Policy Generator
Generate a privacy policy, cookie policy, terms of service, disclaimer and accessibility statement from your business profile and the services detected on your site, embed them on your own pages, and link them from your banner.
The Policy Generator writes five documents for your site: a Privacy Policy, a Cookie Policy, Terms of Service, a Disclaimer and an Accessibility Statement. All five start from a short business profile you fill in once. The Privacy Policy and Cookie Policy also start from the services ConsentStack has detected on your site, so they name your real analytics, advertising and security tools instead of a list you have to remember and keep up to date yourself. The Terms of Service and Disclaimer come from your answers alone, and the Accessibility Statement from your answers plus any accessibility menu detected on your site.
ConsentStack hosts every version you publish, gives you an embed code for your own pages, keeps your banner's policy links pointing at them, and updates the Privacy Policy and Cookie Policy as your tools change. The Policy Generator is included on every plan, including Basic.
For an overview of what the generator does, see the Policy Generator page.
ConsentStack generates the text from your answers and what it detects on your site. It isn't legal advice, so review your documents with your counsel.
You can also set up and publish policies with an AI agent through the ConsentStack MCP server.
Where to find it
Open a site and choose Policies in the sidebar. The page has one card per document. Each card shows its status (Not started, Draft, Published or Needs review) and, once the document is on your website, the page it was last seen on.
Workspace Owners and Admins can write and publish documents. Members can see the cards and open a published document, but can't edit it.
Set up your business profile
Every document draws on the same business profile, so you answer these questions once per site. Until the profile is complete, the document cards can't be started. Click Set up profile on the Policies page to fill it in.
| Section | What it asks |
|---|---|
| Your business | Your legal business name, business type, where the business was formed, the website addresses your documents cover, and where you store and handle personal information. The first website address is the one named at the top of each document. |
| Privacy contact | Who handles privacy requests from your visitors. Canadian law asks you to name the person accountable for your privacy practices; if that is someone else, switch on the second contact. Otherwise the policy names your privacy contact. |
| Policy behavior | Who your website is for (a general audience, or children), how you'll tell visitors when a document changes, and whether your site stops tracking when a browser sends a Do Not Track signal. |
| United States | The states where you do business and whose residents' information you collect, plus your revenue, how many consumers' information you handle each year, whether you sell personal information, and whether you qualify as a small business. |
| Outside the United States | Whether you serve or collect information from people in the EU or EEA, the United Kingdom, Canada (and Quebec), or Australia. |
ConsentStack uses the last two sections to work out which privacy laws apply to you. That decides which rights your Privacy Policy lists, which residents each right applies to, and how quickly you promise to respond to a request.
To change your answers later, use the Business profile button at the top of the Policies page. Each document uses the new profile from the next time it publishes, so publish your documents again to put a change live.
Write a document
Open the editor
Click Start on a document's card. The questions are on the left, split into sections, and a live preview of the finished document is on the right.
Answer each section
Some answers are already filled in for you, as described below for each document. The preview updates as you answer. If a required answer is missing, the preview names the question and gives you a button that takes you to it.
Publish
Your changes save automatically as a draft, and nothing changes on your website until you click Publish. Use Discard to throw away a draft and go back to the published version.
Your documents link to each other: the Privacy Policy links to your Cookie Policy, and the Cookie Policy and Terms of Service link to your Privacy Policy. A link is filled in when the document that carries it publishes, so start with the Privacy Policy. If you publish a document before the one it links to, publish it again afterwards to add the link.
The five documents
Privacy Policy
Explains what personal information you collect, where it comes from and why, who you share it with, and the rights your visitors have under the laws that apply to you. Its questions come in these sections:
| Section | What it covers |
|---|---|
| What you collect | The personal information you collect, where it comes from and why you use it, plus whether you combine it, use it for targeted advertising or profiling, or use it to train AI models. |
| Who you share with | Whether you share personal information with third parties, what you share with each kind of provider, and whether you sell it. |
| Your practices | Whether your site sets cookies, how you protect personal information, how long you keep it, and whether you use it for direct marketing. |
| Text messaging | Your SMS program, if you have one: the number messages come from, how often you send them, and how to opt out. |
| Exercising rights | What you need from a visitor to verify a request, and what an authorized agent must provide on their behalf. |
| Named services | The analytics, advertising and security services the policy names one by one. |
ConsentStack also adds:
- Your rights: each right, the residents it applies to and your response window, from the laws your business profile says apply.
