No Payment Now — Pay Only After the Work Is Done · Delhi & All India · Online + Offline · +91 98913 43962
Legal Space Services (LSS) logoLegal Space Services
Login
Legal Space ServicesLegal Services & Documentation Company
Free Consultation
No payment now · Pay after work
Login
+91 98913 43962 WhatsApp Chat
HomeDocumentsDocument Guides › Website Legal Pack

Website legal pack — every page your website needs, written to match how it works

A boutique in Karol Bagh moves its business from Instagram to its own website. The payment gateway refuses to switch on live payments until the site shows a refund policy, terms and a proper contact page. The developer pastes in pages from a template; a month later a customer demands a refund the pasted policy promises and the shop has never offered, and the privacy policy mentions a newsletter the site does not have and says nothing about the analytics and advertising tags it does. None of this is unusual. The legal pages of most small Indian websites were written for someone else’s business. This page explains which pages your site needs, what each must say, and how to keep them true.

From ₹4,999 2 – 5 days Terms, privacy, refunds, shipping, cookies Nothing payable in advance
Which legal pages does a website in India need?The pages a website needs depend on what it does. Almost every site that collects personal data — a contact form, a call-back request, a newsletter, analytics or advertising tags — needs a privacy notice under the Digital Personal Data Protection Act, 2023. A site that sells goods or services online also needs terms of use, a refund and cancellation policy, a shipping and delivery policy where goods are sent, and, under the Consumer Protection (E-Commerce) Rules, 2020, its legal name, address, customer care details and a grievance officer with published response times; pre-packaged goods also need the legal metrology declarations on each listing. A site where users post content needs community rules and a grievance mechanism under the intermediary rules. A disclaimer sets the limits of the information offered, and a cookie notice with a choice for non-essential cookies covers tracking tools. Payment gateways usually refuse to activate live payments until these pages are in place. Professionals such as advocates and doctors must also keep their sites within their professional rules. The pages should be drafted together so that they agree with each other and with how the site really works, linked from the footer and at the points where they matter, dated, and reviewed whenever the site changes.

Why the legal pages matter

The footer links on a website — terms, privacy, refunds — are the ones almost nobody clicks, and the ones that decide what happens when something goes wrong. When a customer disputes a refund, the consumer commission reads the refund policy. When a visitor asks what was done with their phone number, the privacy notice is the promise the business made. When a payment gateway reviews a new merchant, it checks whether those pages exist and make sense. When a competitor copies the site, the copyright notice and the ownership of the content matter.

For small Indian businesses the risk is rarely a missing page. It is a page that describes a different business: a template privacy policy that talks about cookies from tools the site never used, a refund policy promising a thirty-day return on custom-tailored clothes, terms that choose the courts of a city the business has never traded in. Such documents are worse than useless, because they can be held against the business that published them.

A website legal pack solves this by treating the pages as one system, drafted together, from a description of how the site really works, and kept up to date as the site changes.

What your kind of site needs

Swipe to see the full table
Type of siteCore pagesExtra points
Brochure or company profilePrivacy notice, terms of use, disclaimer, contactCookie notice if analytics or ads tags are used
Lead generation (enquiry forms, call-backs)Privacy notice at every form, terms, contactSeparate consent for marketing calls and messages
Online store (own products)Terms, privacy, refund and cancellation, shipping, contact and grievanceE-commerce rule disclosures, product declarations, GST invoices
Marketplace (other sellers)All of the above, plus seller termsSeller details on listings, grievance officer, intermediary duties
Bookings and appointmentsTerms, privacy, cancellation and rescheduling policyNo-show and refund rules, reminders consent
Courses and subscriptionsTerms, privacy, refund policy, subscription termsRenewal and cancellation, children’s data
Community, reviews, forumsTerms, privacy, community guidelines, grievance pageIntermediary rules, takedown process
Professional practicePrivacy, disclaimer, contactProfessional advertising restrictions
Software or app with a websiteTerms or EULA, privacy, refundSee our app store guide

Many sites combine types. A clinic website that takes online bookings and payments is a booking site and a professional site; a coaching institute that sells recorded courses to school students is a subscription site handling children’s data. The documents should cover each function the site actually performs.

