The CCPA, as amended by the CPRA, is a law your business complies with. It is not a certification, and no CRM can be CCPA certified. What matters when you buy is whether the vendor will sit in the service provider role, accept the contract terms California requires, and give you the tools to answer consumer requests inside the statutory deadline. This page explains who the law applies to, what counts as a sale or a share, the six consumer rights and their timelines, and what HelloGrowthCRM does as a service provider. It also sets out which duties remain yours as the business.
The CCPA applies to for-profit entities doing business in California that collect California residents' personal information, determine the purposes and means of processing, and meet at least one threshold. The thresholds are annual gross revenue above twenty-five million dollars, buying, selling or sharing the personal information of one hundred thousand or more consumers or households, or deriving fifty percent or more of annual revenue from selling or sharing personal information. Only one needs to be met. The revenue threshold is adjusted periodically, so confirm the current figure rather than relying on a number you read in an older compliance article somewhere.
Two features regularly surprise teams evaluating a CRM. First, the definition of consumer includes employees and business contacts. Temporary exemptions for employee and business-to-business data have expired, so the personal information of your California job applicants, staff and business contacts is in scope alongside consumer data. For a sales CRM full of business contacts, that is the material point. Second, personal information is defined broadly and includes information reasonably capable of being associated with a consumer or household, which sweeps in identifiers, commercial information and inferences that a CRM routinely stores as part of ordinary account management.
California is also no longer alone. More than a dozen other US states have enacted comprehensive privacy laws with similar structures: consumer rights, opt-outs for targeted advertising and sale, and contractual requirements flowing down to vendors. The terminology differs and some obligations diverge, particularly around universal opt-out signals and sensitive data. If you are building a compliance process for California, design it so the same operational routes serve other states rather than building California-only tooling. The vendor questions on this page work equally well when you assess a CRM against Virginia, Colorado, Connecticut or Texas requirements.
California defines three roles for entities that receive personal information from a business, and the role determines the rules. A service provider processes personal information on the business's behalf under a written contract that limits what it may do with the data. A contractor is similar but covers disclosures for a business purpose where the recipient certifies it understands and will comply with the restrictions. A third party is anyone else, and a disclosure to a third party for something of value is where sale and sharing analysis begins. A CRM vendor should be sitting squarely in the service provider role.
The role is created by contract, not by the vendor's self-description. The CPRA sets out required terms: the recipient must be prohibited from selling or sharing the personal information, from retaining, using or disclosing it outside the business purposes specified in the contract, from using it outside the direct business relationship, and from combining it with personal information received from other sources except in narrow permitted circumstances. The contract must also grant the business rights to take reasonable and appropriate steps to ensure compliance and to stop and remediate unauthorised use. Confirm those terms are present before you assume the role applies.
This matters commercially as well as legally. A properly documented transfer to a service provider is not a sale or a share, so it does not trigger opt-out obligations for that transfer. Get the contract wrong, and the same data flow can be recharacterised, which changes your notice and opt-out duties overnight. That is why the review order should be contract first, feature list second. Ask any CRM vendor to confirm in writing that it acts as a service provider, and read the terms rather than accepting a statement on a marketing page as sufficient evidence of the arrangement.
Sale is defined broadly. It covers selling, renting, releasing, disclosing, transferring or otherwise communicating a consumer's personal information to a third party for monetary or other valuable consideration. The phrase other valuable consideration is what catches teams out, because no money needs to change hands. Sharing has a narrower and more specific meaning: disclosing personal information to a third party for cross-context behavioural advertising, whether or not for money. Both trigger the consumer's right to opt out, and both require a clear notice and a mechanism to exercise that right, including the Do Not Sell or Share My Personal Information link.
In CRM practice, the risk rarely comes from the CRM itself. It comes from what teams connect to it. Syncing CRM audiences into an advertising platform for retargeting is a classic sharing scenario. Passing contact records to a data enrichment provider that also uses the data for its own purposes can be a sale. Exporting lists to a partner in exchange for their list is a sale even though it is a swap and no invoice exists. Each integration is a separate data flow needing its own analysis, and integrations get added long after the original privacy review concluded.
The practical response is an inventory and a review gate. Keep a current list of every integration attached to your CRM, what data leaves through it, who receives it and under what contract. Review it on a schedule and whenever someone connects something new. Honour opt-out requests and the Global Privacy Control signal where your systems receive it, and make sure an opt-out actually propagates to the downstream systems rather than only being recorded in the CRM. A suppression flag that never reaches your ad platform is a compliance failure that looks like compliance in your own records.
California gives consumers six rights. The right to know covers the categories and specific pieces of personal information collected, the sources, the business purposes and the categories of recipients. The right to delete covers information collected from the consumer, subject to exceptions. The right to correct covers inaccurate information. The right to opt out covers sale and sharing. The right to limit covers the use and disclosure of sensitive personal information to what is necessary to provide the requested service. The right to non-discrimination means you cannot penalise someone for exercising any of these rights.
Timing is strict. You must confirm receipt of a request within ten business days and respond substantively within forty-five calendar days, extendable once to a total of ninety days where reasonably necessary and where you notify the consumer of the extension and the reason. You must also verify the requester's identity to an appropriate standard before disclosing or deleting anything. Build the workflow before the first request arrives, including who owns it, where requests land, how identity is verified and how the outcome is logged. The deadline runs from receipt, not from the day someone in your team notices the email.
Deletion has an important downstream element. When you receive a valid deletion request, you must direct your service providers and contractors to delete the consumer's personal information as well, and where relevant notify third parties to whom you sold or shared it. That means you need to know where the data went. This is another reason to keep the integration inventory current. As service provider, HelloGrowthCRM's role is to make the data reachable and deletable so that your instruction can actually be carried out inside the workspace, but issuing that instruction and tracking completion across systems remains your responsibility.
On the security side, data is encrypted in transit with TLS and encrypted at rest. Customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer rather than only in application code. Production access is least-privilege, MFA-gated, logged and periodically reviewed. Automated backups run with point-in-time recovery. A documented incident-response workflow covers detect, contain, assess, remediate and notify. These matter under California law because the statute creates a private right of action for certain breaches of unencrypted or unredacted personal information caused by a failure to maintain reasonable security procedures.
On the operational side, workspace admins can export contacts, deals and activity data at any time, which is what you need to answer a right to know request and to produce records in a portable form. Records can be corrected in place and account deletion is honoured. Role-based access control inside each workspace lets you limit who can see or change contact data, which supports the purpose limitation the service provider contract requires and reduces the number of people who could copy a list out. Data rights handling is documented at /legal/data-rights, and EU, UK and California customers have equivalent access, correction and erasure rights.
What stays with you is everything that depends on knowing your own business. You publish the privacy notice and the notice at collection. You maintain the Do Not Sell or Share My Personal Information link if you sell or share. You verify requesters and decide whether exceptions apply. You set retention periods and disclose them. You inventory your integrations and decide which flows are sales or shares. You direct service providers to delete when a request is validated. HelloGrowthCRM provides the contract terms, the security controls and the data access that make that work, but the decisions are yours.
Email sales@hellogrowthcrm.com to request the DPA and the SOC 2 Type II report under NDA. The subprocessor list at /subprocessors and the data rights documentation at /legal/data-rights are already public, so your privacy counsel can begin the review before a call is booked.