- Global Privacy Control: if your banner honors Global Privacy Control, the policy says so.
- Last updated: the date the policy was published.
Cookie Policy
Lists the services on your site, grouped by your banner's consent categories, with what each one does, who provides it, which cookies it sets and for how long, and how to opt out. It also explains how visitors can change their choices, through your banner's preferences, their browser settings and, if your banner honors it, Global Privacy Control.
Its main section, Services and cookies, is the list of services (see Detected services). The only other question is an optional introduction of your own.
Terms of Service
Sets the rules for using your website: what visitors may not do, who owns your content, the limits of your liability and the law that governs disputes. It doesn't read your detected services, so it comes from your answers alone.
| Section | What it covers |
|---|---|
| Offers | Whether you sell through your website, what you offer, and anything to note about pricing. |
| Purchases | Whether visitors buy directly on your website, the payment methods you accept, and your cancellation, refund, advance payment and deposit terms. |
| Accounts | Whether visitors can create an account, and the minimum age. |
| Conduct | Anything else visitors may not do. A standard list of prohibited uses is always included. |
| Text messaging | Your SMS program, the number messages come from and how often you send them. |
| Intellectual property | Who owns your website's content (your legal business name unless you enter another), and who receives copyright (DMCA) notices. That is your privacy contact unless you switch on a separate contact. |
| Disputes | The law that governs the Terms, filled in from where your business was formed; where disputes are brought; whether you require binding arbitration and individual claims instead of class actions; and an optional minimum liability limit. |
The Terms limit your liability to what the customer paid you in the 12 months before a claim, or to the minimum liability limit you enter in Disputes if that is greater. Offers, purchases, accounts and text messaging appear in the Terms only when you say they apply.
Disclaimer
Tells visitors the limits of what your website promises, for example that its content isn't professional advice or that you may earn from affiliate links. It doesn't read your detected services: you pick the disclaimers that apply.
The choices are advertising, affiliate links, professional advice, medical advice, legal advice, financial advice, fitness advice, testimonials and reviews, links to other websites, errors and omissions, use of copyrighted material (fair use), and views of guest authors or contributors. Errors and omissions and links to other websites are selected to start. Picking affiliate links lets you list the programs you belong to, and picking professional advice asks which field. You can also add a sentence or two of your own.
Accessibility Statement
Tells visitors that you want your website to be usable by people with disabilities, which standard you aim to meet, and how to contact you if something is hard to use. It never claims more than you tell it.
| Section | What it covers |
|---|---|
| Introduction and goal | The Web Content Accessibility Guidelines (WCAG) version and level you aim for, WCAG 2.2 at level AA to start, plus an optional sentence of your own. Switch on State how well the site conforms today only if an assessment backs it up: you then choose partially or fully conforms and say how the site was assessed, and you can't publish until you do. |
| What we do | Steps you take, such as testing with screen readers. Nothing is checked to start, so check only what you actually do. |
| Accessibility tools | Any accessibility menu on your site, such as UserWay or accessiBe. ConsentStack fills this in from what it detected when you first open the statement. The statement describes a menu as an optional extra for visitors, never as what makes your site accessible. |
| Known limitations | Parts of your site that aren't fully accessible yet. The statement offers to provide that content another way. |
| Feedback | Who visitors contact: your business name with your privacy contact's email and phone, unless you switch on a separate accessibility contact. You can add how many business days you aim to reply within. |
With only your business profile filled in, the statement gives your goal and how to contact you, and you can publish it as it is.
Detected services
The Privacy Policy and Cookie Policy are built from the services ConsentStack has detected on your site, the same list as your Trackers page. A tracker you ignore or block there stays out of your documents, and a tracker you move to another category there appears under that category.
Until the banner is installed and has seen visitors, your most recent compliance scan of one of the site's domains fills the list instead.