What goes in the pack

Swipe to see the full table
DocumentIts job
Terms of useThe contract with visitors and customers: orders, payment, accounts, conduct, content, liability, disputes
Privacy policyThe DPDP notice: what personal data, why, on what basis, who receives it, rights, retention, grievance
Refund and cancellation policyWhen customers can cancel, return or get money back, how, and how fast
Shipping and delivery policyWhere you deliver, how long, what it costs, and what happens if delivery fails
DisclaimerThe limits of the information and services offered
Cookie notice and bannerWhat tracking tools run, and the visitor’s choice
Contact and grievance pageLegal identity, address, customer care, grievance officer, timelines
Optional: community guidelines, seller terms, accessibility statementFor sites with user content, third-party sellers, or a commitment to accessibility

The pages should use the same legal name, the same defined terms and the same contact details; cross-refer rather than repeat; and never contradict each other. If the refund policy says refunds take seven working days, the terms should not say fourteen.

Start with how the site works

Good policies are written from facts. Before drafting, list:

This list becomes the backbone of every document. It also shows where the site itself needs to change — a form asking for more than it needs, a tag nobody remembers adding, a vendor with no contract. Every outside firm that touches your customers’ details should be on a written processing contract; our data processing agreement guide lists which ones.

Payment gateways and the pages they check

For many small businesses, the first time anyone asks about their legal pages is when they apply for a payment gateway. Payment aggregators in India are regulated by the Reserve Bank of India and must carry out due diligence on the merchants they onboard. In practice, gateways review the merchant’s website before switching on live payments, and commonly expect to see:

Each gateway publishes its own checklist, and the requirements change, so read the current one before applying. The most frequent reasons for delay are pages copied from another site with the wrong business name, contact details that do not match the KYC documents, a refund policy that says “no refunds under any circumstances”, and a site that is still under construction. A consistent pack, published before applying, usually avoids all of them.

Terms of use

The terms of use are the contract between the business and its visitors and customers. What they should contain, how they are accepted, and which imported clauses fail under Indian law are covered in detail in our website terms and conditions guide — in particular its sections on what the terms should contain and why imported templates fail. This page does not repeat that material.

Within a pack, the terms act as the hub. They set out the core contract and then point to the other documents — “our Refund and Cancellation Policy”, “our Shipping Policy”, “our Privacy Policy” — incorporating them by reference where they are contractual, and saying which prevails if there is ever a conflict. For a brochure site that sells nothing, the terms can be short: ownership of the content, acceptable use, disclaimers, links and governing law.

The privacy policy for a website

The structure of a DPDP-compliant privacy notice — what it must say, section by section — is set out in our DPDP privacy policy guide. For a website, the practical points are specific to how websites collect data:

A privacy policy that is accurate and short is better than one that is long and wrong. If the business uses an order management or CRM system, its data flows should appear too.

Cookies, tags and consent

Cookies are small files a website stores in the visitor’s browser; related technologies include pixels, tags, local storage and device fingerprints. Some are strictly necessary — keeping a visitor logged in or remembering the items in a cart. Others measure visits, remember preferences, or track visitors across sites for advertising.

India has no law aimed specifically at cookies. But where a cookie or tag processes personal data — and advertising and analytics tools usually do, through identifiers linked to a device or person — the DPDP Act applies, and for purposes such as advertising or behavioural profiling the lawful basis will usually be consent: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give. The rules under the Act are being brought into force in phases, so the details should be checked, but the direction is clear.

A sensible approach for most Indian sites is:

  1. list every cookie and tag the site sets, and classify each as necessary, functional, analytics or advertising;
  2. load only necessary cookies until the visitor chooses;
  3. show a banner with equally prominent “Accept” and “Reject” options and a link to settings;
  4. publish a short cookie notice listing the categories, the tools and how to change the choice later; and
  5. record the choice, and re-ask when the list of tools changes materially.

Banners that hide the reject option, pre-tick every category, or keep reappearing until the visitor gives in are the kind of design that consumer regulators now describe as dark patterns; our app compliance guide lists them.

Refund and cancellation policy

The refund policy is the page customers read most closely and the one most often copied without thought. It must reflect what the business can actually do, while respecting what the law requires. The 2020 e-commerce rules oblige online sellers to state clearly, before the sale, their terms on return, refund, exchange, warranty and cancellation before purchase; and consumer law does not allow a seller to refuse to take back goods that are defective, deficient, spurious or not as described, or to impose cancellation charges that are one-sided.

A good policy for goods covers:

The refund policy should be consistent with the payment gateway’s refund process and the courier’s reverse pick-up service, because a promise the business cannot deliver will be enforced against it.

