Free SaaS Terms of Service & Privacy Policy Template
Download This Resource
Free to download — no sign-up, no email, no account required
Get the fillable ToS + Privacy bundle, the editable version, and an action checklist:
If you are launching a SaaS product, a web app, or anything online that collects so much as an email address, two documents belong on your site before the first signup: a Terms of Service and a Privacy Policy. They do different jobs. The Terms of Service is a contract that protects you; the Privacy Policy is a disclosure the law requires the moment you touch personal data. This guide explains both in plain English, gives you the clause skeleton to build from, and, unlike most template pages, tells you honestly which privacy laws actually apply to a small SaaS in 2026 and which ones you are worrying about unnecessarily.
The short version (2026):
- The Privacy Policy is legally required once you collect personal data (an email counts); the Terms of Service is not required by law but is the contract that caps your liability and lets you remove abusive users.
- Roughly twenty states now have comprehensive privacy laws, and the platforms you depend on (app stores, Stripe, ad networks) require a published policy regardless of any statute.
- The CCPA has thresholds ($26.6M+ revenue, or data on 100,000+ California consumers counting devices and cookies, or selling data). Small SaaS products often sit below them, yet cross the 100k prong faster than founders expect.
- Describe what you actually do. A copied policy that promises encryption you don’t have, or deletion you can’t perform, creates liability instead of preventing it.
Terms of Service vs. Privacy Policy: Two Different Jobs

People lump these together because they live side by side in the footer. Legally they are opposites:
- Terms of Service (ToS) is the contract between you and your users. It sets the rules of the product: what users may do, your payment and refund terms, who owns what, how much you can be liable for, and where disputes go. No statute forces you to have one; going without one means contract law’s defaults apply, which protect you far less. It exists to protect you.
- Privacy Policy is a legally required disclosure of how you collect, use, store, and share personal data. Its obligations come from privacy statutes and from the platforms you build on. It exists to protect the user.
You need both, they should reference each other, and users should accept the ToS (and acknowledge the policy) at signup. How you collect that acceptance determines whether it holds up, which is covered below.
Why Both, Before Launch

Three separate forces make these documents day-one items rather than “when we’re bigger” items:
- Privacy statutes with reach. The EU’s GDPR carries fines up to €20 million or 4% of worldwide annual turnover, whichever is higher, and roughly twenty U.S. states now have comprehensive privacy laws of their own, with more taking effect through 2026. Which of these actually bind a small SaaS depends on thresholds and targeting, covered honestly in the next section, but the direction of travel is one-way.
- Platform gatekeepers. Apple’s App Store, Google Play, Google sign-in, Stripe, and most ad and analytics networks require a published Privacy Policy URL before you operate. These contractual requirements apply at any size, no statutory threshold, and losing a payment processor over a missing policy is a faster death than any regulator.
- Liability limits. When a user disputes a charge, misuses the product, or claims your downtime cost them money, the ToS is what caps the damage, typically to fees paid, and routes the dispute where you chose.
Which Privacy Laws Actually Apply to Your SaaS (The Honest Version)

Template pages love to say “GDPR and CCPA apply the moment anyone visits your site.” The truth has more texture, and knowing it saves you from both panic and complacency:
| Law | When it actually covers you | Core obligation |
|---|---|---|
| GDPR (EU/UK) | You offer your service to people in the EU/UK or monitor their behavior; mere accessibility of a U.S. site is not, by itself, targeting | Lawful basis for processing, honest disclosures, access and deletion rights |
| California CCPA/CPRA | For-profit business meeting a threshold: $26.6M+ annual revenue, or personal data of 100,000+ California consumers or households, or 50%+ of revenue from selling/sharing data | Detailed notice, “Do Not Sell/Share” opt-out, deletion and correction rights |
| Other state laws (~20 states) | Each has its own coverage test, usually volume-based (e.g., data of 35,000–100,000 residents); several exempt small businesses | Similar notice and opt-out rights; one well-built policy covers the overlap |

Two honest observations. First, a bootstrapped SaaS with 2,000 users often is not statutorily covered by the CCPA at all, and panicking about it is wasted energy. Second, the 100,000-consumer prong counts unique identifiers, cookies, device IDs, IP addresses, so a content site or app with modest California traffic can cross it within a year without feeling large. The safe engineering choice is the one regulators and platforms both reward: write one accurate policy, honor access and deletion requests regardless of whether a statute technically compels you yet, and add a cookie banner if you run analytics or ads on EU visitors. That posture satisfies the strictest law you plausibly face and every platform contract at once.
The Clause Skeleton: What Goes in Each Document