What's filled in for you
The first time you open the Privacy Policy editor, ConsentStack fills in what it already knows from your detected services:
- What you collect comes pre-checked with the information your detected services gather through cookies, such as IP address, device identifiers and how visitors interact with your website.
- Who you share with comes pre-filled with the kinds of providers you use, such as analytics providers and advertising networks.
Each pre-checked item names the services it came from (for example, Detected: Google Analytics 4, Meta Pixel).
This happens on the first open only. After that, your answers stay as you left them: automatic updates never change them, and applying a reviewed change about a new service only adds what that service collects and shares.
Named services
The Privacy Policy names each detected analytics, advertising and security service in a table with these columns: Service, Provider, Purpose, Privacy policy (a link to the provider's policy) and Opt out (a link to its opt-out page, where the provider offers one). Other kinds of service, such as a payment processor, aren't named one by one in the Privacy Policy. The Cookie Policy lists every service.
Edit the list
The Privacy Policy's Named services section and the Cookie Policy's Services and cookies section list the services, grouped by your banner's consent categories. Each one is marked Detected, From scan or Added by you. Changes you make in one document's list don't affect the other. In each list you can:
- Switch a detected service off to leave it out of that document.
- Open a service's details to give it a different name in that document.
- Add a service ConsentStack can't detect by searching for it under Add a service you use.
The Privacy Policy's list holds only analytics, advertising and security services, so add other tools, like a payment processor, in the Cookie Policy.
Detection only sees services that run in your visitors' browsers. Payment processors, email marketing platforms, CRMs and other tools you use behind the scenes won't be pre-filled. Add them to the Cookie Policy yourself, and add what they collect and who you share it with in the Privacy Policy's What you collect and Who you share with sections.
Add the policy to your website
Open the menu on a document's card and choose Get embed code. Paste the snippet where the document should appear on your website. For the Privacy Policy it looks like this:
<link rel="preconnect" href="https://policies.consentstack.io" crossorigin>
<style>[data-cs-policy]:not([data-cs-policy-state="filled"],[data-cs-policy-state="error"]){min-height:100vh}</style>
<div data-cs-policy="privacy-policy" data-cs-key="<YOUR_SITE_KEY>">
<noscript><a href="https://policies.consentstack.io/<YOUR_SITE_KEY>/privacy-policy">Read our privacy policy</a></noscript>
</div>
<p class="cs-policy-attribution">Policy generated and kept current by <a href="https://www.consentstack.io/privacy-policy-generator">ConsentStack</a></p>
<script src="https://cdn.consentstack.io/policy.js" async></script>Each document has its own snippet, so copy it from that document's card rather than from this page. The dashboard's copy already has your site key filled in.
| Platform | Where to paste it |
|---|---|
| Squarespace | A Code block on the document's page |
| WordPress | A Custom HTML block |
| Webflow | An Embed element |
| Anything else | Any place that accepts raw HTML |
The embed works whether or not the ConsentStack banner is installed on that page. You only paste it once: every time the document publishes, the embed shows the new version, with no need to paste again.
Once the page loads on one of your site's domains, the card shows where the document is live, for example Live on example.com/privacy, seen 2h ago. Visitors with JavaScript turned off see a link to the hosted copy instead.
Choose a layout
The embed sheet has a Layout setting for each document:
- Accordion folds each detailed entry, such as a kind of information in the Privacy Policy or a service in the Cookie Policy, into a row visitors can expand.
- Flat shows every entry open, one after another.
Changing the layout updates every embed and the hosted page within a few minutes. The Terms of Service, Disclaimer and Accessibility Statement have no expandable rows, so they look the same either way.
Use the hosted page
Every published document is also hosted at its own address:
https://policies.consentstack.io/<YOUR_SITE_KEY>/privacy-policyThe other documents end in cookie-policy, terms-of-service, disclaimer and accessibility-statement. The embed sheet shows each link, and View on a published card opens it. Use it if you don't have a page to paste the embed into. The hosted copy asks search engines not to index it, so it never competes with the page on your own site.
Attribution
On the Basic plan, the embed code ends with a line crediting ConsentStack, and the hosted page shows the same line. While branding is on, the document carries the credit at its end even if you delete the line from your page.
