Getting yourself to come up with a AUP/TOS/Privacy Policy is easy. First, just like lesli, take a look at your datacenter's AUP/TOS and see what their uptime and downtime policies are like. This is going to be the base on your uptime guarantee and other technical related policies.
Then take a look at your business process. Every Standard Operation Procedure you had to follow in your company will and might affect on how you will handle your customers. Things like promotions and refund policies and other related business policies that might be included.
Speaking of refunds, the billing policies are very important too. You have to look into your merchant gateway (if you are using authorize.net or PayPal) and see how they handle refunds and chargebacks to customers.
There are more details you need to figure out of course, but you get the idea.
