A privacy policy is a page explaining what personal information your website collects, what you do with it, how long you keep it and how somebody asks for a copy or asks you to delete it. The moment a form on your site takes a name, an email or a photo of somebody house, you are handling personal data and UK law applies.
What it has to cover
Who you are, with a real way to contact you. What you collect, which for a trade site is usually a name, a phone number, an email, a postcode and sometimes photos of the job. Why you collect it, which is to quote and to carry out the work.
How long you keep it, who else sees it, such as your form provider or your accountant, and the rights people have to see, correct or delete what you hold. Write it in normal words. The Information Commissioner Office publishes free guidance and templates aimed at small organisations.
The bits people get wrong
Copying a policy from another firm and leaving their company name in it. It happens constantly, and it is the kind of detail a customer notices at exactly the wrong moment.
The other one is describing cookies you do not have or analytics you never installed. A policy that does not describe your actual site is worse than a short honest one, because it is a written statement that is not true.
A worked example
A drainage firm has a quote form that takes a name, a number, a postcode and a photo of the drain. Those photos sit in an email inbox for years.
The privacy page says so plainly: what is taken, that photos are kept with the job record, how long for, and that anyone can ask for theirs to be removed. That is a twenty minute job and it is the whole requirement in practice.