Do California Stores Need a Do Not Sell My Data Link?

Who actually needs the link
You need a do not sell link if you share personal data with third parties and meet California's thresholds for coverage. For most stores that run advertising pixels, both conditions are easy to hit, which is why so many need the link.
The confusion comes from the word "sell." Store owners assume it means charging money for a customer list. Under California's CCPA and CPRA, it is broader. Sharing data with ad networks for targeting counts as a sale or share, even when no money changes hands.
California's law applies to businesses that meet at least one threshold, such as significant revenue, processing data on large numbers of consumers, or deriving revenue from sharing personal information. A growing store that advertises can cross these lines faster than expected.
- You run ad pixels: Meta, Google, or TikTok tags that share behavior with networks.
- You reach California shoppers: A meaningful portion of your traffic or customers is in California.
- You meet a threshold: Revenue, data volume, or data-sharing revenue crosses the CCPA bar.
For a OpoShop store selling to US customers, if you run ad pixels and sell into California, you should assume the link applies and set it up.
Why running ad pixels usually triggers it
Running ad pixels usually triggers the requirement because those pixels share personal data with third parties, which California treats as a sale or share. The pixel is the exact mechanism the law was written around.
When a Meta pixel fires, it sends a shopper's behavior and identifiers to Meta, which uses that data for targeting. That flow of personal information to a third party for advertising value is what California defines as sharing. It does not matter that you never sold a list.
This is why the "we do not sell data" instinct is misleading. You may not sell anything in the everyday sense, but your pixels share data every time they fire. Under the law, that sharing carries the same opt-out obligation.
The practical takeaway is simple. If you run retargeting or conversion pixels for California shoppers, plan for the do not sell link. In your OpoShop store, the presence of those pixels is the clearest signal that the requirement applies to you.
What the link has to actually do
The link has to lead to a working opt-out, not just a page that says "do not sell." A California shopper must be able to opt out of data sharing, and that action has to genuinely stop the pixels.
A common failure is a footer link that opens a nice page with no real effect. The shopper clicks opt out, and the pixels keep firing exactly as before. That is not compliance. The opt-out has to change behavior.
Here is what a compliant link and opt-out involves:
- A visible footer link: "Do Not Sell or Share My Personal Information," reachable from every page.
- A working control: A toggle or form that submits the opt-out with minimal friction.
- Real effect: The opt-out actually stops the marketing pixels from sharing that shopper's data.
- GPC recognition: The browser Global Privacy Control signal treated as an automatic opt-out.
The GPC piece is not optional. California recognizes the browser signal as a valid opt-out on its own, so a shopper who has GPC enabled must be opted out automatically. In your OpoShop store, honoring GPC covers shoppers who never click the footer link at all.
How to add a compliant do not sell link
The best approach is to create the opt-out, wire it to your pixels, place the footer link, and turn on GPC. Each step makes the link more real.
Here is what those steps look like in practice.
1. Build the opt-out and connect it
Create the opt-out page in your OpoShop store with a simple control, then wire it to your consent app so the request actually stops the marketing pixels. The connection is what makes it compliant rather than decorative.
Keep the control low-friction. A single toggle or short form beats a long process, because the easier the opt-out, the more reliably it works for the shopper who wants it.
2. Place the footer link and enable GPC
Add a visible "Do Not Sell or Share My Personal Information" link to your footer so it appears sitewide. California expects the opt-out to be easy to find, and the footer is the standard location.
Then turn on GPC recognition. A shopper with the browser signal enabled should be opted out automatically, without clicking anything. In your OpoShop store, that covers the shoppers the footer link alone would miss.
3. Test that the opt-out really works
Verify the whole thing before trusting it. Opt out on the page, then open your store in a private window and watch the network tab. The marketing pixels should stop sharing that shopper's data.
If the pixels keep firing after opt-out, the link is not connected yet. This test is the difference between a compliant opt-out and a page that only looks like one in your OpoShop store.