On paid plans you can remove it with the Remove branding feature. In the Config Builder's Settings tab, turn off Show ConsentStack branding and publish. This removes the credit from your banner and all your documents together. If you pasted the embed code before turning branding off, delete the attribution paragraph from your page, or paste a fresh copy of the embed code.
Link the policy from your banner
Your banner should link to your Privacy Policy and Cookie Policy. You only need to add each link once:
Open the banner text
In the Config Builder, open the Content tab and click into the banner description where the link should go.
Insert the policy link
Click the link icon in the text toolbar, then the document icon in the link bar that opens, and choose the document. The menu lists the documents you've published. If no text is selected, the document's name becomes the link text.
Publish your banner
Publish the Config Builder as usual so the new text goes live.
From then on, the link follows your document. It points to the page where your embed is live, or to the hosted page until the embed has been seen on your site. Until your banner links to each published Privacy Policy and Cookie Policy, the Policies page reminds you and opens Content for you.
If you keep your own privacy policy instead of generating one, you don't need the Policies page at all. Click the link icon in the text toolbar and type your page's address into the link bar, like any other link.
Versions
Every publish, yours or an automatic update, creates a new version, and every version stays available at its own address. Choose Versions in the card menu to see each one with its publish date and why it was published (First version, Edited answers, Automatic update or Reviewed update), and open any of them. The hosted address followed by /versions lists them all.
An older version opens with a notice giving the date it was published and the date it was replaced, so you can show exactly what your document said at any point.
Keeping your policies current
ConsentStack checks your published Privacy Policy and Cookie Policy against your detected services once an hour. Facts update on their own. Anything that changes what a policy promises waits for you.
What updates on its own
Each of these publishes as a new version marked Automatic update:
- A new tool in a category the policy already covers, such as a second analytics tool.
- Removing a tool that has been gone from your site for 48 hours. A tool that disappears for a day and comes back stays.
- Updated provider details and cookie durations, and cookies a tool starts or stops setting.
- Changes to your banner's consent categories (adding or removing one, or changing their names, descriptions or order) or its Global Privacy Control setting, once you publish them in the Config Builder.
- Template updates from ConsentStack that need nothing new from you. These reach every document.
Automatic updates never change your answers.
What waits for your review
These change what a policy promises, so nothing goes live until you act:
- The first tool in a category the policy didn't cover before, such as your first advertising tool.
- A tool that ConsentStack's catalog lists as selling or sharing personal information (for example, for targeted advertising).
- A template update that needs a new answer from you.
- Live detections replacing the compliance scan the policy was first written from.
- A business profile that is missing or incomplete.
While a change waits, that policy's other automatic updates wait too.
Waiting changes appear in a Needs review list at the top of the Policies page, and the Policies item in the sidebar shows how many there are. Click Open to go to the document's editor, where each change is explained at the top:
- Apply publishes the change. For a template update, answer the new question right there first.
- Leave out of policy appears for a tool the policy doesn't name yet. It publishes a new version, marked Reviewed update, that leaves the tool out, and keeps it out so the same change doesn't come back.
The daily email
Once a day, ConsentStack emails your workspace's Owners and Admins a summary of its policies: the automatic updates published in the last 24 hours, and every change still waiting for review, with a button to review each site's changes. The email only goes out when something new happened in the last 24 hours.
Terms of Service, Disclaimer and Accessibility Statement
The Terms of Service, Disclaimer and Accessibility Statement don't depend on your detected services. They change only when you publish new answers, or when a template update reaches them. The Accessibility Statement looks at your detected services once, to fill in any accessibility menu when you first open it.
Copy answers from another site
Each site has its own business profile and its own documents, since different websites often collect different information and use different services. To start a site from another site's answers, open the site's Settings and click Copy from another site on the Copy policy answers card. Workspace Owners and Admins can copy between sites in the same workspace.
It replaces this site's business profile and each document's draft answers with the other site's. It doesn't copy published versions, so this site's live documents keep their text until they next publish.
Check the business profile straight after copying, especially the website addresses, which still belong to the other site. Every publish reads the profile, including automatic updates, so the copied profile reaches this site's live documents at the next one.