The downloadable bundle above contains the full documents. This is the load-bearing skeleton, useful for checking any draft, yours or a generator’s, for missing pieces. Bracketed items are yours to fill; delete what does not apply.
SAAS TERMS OF SERVICE — CORE CLAUSES
1. Acceptance. “By creating an account or using [PRODUCT], you agree to these Terms and acknowledge the Privacy Policy at [URL].” Acceptance happens at signup via checkbox.
2. The Service. Plain-English description of [PRODUCT], plus: “We may modify, add, or discontinue features; material changes will be notified [30] days in advance.”
3. Accounts & Acceptable Use. Accurate information, one person per seat, keep credentials secure. Prohibited: unlawful use, abuse or harassment, reverse engineering, scraping at scale, reselling access, [ADD PRODUCT-SPECIFIC RULES].
4. Billing. Plans and prices at [URL]; subscriptions renew automatically until cancelled; cancellation takes effect [at period end]; refunds: [YOUR ACTUAL POLICY, e.g., “14-day refund on first purchase, none on renewals”]. Price changes with [30] days’ notice.
5. Your Content, Our Software. “You retain ownership of content you upload. You grant us a license to host, process, and display it solely to provide the Service. We own the software, and no rights transfer beyond this subscription.”
6. Suspension & Termination. Your right to suspend or close accounts for violations, non-payment, or legal risk; the user’s right to export data for [30] days after closure.
7. Disclaimers & Liability Cap. Service provided “as is”; no warranty of uninterrupted operation; liability capped at [fees paid in the prior 12 months]; no indirect or consequential damages, to the extent law allows.
8. Indemnification. Users cover losses caused by their content or their breach of these Terms.
9. Governing Law & Disputes. [STATE] law; disputes resolved in [COURTS / binding arbitration]; [optional small-claims and injunctive-relief carve-outs].
PRIVACY POLICY — REQUIRED DISCLOSURES
What we collect: [account data: name, email; payment data via processor; usage data: pages, features, device, IP; cookies: LIST THEM]. Why: [provide the service, billing, support, product improvement, marketing emails with opt-out]. Who we share with: [processors by category or name: hosting, payments, analytics, email; no sale of personal data / or your opt-out mechanism]. Your rights: [access, correction, deletion, portability; how to exercise: EMAIL/FORM; response timeline]. Retention & security: [how long, safeguards you actually use]. Children: [not directed at children under 13; COPPA parental-consent rules apply if you ever are]. Contact: [privacy@yourdomain].
Use this skeleton the honest way: every bracket describes your actual practice, not an aspiration. The fastest way to turn a protective document into a liability is to publish promises, encryption, deletion, “we never share”, that your stack does not keep. Regulators and plaintiffs read policies as admissions.
Want the documents generated from your actual answers and kept current as state laws change? Termly builds the Privacy Policy, Terms of Service, and cookie banner from a questionnaire and updates them as regulations move.
Making Them Stick: Clickwrap Beats a Footer Link

A contract needs agreement, and courts distinguish sharply between two ways of getting it. “Browsewrap,” a footer link with no action required, is regularly held unenforceable because nothing shows the user ever agreed. “Clickwrap,” an unticked checkbox at signup (“I agree to the Terms of Service and acknowledge the Privacy Policy,” each phrase linked), creates a record of assent that holds up. Since electronic agreement is legally valid under the E-SIGN Act, that checkbox is a real signature; treat it that way:
- Signup: required, unticked checkbox linking both documents. Log the timestamp and the version accepted.
- Checkout: restate the billing and refund terms where the card is entered; it prevents the most chargebacks. (Selling physical goods too? Pair this with a proper return and refund policy.)
- Footer: both documents linked on every page, at stable URLs.
- App stores: paste the Privacy Policy URL into your App Store and Google Play listings; both require it.
- Changes: for material ToS changes, email notice plus a fresh acceptance beats silently editing the page; keep dated prior versions.
Cookie Banners, DPAs, and the Other Documents People Ask About

- Cookie policy and consent banner: needed once you run analytics or advertising cookies, and effectively mandatory for EU visitors. The mechanics, what needs consent, what counts as “strictly necessary,” banner design that complies, are in our cookie consent guide.
- DPA (Data Processing Agreement): the vendor-side contract enterprise and EU customers will ask you to sign, governing how you process data on their behalf. Not a launch item; have a template ready by your first enterprise deal.
- EULA: a license for installed software. A hosted SaaS covers the same ground inside the ToS; you rarely need both.
- Website legal pages beyond SaaS: running a content or affiliate site alongside the product? That stack (disclaimers, disclosures) is covered in our website disclaimer guide, and store owners should see the online store legal checklist.
Common Mistakes That Undo the Protection

