CCPA/CPRA Counsel for San Francisco Startups
California privacy compliance sized for an early-stage company, handled by one senior lawyer who reads your data flows himself.
California privacy law, handled before it becomes a problem
San Francisco startups run into the CCPA sooner than they expect. Sometimes it comes from growth, when revenue or user counts cross a threshold. More often, it comes from a customer, when an enterprise buyer's procurement team sends over a service provider addendum and a privacy questionnaire and won't sign until both come back clean.
Stealth Legal helps founders figure out what the CCPA and CPRA actually require of their company today, fix what needs fixing, and put a simple process in place for what comes next. We serve San Francisco startups remotely from Sacramento and meet in person when it helps.
What CCPA/CPRA work covers
A focused engagement that gives you a clear answer on where you stand and the documents to back it up.
-
We start by working out whether the CCPA applies to you directly, whether you're acting as a service provider for customers who are covered, or both. Many B2B startups fall into the second category without realizing it, and their obligations differ.
-
A privacy policy that matches what your product actually does, plus the notices California requires when you collect personal information. No templates copied from a company twice your size.
-
California residents can ask to know, delete, or correct their data and can opt out of its sale or sharing. We have set up a simple way to receive, verify, and respond to those requests within the legal deadlines.
-
The CCPA requires specific contract terms with the vendors who handle personal information for you and with the customers for whom you handle it. We review what you have, draft what's missing, and give you a standard addendum that your sales team can send.
Usually one of four things has happened. An enterprise prospect sent a service provider addendum or a security questionnaire with a privacy section. A consumer emailed asking what data you hold on them. You're about to raise and investors are asking about compliance. Or you've grown quickly and aren't sure whether you've crossed a CCPA threshold. Any of those is a good reason to get a clear answer now rather than after a deal stalls.
CCPA compliance sized to your stage.
When San Francisco founders call us about the CCPA
How it works
Most founders are offered two options: a free template that doesn't fit their product, or a BigLaw compliance program priced for a public company. We work in between. You get a privacy setup built for your company today, written so it extends cleanly as you add customers, features, and states.
It starts with a free call to understand what your product does with data. From there, we quote a flat fee so you know the cost before any work begins. You work directly with principal counsel the whole way through, not a rotating team.
CCPA/CPRA Startup Package. Includes an applicability assessment, privacy policy and notices, a consumer request workflow, and a service provider addendum. Typically delivered in about one week.
A typical engagement: An eight-person San Francisco SaaS startup lands its first enterprise prospect. The prospect's legal team sends a CCPA service provider addendum and a privacy questionnaire. In week one, we map what data the product collects and which vendors touch it. We then update the privacy policy, sign off on the addendum with the right terms, and answer the privacy section of the questionnaire. The deal moves forward, and the startup now has a standard addendum ready for the next customer.
Stealth Legal is a startup law firm focused on technology transactions and data privacy. We've worked in private practice and in-house, so our advice is built around how a growing company actually operates. Our privacy work spans the CCPA, CPRA, GDPR, and AI data questions, and we write regularly about emerging privacy risks for startups.
About Stealth Legal
Frequently Asked Questions
-
It depends. The CCPA applies to for-profit businesses that do business in California and meet at least one threshold: annual gross revenue above the statutory amount (originally $25 million, now adjusted for inflation), buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or earning half or more of annual revenue from selling or sharing personal information. Many early-stage companies don't meet any of these yet. We check on the first call.
-
Because your customers may be covered even if you aren't. When you process personal information on their behalf, the law requires them to have a contract with you that includes specific terms. That's what the service provider addendum in their procurement packet is for.
-
The CPRA amended and expanded the CCPA. It added rights such as correction and limits on sensitive personal information, and it created the California Privacy Protection Agency to enforce the law. Today, they're usually discussed as one law.
-
We serve San Francisco startups remotely from Sacramento, which keeps things fast and costs down. When an in-person meeting would help, we come to you.
Let’s Work TogetherTell us a little about your product and what's prompting the question. We'll follow up to schedule a free consultation.