Refunds for services, bookings and courses

Services need different rules, because they cannot be returned in a box. The policy should say when a booking can be cancelled or rescheduled for free, what charge applies after that point and why, what happens if the customer does not turn up, what happens if the business cancels or cannot deliver, and how partly delivered services are refunded. For online courses and memberships, it should state whether there is a trial or a cooling-off period, whether access already used affects the refund, and how subscriptions renew and can be stopped.

Charges must be reasonable and connected to real loss: a clinic that keeps an appointment slot free, a tutor who has blocked hours, a venue that has turned away other bookings. A policy that keeps the whole fee whatever happens, even when the business itself cancels, invites a consumer complaint. Our SaaS guide on renewals covers recurring payments and e-mandates in more depth.

Shipping and delivery policy

For physical goods, a shipping policy answers the questions customers ask most:

Delivery times should be stated as estimates with a realistic range, not guarantees the business cannot control. Where the business promises a delivery date for a specific occasion — a wedding outfit, a gift for a festival — the terms of that promise should be clear.

Store builders, marketplaces and social shops

Many small businesses sell through a hosted store builder, a marketplace, or a social media shop rather than a site built from scratch. Each brings its own layer of terms. A store builder typically offers policy templates and a checkout; a marketplace has its own seller agreement, return rules and grievance process; a social platform has commerce policies that govern what may be sold and how.

Three points follow. First, platform templates are starting points, not finished documents: they do not know whether your products are custom-made, which pin codes you serve or which tools you have added. Second, where you sell on a marketplace, your own policies must fit within the marketplace’s rules — you cannot promise a longer return window than its logistics support, or refuse returns it requires. Third, customers who find you on social media and pay you directly by UPI still need to know your terms; a short link in your profile to your refund policy and contact page helps both sides.

What an online seller must display

The e-commerce rules made under the Consumer Protection Act in 2020 cover anyone selling goods or services to Indian consumers online — a single-brand shop as much as a marketplace. Among other things, they require the entity to display in a clear and accessible manner its legal name, principal geographic address, website and contact details, including customer care; and to appoint a grievance officer, publish the officer’s name, designation and contact details, acknowledge complaints within the time set by the rules and resolve them within the time set by the rules. Marketplaces must also display details of sellers, and information about return, refund, exchange, warranty, delivery and grievance redressal for each product.

The rules also prohibit manipulating the price of goods or services to gain unreasonable profit, posting fake reviews or misrepresenting the quality of products, and recording a consumer’s consent automatically, such as through pre-ticked boxes. The obligations in the terms themselves are discussed in our website terms guide on e-commerce. The pack puts the display obligations into the contact and grievance page, the product pages and the checkout.

Product details on listings

For pre-packaged commodities sold online, the legal metrology rules on packaged commodities require the e-commerce entity to display, on the listing, the declarations that the law requires on the package itself. These generally include the name and address of the manufacturer, packer or importer; the common or generic name of the product; the net quantity; the maximum retail price; the month and year of manufacture or import where required; consumer care details; and the country of origin.

On a marketplace, sellers provide these details and the marketplace displays them; on a single-brand store, the business must add them to each product page. Food products also need the food safety licence or registration number of the business. These are product-page requirements rather than policy documents, but the pack should include a short checklist for the team that creates listings, because a missing declaration is one of the easiest violations to spot.

Prices, taxes and extra charges

Visitors should know the full price before they pay. The e-commerce rules require the total price, with a breakdown of other charges, to be shown before purchase, and the dark pattern guidelines treat drip pricing — revealing charges only at the final step — and basket sneaking — adding items or donations without consent — as unfair. The site should therefore:

A business that is registered under GST must issue proper tax invoices, and should make them available to customers in their order history; our GST registration service can help a new online business register.

Wholesale and business-to-business websites

A website that sells to other businesses — a distributor’s ordering portal, a manufacturer’s catalogue with bulk pricing, an agency’s service pages — is not usually dealing with consumers, and consumer protection rules generally protect people buying for personal use rather than for a commercial purpose. That gives more freedom to set terms, but not unlimited freedom: the Indian Contract Act still applies, and courts read one-sided exclusion clauses strictly.

A B2B pack typically needs terms of sale covering quotations and acceptance, minimum order quantities, price validity, credit terms and interest on late payment, delivery and risk, inspection and rejection of goods, warranty and returns, and limits of liability; a privacy notice covering the business contacts it collects; and, where buyers log in, account and access rules. If the site sells to both businesses and consumers, the terms should say which rules apply to whom, and the consumer protections must remain for consumers.

