CCPA (California)
CCPA and CPRA-ready consent, opt-out signalling and DSAR — with GPP integration for the rest of the US map.
The California Consumer Privacy Act (as amended by the CPRA) is the reference law that every subsequent US state law borrows from — sometimes almost verbatim. Gravito is the platform that lets you comply with California while quietly picking up every other US state as they pass laws in the same shape.
What the platform gives you.
Opt-out signals propagate to every downstream ad platform in real time — no half-honoured requests, no drift.
Global Privacy Control browser signals are honoured automatically. Users who set GPC never see the banner in the wrong state.
CPRA sensitive-data restrictions applied at the purpose level, so downstream integrations never see data that shouldn't leave.
Right to Know, Right to Delete and Right to Correct requests flow through the same workflow as GDPR DSARs.
What we hear from teams like yours
- Do Not Sell / Do Not Share signals sometimes drop between the CMP and the ad stack
- Opt-out preferences don't reliably propagate to downstream tools
- Global Privacy Control (GPC) support is inconsistent across CMPs
- New US state laws mirror CCPA — but the integration still feels bespoke
When a user opts out, the signal actually gets there.
Gravito propagates Do Not Sell / Share and GPC opt-outs to every downstream ad platform, CRM and analytics tool in real time. Server-side signal replay means even the tools that don't listen to the browser correctly see the current opt-out state.
- ◆ Real-time propagation to Google Ads, Meta, TikTok and every ad partner
- ◆ Server-side signal replay for tools that miss browser events
- ◆ Audit trail proves opt-out was honoured within the CCPA timeframe
Sensitive categories treated differently, enforced at the platform.
CPRA adds a layer on top of CCPA for sensitive personal information — geolocation, race, health, financial account details. Gravito lets you flag sensitive purposes explicitly, and enforces the restriction end-to-end. Downstream integrations never see data a sensitive-data opt-out should have suppressed.
- ◆ Sensitive-purpose flags applied at the consent record
- ◆ Enforcement propagated to every downstream integration
- ◆ Audit trail shows exactly which purposes were live at any moment
What customers see
Californian standards, national reach
Ship CCPA-ready flows without splitting your codebase or your policy — and pick up every subsequent US state law as it passes, because the underlying platform already speaks GPP.