Back to Just the Facts

Just the Facts · Article

Three documents nearly every site gets wrong

Not because they're missing — because they describe a website that no longer exists. A test you can apply to the ones you already have.

Privacy policy, cookie policy, terms of use. Most sites have at least the first. The common failure isn't absence — it's that the document was copied from a template years ago, describes tools you no longer use, omits the ones you added since, and carries a date that gives the game away.

This matters more than it sounds. A policy that describes practices you don't follow is worse than no policy at all: it's a written statement, published by you, that a regulator or a plaintiff can hold you to. In 2025 California's largest privacy settlement to date turned partly on a consent banner that claimed to disable tracking and didn't.

Privacy policy — the test

  • Does it name the actual categories of information you collect, including the things collected automatically — IP addresses, device identifiers, pages viewed?
  • Does it name the third parties you send data to, by name, not as "our trusted partners"? Open your own site with the browser's network tab open and compare that list to your policy. On most sites they don't match.
  • Does it say how long you keep things, and why?
  • Does it explain how someone asks what you hold or asks you to delete it — and does that route reach a person who will answer?
  • Is the last-updated date within the life of the current website?

Cookie policy — the test

It should list what actually gets set, grouped by what it's for, and it should match reality. This is the document most easily checked against the truth and most often contradicted by it. If your cookie policy lists four cookies and your site sets thirty, that gap is documented, dated and published by you.

Terms of use — the test

Terms matter less than people think for a brochure site and more than people think the moment you take bookings, payments, accounts or user submissions. The questions worth asking: is it clear what someone is agreeing to and when they agreed? Does it say who owns what a user uploads? Does it limit your liability in a way that a court would find was actually presented to the reader, rather than buried in a footer link nobody clicked?

The thing we won't do

We won't hand you a template. Generated legal text is how sites end up publishing claims about practices they don't have — the exact failure above. What the scan gives you is a list of what's missing or stale, and what your site actually does, so that whoever writes the document is describing something real.

Practical order of work: find out what your site really collects and where it sends it, then write the policy to match. Almost everyone does it the other way round, which is why almost every policy is wrong.

Educational only, and emphatically not legal advice. These documents have legal effect; have a qualified attorney review anything you publish.