Website Privacy for Home Services: State Rules, Banners, and Pixels
Find out what your website needs before you install a visitor-identification pixel or run retargeting.
Check your website’s privacy setup
Choose your customers’ state and answer simple questions about your business. Get a plan for your privacy policy, cookie banner, and advertising choices.
Use our free privacy toolThe details behind your result
The free tool opens above this guide. Visitor identification and retargeting are the starting setup; change those selections if you only plan direct follow-up or use different tools. Your answers decide which questions and recommendations appear.
The results separate legal requirements from our recommendation to keep optional tracking off until a visitor chooses to allow it. Special information, business relationships, and vendor terms can change the answer; this is a setup guide, not certification of an installation.
Research checked September 23, 2026. Use the sources below to check the rules behind your result.
- State rules and thresholds
- What the questions mean for a home-service marketer
- Practical business examples
- Real US website screenshots
- Privacy-policy and banner wording
- Pixel code and a consent demonstration
- Checks before you go live
Four different parts of website privacy
| Part | Its job | Example on a local-service website |
|---|---|---|
| Privacy policy | Explain collection, sources, purposes, recipients, retention, and applicable rights. | A footer page explaining estimate forms, website tracking, visitor identification, and marketing. |
| Notice at collection | Put required information where people encounter the collection. | A short notice and policy link beside an estimate form; appropriate notice before a tracking tag collects data. |
| Cookie banner or preference center | Present choices and connect those choices to actual tracking behavior. | “Accept optional tracking,” “Reject optional tracking,” and “Manage choices.” |
| Sale/sharing/targeted-advertising opt-out | Stop the covered uses and disclosures, including relevant activity beyond cookies. | A permanent “Do Not Sell or Share My Personal Information” link and recognition of GPC. |
California’s regulations explicitly distinguish a cookie control from an opt-out of sale or sharing. A tool that only deletes cookies does not necessarily stop a business from sharing previously collected information or sending server-side events. See 11 CCR § 7026(a)(4), in the approved regulations.
An “Accept” button also creates an expectation. New York’s attorney general warns that an interface can mislead visitors if it implies tracking starts after acceptance while tags actually fire on arrival. This matters even outside a comprehensive state privacy statute. New York website privacy controls guidance.
Does your business fall under a state privacy law?
Your office address is only one input. Many laws protect that state’s residents and cover businesses that operate there or target products or services to them. A Texas contractor with a California customer does not automatically meet the CCPA’s business thresholds; a business outside California can meet them. Website geolocation can help route controls, but a visitor’s current IP location is not perfect proof of residency.
Before choosing a banner configuration, document:
- The states whose residents you serve or target.
- The number of people whose personal data you actually process in each state, using that law’s counting rules. This is not necessarily your number of paying customers or page views.
- Revenue and any revenue from data sales or sharing, where relevant.
- Whether you meet an exemption, including the specific SBA small-business definition where used.
- Whether you collect sensitive data, information about minors, or consumer health information.
- Whether each vendor acts only on your instructions or uses information for its own purposes. The contract and real behavior both matter.
Being below one comprehensive-law threshold does not mean you can omit a privacy policy or ignore privacy promises. California’s older CalOPPA requires covered commercial websites collecting personal information from California consumers to post a privacy policy without using the CCPA’s revenue threshold. See the California attorney general’s privacy-policy guidance.
What the questions mean for a home-service marketer
Revenue: money from your service business versus money from data
For California, the first question is: “Was your gross annual revenue $26.65 million or more last year?” Use the previous calendar year’s revenue for the whole business. This is a rounded screening question. The exact current legal figure is $26.625 million, so a business between the two figures can already meet the revenue test. The tool does not treat a No as an exemption. CPPA coverage information.
Next, “Do you intend to resell the homeowner data?” means selling a homeowner lead or contact list to another contractor. If you only use the leads to win your own service jobs, answer No. You can still answer Yes to advertising your services. If you plan to resell data, the California tool also asks whether data income makes up half or more of your annual revenue. That includes qualifying sales or sharing of personal information; service-job income is different.
Other states can combine a revenue test with a number-of-people test. The questionnaire asks those one at a time. Connecticut also gets separate questions about sensitive information and offering homeowner data for sale.
For Texas, Nebraska, and Minnesota, the tool asks whether you belong to a larger company group, your main service, and your average annual revenue. It selects the size limit for that trade: $19 million for HVAC, plumbing, electrical, and roofing; $45 million for home remodeling; $9.5 million for landscaping; $17.5 million for pest control; $22 million for house cleaning/janitorial services; and $8.5 million for carpet/upholstery cleaning. These are separate industry classifications, not one limit for every home-service business. SBA size table.
