Two failure modes show up constantly with indie products. One: no Terms of Service or Privacy Policy at all, because it felt like a problem for later. Two: a free generator's output pasted in wholesale, which is legally thin in the places that matter and bloated everywhere else. Neither protects you or tells your customers what they're actually agreeing to.
What the law actually requires you to tell people
If you're selling to UK consumers online, the Ecommerce Regulations and Consumer Contracts Regulations require specific information to be given clearly, before someone buys, not buried in a wall of text after checkout:
- Who you are. Your business or trading name, geographic address (not just an email), and a way to contact you. If you're a registered company, its name and registration number.
- What they're buying and for how much, including any recurring charges spelled out clearly, not left implicit in a "starting at" price.
- Their right to cancel. UK consumers generally have 14 days to cancel a service or digital content contract bought online, with narrower rules for digital downloads where they can waive the cooling-off period to get instant access, but only if you ask for and record their consent to do that.
- How to make a complaint, and what happens if something goes wrong.
Skip these and you're not just risking a bad review, you're not meeting a legal information duty, separate from whatever your Terms of Service document says.
What Terms of Service is actually for
Once the mandatory disclosures are covered, Terms of Service exists to set expectations and limit disputes: what the service does and doesn't promise, acceptable use (what gets an account suspended), how and when you can change the product or pricing, what happens if you shut the service down, and a liability limitation clause (capping what you're on the hook for if something breaks). None of this is legally mandatory in the way the disclosures above are, but a product actually taking payments without any of it is exposed in ways a generic template won't fix, because templates aren't written for what your specific product does.
One thing worth being deliberate about: under the Consumer Rights Act, digital content and services must be of satisfactory quality, fit for purpose and as described. You can't contract your way out of that with clever wording in your Terms; you can be clear about what the product does and doesn't do, which reduces the gap between expectation and reality that generates most disputes in the first place.
What Privacy Policy is actually for
Privacy Policy is where UK GDPR's transparency requirement lives: what data you collect, why, how long you keep it, who else sees it, and how someone exercises their rights (access, deletion, and so on). This overlaps with, but is a different document from, your actual GDPR compliance work (subprocessor agreements, breach procedures). See the GDPR guide for that side of it. The Privacy Policy is the public-facing summary; it should be accurate to what you actually do, not aspirational.
The honest starting point
Write these yourself in plain language covering the points above, or use a template as a first draft and then actually edit it to match what your product does, don't ship it unread. A document that's accurate and slightly informal beats one that's comprehensive and describes a different product.
This is exactly the kind of unglamorous, load-bearing work Qeetoto handles for the developers we work with, alongside the rest of what it takes to go from a working prototype to something you can legally charge for. Get in touch if you'd rather have this reviewed properly than guess.
FAQ
Can I just use a free Terms of Service generator? As a starting draft, sure, but read every line and edit anything that doesn't match your actual product, pricing or cancellation process. A generator can't know your specifics, and an inaccurate Terms of Service is arguably worse than none at all.
Do I need a lawyer to write these? Not necessarily for an early-stage indie product, but get one involved before anything with real financial exposure: enterprise contracts, health or financial data, or before an incubator/investor conversation where these documents get scrutinised.
What's the actual risk of getting this wrong? Mostly disputes you can't resolve cleanly (a refund argument with no stated policy to point to) and, separately, the ecommerce/consumer-disclosure duties are a distinct legal obligation regardless of what your Terms say. It's rarely one dramatic incident; it's friction and exposure that compounds.
Does this apply if I only have customers outside the UK? If you're a UK-based business, UK rules on your own disclosures still apply to you, and you may also need to consider the consumer protection rules of wherever your customers actually are. That's a bigger question than this guide covers; get specific advice if you're selling cross-border at any real volume.