Industries · E-commerce

Do my ad pixels count as “selling” data?

Under California law, sharing personal information for cross-context advertising counts whether or not money changes hands. That is why a store running ordinary remarketing pixels usually owes Californians a working opt-out — and why the biggest CCPA settlements have been about opt-outs that did not work.

The short answer

Probably yes — “sharing” covers ordinary ad pixels, so most stores owe an opt-out that actually propagates.

California does not run an “Accept cookies” wall. It asks for notice at collection, a working “Do Not Sell or Share My Personal Information” mechanism, and automatic honouring of the Global Privacy Control signal. The regulations are explicit that a cookie control is not by itself an acceptable opt-out method, which is why UserGuard ships Do Not Sell as its own mechanism with its own link, panel and record.

What a browser-side opt-out can reach, it reaches: it gates the tags on your pages and publishes the USP string vendors read. What it cannot reach — server-to-server conversion APIs, CRM syncs, audience uploads, data you sell directly — stays yours to switch off. Pretending otherwise is the exact failure mode behind California’s largest settlements.

What a storefront usually sets

Where the exposure actually sits.

Ad platform pixels

Meta, Google Ads, TikTok, Pinterest, Bing, LinkedIn — the default blocking rules name both the loader scripts and the beacon endpoints they call, because gating a script host while a hand-placed image pixel fires anyway is theatre. First match wins, and the rule list is yours to edit.

Remarketing and audiences

Remarketing is the clearest case of cross-context behavioural advertising, and it is what an opt-out is for. UserGuard treats analytics and marketing as sale categories by default — a store that genuinely does not pass analytics data on can take that one out.

Platform and app cookies

Storefront platforms and their app ecosystems add cookies you never chose: reviews widgets, upsell apps, live chat, loyalty. Every install is a new scan’s worth of surprises, which is why scans run monthly and a manual rescan after any change is one click.

Consent Mode v2, because Google asks

Since March 2024, Consent Mode v2 has been required for Google advertising and measurement features covering EEA and UK users. UserGuard sets default-denied signals for all four consent types before any Google tag loads, then updates them the moment a visitor chooses — so campaigns degrade gracefully instead of firing without consent.

The enforcement ledger

Regulators fine the mechanics.

Not the design of the banner. The ignored signal, the opt-out that did not propagate, the request that went unprocessed.

$1.2MSephora

Ignored Global Privacy Control signals while sharing data with ad-tech partners.

$632KHonda

Opt-out flows that made saying “no” harder than saying “yes.”

$1.55MHealthline

Kept sharing data with ad partners after visitors opted out — the largest CCPA settlement to date.

$345KTodd Snyder

Opt-out requests went unprocessed for 40 days, then the form demanded ID before it would honor one.

Coverage

The rules a store actually answers to.

This page is general information about privacy laws, not legal advice. Whether your store is in scope, and which categories count as a sale or share for your business, depend on facts we cannot see from here. Consult qualified counsel for your situation.

Get started $10 a site · 30-day money-back guarantee · cancel anytime

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started 30-day money-back guarantee · cancel anytime