The disclaimer

A disclaimer tells visitors what the site is not promising. Common elements are:

A disclaimer manages expectations; it is not a shield against the law. The law still holds a business to account to consumers for deficient services or defective goods, or liability for the business’s own negligence or misrepresentation. Written honestly, it helps; written as a blanket denial of every responsibility, it reads badly to customers and to consumer commissions. Our disclaimer drafting service prepares one for the site’s actual content.

Websites of advocates, doctors and advisers

Professionals face rules that ordinary businesses do not. Advocates in India may not solicit work or advertise, directly or indirectly, under the Bar Council of India rules. Those rules have been read to permit a website that gives factual information about the advocate — name, contact details, enrolment, qualifications and areas of practice — without testimonials, claims of success, comparisons or fee offers. Many advocates’ websites therefore show a notice on entry, which the visitor accepts, stating that the site is for information and that the visitor is seeking it of their own accord. The content itself should remain factual.

Doctors are subject to professional conduct rules that restrict self-promotion and the use of patient testimonials, and clinics must also treat health data with particular care. Investment advisers and research analysts registered with SEBI, insurance intermediaries, and chartered accountants and company secretaries each have their own rules on advertising and communications. A professional’s website pack should be written with those rules in mind, and the professional body’s current guidance should be checked, because it changes from time to time.

We follow the same principle on our own site: our advocate directory shows no rankings, ratings or fees, and any advocate’s fee is agreed and paid between the client and the advocate directly.

Websites that accept donations

Trusts, societies and section 8 companies increasingly accept donations online. Their websites need the usual privacy notice and terms, and also a clear statement of who is receiving the money — the registered name and registration details of the organisation — what the donations will be used for, whether receipts will be issued and whether donations qualify for any tax deduction under the organisation’s registration, and the refund policy for donations made by mistake.

Foreign contributions are specially regulated: an organisation may accept them only if it holds the required registration or permission under the foreign contribution law, and then only into the designated account. A donation page open to the world should therefore say whether foreign donations are accepted, and the payment set-up should stop them if they are not. Donor data — names, PAN for receipts, addresses — must be protected and used only for the purposes stated.

The contact and grievance page

A contact page is also a legal page. For a business selling online, it should show:

The page should be reachable from every page of the site, and the grievance officer must actually exist and respond. A named officer who never answers is a published promise broken in public. Sites with user content need a grievance mechanism under the intermediary rules as well, which can be combined on the same page, as our website terms guide explains.

Comments, reviews and user content

A site that lets visitors post comments, reviews, questions, photos or listings will usually count as an intermediary in law, with duties under the intermediary rules to publish its rules, act on lawful takedown orders and run a grievance mechanism. The terms should set out what users may not post; the community guidelines should explain the same in plain language; and the site should give a way to report content. Our guide on user content covers the licence the site takes to what users post and the right to remove it.

Reviews need particular honesty. Consumer rules prohibit fake reviews and the concealment of negative ones, and a standard on online consumer reviews has been issued for e-commerce. A business that hosts reviews of its own products should publish its review policy — who can review, how reviews are checked, whether any are removed and why — and should never write or buy reviews.

Careers pages and job applications

A “Careers” or “Work with us” page collects some of the most sensitive data a small business ever holds: CVs, phone numbers, addresses, previous salaries, sometimes identity documents. The privacy notice should cover applicants specifically — what is collected, who sees it, how long unsuccessful applications are kept, and how an applicant can ask for deletion. Ask only for what the recruitment stage needs, and never request identity documents or bank details before an offer is made.

Fake job offers using real companies’ names are a common fraud in India. A short note on the careers page — that the business never asks applicants for money, and that offers come only from its official email domain — protects applicants and the business’s reputation.

Children and students

A site for school students, coaching, toys or children’s clothing is likely to collect data about children, or about parents on their behalf. Indian data protection law treats everyone below eighteen as a child, asks for the verifiable consent of a parent or guardian before their data is processed, and bars tracking, behavioural monitoring and ads aimed at them, save for the exemptions the rules allow. The practical effect for a website is to design forms for parents, to switch off advertising and profiling tools on children’s pages, and to explain this plainly in the privacy notice. The rules are explained in our DPDP guide on children. A contract made by a minor is also generally void, which is another reason for parents to place orders.

