Calendly · Calendly Privacy Notice · View original document ↗

Cookie-Based Data Sale and Sharing Disclosure (CCPA)

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Calendly changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Calendly Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that Calendly's use of cookies and tracking technologies for targeted advertising and analytics may constitute a sale or sharing of Personal Data under the CCPA, and identifies identifiers and internet or similar network activity as the categories sold or shared in the preceding 12 months.

This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows.

Interpretive note: The characterization of cookie-based sharing as a potential sale or share under CCPA reflects ongoing regulatory and legal uncertainty regarding when tracking technology deployments meet the statutory definition; the notice's use of 'may' acknowledges this ambiguity.

Consumer impact (what this means for users)

Under this clause, Calendly discloses that it has shared identifiers and internet activity data with advertising and analytics partners in a manner that may constitute a sale or sharing under California law. California residents can opt out by clicking 'Reject All' in the cookie management module accessible via the website footer, or by using a Global Privacy Control-enabled browser.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Navigate to the footer of the Calendly website and click 'Your Privacy Choices' or 'Cookie Settings'. In the cookie management module, click 'Reject All' to disable all optional cookies including Performance, Functional, and Targeting Cookies. Alternatively, enable Global Privacy Control in your browser.

Cross-platform context

See how other platforms handle Cookie-Based Data Sale and Sharing Disclosure (CCPA) and similar clauses.

Compare across platforms →

Monitoring

Calendly has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may also sell or share information to the extent our use of Cookies and tracking technologies for targeted advertising or analytics purposes constitutes a 'sale' or 'share' under the CCPA. Your opt-out rights are described in the Your Rights and Choices section above. In the preceding 12 months, we have sold or shared the following categories of Personal Data with our targeted advertising and analytics partners: identifiers and internet or other similar network activity.

Excerpt from Calendly's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages the CCPA and CPRA, enforced by the California Privacy Protection Agency and the California Attorney General. The provision's framing that cookie-based sharing 'may' constitute a sale or share reflects ongoing interpretive uncertainty under CCPA regarding when tracking technology deployments meet the statutory definition of a sale, which the California Privacy Protection Agency has addressed in regulatory guidance. 2. GOVERNANCE EXPOSURE: Medium. The disclosure that identifiers and internet activity have been sold or shared with advertising and analytics partners triggers specific CCPA opt-out obligations. The adequacy of the cookie management module as a functional opt-out mechanism, including the operational implementation of GPC signal recognition, is a reviewable compliance question. Failure to honor opt-out requests within the CCPA-specified timeframe could constitute a regulatory violation. 3. JURISDICTION FLAGS: California residents face the primary regulatory exposure. Other states with comprehensive privacy statutes including Colorado, Connecticut, Virginia, Texas, and Oregon may have analogous opt-out requirements for targeted advertising that this notice should be assessed against. The policy's reference to state privacy laws generally suggests awareness of multi-state applicability, but the notice's detailed disclosures are California-specific. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations contracting with Calendly as a business tool should assess whether Calendly's use of advertising cookies on pages where their customer data is present creates any downstream compliance obligations for them as controllers. The sub-processor list referenced in the policy should be reviewed to identify the specific advertising and analytics vendors receiving this data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether the 'Reject All' cookie opt-out mechanism functionally disables all cookies identified as resulting in a sale or share, and whether GPC signals are being honored at all website entry points including booking pages. The 12-month lookback period and the categories of data disclosed should be mapped against actual data flows to confirm accuracy of the disclosure.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • State AG
    The California Attorney General and California Privacy Protection Agency have enforcement authority over CCPA and CPRA opt-out rights, including cookie-based data sales and sharing.
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive practices in data handling and may have jurisdiction over cookie-based tracking disclosures under the FTC Act.
    File a complaint →

Provision details

Document information
Document
Calendly Privacy Notice
Entity
Calendly
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015883
Document ID
CA-D-00563
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9c4f19c5c822aa52a1b2da5bb522c829f8cdb46c74a22604b9e46848c521cc8d
Analysis generated
July 9, 2026 09:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Calendly
Document: Calendly Privacy Notice
Record ID: CA-P-015883
Captured: 2026-07-09 09:03:25 UTC
SHA-256: 9c4f19c5c822aa52…
URL: https://conductatlas.com/platform/calendly/calendly-privacy-notice/provision/CA-P-015883/cookie-based-data-sale-and-sharing-disclosure-ccpa/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Calendly's Cookie-Based Data Sale and Sharing Disclosure (CCPA) clause do?

This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows.

How does this clause affect you?

Under this clause, Calendly discloses that it has shared identifiers and internet activity data with advertising and analytics partners in a manner that may constitute a sale or sharing under California law. California residents can opt out by clicking 'Reject All' in the cookie management module accessible via the website footer, or by using a Global Privacy Control-enabled browser.

Is ConductAtlas affiliated with Calendly?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.