CCPA Compliance for Ecommerce: A Practical Store Owner Guide

By shopifypolicy Editorial Team · Last updated 2026-08-25 · 8 min read

The California Consumer Privacy Act (CCPA), updated by the California Privacy Rights Act (CPRA) amendments, is the main privacy law affecting American ecommerce. It gives California residents the right to know what personal data you collect, the right to delete it, the right to opt out of its sale or sharing, and the right to equal service even when they exercise those rights. If your store sells to California shoppers, and most do, this law likely applies to you. The good news: for a typical ecommerce store, CCPA compliance is mostly about disclosure and process, and you can generate a compliant privacy policy to cover the biggest piece of it.

Does the CCPA apply to your store?

The CCPA applies to for-profit businesses that collect California consumers' personal information and meet any one of three thresholds: annual gross revenue over $25 million; buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50% or more of annual revenue from selling or sharing personal information.

The second threshold is the one that surprises store owners. If your analytics, ad pixels, and marketing tools process data on 100,000+ California consumers or households — counting every visitor, not just buyers — you qualify. Note that the CCPA also applies to businesses outside California and outside the United States, as long as they handle California consumers' data. And if you are below every threshold today, treat that as a grace period, not an exemption: revenue grows, traffic grows, and the CPRA lowered the household counting rules in ways that capture more stores over time.

The consumer rights you must honor

The right to know. A California shopper can ask what personal information you have collected about them, what categories of sources it came from, why you collect it, who you share it with, and how long you keep it. Your privacy policy must answer most of this proactively, and you must respond to individual requests within 45 days.

The right to delete. Consumers can request deletion of the personal information you hold. You must delete it — and instruct your service providers to delete it too — with narrow exceptions (for example, data you need to complete a transaction, detect fraud, or satisfy other legal obligations).

The right to opt out of sale or sharing. This is where most ecommerce stores stumble. Under the CPRA, "sharing" personal information for cross-context behavioral advertising counts — which means your Facebook and Google ad pixels can trigger opt-out obligations. You must post a clear "Do Not Sell or Share My Personal Information" link (or "Your Privacy Choices") and honor opt-out preference signals such as the Global Privacy Control (GPC) browser setting.

The right to correct. The CPRA added the right to have inaccurate personal information corrected, and the right to non-discrimination — you cannot punish shoppers with worse prices or service because they exercised any CCPA right.

What your privacy policy must disclose

CCPA Section 1798.135 and its regulations require specific disclosures in your privacy policy: the categories of personal information you collect (identifiers, commercial information, internet activity, geolocation, and more); the categories of sources; the business or commercial purpose for collecting each category; the categories of third parties with whom it is shared, sold, or disclosed; whether you sell or share personal information; and how long you retain each category of data.

For most stores the list of "third parties" is long: your ecommerce platform, payment processor, shipping carrier, email marketing tool, analytics provider, ad platforms, and review widgets all receive customer data. That is normal and permitted — but only if you disclose it. An accurate, complete inventory of your data flows is the heart of CCPA compliance, and it is exactly what a good privacy policy generator walks you through.

Practical steps to get compliant

1. Inventory your data. List every tool on your site that touches customer data — platform, pixels, analytics, email, chat, reviews. For each, note what it collects and why.

2. Update your privacy policy. It must include the CCPA disclosures above and explain how California consumers can submit requests. You can create one in minutes with our free generator, which builds CCPA and GDPR clauses automatically.

3. Add the opt-out link. Place a "Your Privacy Choices / Do Not Sell or Share" link in your footer and wire it to an opt-out mechanism that also honors GPC signals.

4. Create a request process. Decide how customers can submit requests (email, form), who handles them, and how you will respond within 45 days. Two identical requests from the same person within 12 months let you treat it as one request.

5. Check your contracts. Your service providers and third parties need contract terms restricting how they use the data — most major platforms provide these, but you have to accept them.

CCPA vs GDPR: the short version

Store owners often ask whether CCPA compliance means GDPR compliance. It does not. The GDPR applies to EU/UK visitors, requires a legal basis for all processing, and demands affirmative consent for cookies and marketing. The CCPA is narrower: it centers on disclosure, deletion, and opt-out of sale/sharing rather than consent up front. The practical takeaway is that a well-built policy covers both — our generator includes jurisdiction-aware clauses so you are not rewriting everything the day you get your first EU customer.

What happens if you ignore it

The California Privacy Protection Agency and the Attorney General can enforce the CCPA. Intentional violations carry civil penalties of $2,500 per violation and $7,500 per intentional violation or violations involving minors — and because each affected consumer can technically count as a separate violation, the numbers escalate fast. Beyond fines, a non-compliant store is also exposed to class action risk. Consumers read privacy policies more than store owners expect, and "Your Privacy Choices" links are now a familiar sight to California shoppers.

Start with your policy today

CCPA compliance is a process, but the first and most visible step is your privacy policy — it is what regulators, customers, and auditors look at first. Use the free policy generator to produce a CCPA-ready privacy policy for your store in under a minute, add the opt-out link to your footer, and set up your request process. Those three moves cover the vast majority of what a typical ecommerce store needs to satisfy the CCPA. For a broader look at obligations across jurisdictions, see our GDPR compliance guide for small ecommerce and the ecommerce legal requirements checklist.