# CCPA/CPRA and US state privacy

> How OptinStack supports CCPA/CPRA and US state opt-out and do-not-sell flows, including GPC as a valid signal.

Author: OptinStack Team  
Published: 2026-06-28  
Page: https://community.optinstack.com/articles/ccpa-cpra-and-us-state-privacy  
Markdown: https://community.optinstack.com/llms.md/articles/ccpa-cpra-and-us-state-privacy

This article explains how OptinStack supports opt\-out and do\-not\-sell or share flows under the CCPA/CPRA and other US state privacy laws\. It describes what the platform does, not what your business must do\.

> **Warning:** This is not legal advice. US state law is changing quickly and your obligations depend on where your visitors are. Have a qualified advisor confirm your setup.

## The dont\-sell banner mode

Use the dont\-sell mode for CCPA/CPRA do\-not\-sell or share flows\. It surfaces a clear opt\-out path and records the visitor's choice\. For general opt\-out contexts, opt\-out mode starts optional categories as granted and lets the visitor withdraw\.

## Global Privacy Control as a valid signal

When a visitor's browser sends Global Privacy Control, OptinStack treats it as a valid opt\-out signal\. All optional categories default to denied, and the `gpc` flag is recorded in the synced consent record so you can audit it\.

### Does OptinStack honor Global Privacy Control for CCPA?

Yes. When GPC is active, OptinStack denies optional categories and stores the gpc flag in the consent record. This supports do-not-sell or share and opt-out flows.

### Which mode should I pick for US visitors?

Use dont-sell for explicit do-not-sell or share flows, and opt-out where the law allows opt-out as a valid basis. The choice changes the banner wording and starting state.
