All Blog Posts

Free Cookie Policy Template (and How to Fill It in Correctly)

Close
Read time
13 mins
Published
Sep 24, 2026
Share

  • A cookie policy explains which cookies and similar tracking technologies your website uses, what they do, and how visitors can manage their choices.
  • Use the free cookie policy template below as a starting point, then replace the customizable fields with information specific to your website.
  • A cookie policy is specific to your website, so copying another company's policy can leave you with information that doesn't match the technologies you use.
  • A cookie policy needs to stay current as your website changes, since new plugins, analytics tools, advertising technologies, and embedded content can introduce new cookies and trackers.
  • You can maintain your cookie declaration manually, or use Cookiebot to scan your website for cookies and trackers and generate a cookie declaration for you.

A cookie policy can look deceptively simple. You explain what cookies your website uses and give visitors the information they need. But the wording is only useful if it reflects what’s happening on your website. So copying a policy from somewhere else can leave you describing cookies and trackers your site doesn’t use, while missing the ones it does.

You can use the free cookie policy template below as a starting point for your website. We’ll explain what you need to customize, how to find the information your policy needs, and how to keep it accurate as the cookies and trackers on your site change.

Get my free cookie policy template

A cookie policy is a document that explains how a website uses cookies and similar tracking technologies, including tracking cookies. It tells visitors which technologies may be used when they visit the site, what they are used for, and how they can manage their choices.

Providing this information is an important part of privacy compliance under privacy laws such as the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), and other data privacy laws.

While requirements vary between jurisdictions, these laws can require businesses to be transparent about online tracking and, in certain cases, give users control over how their data is collected or used. A cookie policy is where much of that information can be clearly documented.

A cookie policy and a cookie declaration are often discussed together, but they are not the same thing. Each covers a different part of how your website communicates its use of cookies and similar technologies.

  • A cookie policy explains how and why your website uses cookies and similar technologies, including the choices visitors have and how they can manage them.
  • A cookie declaration is the site-specific list of cookies and trackers your website uses, including details such as their purpose, provider, category, and duration.

While parts of a cookie policy can be based on standard wording, a cookie declaration should reflect the technologies actually used on your website.

Cookie policies generally cover the same basic information, but the details need to reflect your website and the privacy requirements that apply to your business. At its core, your policy should explain what cookies are, how your website uses them, and what choices visitors have.

It should also be written in clear, plain language. Avoid legal or technical terminology where simpler wording will do, and explain unfamiliar terms when you need to use them.

Here’s what to include.

Information About Your Website and Business

Start by identifying the business or organization responsible for the website. Include your business name and website address so visitors know who the policy applies to.

If the policy covers multiple websites or domains, say so clearly. You should also explain if different websites, services, or parts of your business use cookies in different ways. Visitors should be able to understand the scope of the policy without having to figure it out themselves.

An Explanation of Cookies and How You Use Them

Explaining what cookies are is an essential step in your cookie policy. If your website uses similar technologies, such as pixels or local storage, explain those too.

You should then describe how cookies and similar technologies are used on your website. Depending on your setup and the requirements that apply, this can include:

  • The types of cookies you use: Explain the categories of cookies used on your website and what each category means. These might include cookies for essential functionality, preferences, analytics, or advertising.
  • Why you use them: Describe what cookies help you do. Rather than simply labeling a cookie as “analytics,” for example, explain that it helps you understand how visitors use your website or which pages they visit.
  • The cookies and trackers in use: Identify the individual cookies and similar technologies used on your website. Details can include their names, providers, purposes, and duration.
  • How long cookies last: Explain whether cookies expire when a browsing session ends or remain on a visitor’s device for a set period.
  • Third-party cookies and services: Identify third parties that set cookies or similar technologies through your website and explain their role. Depending on the requirements that apply, you may also need to explain what information they receive or provide more information about how they use it.
  • The information collected: Explain what information cookies and similar technologies collect when visitors use your website, where applicable.

Visitors may find this information easier to understand when you present details about individual cookies in a table or structured list. Most importantly, make sure the information reflects the technologies currently used on your website rather than relying on a generic list.

Explain what choices visitors have and how they can manage them. Make sure your instructions match the controls your website actually provides.

If you use a cookie banner or preference center, explain how visitors can use it to make their choices and update them later. If you tell visitors how to manage cookies through their browser settings, explain what changing those settings will do.

Do not describe controls or options that your website does not offer. A visitor should be able to read your policy, follow the instructions, and find the corresponding controls on your site.

Updates and Contact Information

Include a “last updated” date so visitors can see when you most recently reviewed the policy. When you change how your website uses cookies, review the policy to make sure it still accurately describes your practices.

For example, adding an analytics tool, advertising service, plugin, or embedded feature may introduce new cookies or tracking technologies. Removing a service may also leave information in your policy that no longer applies.

