What the law requires

Under California privacy law, a business that sells or shares personal information must give California residents a clear way to opt out. For most Shopify stores this means a "Do Not Sell or Share My Personal Information" link, visible in the footer of every page, that actually works. The link is not decoration. It has to trigger a real opt-out that stops the sale and sharing of that visitor's data.

Two details trip up stores constantly. First, the link wording and placement are specified closely enough that a buried or creatively renamed link does not count. Second, honoring the opt-out means actually suppressing the data flows: the pixels, the audience syncs, the data broker feeds. A link that sets a cookie nobody reads is a violation with a paper trail.

Where the link lives

The footer is the expected home, on every page, persistent and visible without scrolling through a menu. Some stores also surface it in the cookie banner's preference center, which is good practice but not a substitute for the footer link. Regulators and privacy tools look in the footer. Meet them there.

The link should also respect the Global Privacy Control signal as an automatic opt-out. A visitor broadcasting GPC has already opted out. Forcing them to also click your link is both bad experience and legally shaky in California and Colorado. Wire GPC to the same suppression logic as the link.

Wiring the opt-out to your tags

This is where implementations fail. The link sets a preference, but the tag manager, the pixels, and the server-side integrations all have to read it. Audit every tag that sends data to a third party: analytics, advertising, social pixels, data enrichment, audience building. Each one needs a consent gate that checks the opt-out state before firing.

Server-side tracking is the blind spot. Stores that moved to server-side Google Tag Manager or conversion APIs sometimes wire the browser tags correctly and forget the server container keeps firing. The opt-out has to propagate to every collection point, client and server alike. Test with a fresh profile, opt out, and watch the network tab. If data still leaves, the wiring is incomplete.

Documenting the opt-out

Keep a record of each opt-out: when it happened, what it covered, and confirmation that the suppression took effect. Regulators ask for proof, and the stores that can produce it are the ones that treated the link as infrastructure rather than ornament. Log the preference change, the tags suppressed, and the verification test results.

Revisit the implementation quarterly. Tags get added, new integrations appear, and each one is a chance for the opt-out to silently break. A standing test, opt out as a California visitor and confirm no sale or sharing traffic, belongs in the same checklist as the banner review. The link is a promise. Keep it.

Get a free consent audit of your website

Free consent audit