A small home services website rarely meets the revenue or data-volume thresholds that trigger CCPA, but that does not make a privacy policy optional. California’s older CalOPPA law applies to any commercial site collecting personal information from a California resident, with no minimum size, and a handful of other state laws layer on top of that. A carefully completed generator covers most contractor, plumber, or HVAC sites, provided every tool actually running on the site, not just the ones present at setup, ends up listed in the policy.
Why CCPA usually does not apply, but a policy is still expected
CCPA and its CPRA amendments cover a for-profit business only if it crosses at least one threshold: annual gross revenue above 25 million dollars, buying, selling, or sharing personal information of 100,000 or more California consumers or households a year, or deriving 50 percent or more of annual revenue from selling personal information. A local roofing or HVAC company clears none of these in the overwhelming majority of cases. That distinction matters because it means the detailed CCPA consumer-rights machinery, like a dedicated “Do Not Sell or Share My Personal Information” process, is usually not a legal requirement for a small operation. It does not mean no policy is needed at all, since a separate, older law fills that gap.
CalOPPA: the law that actually reaches almost every small site
The California Online Privacy Protection Act applies to any operator of a commercial website that collects personally identifiable information from a California resident, regardless of business size or revenue. A contact form asking for name, email, and phone number is enough to trigger it, and because any visitor could be browsing from California, this covers nearly every public business website in practice. CalOPPA requires the policy to be conspicuously posted, meaning either shown on the homepage or reachable through a clearly labeled “Privacy” link, and it must describe the categories of personal information collected, the categories of third parties data may be shared with, how visitors can review or request changes to their information, how the business will announce material changes to the policy, and the policy’s effective date.
Where COPPA and other state laws fit in
The Children’s Online Privacy Protection Act applies to sites directed at children under 13 or that knowingly collect their data, which does not describe a typical contractor or home services business, so it rarely applies. A growing list of other states, including Colorado, Virginia, Connecticut, and Utah, have passed CCPA-style laws with their own revenue or data-volume thresholds. Those thresholds tend to track CCPA’s structure closely enough that a small local business stays outside their scope too, but a business expanding into multiple states or scaling toward franchise size should recheck this as it grows rather than assume small-business status indefinitely.
A privacy policy is also not the same thing as a data processing agreement with a vendor. Many small business owners assume the policy on their own website covers everything, but a booking tool, a form plugin, or a hosting provider that processes visitor data on the business’s behalf is a separate relationship, usually governed by that vendor’s own terms of service or a data processing addendum. The website policy tells visitors what happens to their data, it does not replace the contractual terms between the business and the tools it runs.
Generators small businesses actually use
Most small home services businesses reach for a generator instead of a custom-drafted policy, and that is generally adequate as long as the questionnaire behind it gets answered accurately.
| Tool | Model | Approximate price |
|---|---|---|
| Termly | Free tier for one policy, paid tiers add cookie banners and more | Free, or roughly 10 to 20 dollars per site per month on paid plans |
| TermsFeed | Generator plus subscription for updates | Low one-time fee or a small monthly subscription |
| Iubenda | Free basic tier, paid tiers for auto-updates | Free basic, paid tiers scale with traffic and features |
Prices and free-tier limits change over time, so it is worth checking current terms directly with the provider before signing up. A free generator with an accurate, current questionnaire beats a paid one filled out carelessly.
The mistakes that show up on real small business sites
A generator can only describe what the questionnaire captured, and most gaps appear after the initial setup, once new tools get added without anyone revisiting the policy:
- Google Maps or another map embed added later for a directions page, never reflected in the original policy.
- Analytics tools like Google Analytics or a privacy-focused alternative, including what data they collect and how long it is kept.
- A contact form vendor or plugin that sends submissions to a third-party server rather than staying entirely in-house.
- A scheduling or booking widget, whose calendar sync often runs through an additional third-party service.
- Embedded video, such as YouTube, which tracks visitors differently than the rest of the page.
- Ad pixels, like a Meta or Google Ads pixel, which can trigger CCPA’s “sharing” definition even for a business otherwise below the revenue threshold.
Treating the privacy policy as a one-time setup task instead of something to revisit whenever a new tool gets added is the single most common failure mode, generator or not.
A quick self-check before publishing
Before trusting a generator’s output, it helps to open the live site and compare it line by line against what the policy actually says:
- Does the contact form vendor appear in the policy under its real name and purpose?
- Is the map embed, whether Google Maps or a lighter alternative, listed as a connected service?
- Does every analytics or tracking script that actually loads in the page source show up in the text?
- If a scheduling or booking tool is running, is its provider and calendar sync mentioned?
- Does the stated retention period still match how long the business actually keeps inquiries?
- Is the policy reachable in one click from every page, not just the homepage?
Any mismatch usually means a short update to the generator questionnaire, not a full rewrite.
Keeping the policy current without turning it into a project
The policy belongs on its own clearly labeled page, linked from the footer of every page so it is reachable in one click from anywhere on the site, and a short notice near the contact form covering what is collected and why is a stronger practice than relying on the footer link alone. Businesses that already have someone maintaining their website regularly can fold this check into that routine instead of tracking it separately. Mr.Site handles exactly this kind of detail work as part of ongoing website management for several hundred business websites, including a check for newly added tools whenever the site changes. Related reading: does your business website contact form need a privacy notice and legal pages a business website needs in Germany.