Finally, tell visitors how they can contact you with questions about the policy or your use of cookies. Provide a contact method you actively monitor, such as an email address or contact form.

Below is a free cookie policy template you can copy and paste into a dedicated cookie policy page on your website, then customize for your business.

Before using the template, read through the full policy and replace all text in [brackets] with information from your website. Remove anything that doesn’t apply to your business, and adjust the wording where needed, so it accurately reflects how your website uses cookies and similar technologies.

Cookie Policy

Last Updated: [Date]

This Cookie Policy explains how [Company Name] (“we,” “us,” or “our”) uses cookies and similar technologies when you visit [Website URL] (the “Website”).

It explains what these technologies are, how we use them, and the choices available to you. This Cookie Policy should be read alongside our [Privacy Policy / Privacy Policy URL], which provides more information about how we handle personal information.

What Are Cookies?

Cookies are small text files that are stored on your device when you visit a website. They can help websites function, remember information about your visit, and provide information about how the website is being used.

Cookies set directly by [Company Name] are known as first-party cookies. Cookies set by another company or service are known as third-party cookies. Third-party cookies may be used when features or services from other providers are included on our Website.

Some cookies last only for the duration of your browsing session and expire when you close your browser. Others remain on your device for a set period or until you delete them.

How Do We Use Cookies?

We use cookies and similar technologies for [describe the purposes that apply to your website].

Depending on how you use our Website, these may include:

  • Necessary cookies: [Explain any cookies needed for your Website to function or provide services requested by visitors.]
  • Preference cookies: [Explain any cookies used to remember visitor settings or preferences.]
  • Analytics cookies: [Explain any cookies used to understand how visitors interact with your Website or measure its performance.]
  • Advertising cookies: [Explain any cookies used for advertising, targeting, or measuring advertising performance.]
  • [Other Category]: [Explain any other type of cookie relevant to your Website.]

[Remove any categories that do not apply to your Website.]

Which Cookies Do We Use?

The cookies and similar technologies used on our Website are listed below.

[Add one row for each cookie or tracker used on your Website. Remove fields that are not relevant or required for your setup.]

Cookie / TrackerProviderPurposeType / CategoryDuration
[Cookie Name][Provider / Domain][What The Cookie Does][Category][Session / Expiry Period]
[Cookie Name][Provider / Domain][What The Cookie Does][Category][Session / Expiry Period]
[Cookie Name][Provider / Domain][What The Cookie Does][Category][Session / Expiry Period]

Third-Party Cookies

Some cookies and similar technologies on our Website may be provided by third parties. These services may use cookies to provide their features, understand how their services are used, measure performance, or for other purposes described in their own privacy information.

We use the following third-party services where relevant:

Third PartyPurposeMore Information
[Provider Name][Explain Why The Service Is Used][Privacy / Cookie Policy URL]
[Provider Name][Explain Why The Service Is Used][Privacy / Cookie Policy URL]

[Remove this section if it does not apply to your Website.]

How Can You Manage Your Cookie Choices?

You can manage your cookie choices through [describe your cookie banner, preference center, or other consent mechanism].

To review or change your choices, [explain how visitors can reopen or access your cookie settings, or insert a link/button to your cookie settings].

You can also manage cookies through your browser settings. Most browsers allow you to view, delete, or block cookies. The steps vary by browser, so check your browser's help or settings menu for instructions.

Please note that blocking or disabling certain cookies may affect how some parts of our Website work.

What About Other Tracking Technologies?

We may use technologies other than cookies to understand how visitors interact with our Website or to provide certain features. These can include technologies such as pixels, tags, or local storage.

[Describe any other tracking technologies used on your Website, what they do, and any relevant third parties. Remove this section if it does not apply.]

How Do We Update This Cookie Policy?

We may update this Cookie Policy when our use of cookies and similar technologies changes or when we need to reflect changes to our business, Website, or applicable requirements.

When we update this Cookie Policy, we will revise the “Last Updated” date at the top of the page.

How Can You Contact Us?

If you have questions about this Cookie Policy or our use of cookies and similar technologies, contact us at:

[Company Name]
[Email Address]
[Postal Address, If Applicable]
[Phone Number, If Applicable]
[Other Contact Method, If Applicable]

Customizing your cookie policy means replacing the generic parts of the template with information that reflects your website. Some fields are straightforward, such as your business name and contact details. Others require you to look at how your website uses cookies, which third-party services are involved, and what choices you give visitors.

The table below shows what you’ll need to add and where to find it.