Newsletters, SMS and WhatsApp

Websites are often the start of a marketing relationship: a newsletter sign-up, a discount code in exchange for a phone number, a “WhatsApp us” button. Each channel has its rules. Under the DPDP Act, marketing is a purpose that usually requires specific consent, separate from the consent to process an order or answer an enquiry, and withdrawal must be easy. Promotional and transactional SMS in India travel only through sender IDs and message templates registered on the operators’ platforms under TRAI’s regulations. Business messaging platforms require the customer’s prior opt-in for messages the business initiates.

So the sign-up form should say exactly what the visitor will receive, through which channel, and how to stop it; every email should carry an unsubscribe link; SMS and WhatsApp messages should honour opt-outs; and the privacy notice should list these channels. Buying lists of numbers or emails is both a legal risk and a waste of money. The same rules for apps are summarised in our app compliance guide.

Advertising platforms and analytics

Advertising and analytics platforms impose their own conditions. The major advertising networks generally require advertisers who collect personal information to have a privacy policy, to disclose their use of the platform’s tools, and to obtain consent where the law requires it; ads that lead to a landing page with a missing or misleading policy can be disapproved. Some categories — financial services, health, legal services, gambling — face additional verification or restrictions.

The website pack should therefore describe each tool that is actually installed: web analytics, advertising pixels, conversion tracking, remarketing lists, and customer match uploads. If the business uploads customer lists to an advertising platform, the privacy notice should say so, and the customers must have consented where consent is the basis. When a new tag is added, the cookie notice and privacy policy should be updated at the same time.

Your content, and other people’s

A website is full of copyright material: text, photographs, illustrations, fonts, icons, videos and code. The business owns what it created or had assigned to it; everything else it uses under a licence. Common problems are images copied from search results, stock photos licensed to the developer rather than the business, fonts used beyond their licence, and product photographs taken from a supplier’s site without permission.

The pack should include a short IP statement — a copyright notice, a note on trade marks, and how to report infringement — and the business should keep a record of licences for images and fonts. A website built by an agency should come with a written assignment of the design and code; see our development guide. To protect the brand itself, register the name and logo with a trade mark application. If others copy your content, a copyright infringement notice is usually the first step.

Selling to customers outside India

A website is visible everywhere, but the business chooses where it sells. If it ships abroad or sells digital services to foreign customers, other laws may apply: the European Union’s data protection rules for sites offering goods or services to people in the EU, consumer rights in the customer’s country, customs and import rules, and restrictions on certain products. Payments in foreign currency also raise questions of export documentation and taxes that belong with a chartered accountant.

The pack should say plainly where the business delivers, in which currency prices are charged, who pays duties and taxes on import, how returns from abroad work, and which law governs. If most customers are in India and a few are abroad, it is usually better to limit international sales to specific countries and products than to promise worldwide delivery on the same terms.

Accessibility

Many customers live with some disability, and older customers often have weak eyesight or unsteady hands; a site they cannot use is lost business. Disability law in India, through the 2016 Act and the standards issued under it, is also moving digital services towards accessible design. The practical basics are text alternatives for images, sufficient colour contrast, text that can be enlarged, full keyboard navigation, labelled form fields, captions for video, and error messages that explain what to fix.

An accessibility statement is optional but useful: it says what standard the business aims for, known limitations, and how a visitor can ask for help or report a problem. It should be honest; claiming full compliance without testing is a promise that can be checked.

Forms, security and incidents

Legal pages promise security; the site must deliver it. The minimum is a valid HTTPS certificate on every page, forms protected against spam and abuse, software and plugins kept up to date, admin accounts protected with strong passwords and two-factor authentication, and backups that have been tested. Personal data from forms should go to a protected system, not to an unmonitored shared inbox or a spreadsheet anyone can open.

If data is exposed, the DPDP Act requires the business, as data fiduciary, to inform the Data Protection Board and affected people, and many kinds of cyber incident must separately be reported to CERT-In within a few hours. The website pack cannot prevent an incident, but the privacy notice should describe security honestly and the business should know in advance who will do what; see our DPDP guide on breaches.

Domain, hosting and accounts

The legal identity on the website should match who actually controls it. The domain name should be registered in the name of the business, with a business email address the business controls as the contact; the hosting, analytics, advertising, payment gateway and email accounts should belong to the business, with developers and agencies given access rather than ownership. When a developer who registered the domain in their own name disappears, the business can lose its website, its email and its customers overnight.

Keep a simple register of every account: provider, owner, who has access, renewal date and where the credentials are kept. Renew the domain for several years at a time, and switch on auto-renewal. The same principle for apps and code repositories is explained in our software development guide.

Where the links should go

A policy protects the business only if the customer had a fair chance to see it at the right moment.

