Skip to main content

CCPA · By industry

CCPA & tracking compliance for restaurant websites

CCPA compliance for a restaurant website means the Meta, Google, and TikTok pixels on your online-ordering, menu, and reservation pages do not amount to selling or sharing a Californian's data before you have disclosed it and honored their opt-out, including the Global Privacy Control browser signal. Online ordering puts that ad telemetry on your highest-traffic pages. Complidar captures every tracker that fires across up to 120 pages, sends a GPC signal the way a regulator's investigator would, and shows you what a 'sale' looks like on your own ordering flow.

Why a restaurant site trips the CCPA

The CCPA's definition of a 'sale' or 'share' is broad enough to catch the ordinary restaurant ad stack: a Meta or TikTok pixel, a Google Ads tag, and GA4 all transmit identifiers and behavior to third parties who use them for cross-context advertising, and that transfer is what the statute regulates. The recurring failure is timing and signal. Those tags fire on the online-ordering, menu, and reservation pages before any consent, and the site never changes its behavior when a visitor's browser sends a Global Privacy Control opt-out. Both are visible from outside, which is exactly why this is enforcement's favorite fact pattern.

The anchor case is a store, but the configuration is identical to a restaurant's. In re Sephora ($1.2M, 2022) was the first public CCPA enforcement, and it turned on two things an automated scan sees directly: third-party advertising trackers that amounted to a 'sale' without the required disclosures and opt-out, and a site that ignored the GPC signal. The California Attorney General named the GPC failure specifically. A restaurant running standard marketing pixels on its 'order now' flow is running the same setup that cost Sephora $1.2M.

Where the exposure lives on a restaurant site

On a restaurant site the CCPA surface concentrates on the pages a hungry customer actually uses, which is where the high-value tracking concentrates too. The mechanical, citable failures are:

  • Meta, Google, and TikTok ad pixels firing on online-ordering, menu, and reservation pages before the visitor has consented
  • GA4 and analytics loading pre-consent on the ordering flow and passing identifiers to a third party
  • A site that does not change behavior when it receives a Global Privacy Control opt-out signal from the browser
  • No working 'Do Not Sell or Share My Personal Information' pathway where one is required
  • Session-replay recording the online-ordering flow, capturing what diners type and select

What it actually costs

The statute prices each violation at $2,500, and $7,500 per intentional violation or any violation involving a minor, enforced by the Attorney General and the California Privacy Protection Agency. Because each affected consumer interaction can count, the figure compounds. The realistic number to plan against is the ad-pixel-before-consent comparable, which runs a median around $4.5 million, with the Sephora $1.2M as the public anchor for what a single operator paid over standard ad trackers and an ignored GPC signal. The nine-figure tracking cases you see in headlines are large-scale illustrations of the same theory, not what a typical restaurant should expect. We can show what your ordering and reservation pages transmit; whether to remediate, respond, or both is a conversation for your counsel.

What the scan checks here

  • Every Meta, Google, TikTok, and analytics tracker that fires on online-ordering, menu, and reservation pages, captured from real network traffic
  • Pre-consent firing flagged: which tags transmit identifiers before the diner has opted in
  • Whether the site honors the Global Privacy Control (GPC) signal the scan sends
  • A 'Do Not Sell or Share My Personal Information' pathway, where required
  • Privacy-policy disclosures: categories collected, sale/share language, consumer-rights mechanics
  • Session-replay and analytics vendors recording the online-ordering flow

Honest limits: A scan verifies what your site does: which trackers fire on which pages, when, whether GPC changes anything, and what your policy says. It cannot determine whether your business meets the CCPA's revenue or volume thresholds, or how your back office handles a consumer's delete or opt-out request; those are counsel and process questions. The report labels which findings are observable site behavior and which need human review, rather than implying a clean scan equals full compliance.

Common questions

Are the Meta and Google pixels on my ordering page really a 'sale' under the CCPA?

They can be. The CCPA defines 'sale' and 'share' broadly enough to cover transferring identifiers to ad platforms for cross-context advertising, which is what those pixels do on your online-ordering flow. That is the exact theory In re Sephora ran on. Whether it meets the statute for your business is a counsel question; whether the tags fire before consent on your ordering and reservation pages is what the scan settles.

Our online ordering and reservations are third-party widgets. Are we still exposed?

Yes. The trackers load on the pages your customers use under your domain, and the disclosure-and-opt-out duty attaches to your site, not the widget vendor. Sephora ran ordinary ad trackers and still paid $1.2M. Complidar scans your real page behavior, embedded ordering and reservation widgets included, because a vendor default is not a defense.

What does a CCPA violation cost a restaurant?

Statutory penalties are $2,500 per violation and $7,500 per intentional violation, and they compound across affected consumers. The realistic comparable for the ad-pixel-before-consent pattern runs a median near $4.5M, with Sephora's $1.2M as the public anchor. The nine-figure cases in the headlines are large-scale illustrations of the same tracking theory, not the typical restaurant's number.

Check your site free

All 22 checks · up to 120 pages · no card

Last updated 2026-06-28 · Informational, not legal advice: how to read this