20 States
Not Just California Anymore
Twenty U.S. states now have comprehensive consumer privacy laws, and the patchwork keeps expanding. Businesses need a clear way to publish privacy rights, opt-out instructions, and consumer request pathways.
Paste one line of code. One widget covers cookie consent, AI disclosure, accessibility, and privacy requests, and the dashboard behind it runs the response clock and records exactly how you answered, and when.
Start by seeing what your site does right now.
Free, no signup. Takes about 30 seconds.
Already know you want it? Start free trial
Worth a look
Meta Pixel and Google Ads loaded before any consent choice was recorded.
Technically: Tracking fired before consent — Fired before consent
Why this matters
A banner that records a choice but doesn't stop the scripts creates a written record that someone declined and the tracking ran anyway. Regulators have specifically pursued businesses whose opt-out mechanisms didn't work the way they were presented.
What to check
Open your site in a private window, decline the banner, and watch whether these same trackers still load.
That panel isn't a mockup — it's running on this page right now. Click the pill in the lower-left corner and you'll get exactly what your visitors get.
One widget covers cookie consent, AI disclosure, accessibility, and privacy requests. The dashboard behind it runs the response clock and records how you answered.

Twenty US states now have comprehensive consumer privacy laws. Regulators are issuing seven- and eight-figure settlements. Demand letters from consumer rights organizations are rising fast. Most websites are dangerously exposed.
Four focused modules, deployed with one embed snippet.

Branded widget handles strictly-necessary, functional, analytics, and advertising cookies. Automatically honors the Global Privacy Control signal — a legal requirement in California and growing states.

Consumers submit access, deletion, correction, and opt-out requests directly through the widget. Each request lands in your dashboard with a 45-day statutory clock running from the moment of receipt.

Tell visitors when and how you use artificial intelligence to interact with them. Required by the FTC's guidance against deceptive AI claims and California's AB 302 (Bolts Act, 2024), with similar bot-disclosure rules in California's B.O.T. Act (SB 1001) and the EU AI Act now in effect.

Publish an accessibility statement referencing WCAG 2.1 Level AA — the standard courts and the DOJ actually use — and give visitors a built-in way to report barriers they hit. You track and respond to each report from your dashboard. No "fully compliant" overlay promises that invite the next ADA lawsuit.

Every consent choice and every request event is written to a tamper-evident log. Export it as a timestamped CSV any time — your own record of what happened, for a regulatory inquiry or litigation hold.
White-label and reseller friendly from day one.

Advise clients on state privacy law and hand them a fully functional compliance tool. Add your branding, hand off the dashboard, bill the management fee.

Add a privacy compliance offering to your web projects. White-label the widget with client branding. Manage dozens of sites from a single agency seat.

The Agency plan supports multi-tenant organizations. Set your own pricing, use your own product name, and give each client their own isolated dashboard.
A cookie pop-up tells visitors about cookies. It does not prove you honored a deletion request within 45 days. It does not give you a timestamped record to hand a regulator. Data Rights OS writes every event to an immutable log the moment it happens — so when someone asks how you handled it, the evidence is already there.
Timestamped audit export
Timestamped CSV of every consent and request event.
45-day deadline tracking
Auto-calculated from request receipt; visible to the whole team.
Organization-level isolation
Each tenant's data is logically separated. No cross-contamination.

SACRAMENTO — Sephora Inc., one of the world's largest cosmetics retailers, has settled a lawsuit claiming that the company sold customer information without proper notice in violation of California's landmark consumer privacy law, state Atty. Gen. Rob Bonta said Wednesday.
Sephora failed to tell customers that it was selling their personal information, failed to allow customers to opt out of that sale, and didn't fix the problem within 30 days as required by the law even after it was notified of the violation, state officials said.
No per-request fees. No surprise overages. Cancel any time.
Try it free for 7 days
Create your account and explore every feature. No credit card required — upgrade any time before your trial ends.
Start free trialCookie consent for one site, free forever. No credit card.
Trials that don’t upgrade roll into the free plan automatically — your widget keeps working.
or $390/year — save $78
Publish your statements, capture and enforce cookie choices, and give visitors a way to report barriers and submit requests.
For a single site that needs to track privacy requests and deadlines.
For firms and agencies running multiple client sites.
Resellers and large agencies with dozens of client organizations.
If your site has no contact form, no analytics, and no customer data, you don't need us — a static brochure site has little to manage. If you want a widget that promises to make you compliant or to fix your accessibility automatically, we're the wrong vendor: no tool can do that, and the ones that say they can have been fined for it. And if you want someone else to take on your legal obligation, that isn't a product any company can sell you.
While building and managing websites for clients across every industry, the team at Bizooma, LLC kept running into the same uncomfortable truth: the overwhelming majority of websites are quietly exposed to litigation. Most have no real mechanism to honor data and privacy laws, no accessible way for visitors to exercise their rights, and no audit trail to prove compliance when it matters.
As privacy regulations, accessibility requirements, and AI disclosure rules spread across US states, that gap became a serious risk for the businesses we serve. So we created DataRightsOS — a single, installable layer that gives any website the consent management, data-rights workflows, and audit logging it needs to stay on the right side of the law.
Get compliance updates, product news, and web tips straight to your inbox.