Swipe to see the full table
PlaceWhat to link or show
Footer of every pageTerms, privacy, refund and cancellation, shipping, disclaimer, cookie settings, contact and grievance
Every formA line such as “We use these details to call you back. See our Privacy Policy”, plus a separate unticked box for marketing
Sign-upTerms and privacy, accepted by an action, with the version recorded
Product pagePrice with taxes, delivery estimate, return eligibility, product declarations
CheckoutFull price breakdown, refund and cancellation summary, acceptance of terms
Subscription screenPrice, renewal period, how to cancel, before payment
Order confirmation emailOrder details, invoice, links to refund policy and grievance contact

How acceptance should be presented and recorded — clickwrap rather than a silent link — is explained in our website terms guide.

Dates, versions and changes

Every legal page should show an effective date. When a page changes materially, the business should keep the earlier version, record the date of change, and tell registered customers in advance where the change affects them — for example new charges, a shorter return window, or a new use of personal data that needs fresh consent. Changes should not apply retrospectively to orders already placed.

A simple change log at the foot of each document, and an archive of previous versions, is enough for most businesses. It answers the question that matters in any dispute: what did the page say on the day the customer placed the order? Our guide on versions of terms discusses this further.

Hindi and other languages

Many Indian customers are more comfortable reading Hindi or a regional language than English. The DPDP Act allows individuals to access the privacy notice in English or in any language specified in the Eighth Schedule to the Constitution, and a business whose customers read Hindi should consider a Hindi version of at least its privacy notice, refund policy and contact page. Where two versions exist, say which prevails in case of difference, keep them in step when either changes, and make sure the translation is accurate rather than machine-generated without review.

The annual review

Websites change quietly: a new plugin, a new payment option, a new product range, a marketing agency that adds tags. Once a year, and whenever the site changes significantly, run through a short check.

Swipe to see the full table
CheckQuestion
IdentityDo the legal name, address and GSTIN match the business’s current documents?
FormsDoes each form ask only for what is needed, and link to the privacy notice?
ToolsDoes the cookie notice list every tag and tool currently installed?
VendorsDoes every vendor that handles customer data have processing terms?
RefundsDoes the refund policy match what the team actually does?
DeliveryAre delivery areas, times and charges still accurate?
GrievancesIs the grievance officer current, and are complaints answered on time?
ListingsDo product pages carry the required declarations?
MarketingAre consents recorded, and do opt-outs work?
AccountsAre the domain, hosting and payment accounts in the business’s name?
VersionsAre effective dates current and earlier versions archived?

For a fuller check of personal data across the whole business, not only the website, our DPDP compliance review covers systems, vendors, staff and processes.

An example: a boutique’s online store

The Karol Bagh boutique from the top of this page sold ready-to-wear clothes and made-to-measure outfits. Its new pack started from a list of how the store worked: orders through the website and Instagram, payment by UPI and cards through a gateway, cash on delivery in Delhi NCR only, delivery through two courier partners, alterations in the shop, and an analytics tool and an advertising pixel installed by the marketing agency.

The refund policy distinguished the two product lines: ready-to-wear items could be returned within seven days of delivery, unused and with tags, for a refund or exchange; made-to-measure outfits could be cancelled free of charge before cutting, and afterwards only for defects or where the garment did not match the agreed measurements, which the shop would correct first. Defective or wrong items were always taken back, with free pick-up. Refunds went to the original payment method within seven working days of approval, and cash-on-delivery refunds to a bank account the customer nominated.

The shipping policy set out delivery areas, estimated times and charges, and a forty-eight-hour window to report damage with photographs. The contact page showed the proprietor’s legal name, the shop address, GSTIN, customer care hours and a grievance officer. The cookie banner held back the pixel until the visitor accepted, and the privacy notice described the pixel and the agency. The gateway activated live payments on the next review, and the refund disputes stopped once the policy matched practice.

An example: a clinic’s appointment website

A physiotherapy clinic in Janakpuri wanted a website where patients could book and pay for sessions. Its pack had to work for a booking site, a health-data site and a professional practice at once.

The terms explained booking, rescheduling up to four hours before a session without charge, a modest late-cancellation charge that reflected the blocked slot, full refund if the clinic cancelled, and packages that could be paused on medical grounds. The privacy notice kept the booking form to name, phone, preferred time and a short reason for the visit, said that clinical notes were recorded at the clinic and not through the website, and described the booking software provider as the clinic’s processor. Marketing messages required a separate tick. The disclaimer made clear that articles on the site were general and not a substitute for assessment, and the site avoided patient testimonials and claims of cures, in line with professional conduct expectations. The grievance and contact page named the clinic’s legal entity, the registered practitioner and the complaint process.

