How to Set Up Termly for an Ecommerce Store (2026)

Affiliate disclosure: This post contains affiliate links. If you buy through them, I may earn a commission at no extra cost to you. Full disclosure

Legal pages are the part of a store nobody wants to build and everybody needs. Not because a regulator is coming for your first ten orders, but because in my experience the payment processor, the ad accounts and the suppliers all ask to see them, and because “we’ll do it after launch” turns into eighteen months of a footer linking to nothing.

Termly generates those pages and runs the cookie banner that sits in front of them. This is how I would set it up on a high-ticket store, in order, and which parts of it I would skip. Every price, limit, screen name and quoted policy below comes from Termly’s own pricing page and support documentation, plus the California Attorney General’s published CCPA guidance, all read on 29 September 2026. Where something is my own experience or opinion, I say so.

One thing up front, and I mean it: I am not a lawyer and none of this is legal advice. What follows is the order of operations for using a tool, not a ruling on what your business is obliged to do. If you are unsure whether a specific law applies to you, that is a question for a lawyer, not for me or for a policy generator.

I run Ecommerce Paradise and I have watched more launches stall on a missing privacy policy than on anything glamorous. If the model itself is new to you, start with what high-ticket dropshipping actually is and come back to the legal pages when you have a store to put them on.

Get Your Footer Links Working This Afternoon

Termly’s free tier includes one basic legal policy, a cookie policy and banner, the cookie script auto blocker and 10,000 banner views a month.

Start on Termly Free →

First, Work Out Whether the Law You Are Worried About Applies

This is the step everyone skips, and skipping it is how people end up paying for compliance features they do not need while missing the ones they do.

Take the CCPA, which is the one US store owners hear about most. According to the California Attorney General’s published guidance, the CCPA applies to for-profit businesses that do business in California and meet any of the following: have a gross annual revenue of over $25 million; buy, sell, or share the personal information of 100,000 or more California residents or households; or derive 50% or more of their annual revenue from selling California residents’ personal information.

Read those three thresholds again and place your own store against them. Are you over $25 million in gross annual revenue? Are you buying, selling or sharing the personal information of 100,000 or more California residents or households? Does half or more of your revenue come from selling California residents’ personal information? Those are questions with answers you already know, and where they land is a conversation for a lawyer rather than for me.

So why build the pages at all? Three practical reasons from my own experience, none of them regulatory. Payment processors have asked me for a privacy policy and terms during underwriting. Ad platforms have asked before running traffic. Suppliers reviewing a dealer application look at whether the site reads as a real business. That is the reason I would do this in week one, and it is a better reason than fear.

The other honest point: the CCPA is one law. Other jurisdictions have their own rules, thresholds and definitions, and whether any of them reach your store is genuinely a lawyer’s question. What I can tell you is that having the pages costs almost nothing and not having them blocks real things.

What Each Termly Tier Actually Gives You

Termly’s published pricing runs to four tiers, and the differences that matter to a store are narrower than the feature lists suggest.

Tier Price Legal policies Banner views Cookie scans
Free $0 a month 1 basic legal policy 10,000 a month Quarterly
Starter $14 per website per month 2 legal policies, 10 policy edits 50,000 a month Monthly
Pro+ $20 per website per month Unlimited policies and edits Unlimited Weekly
Agency Custom Everything in Pro+ Everything in Pro+ Everything in Pro+

Free also includes the cookie policy and banner, the cookie script auto blocker and HTML embeddable policies, on one website with one user. Starter adds regulation monitoring, regular policy updates and five users. Pro+ adds auto-updated policies, the ability to remove the Termly logo, Google Consent Mode v2, IAB TCF 2.3, custom banner styles, multi-language support, regional consent rules and unlimited users. Agency adds multi-domain management and bulk discounts.

A note on annual billing. Termly advertises annual billing at up to 25% off, but when I read the pricing page the monthly and annual figures displayed the same numbers, so I cannot tell you a reliable annual per-month price. Check the figure on the page for the tier you want before you commit to twelve months.

My read on which tier: start free, and the trigger to upgrade is the policy count, not the traffic. Free gives you one basic legal policy. A store realistically needs a privacy policy, terms of service and a returns or shipping policy, which is already past one. Starter’s two policies plus ten edits is still tight. If you want the full set generated and kept current, Pro+ at $20 per website per month is the tier that stops you fighting the limit, and that is my opinion rather than a Termly recommendation.