- Copying a competitor’s policy. It describes their data flows and their processors, and it is wrong about yours from the first paragraph. Courts and regulators have seen the copy-paste artifacts before.
- Overpromising. “Military-grade encryption,” “we never share your data,” “deleted immediately”: if your stack does not do it, the policy is evidence against you.
- Browsewrap-only acceptance. No checkbox at signup means you may have no enforceable contract when you need the liability cap most.
- Analytics with no cookie disclosure. The pixel fires before the policy mentions it; align the two the same week you add any tracker.
- Set-and-forget. New processor, new feature, new state law: the documents are living. Calendar a review every six months, or use a generator that pushes updates.
- Ignoring the under-13 question. If children can realistically use your product, COPPA’s parental-consent regime applies, and it is not a template problem; that one goes to counsel.
When to Bring in a Lawyer

A template or generator covers the standard case: a subscription product collecting ordinary account and usage data from adults. Get counsel when the facts leave that lane: regulated data (health, financial, biometric, children’s), enterprise customers negotiating custom data terms, heavy EU operations that need a GDPR representative and records of processing, or a funding round where diligence will read every promise you have published. The efficient pattern is the usual one: launch on an accurate template, then buy review when the data footprint or the contract stakes grow past it.
Frequently Asked Questions

Do I legally need a Terms of Service for my SaaS?
No statute requires one, but going without it means no liability cap, no refund rules, no acceptable-use standard, and no chosen forum for disputes. The Privacy Policy is the legally required one; the ToS is the one that saves you money in a dispute.
Is a Privacy Policy required if I only collect emails?
Yes in practice. An email address is personal data under privacy laws, and the platforms you rely on, app stores, payment processors, ad networks, contractually require a published policy regardless of your size.
Does the CCPA apply to my small SaaS?
Only if you meet a threshold: over $26.6 million in annual revenue, or personal data of 100,000+ California consumers or households (devices and cookies count toward this), or half your revenue from selling or sharing data. Many small products are below all three, but modest traffic plus analytics can cross the 100k prong faster than expected.
Does GDPR apply to a US-based SaaS?
It applies when you offer the service to people in the EU/UK or monitor their behavior, accepting EU customers, pricing in euros, or running EU-targeted ads all count. A U.S. site that is merely reachable from Europe is not automatically covered, but the moment EU users become customers, you are.
Can I write my own SaaS legal documents?
For a standard subscription product, yes: start from an accurate template or a generator, make every clause describe your real practices, and collect clickwrap acceptance at signup. Bring in an attorney for regulated data, enterprise data terms, or a funding round.
What’s the difference between a Terms of Service and an EULA?
A ToS governs use of a hosted service; an EULA licenses installed software. A web-based SaaS covers licensing inside the ToS and rarely needs a separate EULA unless it ships downloadable apps with meaningful local code.
How do I make my Terms of Service enforceable?
Clickwrap: an unticked checkbox at signup linking the Terms and Privacy Policy, with the acceptance logged. Footer links alone (“browsewrap”) are routinely held unenforceable because nothing proves the user agreed.
Policies that update themselves when the next state law lands: Termly generates your Privacy Policy, ToS, and cookie consent from your actual practices and keeps them current.
The Bottom Line
Two documents, two jobs: the Privacy Policy discloses what you really do with data, because the law and every platform you build on demand it; the Terms of Service sets the contract, because the alternative is defending disputes with no liability cap and no rules. Know which privacy laws genuinely reach you, roughly twenty state statutes with thresholds, GDPR when you serve Europe, platform contracts always, then write documents that describe your actual stack, collect real clickwrap acceptance at signup, and revisit them every six months. Accurate and boring beats impressive and false in every venue this will ever be tested.
Sources & References
This guide is fact-checked against the following official and authoritative sources:
- FTC — Privacy and Security Guidance
- European Commission — Data Protection (GDPR)
- California AG — CCPA
- FTC — COPPA Rule
Fact-checked: July 2026 · ClearLegalTips editorial team. This is legal information, not legal advice.

Marcus Thorne writes about business law and contracts for ClearLegalTips. He focuses on making non-compete agreements, buy-sell terms, and everyday business paperwork understandable for owners handling them without a lawyer.