Website basics

What Legal Pages Does My Website Actually Need?

Most small sites launch with zero legal pages, and most of the time nothing happens - until something does: a payment dispute with no refund terms to point to, a GDPR complaint with no privacy policy, or a platform (Google AdSense, Stripe, the App Store) that simply won't approve you without one. Here's what each page actually does, when you need it, and what the real risk is if you skip it - no scare tactics, just the honest version.

Terms of Service (ToS)

What it does: sets the rules for using your site or product - acceptable use, account termination, intellectual property, limitation of liability, and which law governs disputes. It's the contract between you and every visitor or user.

When you need it: if users create accounts, submit content, or use a paid product or service. A pure brochure site with no accounts and no user content can often skip it, though it's cheap insurance either way.

What happens without it: not much, day to day - but if a user disputes a charge, abuses your platform, or claims ownership over something they submitted, you have no stated rules to point to. Courts also generally won't enforce a liability limitation you never disclosed.

Privacy Policy

What it does: discloses what personal data you collect (name, email, IP address, payment info, analytics data), why, how it's stored, who it's shared with, and what rights users have over it.

When you need it: almost always, and often legally required rather than optional - if you use analytics, run ads, collect emails, or take payments, you're collecting personal data and disclosure is required in most jurisdictions (GDPR in the EU/UK, CCPA in California, and similar laws elsewhere). Google Analytics and most ad networks require a linked privacy policy as a condition of use.

What happens without it: this is the one with real regulatory teeth. GDPR and CCPA both carry statutory penalties for non-disclosure, ad networks can suspend your account, and app stores will reject a submission that lacks one. It's the single highest-priority page on this list for almost any site that collects any data at all.

Cookie Notice / Cookie Policy

What it does: discloses what cookies and tracking technologies your site uses (analytics, ads, session cookies) and, where required, lets visitors accept or decline non-essential ones.

When you need it: if you use any tracking or analytics cookies and you have EU/UK/certain other visitors, a cookie notice with consent is a legal requirement (this is the ePrivacy Directive alongside GDPR, not GDPR itself). Purely essential, functional cookies (keeping someone logged in) generally don't require consent, only disclosure.

What happens without it: for sites with real EU traffic, this is a genuine compliance gap, and it's one of the more commonly enforced ones because it's easy to check with a browser's dev tools. For a small US-only audience, the practical risk is lower, but disclosure is still good practice.

Disclaimer

What it does: states the limits of what you're offering - that content is for informational purposes, not professional advice; that results aren't guaranteed; that external links aren't endorsements. It manages expectations and limits liability for advice-style content.

When you need it: any site giving advice in a regulated-adjacent area - health, finance, legal, fitness - should have one. A blog with general opinions has less need; a calculator or template tool that people rely on for a real decision benefits from a clear "this is a starting point, not professional advice" line.

What happens without it: low regulatory risk, but real reputational and dispute risk - if someone acts on your content and it goes badly, an explicit disclaimer is what separates "you should have known this wasn't guaranteed advice" from a legitimate grievance.

Refund Policy

What it does: states, in specific terms, whether refunds are offered, the window to request one, and the process. "All sales final" and "14-day money-back guarantee" are both valid refund policies - the point is stating one clearly, not necessarily being generous.

When you need it: any site selling a paid product or service. Payment processors like Stripe and platforms like Gumroad often require a stated refund policy, and having no policy doesn't mean you avoid refund requests - it just means you handle every dispute from scratch with no stated terms to fall back on.

What happens without it: chargebacks become harder to contest (a documented, disclosed refund policy is standard evidence in a chargeback dispute), and buyers get inconsistent outcomes depending on who's answering support that day.

GDPR and CCPA, in plain terms

These aren't separate pages - they're legal frameworks your privacy policy and data practices need to satisfy, and it's worth knowing which applies to you. GDPR applies if you have visitors or customers in the EU or UK, regardless of where your business is based - it requires disclosure of what you collect, a lawful basis for collecting it, and specific user rights (access, deletion, portability). CCPA (and its update, CPRA) applies to businesses meeting certain size or revenue thresholds that handle California residents' data, and grants similar rights - know what's collected, opt out of sale/sharing, and request deletion. For a small site, the practical response to both is the same: a clear, accurate privacy policy that actually describes what you collect, plus a straightforward way for someone to ask you to delete their data.

This is general information, not legal advice. What's actually required depends on where your visitors are, what data you collect, and what you sell - and the specifics change by jurisdiction. For a site handling payments, sensitive data, or meaningful traffic, it's worth having a qualified professional in your jurisdiction review your final pages, especially the privacy policy.

The honest priority order

If you're starting from zero and can only do this in stages: privacy policy first (highest regulatory exposure and most commonly required by tools you already use), then terms of service if you take payments or user content, then a refund policy if you sell anything, then a disclaimer if you give advice, then a cookie notice if you have EU traffic and use tracking cookies. Most small sites can reach a reasonably solid legal footing with all five in an afternoon.

You don't need a lawyer to get a first, solid draft of each of these - you need accurate, specific answers about what your site actually does and collects, put in writing where visitors can find them. The free PolicyForge generator builds a plain-English privacy policy covering analytics, cookies, ads, payments, and GDPR/CCPA rights in your browser, no signup, so you can get the highest-priority page done in a few minutes.

More SoloDesk tools

We're expanding the legal template library beyond the free generator - full ToS, refund, and disclaimer packs. Check back or browse what's live now.

Browse the store →