Terms of Service Generator for California Businesses
Enter your URL. We'll find the services collecting visitor data and generate the documents that disclose them.
Free scan and score. Privacy Policy, Terms and Cookie Policy for $19 one-time.
California has more website privacy law than any other state, and much of it applies to businesses far smaller than the CCPA thresholds. The California Online Privacy Protection Act, CalOPPA, requires any commercial website or app that collects personally identifiable information from California residents to post a conspicuous privacy policy. That policy must list the categories of information collected, the categories of third parties it may be shared with, how users can review and request changes to their information, how the operator responds to Do Not Track signals, whether third parties collect data across sites, the effective date, and how users are notified of changes. There is no revenue threshold; a contact form is enough.
The CCPA and CPRA add the rights to know, delete, correct and opt out for businesses that meet the revenue or volume thresholds, and the Shine the Light law gives customers the right to ask what information was disclosed to third parties for direct marketing. Enforcement has focused on the practical details: whether a Do Not Sell or Share link exists, whether opt-out requests actually stop Meta Pixel and Google Ads from firing, and whether the policy is current.
VerifiedPrivacy scans your site for the analytics, advertising, form and embed services that must be disclosed, then generates a Privacy Policy with California sections, plus Terms of Service and a Cookie Policy. Enter your URL below to see your free coverage score.
Frequently asked questions
Is CalOPPA different from the CCPA?
Yes. CalOPPA, in force since 2004, requires any commercial website collecting personal information from California residents to post a privacy policy with specific contents, with no size threshold. The CCPA and CPRA, from 2020 and 2023, grant consumers rights and impose obligations only on businesses above revenue or data-volume thresholds. Most California-facing sites must satisfy CalOPPA; fewer must also satisfy the CCPA. The generated policy addresses both.
Do I have to say how I respond to Do Not Track?
CalOPPA requires the policy to disclose how the site responds to browser Do Not Track signals, or to link to a program that describes it. The law does not require you to honor the signal, only to say what you do. The generated Privacy Policy includes a Do Not Track statement in the California section that you should adjust to reflect your actual practice, particularly if you also honor Global Privacy Control.
My business is outside California. Does this apply to me?
CalOPPA applies to operators of commercial websites that collect personal information from California residents, wherever the operator is located. If Californians can reach your site and submit a form or be tracked by analytics, the law's authors intended it to reach you. The CCPA likewise applies to out-of-state businesses that meet its thresholds and do business in California. Answer yes to the California question if this describes you.
What is the Shine the Light law?
California Civil Code section 1798.83 gives customers the right to ask a business once a year which personal information it disclosed to third parties for those parties' direct marketing, and who those parties were. Businesses with fewer than twenty employees are exempt, and businesses can instead offer a free opt-out. The generated Privacy Policy includes a short Shine the Light statement in the California section for you to confirm.
Does the policy include an effective date and change notice?
Yes. CalOPPA requires both, and the questionnaire asks for an effective date, defaulting to today. The generated Privacy Policy displays it in the introduction and includes a changes section explaining how updates are communicated. When you regenerate from your permanent link after a change, update the effective date in your answers so the published policy reflects when it was last revised.
Other guides
VerifiedPrivacy generates documents from a clause library. It is not a law firm and does not provide legal advice. Have a licensed attorney review documents before use.