If you've recently started an ecommerce business using WooCommerce, you're going to be focused on sales, suppliers, and investment. But you have other important duties too, such as complying with privacy law.
As an ecommerce business, you need to collect and process the personal information of your customers, your potential customers, and the visitors to your website.
How You Collect Personal Information
There are probably two main ways in which you collect personal information:
- When your users provide it to you voluntarily (e.g. via order forms, emails, etc.)
- When you collect it automatically (e.g. via cookies and analytics tools)
You might also receive personal information from third parties, such as social media channels or subsidiary companies.
Your users provide the following types of personal information to you voluntarily:
- Email address
- Phone number
- Shipping address
- Payment card details
- Billing address
Here's an example from ecommerce store Boodles:
Boodles explains that people might provide their personal information via the following channels:
- Filling in forms
- Via telephone
- Attending events
- Visiting Boodle stores
- Registering to use the website
- Entering a competition or promotion
- Reporting a problem with the site
- Contacting Boodle
- Placing an order
In addition to the personal information your customers provide to you, there's also the personal information you automatically collect from visitors to your website. The means by which you collect this type of personal information might include:
- Cookies, pixels, and web beacons
- Crash reporting
The types of personal information you collect in this way might include:
- IP address
- Cookie ID
- Device ID
- Operating system
- Browser type
- Website or app usage information
- Referral information (i.e. the website the visitor came from)
Here's an example from PhotoBite:
You might be surprised to see some of these types of data listed as "personal information." However, personal information is defined very broadly, especially in places such as California, Canada, and the EU.
How You Use Personal Information
The table below describes some typical activities of an ecommerce business, together with the types of personal information it might need to collect for these purposes.
|Some typical activities of an ecommerce business:
||Types of personal information it might need to collect for these purposes:
|Communicating with a customer about their order or their customer service queries:
||Name, email address, phone number
|Processing a customer's order:
||Name, shipping address, billing address, payment card details
||Cookie ID, email address
|Improving your website or app:
||Analytics data, e.g. website usage
|For security and fraud prevention:
||IP address, cookie data
|Setting up an account:
Here's how clothing retailer River Island explains some of the ways in which it uses personal information:
- What cookies are
- Why you use them
- What types of cookies you use
- Whether you use tracking cookies that can log user activity on other websites
- How long each type of cookie you use will remain on your users' device
- How users can disable cookies
Third Parties With Whom You Share Personal Information
Practically every business needs to share personal information or to allow other companies to collect personal information on its behalf.
If you run a WooCommerce store, it's likely that your customers' personal information will be processed by third parties such as Wordpress, WooCommerce, and Stripe (which processes payments on behalf of WooCommerce Payments).
You might also share personal information with:
- Email marketing companies such as MailChimp
- Online survey companies such as SurveyMonkey
- Mail carriers such as FedEx
The business lists Wordpress, WooCommerce, Google Analytics, and MonsterInsights among the third parties with which it shares personal information.
You should also provide links to the Privacy Policies of your third-party service providers.
Here's how jewelry retailer Eileen Gatt does this:
Note that you don't necessarily have to identify your third parties service providers by name. It may be sufficient to list the types of third parties with which you share personal information (e.g. "payment processors," "mail carriers").
You should provide contact details for your company in case visitors have any questions about your privacy practices.
Here's an example from Kefi:
Note that Kefi has set up a dedicated email address to deal with privacy queries. This helps the business demonstrate to its customers it's taking their privacy seriously.
Additional Information By Region
If you have customers in the US, your main concern should be complying with that state privacy law of California, specifically the California Online Privacy Protection Act (CalOPPA).
CalOPPA applies to all commercial websites that are accessible in California.
- Identify the types of personal information you collect
- Identify the types of third parties with whom you share personal information
- Disclose how your website treats browser "Do Not Track" signals
- Disclose whether you use tracking cookies
Here's an example of how Medtronic discloses how its website treats "Do Not Track" signals:
- California "Online Eraser" Law
- California "Shine the Light" Law
- California Consumer Privacy Act (CCPA)
European Union and United Kingdom
The EU has the highest privacy standards in the world, and the UK still enforces them despite having left the EU.
If you have customers in the European Economic Area (the EEA, which includes all 27 EU countries plus Iceland, Liechtenstein, and Norway) or the UK, you must comply with the General Data Protection Regulation (GDPR).
Here's how Bowles & Wyer explains how users can make a complaint to the UK's Data Protection Authority, the Information Commissioner's Office (ICO):
Note that the business encourages users to make a direct complaint before going to the ICO. This is perfectly reasonable.
- Provide contact details for whoever is responsible for managing privacy in your business
- Explain how users can access and rectify the personal information you hold about them
- Identify the types of personal information you process
- Explain how you use personal information
- Provide copies of any other relevant company policies
- Explain how you share personal information with third parties
Here's how Bayer Canada explains the right to access personal information under PIPEDA:
Here's our guide to privacy laws by country to help you out.
Here's how Woocommerce-powered clothing retailer The Neighbourgoods does this:
Here's how the WooCommerce-powered website Spike Island does this:
Newsletter Signup Form
Here's how WooCommerce-powered website The Wellbeing Project does this:
Check the other legal requirements that might apply in your target markets.
- In your website's footer
- At checkout
- On your newsletter or direct marketing signup page