Privacy & cookie law compliance for online businesses

California fined a company $2.75 million
for what your site might be doing right now.

A cookie banner on your site does not mean tracking stops when a visitor clicks reject. We start with a full audit of every tracker and vendor, tested against US state and EU law. Then we keep you compliant with an always-on consent banner and monitoring subscription, so the file never goes stale. Not a plugin. Documented proof, and continuous coverage.

Real enforcement cases, not theoryUS state + EU coverageLawyer-reviewed documentation
Start with what's on your website

Run a free scan before you book anything.

Enter your domain and we'll surface the trackers and cookies already active on your homepage, right here, in under a minute. No email required to see the result.

Free, one page, homepage only. The full audit crawls every page and app and tests whether Reject actually works.

Sound familiar?

The banner is not the problem.
What is behind it usually is.

ExhibitA

You think the banner covers you

A cookie popup does not mean tracking actually stops when a visitor clicks reject. Regulators have fined companies for exactly this gap: a banner that shows up but does not function.

ExhibitB

The rules keep moving

Nineteen states now run their own privacy law, and New Jersey's warning period for violations just ended. A site that passed a check last year can fail one today without anyone touching it.

ExhibitC

Your vendors are the real exposure

Every ad and analytics tool on your site is a vendor with access to visitor data. Most of those relationships have no signed agreement behind them, and that is exactly what regulators check first.

None of this needs a regulator's letter to find out. A proper audit checks every tracker, every vendor, and every opt-out control against the law before an investigation does. That is the entire job we do.

What we check

Four places compliance actually breaks down.

We go deep in the areas regulators actually cite. Start with the one that worries you most, or cover all four in one audit.

§01

Consent & Tracking

What fires before anyone clicks anything

What we find
  • Trackers load before a visitor makes a choice
  • A reject button that doesn't actually stop data collection
  • Global Privacy Control signals never wired up
What we build
  • Full tracker and cookie inventory
  • Consent-gated tag manager rebuild
  • Opt-out controls tested, not assumed
§02

Vendor Contracts

The paperwork regulators ask for first

What we find
  • Ad and analytics tools with no signed data agreement
  • No record of what data leaves your site or where it goes
  • Vendor terms nobody on your team has read
What we build
  • Full vendor and data-flow inventory
  • Data processing agreements executed
  • A file ready to produce on request
§03

Legal Documentation

Proof, not promises

What we find
  • A privacy policy that doesn't match what your site does
  • No Data Protection Impact Assessment on file
  • Nothing a lawyer has reviewed or signed
What we build
  • A complete Data Protection Impact Assessment
  • Independent legal review and sign-off
  • Documentation built to hold up under scrutiny

Documentation only, reviewed by independent counsel. Not representation in an active investigation or lawsuit.

§04

Multi-State & EU Coverage

One audit, every jurisdiction you sell into

What we find
  • Compliant in one state, exposed in nine others
  • GDPR treated as someone else's problem
  • No one watching when a new state law takes effect
What we build
  • Coverage mapped to every state and country you sell into
  • GDPR-aligned documentation for EU visitors
  • Ongoing monitoring as laws change
How it starts

Two ways to work with us: one audit, one subscription.

Start with the audit to see exactly what is exposed, or go straight to the banner and scanner subscription if you already know you need ongoing coverage. Most clients do both.

Start here

The Compliance Audit

A full scan of every tracker and cookie on your site, tested against California, Texas, Connecticut, New Jersey, and EU rules. You leave knowing exactly what is exposed, what it would take to fix, and whether you need it at all.

$1,500fixed fee

1–2 weeks · credited toward any fix work

  • A full tracker and vendor inventory
  • Opt-out and consent testing, not just a banner check
  • A prioritized list of what to fix first
Monthly subscription

Banner + Scanner

Once you are compliant, stay that way. An always-on consent banner with pre-consent blocking, plus continuous monitoring that flags new trackers, new vendors, and new law before they become exposure.

Starter
$49/moUp to 10,000 monthly visitors · 1 domain
Scale
$399/mo100,000+ monthly visitors · unlimited domains

If the audit finds real exposure:

The Fix & Documentation

Custom quote & timeline

We rebuild what is broken, get vendor agreements signed, and produce a complete, lawyer-reviewed Data Protection Impact Assessment for your business. Priced to what the audit finds, agreed up front.