Use the last five completed financial years, including related companies under the applicable ownership/control rules. A newer business uses average weekly revenue multiplied by 52. For a group, add each company’s annual average and use the group’s main industry. Acquisitions or a mixed business may need an accountant to confirm the calculation and classification. The legal measure is SBA annual receipts, generally total income plus cost of goods sold, rather than profit. SBA calculation and affiliation guidance.
For example, an independent Texas plumber with a five-year average of $3 million answers No to “Was your average annual revenue more than $19 million?” The result uses the small-business size exemption while retaining the sensitive-data-sale check. A Minnesota business above its trade’s size limit still gets the state’s separate data-volume questions. Choosing another service or leaving ownership or revenue uncertain does not create an exemption.
California traffic: an easy starting question
The tool asks: “Does your website get more than 20,000 visits per month from Californian residents or households?” Check California traffic in your analytics and answer Yes or No. A Yes flags a closer review. Either answer leads to practical setup recommendations.
20,000 visits is this tool’s planning review point, not a legal cutoff. The legal test covers personal information bought, sold, or shared about 100,000 or more California residents or households in a year. Bought homeowner leads and qualifying disclosures to ad partners can count too. California definitions and coverage tests.
For illustration, 20,000 monthly visits at an assumed 30–40% identification rate would produce 72,000–96,000 match events a year. Those are not necessarily distinct people: visitors repeat, audiences overlap, and ad tools can receive linkable identifiers before a name is matched. Your agency should confirm the actual annual count across qualifying uses. A low traffic answer therefore does not produce a “you are exempt” result.
Other states use their own tests. Their questions name your website data, homeowner leads, quote requests, and customer records so you know what to count. Service-job revenue is kept separate from selling personal data. Texas and Nebraska use the trade and revenue questions instead of a traffic cutoff.
Advertising your own services versus reselling homeowner leads
These are separate questions. You might answer Yes to retargeting and No to reselling homeowner data.
| Your marketing activity | What to check |
|---|---|
| A plumber identifies a visitor and sends its own follow-up email or postcard. | Explain the matching and follow-up in the policy; check the source, vendor’s role, and outreach rules. This alone does not prove the company resells leads or uses cross-site ad targeting. |
| An HVAC company sends website activity to an ad platform so visitors see its ads elsewhere. | Check advertising-sharing and targeted-advertising choices. California can call this sharing even when the HVAC company never receives money for the data. |
| A roofer uploads a homeowner list to an ad platform. | Check the audience feature, use across sites, partner rights, and any service-provider restrictions. Being your own customer list does not automatically settle the classification. |
| A contractor resells a lead to another contractor, or lets a vendor reuse information for its own customers. | Check the state’s sale definition and exceptions. Payment, discounts, or other benefits can matter; an agency acting only on your instructions is a different relationship. |
California’s sharing rule concerns advertising based on activity across different businesses, websites, apps, or services. An ad based only on the current page and your own direct follow-up are different activities. Check the actual arrangement rather than treating every use of personal data as the same thing. California AG explanation.
Cookies, pixels, and “anonymous” identifiers
A cookie is one storage mechanism. A pixel or script can transmit information with or without a cookie. Server-to-server events, local storage, hashed emails, and persistent device identifiers need the same data-flow review.
A hash is not automatically anonymization. If information can be linked back to a consumer or household, or matched to another database, do not describe it as anonymous merely because a visitor did not type their name into your form. California’s definition expressly reaches reasonably linkable information and inferences. California privacy definitions.
The same reasoning applies to a public street address enriched with private browsing behavior: the availability of an address in a public record does not establish an exemption for every new profile or inference created using it.
State-by-state website privacy rules
How to read this table: These are simplified ordinary-business coverage paths, not exhaustive applicability opinions. Counts refer to residents/consumers under each law, not national website traffic; some laws exclude payment-only processing. “Sale” can include non-cash consideration in some states. Read the linked authority for definitions, exempt entities/data, affiliated businesses, and special provisions.
“Opt-out” below means a covered business must provide the relevant sale/sharing or targeted-advertising choices. It does not mean every tag can run until someone objects, or that sensitive data can be processed without permission. The table focuses on website tracking rather than every access, correction, deletion, security, assessment, or appeal obligation.
Laws already in effect
On a phone, scroll the table sideways to read all three columns.
| State | Main coverage screen | What changes the website setup |
|---|---|---|
| California | For-profit business doing business in California; the adjusted annual-gross-revenue threshold is $26.625m, or a business buys, sells, or shares 100,000 residents’/households’ data, or derives 50%+ of revenue from selling/sharing. Check the statutory definitions and measurement period. | CCPA notice, sale/sharing opt-out, GPC, and applicable sensitive-information limits. It is not a universal opt-in cookie law. CalOPPA separately reaches smaller sites. CPPA. |
| Colorado | 100,000 consumers; or 25,000 plus revenue or a discount from selling data. | Sale/targeted-advertising opt-outs and recognized GPC; consent for sensitive data and certain secondary uses. Additional children’s-data provisions can reach below these general thresholds. Colorado AG and GPC guidance. |
| Connecticut | Current rules: 35,000 consumers, or processing sensitive data, or offering personal data for sale; applicable exemptions still matter. | Do not reuse an old 100,000/25,000 threshold chart. Sensitive-data processing can trigger coverage without a large audience. Honor opt-out signals and obtain required consent. Connecticut AG’s current FAQ. |
| Delaware | 35,000 consumers; or 10,000 and over 20% gross revenue from data sales. | Sale/targeted-advertising choices; universal opt-outs required from January 1, 2026; sensitive-data consent. Explain actual Delaware rights clearly. Delaware DOJ. |
| Florida | Core controller definition is unusually narrow: over $1bn annual global gross revenue plus specified digital-business criteria. | Do not apply Florida’s core law to every contractor. Separately assess the broader sensitive-data-sale restriction in § 501.715, which can affect other for-profit businesses. Florida statutes, §§ 501.702–501.715. |
| Indiana | 100,000 consumers; or 25,000 and over 50% gross revenue from data sales. In effect January 1, 2026. | Sale/targeted-advertising opt-outs, privacy notice, and sensitive-data consent. Do not label this a future law. Indiana AG. |
| Iowa | 100,000 consumers; or 25,000 and over 50% gross revenue from data sales. | Adult sensitive-data rule uses notice and an opportunity to opt out, unlike the consent model in many other states. § 715D.4 also addresses disclosures and opt-out methods for sales/targeted advertising; children’s rules are separate. Iowa Code chapter 715D. |
| Kentucky | 100,000 consumers; or 25,000 and over 50% gross revenue from data sales. In effect January 1, 2026. | Sale/targeted-advertising choices, a meaningful notice, and consent before processing sensitive data. Kentucky AG and KRS 367.3613. |
| Maryland | 35,000 consumers; or 10,000 and over 20% revenue from data sales. Effective October 2025; the original act excludes processing before April 1, 2026. | Strong minimization rules; no sale of sensitive data; sensitive processing must be strictly necessary for a requested product/service. Consent is not a workaround for that ban. Maryland AG, § 14-4707, and enrolled act’s application dates. |
| Minnesota | 100,000 consumers; or 25,000 and over 25% revenue from data sales; general SBA small-business exemption. | Universal opt-outs and sensitive-data consent for covered controllers. Even generally exempt small businesses need consent to sell sensitive data. Minnesota AG and § 325M.14. |
| Montana | Since October 2025: 25,000 consumers; or 15,000 and over 25% gross revenue from data sales. | Older 50,000/25,000 charts are stale. Provide covered opt-outs, recognize applicable browser signals, and assess broader minor-related provisions separately. Enacted SB 297, §§ 3 and 9–11. |
| Nebraska | No general consumer-count threshold; businesses outside the federal small-business exemption can be covered. | Sale/targeted-advertising choices and technology-based authorized-agent requests subject to statutory conditions. Small businesses retain a sensitive-data-sale consent duty. Nebraska Data Privacy Act. |
| New Hampshire | 35,000 unique consumers; or 10,000 and over 25% gross revenue from data sales. | Opt-out preference signals, sale/targeted-advertising choices, and sensitive-data consent. Read current and future-effective text separately. RSA 507-H. |
| New Jersey | 100,000 consumers; or 25,000 and revenue or a discount from data sales. | Universal opt-out mechanisms, sale/targeted-advertising choices, and sensitive-data consent. The second coverage path does not require 25% or 50% of revenue. Enacted NJ law. |
| Oregon | 100,000 consumers; or 25,000 and 25%+ annual gross revenue from data sales; certain motor-vehicle businesses have a separate rule. | Universal opt-outs from January 1, 2026. Sale of precise geolocation is prohibited. Under-16 data has sale/targeted-advertising/profiling restrictions. Oregon DOJ. |
| Rhode Island | Main rights/controller duties: 35,000 customers; or 10,000 and over 20% gross revenue from data sales. In effect January 1, 2026. | A separate commercial-website provision has broader reach and requires specific disclosures when its collection/storage/sale conditions apply. Do not assume being below the main threshold removes that duty. § 6-48.1-3 and § 6-48.1-7. |
| Tennessee | Over $25m revenue and either 175,000 consumers or 25,000 and over 50% gross revenue from data sales. | Covered businesses need sale/targeted-advertising choices, notice, and sensitive-data consent. Both the revenue and a volume/data-sales path matter. Tennessee AG and legislature’s adopted-amendment summary. |
| Texas | No general consumer-count threshold; most SBA-defined small businesses are exempt from the main act. | Covered businesses need privacy choices and applicable technology-based opt-outs. Small businesses still need consent before selling sensitive data. “We have fewer than 100,000 visitors” is not the Texas test. Texas AG. |
| Utah | $25m+ revenue and either 100,000 consumers or 25,000 and over 50% gross revenue from data sales. | Sale/targeted-advertising opt-outs. Adult sensitive-data processing generally requires clear notice and an opportunity to opt out; do not generalize other states’ consent rules to Utah. Utah AG and official threshold summary. |
| Virginia | 100,000 consumers; or 25,000 and over 50% gross revenue from data sales. | Sale/targeted-advertising choices, privacy notice, and sensitive-data consent. B2B/employment-context exclusions are not permission to ignore other applicable laws. Virginia Code chapter 53. |
Enacted laws with later general effective dates
These laws belong in implementation planning, not in a claim that their general duties are already in effect today.
| State | General effective date | Primary source |
|---|---|---|
| Oklahoma | January 1, 2027 | Oklahoma House announcement of signed SB 546. |
| Louisiana | January 1, 2027 | SB 386 / Act 502 status and effective date. |
| Alabama | May 1, 2027 | Enrolled HB 351, § 12. |
| Vermont | January 1, 2028 | Act 145 as enacted. Separate Vermont laws can apply earlier. |
The other states are not a “tracking allowed” list
For Alaska, Arizona, Arkansas, Georgia, Hawaii, Idaho, Illinois, Kansas, Maine, Massachusetts, Michigan, Mississippi, Missouri, Nevada, New Mexico, New York, North Carolina, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Washington, West Virginia, Wisconsin, and Wyoming, the comprehensive-law roster we checked does not establish a broad law already in effect comparable to the main table. That statement is limited to comprehensive consumer privacy legislation, not all privacy law. D.C. also needs a separate assessment.
We used the IAPP tracker, updated September 8, 2026, to cross-check the roster and primary state sources for the operative rules above. Bills still moving through a legislature are not enacted requirements. Check developments after that roster date before making a state-specific deployment decision.
Some particularly relevant additional rules:
- Washington: My Health My Data reaches many businesses, including small businesses, handling consumer health data. It can require a separate prominent health-data policy, consent for collection/sharing, and an authorization for sale. Health inferences can matter; being outside HIPAA does not end the inquiry. Washington AG.
- Nevada: Its online-operator notice/sale-opt-out law and consumer-health-data law are separate from the comprehensive-law roster. NRS chapter 603A.
- New York: Privacy promises and controls must be truthful; the Child Data Protection Act adds protections for covered minors’ data. Website guidance and children’s-data guidance.
- Pennsylvania and California: Wiretap, interception, and related tracking claims require their own analysis. For a concrete Pennsylvania example of why an ordinary retail tag can raise separate issues, see the Third Circuit’s Popa v. Harriet Carter Gifts opinion. California has its own Penal Code § 631. These are not a ruling that every pixel is unlawful, nor a nationwide safe harbor.
Practical examples: what you can and cannot assume
These fictional home-service businesses illustrate the decisions behind the questionnaire.
A small Texas plumbing company installs visitor identification
Scenario: A five-person plumbing company adds a pixel and wants to match website visits to contact or household information.
What to do: Check the actual SBA small-business test and other applicable laws; explain visitor identification and follow-up in the policy; give the promised choices; review vendor contracts and downstream uses. Our recommended opt-in setup can be used even if the main Texas act does not cover the company.
What not to assume: “Small business” does not mean any form of sensitive-data sale is permitted. Nor does a matched telephone number prove permission to send marketing texts. Texas AG.
A California HVAC company identifies visitors and runs retargeting
Scenario: An HVAC company meets a CCPA coverage threshold. It identifies website visitors and sends activity to an ad partner to advertise its own AC services elsewhere. It does not resell homeowner leads.
What to do: Assess sale/sharing, give the required notice and choices, honor GPC, and make opt-outs reach the relevant browser and server flows. A qualifying service-provider relationship has contractual and operational conditions; it cannot be established just by calling every recipient a “service provider.”
What not to assume: “We never sell a spreadsheet” does not answer the statutory sale/sharing question. The Sephora settlement is a real enforcement example involving tracking, sales disclosures, and GPC.
