Do California Stores Need a Do Not Sell My Data Link?

Some California-Facing Stores Do, but It Depends on How You Use Shopper Data
Some California-facing stores need a do not sell my data link because California privacy rules focus on data sharing, not just store location. A store in Texas, London, or Berlin can still face California privacy obligations if California shoppers visit the site and the store uses shopper data in ways that count as selling or sharing.
That is the part that trips people up. Merchants often think, "We are not in California, so this probably does not apply to us." That is not a safe assumption if the store gets California traffic and runs tools like Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, or TikTok.
A cookie banner and a do not sell request path are also not the same thing. One manages tracking choices. The other gives shoppers a place to ask the store not to sell or share personal information, or to request deletion or other privacy actions.
If your store sells across California, the EU, and the UK at the same time, separate regional rules are usually part of the job. If you want one place to handle consent settings and privacy requests without patching together forms and spreadsheets, this is a good point to look at your setup.
What Is a 'Do Not Sell My Data' Link?
A do not sell my data link is a visible link that gives shoppers a way to tell a store not to sell or share their personal information. For an online store, that usually means a page or form where a California visitor can submit a privacy request without hunting through legal text.
In plain ecommerce terms, this is the shopper's front door for a specific kind of privacy request. It is not just a sentence buried in the privacy policy, and it is not just banner copy floating at the bottom of the screen.
A lot of small merchants blur these together. They add a cookie banner, update the privacy policy, and assume that covers the whole job. It does not. A consent banner handles tracking choices. A do not sell link handles request intake.
Here is the practical difference:
| Tool | What it does | What it does not do |
|---|---|---|
| Cookie consent banner | Lets shoppers accept or reject certain tracking activity | Does not give shoppers a request form for do not sell or deletion requests |
| Privacy policy | Explains data practices in writing | Does not create a clear request path by itself |
| Do not sell my data link | Gives California shoppers a direct path to submit a request | Does not replace consent controls for cookies or pixels |
That distinction matters on a live store. If a shopper wants to opt out of data sharing, the shopper should not have to read a long policy and guess what to do next.
Why This Matters for OpoShop Stores Selling to California Shoppers
This matters because small OpoShop stores often use more tracking than they realize. A merchant can install Google Analytics for traffic, Google Tag Manager for scripts, Meta Pixel for ads, Hotjar for behavior tracking, and TikTok for campaign measurement, then assume the privacy side is handled because the tools are common.
Common does not mean covered.
A solo merchant selling handmade candles from Oregon can still have California exposure if California shoppers buy from the store, join the email list, or browse product pages while tracking tools are active. That same merchant may also sell into the EU or UK, where consent rules around non- tracking are stricter. Now the store is juggling more than one privacy rule set at once.
This is where the work needs to feel manageable. Most independent merchants do not have a legal team. Most do not have a developer on standby. They need a setup that does three things well: shows the right consent experience by region, blocks non- pixels where needed, and gives shoppers a clean way to submit privacy requests.
Taste matters too. A lot of merchants put this off because they do not want an ugly banner or a clunky footer experience. Fair. Privacy UX still has to fit the brand.
How to Decide Whether Your Store Needs a Do Not Sell My Data Link
The fastest way to decide is to check four things: California exposure, tracking tools, request paths, and request handling. If those four pieces are clear, the answer usually gets a lot less fuzzy.
A simple scenario makes this easier. Say an OpoShop merchant sells skincare nationwide, runs Meta Pixel for retargeting, uses Google Analytics for reporting, and gets orders from Los Angeles and San Diego every month. That merchant should not assume a privacy policy page is enough. California shoppers need a clear request path, and the merchant needs a way to act on those requests.
Placement matters too. A do not sell my data link should be easy to find, especially on mobile. Footer placement is common, and many stores also include the link in privacy menus or account-access areas. Hidden links are where good intentions go to die.
Here is a weak versus stronger version of that setup:
Weak: "Privacy choices are described in our policy." Stronger: "Do Not Sell or Share My Personal Information" in the footer, linked to a short request page with a simple form and clear next steps.
That second version removes guesswork. Shoppers know where to click, and the store knows what kind of request is coming in.
If you want a cleaner way to set region rules, block non- tracking where needed, and keep privacy requests in one place, that is exactly the point where a more connected setup starts saving time.
Best Ways to Handle California Privacy Requests on a Small Ecommerce Store
Small stores usually handle California privacy requests in one of three ways: a manual page and email address, a standalone request form, or a combined setup that handles consent and request intake together. The right choice depends on store traffic, tool sprawl, and how much manual work the merchant can actually keep up with.
| Approach | How it works | Good fit | Tradeoff |
|---|---|---|---|
| Manual page and email | A footer link points to a page telling shoppers to email privacy requests | Very small stores with low request volume | Easy to miss requests, hard to track deadlines |
| Standalone request form | A form collects do not sell, deletion, or related requests in one place | Small stores that want cleaner intake | Still separate from consent controls |
| Combined consent plus request workflow | Region-aware banner rules and privacy request intake live together | Stores selling across California, the EU, and the UK | Better coordination, less duct-tape admin |
The manual route looks easy at first. Then one request lands in a general inbox, another comes through a contact form, and a third gets buried under order notifications. That is where small teams get exposed. Not because they meant to ignore a request, but because the process was loose from the start.
A more workable setup for a solo merchant is simple: one-screen setup, region rules for EU, UK, and California, a brand-matched banner, and an inbox that tracks privacy-request deadlines. That keeps the privacy side from turning into a scavenger hunt.
And no, a cookie banner cannot replace a do not sell my data link. Banner controls and request intake solve different problems. Stores that treat them as interchangeable usually end up with gaps.
Common Mistakes California-Facing Merchants Make
The most common mistakes are not dramatic. They are small misses that stack up.
The first mistake is assuming a privacy policy alone is enough. A policy explains. A request link receives. You need both jobs covered.
The second mistake is relying only on banner text. A banner can ask for consent or present choices, but California shoppers may still need a direct path for a do not sell request or a deletion request.
The third mistake is forgetting mobile placement. If the footer link is impossible to find on a phone, the link exists on paper but not in real life.
The fourth mistake is collecting requests without tracking deadlines. This is a quiet one, but it matters. If requests come into a regular inbox with no system around them, follow-up gets messy fast.
The fifth mistake is using one privacy setup for every region without checking whether the rules actually match. Stores that sell to the EU, UK, and California at the same time often need region-aware behavior, not one blanket experience for every visitor.
What We Recommend for Independent OpoShop Merchants
We recommend a setup that handles consent choices and privacy requests as two connected jobs. For most independent OpoShop merchants, that means showing region-aware consent rules, blocking non- tracking until consent where the rule calls for it, and giving California shoppers a clear path for do not sell or deletion requests.
That recommendation is practical, not fancy. If your store uses Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, or TikTok, you already have enough moving parts that manual privacy handling can get sloppy. Add EU or UK traffic on top, and the patchwork approach gets old fast.
A tasteful, brand-matched privacy experience also matters more than people think. Merchants are more likely to keep privacy controls in place when the banner and request flow feel like part of the storefront, not a generic bolt-on.
Best answer: Independent OpoShop merchants should treat California privacy requests and cookie consent as separate but connected tasks. Put a clear do not sell request path where shoppers can find it, use region-aware rules for California, the EU, and the UK, and make sure someone can actually receive and track the requests that come in. That is the setup that keeps the work manageable.
If you want one place to show a brand-matched consent banner, block non- pixels, and collect do not sell or deletion requests without involving a developer, Consently is built for that kind of store.
FAQs
Does every online store that gets California traffic need a do not sell my data link?
No. California traffic alone does not settle the question. The real issue is whether the store sells or shares personal information and whether California shoppers need a clear path to submit that kind of privacy request.
Is a cookie consent banner enough for California privacy compliance?
No. A cookie consent banner manages tracking choices, but a do not sell my data link gives shoppers a way to submit a privacy request. Small stores often need both pieces, especially if the store also sells into the EU or UK.
Where should I put a do not sell my data link on my store?
The link should be easy to find in the footer, and it should still be visible and usable on mobile. Some stores also place the link in a privacy center or account area, but the footer is the usual starting point.
What is the difference between a do not sell request and a data deletion request?
A do not sell request tells the store not to sell or share personal information in the covered way. A data deletion request asks the store to delete personal information, subject to any lawful reasons the store needs to keep some records.
Do I need separate privacy settings for the EU, UK, and California?
Yes, many stores do. A store selling across those regions often needs different consent and request handling rules by location, because EU and UK cookie requirements and California privacy rights do not work exactly the same way.
Summary
Some California stores need a do not sell my data link, and some do not. The answer turns on how the store uses shopper data, whether California visitors are in the mix, and whether the store has a real process for privacy requests.
For most small OpoShop merchants, the cleanest path is straightforward: review the tracking stack, give California shoppers a visible request path, and use region-aware controls for California, the EU, and the UK. If you want that handled in one place, with a brand-matched banner and a privacy-request inbox that does not turn into manual chaos, Consently is worth a look.


