Home/Services/Web compliance

Ship

Web and privacy compliance for internet businesses

Most internet businesses are running third-party scripts nobody has inventoried, a privacy policy that doesn’t describe what the product actually does, and a billing flow that has never been checked against California’s rules. None of that is unusual. All of it is cheaper to fix now than after someone points it out.

from $1,950 flat

A few documents and an honest look at what your site actually loads. Bounded work, one flat fee, and a written scope before anything starts.

01

What are the most common compliance problems for internet businesses?

The same handful, in nearly every case: third-party scripts running before anyone consents, a privacy policy that describes a different product than the one you shipped, a subscription flow written before California’s current rules, storage nobody has reviewed, and social proof that can’t be substantiated. Each is a small fix on its own. Together they are why a demand letter, a diligence request, or a chargeback dispute turns expensive.

These are not exotic failures. They are what happens when a product ships faster than its paperwork — which is nearly always. The gaps below are common; what varies is who notices, and when. Sometimes it is a plaintiff’s firm running automated scans. Sometimes it is an acquirer’s diligence checklist, or a payment processor, or an enterprise customer’s security review.

Who this is for

Web and mobile apps, Shopify and e-commerce stores, dropshipping operations, Amazon FBA sellers, subscription products, AI tools and chatbots, agencies and creators — any California-facing site running third-party scripts, billing on a recurring basis, or shipping an AI feature. Increasingly that includes products built quickly with AI coding tools, where the stack outran the paperwork.

Six gaps account for most of what turns up on a California-facing site, with what each one exposes you to when somebody does look.

California-facing web businesses. General information, not legal advice — and this area is moving quickly.
The gapHow often it’s thereWhat it exposes you to
Tracking scripts firing
before consent
Most sites Statutory damages of $5,000 per violation under California’s wiretapping statute, and “per violation” is doing heavy lifting. Demands are sent at volume by firms running automated scans, and priced to sit just under what fighting would cost.
A privacy policy that
doesn’t match the product
Very common Attorney General and CPPA enforcement, plus the quieter cost: it is the first document an acquirer, an enterprise customer, or a payment processor reads — and an inaccurate one invites the whole file to be pulled.
Subscription and cancellation
flow written before the rules
Most recurring billers Consumer class actions and refund exposure. California’s rules bind in full and were strengthened in 2025 — the federal “click-to-cancel” vacatur changed nothing here, which a lot of published guidance still gets wrong.
A companion chatbot with
no crisis protocol
Most new AI products The shortest path on this page from non-compliant to being sued personally: direct claims at $1,000 per violation plus attorney’s fees, which is what makes small cases worth a plaintiff lawyer’s time.
Storage and retention
nobody has reviewed
Common $100–750 per consumer, per incident if data is exposed — multiplied by every user record you kept and didn’t need. Plus breach-notification duties, and the customer conversations that follow.
Testimonials you can’t
substantiate
Common Federal penalties north of $50,000 per violation, and every incentivized review can count separately. Among the cheapest items here to fix and the most expensive to be caught on.

None of this requires a bad actor. Every gap above is the ordinary result of shipping a product faster than its paperwork, and every one is materially cheaper to close now than to argue about later. Closing them is a few documents and an afternoon of looking at what your site actually loads — after which you stop wondering.

The longer version of this ranking is here.
02

Which rules apply to my product?

Not all of it will. The scope depends mostly on what your product does, and a short conversation usually removes more items than it adds.

If you run

A marketing site or storefront

Anything with analytics, ad pixels, a chat widget or session replay — which is nearly everything.

  • Tracking & consent review
  • Privacy policy and notice at collection
  • Testimonial and review claims
If you run

A subscription product

Recurring billing, free trials, or anything that converts from free to paid.

  • Everything in the first column
  • Signup and renewal disclosures
  • Cancellation flow review
  • Terms of service
If you run

An AI or chatbot product

Conversational features, AI acting on user data, or a companion-style assistant.

  • Everything in the first column
  • AI disclosure in your privacy policy
  • Crisis-response protocol and bot disclosure
  • Protections where minors may be users
03

What does the launch compliance package include?

One flat fee, scope confirmed in writing

From $1,950 · typically 5–10 business days

  • Privacy policy — written to describe what your product actually does, including AI use and third-party recipients
  • Terms of service — liability, IP, acceptable use, termination, dispute resolution
  • Tracking & consent review — an inventory of what loads on your site and what your disclosures need to say about it
  • Subscription flow review — signup, renewal and cancellation, where applicable
  • Reviews & testimonials review — social proof you can actually substantiate
  • Data-handling checklist — retention, deletion and access posture in plain terms your developer can act on
  • Chatbot addendum — only if your product has a conversational AI feature

Not included

  • Health, financial or children’s-privacy regimes (HIPAA, GLBA, COPPA)
  • European or UK data protection
  • State-by-state coverage beyond California
  • Security engineering or implementation work
  • Representation in any active dispute or filed matter
Before you write in

If you’ve already received a demand letter or been served, this isn’t the right engagement. That work moves on someone else’s deadline and needs a lawyer who handles active disputes — sooner rather than after a consultation with me. I’d rather say so on this page than after you’ve filled in a form.

This page is for the business that hasn’t received one yet, which is the far cheaper place to be standing.

04

Common questions

How much does web and privacy compliance cost?
A flat-fee launch compliance package starts at $1,950 and typically takes five to ten business days. It covers a privacy policy, terms of service, a tracking and consent review, subscription and cancellation flow review, endorsement and review compliance, a data-handling checklist, and an AI chatbot addendum where the product has one.
I built my app with AI coding tools. Does that change anything legally?
Not the rules, but often the exposure. Products assembled quickly tend to ship with analytics and pixels added by default, a generated privacy policy that does not match what the app actually does, and storage left more open than intended. The obligations are the same as for any other business; what differs is how much of the stack nobody has looked at.
Do I need a privacy policy for my Shopify store or dropshipping site?
In practice yes, for almost any store with California customers. California law requires notice of what personal information you collect and who receives it, and a storefront running analytics, ad pixels and a chat widget is sharing more than most operators realise. A policy that does not describe your actual apps and integrations is worse than a short accurate one.
What is a CIPA demand letter?
A letter asserting that analytics tags, advertising pixels, chat widgets, or session-replay tools on your site captured a visitor's activity without consent, under California's Invasion of Privacy Act. They are sent at volume by a small number of firms and are the most common first legal contact for a small web business.
Does the FTC click-to-cancel rule still apply?
The federal rule was vacated by the Eighth Circuit in July 2025 and the FTC reopened rulemaking in March 2026, so no federal click-to-cancel rule is currently in force. California's Automatic Renewal Law still applies in full and was strengthened in July 2025, so subscription businesses selling to Californians are largely unaffected by the federal rule's absence.
Do you respond to demand letters?
No. This is a preventive engagement only. Response to an active demand, and representation in any filed matter or dispute, is outside scope — that work moves on someone else's deadline and needs a lawyer who handles active disputes.
05

Other services

06

Start here

Tell me what you’re running and what’s loading on it. I read every submission personally and reply within one business day — including when the honest answer is that you need less than you think.

Submitting this form does not create an attorney-client relationship, and I can’t treat what you send as confidential until we’ve signed an engagement letter — so keep the sensitive specifics for the call.