If you schedule clients in California — or your scheduling tool does business with Californians — CCPA (as amended by CPRA) applies. The law is meaningfully different from GDPR: narrower in some ways, broader in others, and enforced by a more aggressive attorney general.
The core CCPA obligations
Four things the CCPA demands of scheduling tools: (1) disclose what personal information they collect, (2) disclose to whom they disclose it, (3) give consumers the right to delete that information on request, and (4) honor "do not sell or share my personal information" signals via the Global Privacy Control (GPC) header.
Sensitive personal information under CPRA
CPRA expanded CCPA with a category for "sensitive personal information" — including precise geolocation, racial/ethnic origin, religious beliefs, genetic data, health, and sexual orientation. If your booking form collects any of these (e.g. health intake forms for therapy), you must offer an explicit opt-out from using it for purposes beyond the immediate booking.
The "sale or share" language trap
CCPA's definition of "sale" includes the exchange of personal information for anything of value — including free advertising impressions. Most scheduling tools that load Meta Pixel, Google Ads, or LinkedIn Insight tags on booking pages are technically "selling" your clients' data under this definition.
Global Privacy Control (GPC) handling
The GPC browser header is a do-not-sell signal that some US states now require to be honored. Your scheduling tool should detect and respect this header automatically — without requiring the invitee to fill out a separate form.
This is part of our privacy-first scheduling pillar guide — 18 articles covering every privacy angle.
Frequently Asked Questions
Is a scheduling tool a 'service provider' under CCPA?
Usually yes — if you have a written agreement that restricts the tool from using personal information for any purpose other than providing the scheduling service. Without that agreement, the tool becomes a 'third party' and its data practices are directly regulated.
Does Cal Clear respect the Global Privacy Control header?
Yes. Cal Clear is privacy-first by default — we don't sell or share personal information with anyone, and we honor GPC signals automatically.
Try privacy-first scheduling, free
Cal Clear runs zero trackers on booking pages and auto-deletes booking data on your schedule. Start at calclear.app.