CCPA/CPRA and US state privacy
By OptinStack Team - Jun 28, 2026 - 2 min read
This article explains how OptinStack supports opt-out and do-not-sell or share flows under the CCPA/CPRA and other US state privacy laws. It describes what the platform does, not what your business must do.
This is not legal advice. US state law is changing quickly and your obligations depend on where your visitors are. Have a qualified advisor confirm your setup.
The dont-sell banner mode
Use the dont-sell mode for CCPA/CPRA do-not-sell or share flows. It surfaces a clear opt-out path and records the visitor's choice. For general opt-out contexts, opt-out mode starts optional categories as granted and lets the visitor withdraw.
Global Privacy Control as a valid signal
When a visitor's browser sends Global Privacy Control, OptinStack treats it as a valid opt-out signal. All optional categories default to denied, and the gpc flag is recorded in the synced consent record so you can audit it.
Related articles
Basic vs Advanced Google Consent Mode
Compare Basic and Advanced Google Consent Mode, including tag loading, cookieless pings, GTM settings, verification, and when each mode makes sense.
Brand the banner and preferences dialog
Brand the banner and preferences dialog using dedicated tokens injected into the Shadow DOM.
Set up Google Consent Mode v2
Map OptinStack's four consent categories onto Google Consent Mode v2 and keep them in sync as visitors choose.
How helpful was this article?