Step 1: Generate the Policies Before You Touch the Banner

Policies first, banner second. The banner references the cookie policy, so building it the other way round means redoing work. Termly’s generator is the part I would start with on day one.

Before you start, my own habit is to have the real details in front of me rather than improvising them: the legal entity name, the business address, the email address you will actually monitor for privacy requests, the list of analytics and ad tools you run, and whether you collect payment details directly or hand off to a processor. That is my preparation checklist, not a description of Termly’s form.

That last one catches people. If checkout runs through Shopify Payments or Stripe, you are not storing card numbers yourself, and the policy should say what is true rather than what sounds impressive.

On a quote-request store there is one extra thing to get right. You are collecting names, emails, phone numbers and delivery addresses through a form, often before any purchase exists. That is personal information sitting in your CRM, and the privacy policy should describe it honestly. If you have not built that funnel yet, I have written up how I set up a free CRM for quote requests, and it is worth reading the two together so the policy matches the plumbing.

For reference on what a privacy policy is expected to contain, the California Attorney General’s guidance describes privacy policies as including information on consumers’ privacy rights and how to exercise them: the Right to Know, the Right to Delete, the Right to Opt-Out of Sale, the Right to Correct, the Right to Limit, and the Right to Non-Discrimination. Even if your store is under the thresholds, that list is a reasonable sanity check on whether a generated policy is thorough or thin.

Step 2: Scan for Cookies and Classify What Comes Back

Now the cookie side. Termly’s documented setup flow for the consent manager is four steps, and it starts with a scan rather than a banner.

  1. Under Consent Management, click Scan Report. On the page, click Scan Now to begin scanning your website for cookies.
  2. Your cookies will be shown in a table and categorized for you. If you have any Unclassified cookies, you may edit their description under the Unclassified tab.
  3. Once you are happy with the list of cookies, click Generate Cookie Policy to review your policy.
  4. Click the Add To Website button to select how you want to add your new policy to your website or app.

The Unclassified tab is the step worth your attention. On a typical store the scan finds cookies from your theme, your analytics, your ad pixels, your chat widget and your review app, and the ones it cannot categorise are usually from whichever plugin you installed and forgot about. Going through that list is the only time you will ever have a complete inventory of what your store is loading into a visitor’s browser, and on more than one store I have found a pixel nobody remembered adding.

Scan frequency is one of the real tier differences: quarterly on Free, monthly on Starter, weekly on Pro+. This matters because every app you install can add cookies, so a policy accurate in January is not necessarily accurate in June. If you install apps rarely, quarterly is fine and you can rescan manually after any change.

Have the Whole Store Built Properly Instead

My done-for-you builds cover the store, the suppliers and the boring foundational pieces like this one, so nothing is left as a footer link to nowhere.

See the Done-For-You Build →

Step 3: Decide How You Are Blocking Cookies, Then Install

This is the step with the highest chance of being done wrong, and Termly is blunt about it. Their banner installation documentation states that installing a consent banner without blocking third-party cookies could mean you are not in compliance.

Read that sentence carefully, because it describes the most common failure in the whole category. A banner that appears, collects a click and then does nothing to the cookies already loading is decoration. It looks compliant to you and behaves exactly like having no banner at all. Termly’s documentation says to decide on your cookie blocking method before installation, not after.

The good news is that Termly’s free tier includes the cookie script auto blocker, so this is not a feature you have to pay for to get right.

Where the Code Goes

Termly’s instruction is specific and it is the detail people get wrong: copy and paste the code snippet into the <head> section of your website, and the code snippet must be the first script on the page to work properly.

First script. Not somewhere in the head, not after your analytics, first. The logic is obvious once you see it: a blocker that loads after the thing it is supposed to block has already fired is not blocking anything. If your theme or a performance plugin reorders or defers scripts, that is a thing to check rather than assume.

The documented install flow is: scan your site via the Consent Management dropdown, customise the appearance in Banner Settings, click Install to get the Termly-generated snippet, paste it into your head section, then verify the installation from the dashboard. Do the verify step. It is the only thing standing between you and a banner that you believe works.

