloses its use of the Google Analytics features:

Sierra Trading Post Privacy Policy: Opt-out and Restrict Cookies and Online Behavioral Advertising clause

If you have enabled the Advertising Features in your Google Analytics account, update your Privacy Policy by adding a new clause titled "Interest-Based Online Advertising and Google Analytics" or something similar, and make sure it includes the required information about your usage of these features.

Summary of a Google Analytics Privacy Policy

Download Sample Google Analytics Privacy Policy Template

Generate a Privacy Policy in just a few minutes

Our Sample Google Analytics Privacy Policy is available for download, for free. The template includes these sections:

  • Definitions
  • Collecting and Using Personal Information
  • Usage Data
  • Use of Personal Information
  • Transfer of Personal Information
  • Disclosure of Personal Information
  • Security of Personal Information
  • Detailed Information on the Processing of Your Personal Data
  • Links to Other Websites
  • Changes to Privacy Policy
  • Contact Information

Sample Google Analytics Privacy Policy Template (HTML Text Download)

You can download the Sample Google Analytics Privacy Policy Template as HTML code below. Copy it from the box field below (right-click > Select All and then Copy-paste) and then paste it on your website pages.

Sample Google Analytics Privacy Policy Template (PDF Download)

Download the Sample Google Analytics Privacy Policy Template as a PDF file

Sample Google Analytics Privacy Policy Template (Word DOCX Download)

Download the Sample Google Analytics Privacy Policy Template as a Word DOCX file

Sample Google Analytics Privacy Policy Template (Google Docs)

Download the Sample Google Analytics Privacy Policy Template as a Google Docs document

Sample Google Analytics Privacy Policy Template

More Privacy Policy Templates

More specific Privacy Templates are available on our blog.

Sample Privacy Policy Template A Privacy Policy for all sorts of businesses.
Sample Mobile App Privacy Policy Template A Privacy Policy for mobile apps on Apple App Store or Google Play Store.
Sample GDPR Privacy Policy Template A Privacy Policy for businesses that need to comply with GDPR.
Sample CCPA Privacy Policy Template A Privacy Policy for businesses that need to comply with CCPA.
Sample California Privacy Policy Template A Privacy Policy for businesses that need to comply with California's privacy requirements (CalOPPA & CCPA).
Sample Virginia VCDPA Privacy Policy Template A Privacy Policy for businesses that need to comply with Virginia's VCDPA.
Sample PIPEDA Privacy Policy Template A Privacy Policy for businesses that need to comply with Canada's PIPEDA.
Sample Ecommerce Privacy Policy Template A Privacy Policy for ecommerce businesses.
Small Business Privacy Policy Template A Privacy Policy for small businesses.
Sample CalOPPA Privacy Policy Template A Privacy Policy for businesses that need to comply with California's CalOPPA.
Sample SaaS Privacy Policy Template A Privacy Policy for SaaS businesses.
Sample COPPA Privacy Policy Template A Privacy Policy for businesses that need to comply with California's COPPA.
Sample CPRA Privacy Policy Template A Privacy Policy for businesses that need to comply with California's CPRA.
Blog Privacy Policy Sample A Privacy Policy for blogs.
Sample Email Marketing Privacy Policy Template A Privacy Policy for businesses that use email marketing.

Privacy Policy Generator
Comprehensive compliance starts with a Privacy Policy.

Comply with the law with our agreements, policies, and consent banners. Everything is included.

Generate Privacy Policy