A Maryland HVAC marketer builds a health-related audience
Scenario: A marketer uses indoor-air-quality browsing or form answers to infer a homeowner’s health condition, then proposes using that information for an ad audience.
What to do: Stop and assess whether the data and proposed use are prohibited. For covered processing, Maryland prohibits selling sensitive data and limits sensitive collection/processing/sharing to what is strictly necessary for a requested product or service.
What not to assume: An “Accept all” button does not override those restrictions. Maryland § 14-4707.
An Oregon roofer uses homeowner addresses for postcards
Scenario: A roofer wants to mail an offer to a service address. Its vendor also proposes a separate audience product based on precise device locations.
What to do: Review the address use and the precise-location product separately. Where the OCPA governs, do not sell precise geolocation or treat cookie acceptance as an exception to that prohibition. Also assess age restrictions separately.
What not to assume: Ordinary service-area estimates, mailing addresses, IP-derived regions, and statutory precise geolocation are interchangeable categories. Review how the location is obtained and how precise it is. Oregon DOJ.
A homeowner rejects tracking but requests an estimate
Scenario: A visitor rejects optional tracking and then submits their name, phone number, and leaking-water-heater problem.
What to do: Honor the rejection while processing the information needed to answer the requested estimate, subject to the applicable law. Separate responding to that request from unrelated advertising, audience uploads, and future campaigns.
What not to assume: Submitting the form silently reverses the opt-out. A quote request, a sale/sharing choice, a newsletter subscription, and telemarketing consent are different records.
An HVAC company adds chat, session replay, or a financing form
Scenario: A new tool can capture typed text, page contents, or financial/health information.
What to do: Review the new collection before launch; mask or exclude sensitive inputs and routes; assess interception law, vendor access, retention, and any consent requirement. Default our optional tracking setup to off on sensitive journeys.
What not to assume: A previous generic cookie acceptance covers every future recording or new purpose. A comprehensive-law exemption is not an exemption from every interception or consumer-protection rule. Popa opinion.
A home-service company identifies a visitor and wants to contact them
Cookie permission is not a universal outreach license. Federal CAN-SPAM generally uses an opt-out framework for ordinary commercial email; it does not impose a blanket prior opt-in requirement on every commercial email. Accurate headers, nondeceptive subjects, required advertising disclosures, a postal address, and effective unsubscribe handling still matter. Other laws, promises, data-source restrictions, and email-provider terms can be stricter. FTC CAN-SPAM guide.
Marketing calls and texts have separate TCPA, do-not-call, state-law, and platform requirements. Do not convert a browser’s tracking acceptance into a record of written telemarketing consent. FCC explanation of telemarketing consent requirements.
Direct mail is also not a universal exemption from laws governing the data used to choose the recipient. A postcard does not erase an earlier opt-out or justify an otherwise prohibited identity match.
Real website examples with screenshots
These are observed interfaces, not compliance endorsements. Screenshots were captured September 23, 2026 in a desktop browser. The browser’s geographic treatment and any earlier site preferences were not independently verified. Banners can vary by region, device, experiments, and saved choices. We did not audit these companies’ network traffic or downstream data handling.
Select a screenshot to open it at full size.
Roto-Rooter: separate footer routes for privacy and cookie settings
Observed: The Roto-Rooter homepage had footer links for cookie settings, a privacy policy, a CCPA notice, and a do-not-sell request. Opening cookie settings and selecting the targeting category exposed a switch and a confirmation button. A small cookie notice was also visible during the visit.
Useful idea: A customer can return to controls after the initial notice disappears. A plumbing site can expose privacy controls without hiding its main service information.
What still needs testing on your own site: Whether rejecting the category stops each relevant tag and backend use. A category name or switch position cannot prove that on its own.
Cloudflare: a category-based preference center
Observed: Clicking “Your privacy choices” on Cloudflare’s homepage opened a settings dialog with cookie categories and rejection/confirmation controls.
Useful idea: Explain the purpose of each optional category and keep a visible way to save the choice.
Do not infer: This screenshot does not establish the default shown to every new visitor, whether a sale/sharing opt-out reaches every system, or what fires before a choice.
Microsoft: an ongoing advertising-data choice
Observed: Microsoft’s homepage privacy-choice link led to its third-party ad settings page, which explained a sharing choice and displayed a control without requiring us to sign in to view it.
Useful idea: Explain the use of data being controlled, not just the word “cookies.” Keep ongoing choices accessible.
Do not infer: Browser, account, device, and product coverage may differ. Tell your visitors what their choice affects and provide an appropriate route for broader requests.
An enforcement example: Honda’s privacy choices
In March 2025, California’s privacy agency announced a $632,500 Honda resolution involving its privacy-request and choice practices. The case is a useful reminder to review how much work opting out requires compared with opting back in, and whether unnecessary identity checks obstruct an opt-out. CPPA announcement and the agency’s order with interface examples.
The practical lesson is to evaluate the entire interaction: first layer, settings, saving, later withdrawal, and actual processing.
Sample wording to adapt to your website
These are starting points, not a complete privacy policy. Replace brackets and remove purposes you do not use. Do not promise an opt-out mechanism, retention period, or GPC behavior until it exists and has been tested.
A plain-English tracking section for a privacy policy
Website activity and visitor identification. We use [list the technologies you actually use] to collect information such as [actual categories: device/browser identifiers, IP address, pages visited, and interactions]. We use this information for [actual purposes: website analytics, advertising measurement, relevant advertising, visitor identification, and marketing follow-up]. Where we use visitor identification, we may associate website activity with contact, business, or household information obtained from [describe the actual categories of sources]. This does not mean every visitor is identified or that every match is correct.
Recipients and choices. We disclose [actual data categories] to [actual recipient categories] for [specific purposes]. Some disclosures may constitute a sale, sharing for cross-context behavioral advertising, or targeted advertising under applicable law. You can use [working privacy-choice link] to make the choices described there. [Describe precisely how you handle GPC and the scope of browser/account choices.] Contact [working request channel] to exercise applicable access, correction, deletion, or other privacy rights.
Finish the policy with your business identity/contact details, collection sources, purpose-specific recipients, actual retention periods or criteria, security description, required state rights and methods, appeal process where applicable, children’s practices, material-change process, and effective date. Add the required notice at the collection point instead of relying exclusively on a footer page.
Vendor categories are not sufficient in every situation. For example, Rhode Island’s commercial-website provision can require identifying third parties to whom information has been sold or may be sold. Oregon and Minnesota also provide rights involving specific third-party recipients. Confirm the applicable disclosure level before removing vendor names. Rhode Island § 6-48.1-3, Oregon rights, Minnesota rights.
Banner wording for the conservative opt-in setup
Your website privacy choices
We use necessary technologies to make this site work. With your permission, we also use optional technologies to measure visits, support advertising, and associate website activity with contact or household information for follow-up. Choose which optional purposes to allow. You can change your choices at any time using the privacy link below.
Buttons on the same layer: “Accept optional tracking” · “Reject optional tracking” · “Manage choices.”
Links: “Privacy policy” and a working sale/sharing/targeted-advertising opt-out.
Only use that wording if the named optional activities really wait for permission. Give the accept and reject actions comparable prominence and effort. Do not pre-check optional purposes, interpret scrolling as consent, or make closing the banner mean yes. California’s choice-design rules address symmetry and manipulative interfaces. 11 CCR § 7004.
Wording for an opt-out model
If counsel approves an opt-out model for a specific use and audience, describe it accurately:
We use [actual data and technologies] for [actual purposes]. [Describe any sale/sharing/targeted advertising accurately.] Use “Do Not Sell or Share My Personal Information” to opt out of those covered uses, or open cookie settings to manage optional technologies. Read our privacy policy for details.
That copy is not appropriate for a consent-required use that has already started. It also does not excuse a missing notice or an ignored browser signal.
A short form notice
We use the details you submit to respond to your estimate request and arrange service. See our Privacy Policy for how we handle your information and your choices.
Link the actual policy. Put any separate newsletter or marketing-text choice next to its own clear disclosure; do not hide it inside the estimate submission or cookie acceptance.
A permanent footer choice
The most explicit California label is “Do Not Sell or Share My Personal Information.” California also permits specified alternative privacy-choice links subject to its conditions, including the required icon and destination behavior. A generic “Privacy” page link is not automatically an equivalent opt-out. CPPA rights FAQ and §§ 7013–7015 in the regulations.
Code: how to keep the pixel off until permission
Open the interactive consent demonstration. It shows the recommended default-off behavior, separate purposes, rejection, withdrawal, and a simulated GPC signal. It installs no real tracking tags and sends no tracking requests. The demonstration itself is not a consent-management platform.
1. Put the gate before the script
Do not paste an unconditional pixel above your banner and expect the banner to undo the request. Even downloading a third-party script creates a request to that server.
For PipelineOn, use the public tag from your installation screen. The code below is a developer illustration of an initial-load gate, not a complete CMP integration. choice and context are your site’s normalized records, not built-in PipelineOn APIs. Call it only after your consent manager has resolved current, unexpired choices. Keep approvedForThisUse false until the business has reviewed the purpose, audience, notices, and any special restrictions.
// Initial-load example. Remove every other unconditional copy of the tag.
function loadPipelineOnAfterPermission(choice, context, publicTag) {
const gpc = navigator.globalPrivacyControl === true;
const allowed =
context?.approvedForThisUse === true &&
context?.sensitiveJourney === false &&
context?.knownMinor === false &&
choice?.current === true &&
choice?.marketing === true &&
choice?.visitorIdentification === true &&
choice?.saleSharingOptOut === false &&
!gpc;
if (!allowed) return false;
if (typeof publicTag !== "string" || !publicTag.trim()) return false;
if (publicTag === "YOUR_PUBLIC_TAG") return false;
if (document.querySelector("script[data-po-tag]")) return false;
const script = document.createElement("script");
script.src = "https://pp-n.com/p.js";
script.async = true;
script.dataset.poTag = publicTag;
document.head.appendChild(script);
return true;
}
This intentionally blocks loading when any required input is missing. The business’s approval and a visitor’s choice are different inputs. An accepted cookie choice cannot make Maryland sensitive-data sales or Oregon precise-location sales permissible.
This function does not revoke a running pixel. Removing its script element after execution does not cancel timers, listeners, network calls, or information already sent. Before production use, implement the CMP’s documented change callback, immediate vendor teardown where available, suppression of new server-side processing, and a controlled reload if required. A reload alone can still trigger unload beacons and does not delete earlier records. If you cannot stop the current integration as promised, leave it off until that integration is resolved.
2. Map the consent manager to the actual purposes
Classify each tag by what it does, not the vendor’s name. An identity-resolution tag should not inherit permission just because the visitor allowed audience-counting analytics. For this example, both advertising/follow-up and visitor-identification permission are required, and any sale/sharing opt-out takes precedence.
For WordPress, check plugins, theme headers, and the tag manager for duplicate installations. For Webflow, Wix, and Squarespace, inspect both global custom code and embedded page code. For Google Tag Manager, connect the CMP’s consent lifecycle to each tag’s trigger and consent checks; a custom HTML tag does not become consent-aware because Google Analytics is configured correctly.
If you use Google Consent Mode, distinguish the modes. Google’s basic implementation blocks the Google tags until consent; advanced mode loads them and can send cookieless pings while consent is denied. “Denied” therefore does not always mean “no requests.” Neither mode controls a separately installed PipelineOn tag automatically. Google’s consent-mode documentation.
3. Carry the choice into server-side uses
GPC can be exposed as navigator.globalPrivacyControl and as the Sec-GPC: 1 request header. Recognize the signal before the relevant processing; keep your stored opt-outs even when a later request does not include the header. A missing signal is not consent. GPC implementation resources from Colorado’s AG.
Your server needs its own decision before creating an audience, resolving identity, exporting to a CRM, or forwarding an advertising event. For the conservative setup, the logic is conceptually:
// Pseudocode: adapt to your server, CMP records, and vendor contracts.
const mustBlockOptionalMarketing =
request.headers.get("Sec-GPC") === "1" ||
storedChoice?.saleSharingOptOut !== false ||
storedChoice?.current !== true ||
storedChoice?.marketing !== true ||
storedChoice?.visitorIdentification !== true ||
context?.sensitiveJourney !== false ||
context?.knownMinor !== false ||
context?.approvedForThisUse !== true;
if (mustBlockOptionalMarketing) {
// Do not enqueue identity resolution, audience uploads, or marketing events.
// Apply the relevant suppression to existing downstream workflows too.
}
Do not trust an arbitrary browser-supplied consent: true as proof. Resolve the server decision against your own consent record and applicable restrictions. Opt-out, deletion, access, and email unsubscribe also have different effects; preserve enough minimal suppression information to avoid reintroducing an opted-out person while applying deletion obligations and exceptions correctly.
4. Store a useful record without building another tracking system
Record the notice/policy version, purpose-specific choices, time, source of choice, scope, and later changes using a proportionate identifier. Set a defensible retention policy. Do not turn consent logging into unnecessary capture of full browsing histories or raw sensitive form fields.
When a preference cannot be saved or read, the conservative implementation should keep optional tracking off and tell the visitor that persistence failed. Never show “saved” while silently falling back to tracking.
Test the behavior before you go live
Use a clean browser profile and the browser’s Network and Storage tools. Run the checks on the homepage, service pages, landing pages, forms, and mobile layouts. An agency’s screenshot of the banner is not the acceptance test.
| Test | Expected result for the conservative setup |
|---|---|
| New visitor, no choice | Optional tags and their requests remain absent. Forms and essential site functions still work. |
| Reject optional tracking | No optional pixel, identity-resolution, ad, or optional analytics requests. The rejection survives navigation. |
| Accept analytics only | Only the separately classified analytics setup becomes eligible; visitor identification stays off. |
| Accept all relevant optional purposes | Approved tags load once; they do not duplicate through another plugin or tag-manager path. |
| GPC enabled before the visit | Covered sale/sharing/targeted-advertising paths stay off; in this conservative setup, the visitor-identification pixel stays off too. |
| GPC conflicts with a saved “accept” | The opt-out takes precedence in this setup. Do not silently let an old acceptance override it. |
| Change from accept to reject | Future optional collection stops; your teardown/reload design and server-side suppression are verified. |
| Reload or visit a second page | The saved choice remains effective. A missing/corrupt/expired record does not become permission. |
| Open another tab | Choice changes reach active tabs, or the documented scope clearly explains the limitation and prevents continued prohibited processing. |
| Storage is blocked or unavailable | Optional tags remain off; the interface does not falsely claim a persisted choice. |
| Submit an estimate after rejection | Requested service handling works without silently restoring optional tracking. |
| Opt out after an earlier match/export | Relevant future marketing and disclosures are suppressed in the CRM, audiences, integrations, and queues—not only in browser cookies. |
| Request access/correction/deletion | The request reaches an owner, can be traced across vendors, and follows the correct legal timetable and verification rules. |
Inspect requests as well as cookies. A request can disclose data even when the browser does not save a cookie. Check URLs, referrers, request bodies, duplicate tags, server event logs, and destinations. Test both permitted and prohibited paths using synthetic test identities; do not upload real customers merely to test suppression.
Use a real GPC-capable browser or extension for the production GPC test. The switch in our educational demo only simulates the decision; it does not enable the browser-level signal.
What to check before copying your PipelineOn pixel
Before you install the tag, confirm that your website’s policy describes the actual tracking and matching purposes; the relevant notices and choices exist; the CMP gates the tag; and downstream requests have an owner and a tested process. The pixel installation itself does not create your privacy policy, supply a CMP, or establish consent for calls, texts, emails, or mail.
After installation, verify permitted tracking and rejection separately. Seeing traffic in a dashboard proves that a tag can run; it does not prove that it stops when required. An onboarding checkbox records an acknowledgment, not a legal audit or technical consent test.
For an installer or agency, a useful handoff is: “Here are the allowed purposes, the notices, the CMP categories, the GPC behavior, the opt-out/deletion contacts, and the test results.” That is more actionable than “We have a cookie banner.”
Sources and update notes
Each state row links to a statute or regulator source. The roster check uses the dated IAPP tracker; screenshot observations are separately labeled. This guide does not rely on a cookie vendor’s marketing claims to certify a setup.
Recheck the guide when you add a vendor, change data purposes, enter another market, add sensitive forms, or approach a new law’s effective date. As of this review, Oklahoma and Louisiana have January 2027 general effective dates, Alabama follows in May 2027, and Vermont follows in January 2028. California’s updated regulations also have staged obligations; do not assume every provision shares the January 2026 effective date. California’s rulemaking and compliance materials.
For children-directed sites or actual knowledge of under-13 users, review the FTC’s current COPPA guidance, including the 2025 rule amendments and their compliance dates. This general-business guide and its ordinary visitor banner are not a parental-consent system.
Frequently Asked Questions
Does every U.S. home-service website need a cookie banner?
No universal rule requires an opt-in banner on every U.S. business website. Coverage, data, purposes, and other laws matter. If you offer a banner, its controls and wording must match actual behavior. A privacy notice and working opt-outs can still be required without a pop-up.
Does installing PipelineOn create a privacy policy or cookie banner?
No. Installing the pixel does not create your website privacy notice, configure your consent manager, or establish permission for follow-up. Put the tag behind the appropriate website controls and review downstream processing.
Is first-party or cookieless tracking automatically exempt?
No. State laws generally focus on personal data and its collection, use, and disclosure. A first-party cookie, hashed email, server event, or household match can still involve regulated data.
Is accepting cookies permission to send marketing texts?
No. Cookie choices and permission for marketing calls or texts are separate. Assess channel-specific law and platform requirements before outreach.
We do not resell homeowner leads. Can our advertising still count as sharing?
Yes. California sharing includes certain disclosures for advertising across different businesses or websites, even without payment for the data. Retargeting and ad-audience tools need a separate check from lead resale. Your own direct follow-up is a different use, and vendor contracts and behavior still matter.
Why does the tool ask about 20,000 monthly California visits?
It is a simple planning question that flags traffic for a closer review. It is not the legal cutoff. The California count is 100,000 residents or households whose personal information is bought, sold, or shared in a year. The tool gives a setup plan without declaring lower-traffic businesses exempt.
Written by
PipelineOn Research Team