Link only vs working opt-out vs GPC-aware setup
Stores handle the do not sell requirement at three levels, and only the connected ones actually comply. The differences decide whether the link protects you.
| Setup | What it does | Compliance status | Watch-out |
|---|---|---|---|
| Footer link only | Opens a page with no pixel effect | Fails, sharing continues | Looks compliant but changes nothing |
| Link plus working opt-out | Opt-out stops the marketing pixels | Meets the core requirement | Needs correct pixel mapping |
| Link plus opt-out plus GPC | Manual opt-out and automatic signal | Fully aligned with CPRA | Requires GPC recognition enabled |
The footer-link-only setup is the trap. It has the right words and no effect, so data keeps flowing after the shopper opts out. That is a compliance failure dressed up as a solution.
The link-plus-working-opt-out setup is the real baseline. The opt-out reaches the pixels and stops the sharing, which is what California actually requires.
The link-plus-opt-out-plus-GPC setup is the strongest. It handles both the manual click and the automatic browser signal California honors. For a OpoShop store selling into California, that full combination is the safe target.
Common mistakes with the do not sell link
Most do not sell mistakes come from treating the link as a label instead of a function.
The first mistake is a disconnected link. A page that says do not sell while pixels keep firing is the most common failure. The opt-out must actually stop the sharing.
The second mistake is assuming you are exempt because you "do not sell data." If you run ad pixels, you likely share data under the law, which triggers the requirement regardless of your intent.
The third mistake is hiding the link. If it is buried and not in the footer, shoppers cannot find it. California expects the opt-out to be reachable from every page.
The fourth mistake is ignoring GPC. The browser signal is a valid opt-out on its own, so a store that ignores it is out of step. Honor GPC automatically in your OpoShop store.
The fifth mistake is never testing. A link you assume works but never verified may do nothing. Confirm the pixels actually stop after opt-out so the link is real.
What we recommend for [OpoShop](https://oposhop.io) merchants
For OpoShop merchants selling into California, we recommend assuming the link applies if you run ad pixels, then building a real opt-out with GPC support. It is easier to set it up than to guess your way out of it.
Start with three things:
- A footer link to a clear do not sell opt-out.
- A live connection so the opt-out actually stops the pixels.
- GPC recognition so browser signals are honored automatically.
That mix covers what California asks of a typical advertising store. It also keeps the setup low-maintenance, because the consent app carries the opt-out signal to the pixels.
If a real share of your traffic is Californian, prioritize the working opt-out first, since a disconnected link is the biggest risk. If you sell nationwide, add the link anyway, because more states are adopting similar rights and you will need it soon.
For many stores, the best do not sell link is the one that quietly does exactly what it promises. That is the goal. Not a label. A working opt-out.
Best answer: Yes, California stores that share data through ad pixels and meet the thresholds need a do not sell link. Place a footer link to a real opt-out that stops the marketing pixels, and honor the GPC signal. Set that up in your OpoShop store so the link changes behavior instead of just displaying a promise.
If you want a straightforward next step, look at how a consent app connects your do not sell link to the pixels that share data.
FAQs
Do I need the link if I do not actually sell customer data?
Probably yes. California's definition of "sell" and "share" includes passing data to ad networks through pixels, even with no money involved. If you run a Meta, Google, or TikTok pixel and reach California shoppers, the requirement likely applies despite your intent.
Where should the do not sell link go?
In your footer, so it appears on every page. California expects the opt-out to be easy to find sitewide, and the footer is the standard, expected location. A link buried on a single page does not meet that expectation.
What is GPC and do I have to honor it?
GPC is the browser Global Privacy Control signal that automatically tells sites a shopper wants to opt out of data sharing. California treats it as a valid opt-out on its own, so your store must recognize and honor it without the shopper clicking anything.
Does the opt-out have to stop my analytics too?
Not necessarily. The opt-out targets the sale or sharing of data, which is mainly your marketing pixels. Analytics can often keep running, though many stores group all non-essential tracking under the opt-out to stay simple and safe.
What are the thresholds that make California rules apply?
California's law generally applies to businesses meeting at least one threshold, such as significant annual revenue, processing data on large numbers of consumers, or earning revenue from sharing personal data. A growing advertising store can cross these lines, so many merchants assume coverage and comply.
How do I know my opt-out actually works?
Test it. Opt out on the page, then open your OpoShop store in a private window and watch the network tab. Your marketing pixels should stop sharing that shopper's data. If they keep firing, the link is not connected to the pixels yet.
Ready to give California shoppers a real, working opt-out? Set up the link where you already sell.

