Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Calendly's use of cookies and tracking technologies for targeted advertising and analytics may constitute a sale or sharing of Personal Data under the CCPA, and identifies identifiers and internet or similar network activity as the categories sold or shared in the preceding 12 months.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows.
Interpretive note: The characterization of cookie-based sharing as a potential sale or share under CCPA reflects ongoing regulatory and legal uncertainty regarding when tracking technology deployments meet the statutory definition; the notice's use of 'may' acknowledges this ambiguity.
Under this clause, Calendly discloses that it has shared identifiers and internet activity data with advertising and analytics partners in a manner that may constitute a sale or sharing under California law. California residents can opt out by clicking 'Reject All' in the cookie management module accessible via the website footer, or by using a Global Privacy Control-enabled browser.
Cross-platform context
See how other platforms handle Cookie-Based Data Sale and Sharing Disclosure (CCPA) and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may also sell or share information to the extent our use of Cookies and tracking technologies for targeted advertising or analytics purposes constitutes a 'sale' or 'share' under the CCPA. Your opt-out rights are described in the Your Rights and Choices section above. In the preceding 12 months, we have sold or shared the following categories of Personal Data with our targeted advertising and analytics partners: identifiers and internet or other similar network activity.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: This provision directly engages the CCPA and CPRA, enforced by the California Privacy Protection Agency and the California Attorney General. The provision's framing that cookie-based sharing 'may' constitute a sale or share reflects ongoing interpretive uncertainty under CCPA regarding when tracking technology deployments meet the statutory definition of a sale, which the California Privacy Protection Agency has addressed in regulatory guidance. 2. GOVERNANCE EXPOSURE: Medium. The disclosure that identifiers and internet activity have been sold or shared with advertising and analytics partners triggers specific CCPA opt-out obligations. The adequacy of the cookie management module as a functional opt-out mechanism, including the operational implementation of GPC signal recognition, is a reviewable compliance question. Failure to honor opt-out requests within the CCPA-specified timeframe could constitute a regulatory violation. 3. JURISDICTION FLAGS: California residents face the primary regulatory exposure. Other states with comprehensive privacy statutes including Colorado, Connecticut, Virginia, Texas, and Oregon may have analogous opt-out requirements for targeted advertising that this notice should be assessed against. The policy's reference to state privacy laws generally suggests awareness of multi-state applicability, but the notice's detailed disclosures are California-specific. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations contracting with Calendly as a business tool should assess whether Calendly's use of advertising cookies on pages where their customer data is present creates any downstream compliance obligations for them as controllers. The sub-processor list referenced in the policy should be reviewed to identify the specific advertising and analytics vendors receiving this data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether the 'Reject All' cookie opt-out mechanism functionally disables all cookies identified as resulting in a sale or share, and whether GPC signals are being honored at all website entry points including booking pages. The 12-month lookback period and the categories of data disclosed should be mapped against actual data flows to confirm accuracy of the disclosure.
This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows.
Under this clause, Calendly discloses that it has shared identifiers and internet activity data with advertising and analytics partners in a manner that may constitute a sale or sharing under California law. California residents can opt out by clicking 'Reject All' in the cookie management module accessible via the website footer, or by using a Global Privacy Control-enabled browser.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.