July 2026 · Platform Guide

Privacy Policy for Squarespace Sites: Free Generator & Guide

Squarespace is one of the most popular website builders for creatives, small businesses, and online stores. Unlike many platforms, Squarespace does not use Google Analytics by default — it runs its own privacy-focused analytics system. Between Squarespace Commerce, Email Campaigns, Member Areas, Form Blocks, and Acuity Scheduling, there is a lot to cover in your privacy policy. Here is exactly what you need to include.

Squarespace-Specific Privacy Considerations

1. Squarespace Analytics (No Google Analytics by Default)

Squarespace comes with its own built-in analytics system that tracks page views, traffic sources, visitor locations, device types, and browsing behavior. Unlike most other platforms, Squarespace does not automatically install Google Analytics — you must add it manually via code injection. Squarespace Analytics collects anonymized aggregate data alongside individual visitor session data. Your privacy policy must disclose that Squarespace Analytics tracks visitor behavior using first-party cookies and that this data is stored on Squarespace's own servers.

2. Squarespace Cookies: Crumb, SS, Test & More

Squarespace sets several platform-specific cookies that you must list. The primary cookies include: Crumb (security, prevents cross-site request forgery — essential), SS (session identifier, used for site functionality), Test (used by Squarespace for testing new features and A/B experiments), _squarespace_session (session management), _squarespace_analytics (analytics tracking, first-party), sq-site-cookie (stores cookie consent preferences), sq-traffic (traffic source attribution), and JSESSIONID (maintained by Squarespace's Java application server). Squarespace also sets Locale and Currency cookies for sites with multi-currency or localization enabled.

3. Squarespace Commerce & Payments

Squarespace Commerce collects extensive customer data: full name, email address, shipping address, billing address, phone number, order notes, IP address, and purchase history. Squarespace does not process payments directly — it integrates with Stripe (primary), PayPal, and Square. Credit card data goes directly to the payment processor via Stripe.js or PayPal's hosted checkout. Your privacy policy must name each payment processor and link to their privacy policies. If you use Squarespace's Commerce Tax automations, additional location data is collected for tax calculations.

4. Squarespace Email Campaigns

Squarespace Email Campaigns lets you send newsletters and promotional emails directly from your Squarespace dashboard. It collects subscriber email addresses, names, signup source (which form or page), open rates, click-through rates, and unsubscribe history. Squarespace uses its own email delivery infrastructure (integrated with SendGrid on the backend) to send emails. Your privacy policy must disclose that email campaign data is stored on Squarespace's servers and that you use third-party email delivery services. Also disclose whether you use the built-in "automated email" triggers (abandoned cart recovery, order confirmations, welcome sequences).

5. Squarespace Member Areas

Squarespace Member Areas allow you to create gated content accessible only to logged-in members. If you use Member Areas, you collect registration data (email, name, password), login history, IP addresses, content access logs, and any custom profile fields you add. Member Areas can also integrate with third-party authentication providers (Google OAuth, Apple Sign In, Facebook Login). Each integration introduces additional data collection by the provider. Your policy must disclose all authentication providers used.

6. Squarespace Form Blocks

Squarespace Form Blocks are a primary data collection point on most Squarespace sites. Form submissions — including contact forms, newsletter signups, application forms, and order forms — are stored directly on Squarespace's servers and emailed to the site owner. Squarespace does not encrypt form submission data at rest by default. Form submissions may be retained indefinitely unless you manually delete them. Your privacy policy must disclose what form data you collect, how long you retain it, and that it is transmitted and stored via Squarespace's infrastructure.

7. Acuity Scheduling

Acuity Scheduling is Squarespace's appointment booking tool. It collects client names, email addresses, phone numbers, appointment history, cancellation/rescheduling history, payment data (if paid appointments), and any custom intake forms. Acuity stores data on Squarespace servers and integrates with calendar services (Google Calendar, iCloud, Outlook) and video conferencing (Zoom). Your privacy policy must disclose appointment scheduling data practices, including that client data is shared with integrated calendar and video services.

8. Squarespace GDPR Cookie Banner

Squarespace includes a built-in GDPR cookie banner that you can enable in the site settings. It detects visitor location by IP address and automatically shows cookie consent options to EU visitors. The banner supports granular opt-in categories (Essential, Analytics, Marketing) and stores consent in the sq-site-cookie cookie. However, the banner only covers cookies — it does not replace a full privacy policy that covers data collection, processing, retention, and sharing practices across all Squarespace features.

Generate Your Squarespace Privacy Policy — Free

Select "Privacy Policy", choose "Squarespace" as your platform, and check the features you use — Commerce, Email Campaigns, Member Areas, Acuity Scheduling, and third-party integrations.

Generate Squarespace Privacy Policy →