On WordPress, Use the Plugin

If your store runs on WordPress, Termly publishes a plugin called GDPR/CCPA Cookie Consent Banner and it is easier than hand-editing your theme header, which is the kind of edit a theme update quietly reverts.

Install it from Plugins then Add New then Upload Plugin, or just search “Termly” under Plugins and Add New. Then click the Termly menu in your WordPress menu bar, enter your Termly API key on the sign-up page and click Save API Key. If you do not have an account yet, their documentation offers a Sign up & Get API Key button as the alternative.

The plugin handles three things: Site Scan for running cookie scans and adjusting settings, Cookie Management for viewing and editing cookies and categories, and Banner Settings for adding or deleting the banner, enabling the consent banner and toggling the Auto Blocker.

Everything else stays in the Termly dashboard. Their documentation is explicit that all other functionality, including banner customization, consent log management and DSAR form creation, will be managed in the Termly dashboard. So do not go hunting for those screens in WordPress.

Other Platforms

Termly publishes dedicated installation guides for WordPress, Wix, ExpressionEngine, Kajabi, React, Next.js and Tealium iQ Tag Management, plus a Wix-specific guide for adding a cookie preferences button.

Shopify is worth a specific note, because Termly’s own sources disagree. The banner-installation article’s prose refers to dedicated guides for WordPress, Wix, Squarespace, Shopify and Kajabi, but Shopify and Squarespace do not appear in the published guides index I read. Treat a dedicated Shopify guide as unconfirmed and check their help centre yourself.

Either way the head-snippet method is the documented universal path. On Shopify that means adding the snippet to your theme’s layout file as the first script, and the same warning about theme updates applies, so note what you changed somewhere you will find it again.

Step 4: Put the Links Where People Look

Generated policies that live at URLs nobody links to do not help you with processors, ad platforms or buyers.

The footer is the minimum: privacy policy, terms, and your returns or shipping policy. On a high-ticket store I would go further and link the returns policy from the product page itself, because on a $6,000 order the return terms are a genuine purchase objection and burying them in the footer does not answer it.

If you are running quote requests, the form needs a line near the submit button saying what happens to the details, linking the privacy policy. That is not a legal flourish, it is the difference between a form that reads as a business and one that reads as a lead broker.

Termly also handles DSAR form creation, for data subject access requests, and their documentation states that this is managed from the Termly dashboard rather than from the WordPress plugin. On a small store you will get approximately none of these. Set it up anyway if your account offers it, because the first one arriving with no process in place is a bad afternoon.

What I Would Skip

Termly has features that exist for companies much larger than a first store, and paying for them early is a waste.

IAB TCF 2.3 is a programmatic advertising consent framework, as I understand it rather than on Termly’s authority. If you are running Google Shopping and some retargeting, my view is that this is not your problem.

Multi-language support and regional consent rules matter when you have meaningful traffic from multiple jurisdictions. If your store ships to the United States only, it is solving a problem you do not have.

Removing the Termly logo is the one I would weigh differently. On a store asking people for four figures, a third-party badge on the consent banner is a small trust cost, and whether that is worth the Pro+ price is a judgement call rather than a rule.

Agency and multi-domain management is for people running several stores. Worth knowing it exists if you get there, irrelevant on store one.

What This Costs Over a Year

Setup Monthly Twelve months
Free tier, one website $0 $0
Starter, one website $14 $168
Pro+, one website $20 $240
Agency Custom Custom

Those twelve-month figures are the monthly prices multiplied out, not annual plan prices. Termly advertises up to 25% off for annual billing, so the real annual cost should be lower, but since the page showed me the same number on both toggles I would rather give you arithmetic you can check than a discount figure I cannot verify.

Either way Termly is likely to be among the cheapest line items in your stack. Compare $240 a year to what you will spend on hosting, apps and a single week of ads, and the calculation stops being interesting. I have broken the tier-by-tier detail down further in my Termly pricing guide.

Where This Sits in the Rest of the Setup

Legal pages are one piece of the boring foundation, and they are not the first piece. The order I teach is entity first, then bank account and processor, then the site and its pages.

The entity matters because the privacy policy and terms both name a legal entity, and writing your own name there because the LLC is not formed yet means redoing both. That sequence is covered in business formation for high-ticket dropshipping.