Template FieldWhat To AddWhy It Matters
Business detailsYour business or organization name, website URL, and any other identifying information requested in the template.Makes clear who the policy belongs to and which website it covers.
How you use cookiesThe purposes that apply to your website, based on how you use cookies and similar technologies. Remove examples that don't apply.Keeps the policy specific to your website rather than describing uses that aren't relevant to your business.
Cookies and trackersThe cookies and similar technologies used on your website, including relevant details such as their names, purposes, providers, and lifespans.Gives visitors information about the technologies they may encounter when using your site.
Third-party servicesDetails of third parties that set cookies or use similar technologies through your website, where relevant.Helps visitors understand when another company is involved in the use of cookies or tracking technologies.
Cookie choicesInstructions that match the way visitors can manage their cookie preferences on your website.Makes it clear how visitors can exercise the choices described in your policy.
Contact detailsThe email address, contact form, or other contact method you want visitors to use for cookie-related questions.Gives visitors a clear way to contact you about the policy.
Last updated dateThe date you last reviewed or made changes to the policy.Shows visitors how current the policy is.

Don't add information simply because it appears as an option in the template. If your website doesn't use advertising cookies, for example, remove language about advertising cookies rather than leaving it in as generic wording.

A cookie policy is only useful if it reflects what your website is actually doing. But your website’s use of cookies and trackers isn’t necessarily static. It can change over time as the tools, services, and features behind your site evolve.

That means keeping your cookie policy accurate is an ongoing process rather than a one-time task. Regularly checking what your website uses, and reviewing it again when you make relevant changes, can help you spot when your policy needs to be updated.

A consistent review process can help you catch these changes and keep your policy aligned with your website.

Identify the Cookies and Trackers on Your Website

Start with an inventory of the cookies and trackers currently active on your website. You can inspect these manually using your browser’s developer tools or use a website scanner to identify them.

A best practice is to check more than your homepage. A cookie may only appear on a particular page, after an embedded video loads, or when a visitor interacts with a specific feature.

For each cookie or tracker you find, record the information you need for your policy. This can include its name, provider, purpose, and lifespan, along with whether it comes from your website or a third party.

Use the scan results to check whether the cookie information you're providing to visitors still reflects your website.

Look for newly detected cookies and trackers that aren't covered, as well as technologies listed in your policy that are no longer present. Details can change too, so check whether existing information about purposes, providers, or lifespans still holds.

You can carry out these checks manually, or use a consent management platform (CMP) to run periodic scans and help identify changes in the cookies and trackers your website uses.

If your review reveals a discrepancy, update your cookie policy accordingly. Add newly detected technologies, remove entries that no longer apply, and correct any details that are out of date.

Consider whether the change affects the wider policy too. For example, adding a third-party advertising service could change your explanation of why cookies are used, not just the information you provide about individual cookies.

Once you’ve made the necessary updates, change the “last updated” date and review the published policy to make sure everything is accurate. The information visitors read should reflect the cookies and trackers they can actually encounter on your website.

A cookie policy template gives you a starting point. But the information it contains still needs to reflect the cookies and trackers on your website, and that picture can change as your site evolves.

Cookiebot by Usercentrics is a consent management platform (CMP) that helps businesses manage cookie consent and website tracking. It scans your website for cookies and trackers, including technologies introduced as your site changes, giving you ongoing visibility into what is being used.

Based on those scan results, Cookiebot CMP generates a cookie declaration that provides visitors with information about the cookies and trackers detected on your website. It also applies visitors’ consent choices and keeps records of those choices, bringing your cookie declaration and consent management into the same process.

A cookie policy should not become outdated the moment your website moves forward. With Cookiebot CMP, your declaration can keep pace with what is happening on your site, while your visitors’ consent choices are carried through.

Frequently asked questions

It depends on the privacy laws that apply to your business and how your website uses cookies and tracking technologies. Many privacy laws require businesses to provide information about their use of cookies, although this does not always have to be published as a separate cookie policy.

A cookie policy should explain what cookies are, how your website uses them, and what choices visitors have. It should also provide relevant details about the cookies and trackers in use, including third-party technologies where applicable.

The essential elements typically include information about your website, the types and purposes of cookies you use, relevant details about individual cookies and trackers, visitor choices, and contact information.

A cookie policy focuses specifically on cookies and similar tracking technologies. A privacy policy covers the broader ways a business collects, uses, shares, and protects personal data. Depending on your setup, cookie information may appear within a privacy policy or in a separate document.

You shouldn't copy another website's cookie policy because its cookies, third-party services, and privacy requirements may differ from yours. Use a cookie policy template instead and customize it to reflect your own website.

You can use the free cookie policy template above. Copy the template, replace the placeholders with your own information, and remove any wording that doesn't apply to your website.

Add your business details and replace the generic cookie information with details from your website. Check which cookies and trackers are in use, then make sure the policy accurately describes their purposes and the choices available to visitors.

Start with a clear policy that reflects the cookies and trackers used on your website, then check it against the privacy requirements that apply to your business. Keep the information current as your website and tracking technologies change.