Where website policies go wrong

Our fee and what you get

Our website legal pack costs ₹4,999 and is ready in 2 – 5 days. We start from how your site works — what it sells, what it collects, which tools and vendors it uses — and draft every page together so that they agree with each other and with your practice.

Swipe to see the full table
IncludedWhy it helps
Terms of useA clear contract for orders, accounts and content
DPDP-compliant privacy policyAn honest notice matched to your forms and tools
Refund and cancellation policyRules customers understand and your team can follow
Shipping and delivery policy (for goods)Fewer delivery disputes
Disclaimer and cookie notice with banner textExpectations set, tracking choices given
Contact and grievance page, and a placement checklistWhat payment gateways and consumer rules expect

Individual documents are also available on their own: a privacy policy, terms and conditions, a refund policy or a disclaimer. We tell you the total before we start. Should a dispute reach a consumer commission, an arbitrator or a court, it is for your advocate, whose fee is engaged and paid by you directly; we do not quote, collect or share it. You can find an advocate through our directory.

FAQ

Website legal pack — questions people ask

What legal pages does a website need in India?
It depends on what the website does. Almost every site that collects any personal data — even through a contact form — needs a privacy notice under the DPDP Act. A site that sells goods or services online also needs terms of use, a refund and cancellation policy, delivery terms where goods are shipped, and the contact and grievance officer details required by the consumer protection e-commerce rules. Sites with user content need community rules and a grievance mechanism under the intermediary rules. A disclaimer and a cookie notice complete the usual set.
What is a website legal pack?
A set of legal documents prepared together for one website, so that they are consistent with each other and with how the site actually works: usually terms of use, a privacy policy, a refund and cancellation policy, a disclaimer, a cookie notice, and for online sellers a shipping or delivery policy and a grievance and contact page. Preparing them together avoids contradictions, such as a privacy policy that promises something the terms deny.
Do I need a privacy policy if my website only has a contact form?
Yes, in most cases. A contact form collects names, phone numbers and email addresses, which are personal data. The DPDP Act requires a notice explaining what is collected and why before consent is sought. A short, accurate privacy notice for a simple site is not difficult to write, but it should describe what that site actually does, including analytics and embedded services.
Why does my payment gateway ask for a refund policy and terms?
Payment aggregators regulated by the Reserve Bank of India must carry out checks on the merchants they onboard, and they generally require the merchant’s website to show its terms and conditions, privacy policy, refund and cancellation policy and contact details before activating live payments. Missing or copied pages are one of the most common reasons for delayed activation.
Is a refund policy compulsory for an online store?
The consumer protection e-commerce rules require online sellers and marketplaces to give clear information about return, refund, exchange, warranty and cancellation before purchase. A seller can set reasonable conditions, but cannot refuse to take back goods that are defective, deficient, spurious or not as described, and cancellation charges must be fair. A written refund policy is how those terms are communicated.
Do Indian websites need a cookie banner?
Indian law has no cookie-specific rule, but cookies and similar tools that collect personal data for purposes such as advertising or behavioural analytics generally need a lawful basis under the DPDP Act, usually consent. Strictly necessary cookies that make the site work are different. A simple banner that lets visitors accept or reject non-essential cookies, with a short cookie notice, is the safer practice, and is expected by visitors from Europe.
Can I copy terms and a privacy policy from another website?
You should not. Another site’s documents describe its business, not yours; they may be protected by copyright; and imported templates often contain clauses that do not work under Indian law or contradict what your site actually does. A regulator or court will judge your documents against your real practices, so accuracy matters more than length.
What is a disclaimer, and does it protect me?
A disclaimer tells visitors the limits of what the site offers — that information is general and not professional advice, that results are not guaranteed, that external links are not endorsed. It reduces misunderstandings and sets expectations. It cannot exclude liability the law does not allow to be excluded, such as liability to consumers for deficient service or for your own negligence.
Can an advocate have a website in India?
Advocates may not advertise or solicit work under the Bar Council of India rules. The rules have been read to allow a website that gives factual information — name, address, contact details, enrolment, qualifications and areas of practice — without self-praise, client testimonials or claims of results. Many advocates’ sites show an entry notice confirming that the visitor is seeking information of their own accord. Advocates should take care that their site stays within these limits.
What details must an e-commerce website display about itself?
Under the consumer protection e-commerce rules, an e-commerce entity must display its legal name, principal geographic address, website, contact details including customer care, and the name, designation and contact details of its grievance officer, who must acknowledge complaints and resolve them within the times set by the rules. Marketplaces must also show key details of sellers.
Do product listings need MRP and country of origin?
For pre-packaged goods sold online, the legal metrology rules require the e-commerce entity to display the declarations that must appear on the package, such as the manufacturer or importer, the common name of the product, net quantity, maximum retail price, consumer care details and country of origin. Sellers should supply these for every listing.
Where should the legal pages be linked on a website?
In the footer of every page, and at the points where they matter: the privacy notice next to every form that collects personal data, the terms and refund policy at checkout with a clear acceptance step, subscription terms before payment, and community rules at sign-up for sites with user content. A policy that exists but cannot be found at the right moment protects no one.
How often should website policies be updated?
Whenever the site changes in a way that affects them — a new payment method, a new analytics or advertising tool, a new product line, a new country — and at least once a year. Show the effective date on each document, keep earlier versions, and tell registered users about material changes before they take effect.
Do I need a separate policy for WhatsApp and email marketing?
Not a separate document, but the privacy policy should describe each channel, and the site should collect a separate, specific consent for marketing messages, with an easy way to opt out. Commercial SMS must also follow the telecom regulator’s rules on registered senders and templates, and business messaging platforms require prior opt-in.
Does my website need to be accessible to people with disabilities?
It should be. Accessibility is expected more and more, both by customers and under the Rights of Persons with Disabilities Act, 2016 and the accessibility standards issued for digital services. Building a site that works with screen readers and keyboards, with good contrast and captions, is good practice for every business.
Should the website be in the name of the business?
Yes. The domain name, hosting account, analytics, payment gateway and email should be registered to the business and controlled by it, not by a developer or employee. The legal pages should identify the same legal entity, so that customers know whom they are dealing with and the business can prove the site is its own.
What does your website legal pack cost?
Our website legal pack costs ₹4,999 and is ready in 2 – 5 days. It includes terms of use, a DPDP-compliant privacy policy, a refund and cancellation policy, a disclaimer and a cookie notice, and, where the site sells goods, a shipping and delivery policy and a grievance and contact page, all drafted for your site and consistent with each other. We tell you the total before we start. Any dispute that goes to a consumer commission, arbitration or court is for your advocate, whose fee is engaged and paid by you directly.
Related

