You must have a privacy and cookie policy if your site collects, uses or stores personal data, uses cookies or third‑party tools.
You must have a privacy and cookie policy when your website or app collects, uses or stores personal data about visitors or users.
This especially applies if you:
Collect personal data – such as name, email address, phone number or other identifying information.
Use cookies – to track the user's behaviour, e.g. for statistics or marketing purposes.
Use third‑party tools – such as Google Analytics or Facebook pixels, which can also collect user data.
In the EU, under the GDPR (General Data Protection Regulation), you are required to inform users about what data you collect, how it is used, and obtain their consent where required. The same applies in many other jurisdictions with similar data‑protection legislation.
A cookie policy is also typically required if you use cookies that are not strictly necessary for the website to function (e.g. analytics or marketing cookies).
Therefore, under GDPR rules you must ask your visitors for cookie consent and set up a privacy and cookie policy on your website.
Article from the support category: iubenda