Not to mention some jurisdictions requiring a privacy policy, like California.
One of the best "features" of the internet is that it is jurisdictionally grey.
Otherwise, why not just subject the entire world to the stringent requirements of China?
In other words: They should post a privacy policy - not because it's a legal requirement (though it may be) - but because it's good business. And no one will trust them otherwise.
I can summarize 95% of privacy policies right here:
* We won't sell your info (directly)
* We "may" provide your info to third parties based on ill-defined criterion
* We can change this at any time without telling you first
* If we get bought (which is likely), this is all rendered invalid
* If we break our word here, your recourse is precisely jackhttp://leginfo.ca.gov/cgi-bin/displaycode?section=bpc&group=...
Whether this really matters to a particular company depends on where they are, but full-faith-and-credit means that at a minimum anyone based in the US has to worry about it.