The record

Real cases. Real fines. Not hypothetical.

Every one of these started with a business that assumed its cookie banner already covered it.

$1.35M
Its opt-out link did not actually stop data sharing, and the site ignored the Global Privacy Control signal until mid-2024.
Tractor Supply Co.Fined by the California Privacy Protection AgencySeptember 2025
€150M
Advertising cookies fired before visitors interacted with the consent banner, and Reject All did not stop new tracking.
SheinFined by CNIL, FranceSeptember 2025
$345K
A mid-size clothing retailer mishandled opt-out requests the same way most small sites still do today.
Todd SnyderFined by the California Privacy Protection AgencyMay 2025
0 days notice
New Jersey's mandatory 30-day warning period for privacy violations ended July 15, 2026. Enforcement now starts with a penalty, not a warning.
New JerseyNJDPA cure period sunsetJuly 2026
Read the full case files →
How it works

From first call to a compliance file that holds up.

1

Discovery call

Free · 30 min

We look at what you sell, where your buyers are, and what is currently running on your site. If there is no real exposure, we tell you that directly.

2

The audit

Week 1–2

We scan every tracker and cookie, test your consent flow, and map every vendor with access to visitor data.

3

Fix & document

Week 3–4

We rebuild what is broken, get vendor agreements signed, and produce your Data Protection Impact Assessment.

4

Legal review

Included

Independent counsel reviews the findings and signs off on the assessment addressed to your business by name.

5

Banner & monitoring

Ongoing

Move onto the Banner + Scanner subscription. We keep watching for new trackers and new state or EU rules, so the file does not go stale.

Why us

We have been the ones getting audited for thirty years.

Optima's manufacturing operation has held ISO 9001, ISO 14001, and ISO 45001 certification, plus SEDEX 4-Pillar audits, for buyers like Amazon and Disney, for decades. We know what an auditor looks for, because we have been the ones producing the paperwork, not just reading about it.

That is the difference here. We are not a plugin reselling generic templates. We build documentation the way a real compliance audit expects to see it, because we have sat on the other side of that audit for thirty years.

30 yrsPassing real compliance audits
4ISO & SEDEX certifications held
Factory-testedNot a template
US + EUCoverage built in from day one
Who you work with

Two operators, not a sales team.

We met building a company together. Then we went and ran real things. One of us runs a factory and has spent thirty years being the one audited. The other builds relationships with the businesses that need this most.

PK

Pranjal Kukreja

Technical and Delivery

He runs the audits. He has also spent thirty years being the one audited.

Zone President and CEO for India at Optima Industries, a manufacturing operation producing for Amazon, Disney, Reebok and Skechers. ISO 9001, 14001 and 45001 certified, SEDEX 4-Pillar audited. That same audit discipline is what this service is built on.

He also builds the internal systems his own business runs on, including the ERP that manages purchasing, production and inventory. Turning a real operation's compliance requirements into working documentation is not new to him. It is what he already does for his own factory.

LinkedIn
KJ

Khizar I. Jamil

Growth and Client Relations

He knows the businesses. He has spent his career inside the industries that need this most.

Chief Executive Officer at K and Q Ventures, a real estate development firm in New York, and a Realtor Sales Associate with Keller Williams Village Square Realty in Ridgewood, New Jersey.

He founded LifeShyft AI, a predictive intelligence platform for realtors, after watching an entire industry run on cold calls. The same instinct applies here: find where a business is exposed and fix it before someone else finds it first.

LinkedIn
Book your audit

Tell us what is running on your site.

Flag which states or countries your buyers are in, add a line about what worries you most, and send it over. We will set up a short call and, if there is real exposure, book your $1,500 audit. If there is not, we will tell you straight.

1

Where does it hurt most?

Pick the areas costing you the most time. Choose as many as fit.

2

How big is your team?

Helps us come prepared. Optional.

3

Describe the single worst part.

In your own words. One or two sentences is plenty.

Pick at least one area to continue.

No sales sequence, no spam. One human reply to set up a call.

  • A real person replies, not an autoresponder
  • No obligation, no sales sequence
  • Walk away with clarity either way