None of it matters if the store sells something nobody wants at a margin that does not work. If you are still deciding, my high-ticket niches list is where to start.

After the niche, the supplier side is the real bottleneck, which is why I wrote a full guide to finding high-ticket suppliers. Suppliers will look at your site before they approve a dealer application, which is a decent argument for having the footer finished before you apply.

The Whole Thing, in Order

Step What you do
1 Check your store against the CCPA thresholds so you know what you are actually solving for
2 Gather entity name, address, monitored privacy email, and your list of analytics and ad tools
3 Generate the privacy policy and terms from real answers, not placeholders
4 Run Scan Now under Consent Management, then work through the Unclassified tab
5 Generate the cookie policy once the list looks right
6 Decide your blocking method, then customise the banner in Banner Settings
7 Install the snippet as the first script in the head, or use the WordPress plugin
8 Verify the installation from the dashboard, then load your own store and watch the banner behave
9 Link every policy from the footer, and the returns policy from product pages too
10 Rescan after you install any new app or pixel

That is an afternoon, not a project. The reason it takes people six months is that it is the least interesting afternoon in the whole build, so it keeps losing to something more fun.

Cross This Off the List Today

The free tier covers one policy, the cookie banner and the auto blocker at $0. Paid tiers start at $14 per website per month, and the unlimited policy set is Pro+ at $20.

Open a Termly Account →

Six Mistakes to Avoid

Installing the banner without blocking. Termly’s own documentation says a banner without third-party cookie blocking could mean you are not in compliance. A banner that only collects clicks is theatre.

Putting the snippet anywhere but first. The instruction is that it must be the first script on the page to work properly. Check that no performance plugin is reordering it.

Generating policies from placeholder answers. A policy describing card storage you do not do, or omitting the CRM you actually use, is worse than a short honest one.

Hand-editing the WordPress theme header instead of using the plugin. Theme updates revert that edit, usually silently, usually months later.

Never rescanning. Every app can add cookies. Free scans quarterly, so rescan manually after you install anything.

Assuming a generator settles the legal question. It produces documents. Whether your business is compliant with a given law is a lawyer’s call, and I am not one.

Frequently Asked Questions

Is there a free plan?
Yes. Termly’s free tier is $0 a month and includes one basic legal policy, a cookie policy and banner, the cookie script auto blocker, HTML embeddable policies, quarterly cookie scans and 10,000 banner views a month, on one website with one user.

What does the paid version cost?
Starter is listed at $14 per website per month and Pro+ at $20 per website per month. Agency is custom. Annual billing is advertised at up to 25% off, though the page showed me the same figures on both billing toggles, so check it yourself.

How many policies do I get?
One basic policy on Free, two policies plus ten policy edits on Starter, and unlimited policies and edits on Pro+.

Where does the code go?
Into the <head> section, and Termly states it must be the first script on the page to work properly.

Is there a WordPress plugin?
Yes, called GDPR/CCPA Cookie Consent Banner. It handles Site Scan, Cookie Management and Banner Settings, while banner customization, consent log management and DSAR form creation stay in the Termly dashboard.

Is there a Shopify guide?
Termly’s sources conflict on this. Their banner-installation article’s prose refers to dedicated guides for Shopify and Squarespace, but neither appears in the published guides index I read, which lists WordPress, Wix, ExpressionEngine, Kajabi, React, Next.js and Tealium iQ. Treat it as unconfirmed and check their help centre. The head-snippet method is the documented universal path regardless.

How often does it scan for cookies?
Quarterly on Free, monthly on Starter and weekly on Pro+.

Does the CCPA apply to my store?
The California Attorney General states the CCPA applies to for-profit businesses doing business in California that have gross annual revenue over $25 million, or buy, sell or share the personal information of 100,000 or more California residents or households, or derive 50% or more of annual revenue from selling California residents’ personal information. Place your own store against those thresholds, and ask a lawyer if you are unsure. This is not legal advice.

Should I still have policies if I am under the thresholds?
In my experience yes, because payment processors, ad platforms and suppliers have all asked to see them. That is a business reason rather than a legal one, and whether a law obliges you is a lawyer’s question.

Related Articles

Free 1,000+ high-ticket niches list

Still deciding what to sell?

Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.

Free. Unsubscribe any time.