Any business holding customer names, addresses, payment details or photographs of their property is handling personal information, and that carries obligations.
They apply to small businesses
Thresholds exist in some laws and not in others, and several apply from the first customer. Assuming the business is too small is a common and unreliable position.
Obligations are also frequently set by where the customer is rather than where the business is, so serving customers across a state line can bring another regime into play.
The recurring obligations
Collect only what is needed for the work.
Keep it securely, with access limited to people who need it — see deciding who has access.
Keep it only as long as required — see record retention.
Dispose of it properly. Records with personal information cannot simply be discarded.
Say what is collected and why, which is what a privacy policy is for.
Respond to requests from individuals about their own information, within a time limit in several regimes.
Notify people if it is exposed, generally on a short deadline — see cyber liability insurance.
Privacy policy and terms of service
A privacy policy describes what is collected and how it is used. Required in most places where a business collects anything online, including through a contact form.
Terms of service govern use of a website or an online service, which is a different document with a different purpose.
Both are commonly copied from another business, and both then describe practices the business does not follow — which is worse than not having them, because they become a documented commitment.
Payment details
Card data carries its own requirements. The practical answer for a small business is not to store it at all, letting the payment processor hold it — see payment processing.
Where to get it right
The specific regimes and thresholds vary and change. This is a question for an attorney familiar with the jurisdictions the business serves.
