---
title: "CCPA and CPRA Analytics Review for HitKeep | HitKeep"
description: "Review how HitKeep supports a lower-risk CCPA/CPRA analytics posture, including notices, request handling, and service-provider positioning."
canonical: "https://hitkeep.com/compliance/ccpa-cpra/"
---

# CCPA and CPRA Analytics Review for HitKeep

HitKeep can support a lower-risk **CCPA / CPRA** posture, but it does not replace your own privacy program.

## Where HitKeep Helps

HitKeep does **not** natively behave like an ad-tech sharing platform:

- no built-in cross-context behavioral advertising stack
- no vendor-side analytics data resale model
- no default third-party analytics distribution
- self-hosting can keep analytics inside your own environment

It also gives you building blocks for consumer-right workflows:

- [takeout exports](https://hitkeep.com/guides/data/takeout/)
- [retention controls](https://hitkeep.com/guides/data/retention/)
- admin deletion of users and sites
- clearly bounded analytics data stores

## What CCPA / CPRA Still Requires From You

CCPA / CPRA obligations still sit with the business operating the site or service.

HitKeep does not automatically satisfy:

- your **notice at collection**
- your **privacy policy**
- your **methods for rights requests**
- your **consumer identity verification workflow**
- your **opt-out of sale/share** obligations, if applicable
- your **Global Privacy Control** handling, where applicable

## Analytics Review Checklist

Use this checklist with counsel or your privacy owner:

| Question | What to inspect in HitKeep |
| --- | --- |
| Is analytics data sold or shared for cross-context advertising? | HitKeep does not include an ad-tech resale or cross-context advertising workflow by default. Your own integrations still matter. |
| Where does analytics data live? | Self-hosted data stays in your HitKeep data directory. Cloud workspace analytics data and backups live in the selected managed region. |
| Can a consumer request export be handled? | Use takeout exports for supported JSON, CSV, Parquet, NDJSON, and XLSX surfaces. |
| