Skip to content
Patrick Webby

Privacy & Compliance

Compliance built for how small businesses actually operate

GDPR, CCPA and other state privacy laws, and California CIPA exposure usually comes from tools you already have installed. We find it, explain it in plain language, and fix it — with real cookie consent and script blocking, not just a policy page.

GDPR Compliance

If your site collects data from visitors or customers in the EU or UK — even a contact form or an email newsletter signup — GDPR likely applies to you, regardless of where your business is based.

  • Cookie consent and tracking-tool audit
  • Privacy policy and data-handling documentation
  • Data subject access and deletion request workflows
  • Vendor and analytics review for GDPR-compliant configuration

CCPA & US State Privacy Laws

California's CCPA (updated by the CPRA) was the first comprehensive US state privacy law, and a growing list of others — Virginia, Colorado, Connecticut, Utah, and more — have since passed their own. Requirements vary, but most come down to the same basics: disclose what you collect, honor opt-out requests, and don't sell data quietly.

  • CCPA/CPRA compliance review for California-based traffic and customers
  • "Do Not Sell or Share My Personal Information" opt-out implementation
  • Privacy policy updates that reflect the state laws that actually apply to you
  • Ongoing guidance as new state laws take effect — the list keeps growing

California Invasion of Privacy Act (CIPA)

CIPA is behind a wave of demand letters landing in small business owners' inboxes — often pointing at an ordinary chat widget, session-replay tool, or tracking pixel as an illegal wiretap. The letters are real and the statutory penalties they threaten are real, so a fast, correct response matters.

  • Audit of chat widgets, session replay, and analytics tools on your site
  • Fast technical response if you've already received a demand letter
  • Configuration changes to reduce exposure from third-party trackers
  • Ongoing monitoring so a newly added tool doesn't quietly reopen the risk

Not legal advice

This page is general information, not legal advice. Privacy law changes frequently and applies differently depending on your business — pair our technical work with your attorney's review of anything you publish or represent as compliant.

We implement industry-standard best practices for the latest privacy and compliance requirements, and we work to stay ahead of new regulations and enforcement trends. But no technical implementation can guarantee against a predatory demand letter or lawsuit — nobody can promise that. What we can promise is that we do our best to stay one step ahead.

Let's talk

Not sure where to start? Let's map it out together.

Also explore Web Development or IT Support, or just tell us what's broken.