About this tool
Create a mailing list privacy policy with consent records, tracking pixel disclosure and CAN-SPAM and CASL opt-out deadlines worked out.
A newsletter privacy policy is the subscriber-facing notice that records three separate things: how consent to email was obtained and can be proved, what the tracking pixel and wrapped links inside each message collect, and what happens to an address after someone unsubscribes. This generator assembles that notice and works out the deadlines the law attaches to it — the 10 business days both CAN-SPAM and CASL allow for actioning an opt-out, the 60 days a CASL unsubscribe link must stay live, and the 24-month or 6-month expiry of implied consent under Canadian law.
Open Newsletter Privacy Policy Generator on AltFTool — it loads instantly in your browser.
Provide your input — an image, text, or data.
Let the tool analyze or generate the result.
Review, refine, and reuse the output wherever you need it.
Opt-out, unsubscribe-link validity and implied-consent expiry are calculated, with business days counted properly.
Open and click tracking are set out as what they are, and tied to the consent rule that actually covers them.
The notice records the date, form wording and IP kept as proof, because the sender carries that burden.
Within 10 business days under the CAN-SPAM Act at 15 U.S.C. section 7704(a)(4), and without delay and in any event within 10 business days under Canada's Anti-Spam Legislation. The opt-out mechanism itself must keep working for at least 30 days after the message was sent under CAN-SPAM, and at least 60 days under CASL, so a link that dies with the campaign is a breach even if the request was actioned.
No law names double opt-in, but Article 7(1) of the GDPR puts the burden of proving consent on the sender, and a confirmation click is the evidence supervisory authorities expect. Single opt-in also lets anyone add someone else's address to your list, which turns a complaint into a problem you cannot rebut.
Twenty-four months from a purchase, contract or other transaction, and six months from an inquiry. Express consent does not expire on a timer and lasts until it is withdrawn, so the practical rule is to convert implied consent to express consent before the clock runs out.
For subscribers in the EU and UK, yes. Article 5(3) of the ePrivacy Directive covers storing or reading information on a person's device, and loading a tracking pixel reads information from theirs, so it is treated the same way as a cookie rather than being covered by the consent to receive the email. Disclose it in the notice and let people opt out of tracking separately where you can.