Squarespace's own platform-level privacy notice covers Squarespace as a company, what it does with billing and account data for site owners. It says nothing about what your specific site collects from your visitors, because it can't, Squarespace has no way of knowing which form blocks you've added, whether you've turned on Acuity booking, or what you're selling through Commerce. That's a document you have to write yourself, built around your own site.
Here's how to write one that actually matches what a Squarespace site collects: the built-in form blocks, Acuity Scheduling if you've connected it, Squarespace's own analytics, and Commerce checkout data if you're running a store.
Form blocks collect more than they look like they do
Squarespace's drag-and-drop Form Block is the most common data-collection point on a typical Squarespace site, and it's easy to underestimate because adding one takes seconds. Every submission through a Contact Form or a custom Form Block is stored in Squarespace's own backend (visible under the block's Storage panel) and, if you've connected an email notification, forwarded to your inbox as well. Whatever fields you've added, name, email, phone, a free-text message, a dropdown, all of it persists in that storage panel indefinitely unless you delete entries manually.
If you've connected a Form Block to Mailchimp, Klaviyo, or another email platform (Squarespace supports native storage integrations to several providers), that submission is no longer just sitting in your Squarespace backend, it's been forwarded to a third party's list, and that provider needs naming in your policy the same way any other data recipient would.
The built-in Newsletter Block works the same way but with a narrower purpose: it collects just an email address (sometimes a name) for the specific goal of adding someone to a mailing list, either Squarespace's own Email Campaigns tool or a connected third-party provider.
Squarespace features and what they collect
| What it collects | Must be named | |
|---|---|---|
| Form Block / Contact Form | Name, email, phone, custom fields | Squarespace storage plus any provider |
| Newsletter Block | Email address, sometimes name | Email Campaigns or connected provider |
| Acuity Scheduling | Name, email, phone, intake answers | Acuity by name, as a separate processor |
| Squarespace Analytics | Page views, device, approximate location | That built-in analytics is enabled |
| Commerce checkout | Address, phone, order history, payment | Squarespace Payments or your gateway |
Acuity Scheduling is a separate processor, not part of your site
If your Squarespace site has a booking or scheduling page, it's very likely running on Acuity Scheduling, which Squarespace owns but operates as a distinct product with its own data storage. When a visitor books an appointment, Acuity collects their name, email, phone number, and any intake form answers you've configured, and stores that data on Acuity's own systems, separate from your Squarespace site's storage panel.
This is worth calling out explicitly in your privacy policy rather than folding it into a generic "we use third-party tools" sentence, because Acuity functions as its own data processor with its own retention behavior and its own privacy notice a client can look up independently. If your intake form asks for anything sensitive, health information for a wellness business, financial details for a consulting intake, that's exactly the kind of specific data type a privacy policy needs to name rather than gloss over.
Squarespace's built-in analytics runs even if you never added Google Analytics
Every Squarespace site collects visitor analytics by default through Squarespace's own Analytics panel, page views, referrer, approximate location, and device type, without you installing anything. Many site owners assume they have no analytics running because they never added Google Analytics, and write a privacy policy that mentions no tracking at all. That's inaccurate: Squarespace's built-in analytics is on unless you're using an older plan tier that predates it, and it needs disclosing the same as any third-party analytics tool would.
If you've also connected Google Analytics or Google Tag Manager, which Squarespace supports natively through Settings > Advanced, that's a second, separate disclosure on top of the built-in tool, not a replacement for it.
Commerce checkout adds a payment layer
If you're selling through Squarespace Commerce, checkout collects a fuller data set: full name, shipping and billing address, phone number, and payment details, processed through Squarespace Payments or a connected gateway like Stripe or PayPal, depending on your setup. Squarespace itself doesn't retain full card numbers, the payment processor does, but your policy should still name whichever processor you use, since that's the entity actually storing sensitive payment data.
Commerce also generates order history tied to customer accounts if you've enabled account creation at checkout, and any abandoned-cart or post-purchase email automations you've turned on are their own data flow worth a line, since they involve Squarespace (or a connected app) reaching back out to someone based on incomplete checkout data.
Where to publish and link it on Squarespace
Squarespace has a dedicated home for legal pages: under Settings > Legal Pages (or Website > Legal Pages on newer sites), you can add and designate a Privacy Policy page directly, and Squarespace surfaces it automatically in the footer of most templates once it's set there rather than added as an ordinary page. That's the most reliable placement, it survives template switches better than a manually added footer link.
If you're running Commerce, also check that your checkout flow itself references the policy, most Squarespace checkout templates show a small link near the payment button by default once a Legal Page is configured, but it's worth confirming after any major template change.
Get a Squarespace-accurate policy without starting from scratch
Writing an accurate privacy policy by hand means tracking every form block, confirming whether Acuity or Commerce are connected, and keeping the document current as you add integrations. Our Privacy Policy Generator builds a policy around your actual data sources, forms, booking tools, and payment processors, so the document you publish matches your real Squarespace setup instead of a generic template.
For the equivalent guide on another builder platform, see our Shopify privacy policy guide, or read the anatomy of a compliant privacy policy for a section-by-section breakdown of what a finished policy should contain.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.