It is difficult for others to say whether you actually
need it or not, but I would recommend it for anything that accepts user input. It is both encryption and authentication.
* It identifies the server as being yours and not an imposter
* It guarantees that the data was not tampered with between sender and receiver
* It encrypts each transaction making it unreadable by others in between
You can get free certs -
LetsEncrypt.org, I use these and there is nothing second-rate about them. You will need to renew them every ninety days, but there are automated tools to do that for you.