Website, app and privacy documents

Privacy policy Website terms and conditions Refund policy Disclaimer DPDP compliance review App store compliance documents Data processing agreement Trademark registration GST registration Website terms guide DPDP privacy policy guide App store compliance guide Find an advocate All document guides

Make the small print tell the truth.

The pages at the bottom of your website decide what happens when a customer wants a refund, a regulator asks about data, or a payment gateway reviews your account. Tell us how your site works and we will write every page to match it — together, consistent, and in plain language.

No payment now · Pay only after the work is done
Tis Hazari Court Complex, New Delhi, Delhi 110054
Keep reading

Related guides

App Store Compliance — The Documents the Stores Ask For, and the Indian Law Behind Them Data Processing Agreement — When Someone Else Handles Your Customers’ Data End User Licence Agreement — What the User Buys When the Software Stays Yours Software Development Agreement — Build It, Test It, Own It Revenue Sharing Agreement — Share the Income, Not the Arguments Co-founder Agreement — Decide It Before It Costs Money
82 of 281 document services now have an in-depth guide199 still to be written · see them all →
We are writing these one at a time rather than generating them, which is why it is taking a while. 29% done.
Advocates & Clients

Need an advocate? Or are you one?

Two doors, both free. Clients search a factual directory of enrolled advocates. Advocates apply to be listed on it — no fee, no commission, nothing paid in either direction.

Looking for an advocate?

Search Bar Council enrolled advocates by what your matter is about, by court, or by city. Searching and sending a request are both free.

Are you an advocate?

Enrolled advocates anywhere in India can apply to be listed. Your entry is published only after we verify your enrolment number with your State Bar Council.

  • No listing fee, no subscription, no commission — no money moves in either direction.
  • A directory entry, not an advertisement: only the particulars the Bar Council permits.
  • You keep the client. We do not take instructions for you and take no share of your fee.

This directory carries no ratings, no reviews, no rankings and no fees — only the factual particulars the Bar Council of India permits, published at each advocate's own request. Browse the network · Terms for Advocates

Help