Smart. Focused. Email.
Fast, cross-platform email designed to filter out the noise - so you can focus on what's important.
💡 CCPA: the California Consumer Privacy Act, a state law that gives you the right to know what personal information businesses collect about you, ask them to delete it, and tell them to stop selling it. If you've ever seen a "Do Not Sell My Personal Info" link at the bottom of a website, that's CCPA in action. CCPA applies to California residents, but plenty of companies apply the same rules everywhere because it's simpler than maintaining two systems. If a business collects your email address, browsing behavior, or purchase history, CCPA gives you leverage over what happens to it next.
Most people think of privacy law as something for compliance teams to worry about. Fair enough. But CCPA is one of the few privacy laws written with an actual consumer-facing right to act, not just a policy buried in fine print. It's also a different animal from the CAN-SPAM Act, which governs what your marketing emails can say. CCPA governs what happens to your data afterward.
Think about how much of your digital footprint runs through your inbox. Every newsletter signup, every online purchase, every "create an account" flow, most of it starts with an email address. That address becomes a thread that connects your identity across dozens of businesses you've never met in person. CCPA is the tool that lets you pull on that thread.
Under the law, you can ask any covered business three things: what they've collected about you, that they delete it, and that they stop selling it. It works a bit like an unsubscribe request, except instead of just stopping emails, it can stop your data from being sold or shared at all. Businesses have to give you a working method to submit that request, whether it's a toll-free number, a web form, or (increasingly common) a dedicated email address. And they generally have to respond within 45 days.
Here's the part that surprises people: this isn't limited to giant tech platforms. Any for-profit business that meets certain thresholds, generally $25 million or more in annual revenue, or buying and selling data on 100,000 or more people, falls under CCPA. Even a sender you've deliberately added to your email whitelist is still a business that can collect and sell whatever data it gathers from you, unless you exercise your rights. That's a lot of the companies filling up your promotional folder.
Two ways CCPA shows up practically, and they're pretty different from each other.
Data requests. You email a company (or use their form) and ask what they have on you. This one's slow and formal, but it works. Expect a response within a few weeks, not immediately.
Global Privacy Control. This is the newer, faster option. It's a browser-level signal, available in Firefox, DuckDuckGo, and Brave, that automatically tells every site you visit "don't sell or share my data." No individual requests needed. Set it once, and it applies everywhere.
The data request route gives you more detail. The signal-based route saves you the hassle. Most people are better served by turning on the signal and only filing manual requests for the handful of companies that actually matter to them.
To submit a request: Find the company's privacy policy (usually linked at the bottom of their homepage) and look for their designated request method. Most give you a form or a dedicated email address. Some will send a verification email first, just to confirm the request is really coming from you before they act on it.
To use Global Privacy Control: Turn it on through your browser settings or install a supporting extension. Once enabled, it broadcasts your opt-out preference automatically to every site you visit that recognizes the signal.
If a business ignores you: You can file a complaint directly with the California Attorney General's office. Businesses that don't provide a working opt-out method are, technically, in violation.
Does CCPA only protect California residents?
Technically, yes. But many businesses apply the same rights to everyone rather than build two separate systems, so you may get CCPA-style protections even outside California.
How is Global Privacy Control different from filing a request?
A request gets you specific detail on one company. Global Privacy Control is a standing signal that tells every site you visit to stop selling or sharing your data, without you lifting a finger per site. It works.
How long does a business have to respond to my request?
Generally 45 days. That's slower than most people expect, so don't panic if you don't hear back the same week.
What if a business ignores my opt-out request?
Report it to the California Attorney General's office. A business that can't provide a working opt-out method is out of compliance, plain and simple.
Is CCPA the same as GDPR?
No. They overlap in spirit, but GDPR is broader and applies across the EU, while CCPA is a California state law with its own specific thresholds and rights.