Copied policies describe someone else’s business
A privacy policy is a factual statement about what you collect, why, and who you share it with. Borrowed from another site it describes their practices, which makes it inaccurate about yours in ways that matter if anyone checks.
They are read more than you think
Procurement teams, enterprise buyers and cautious individuals do read them, and increasingly assistants summarise them when asked about your data practices. A vague or contradictory policy becomes part of how you are described.
Your privacy policy is a factual claim about your systems. Copying one makes it a false claim about your systems.
Start from what you actually do
List the tools that receive visitor data: analytics, forms, chat, embedded video, mail. That inventory is the policy’s content, and building it usually reveals trackers nobody remembers adding — which also makes your consent banner smaller.
Say where the data goes and for how long
Retention and recipients are the questions people are actually asking. Being specific is both more useful and easier to keep true than boilerplate about respecting privacy.
Include the AI systems
If an assistant handles enquiries, that involves processing and often a third party. It belongs in the policy — the retention decision you made for conversation logs needs stating publicly.
Keep them current
Policies go stale whenever tools change, which happens more often than anyone updates them. Add them to the review that checks facts are still true, and take real advice for anything consequential.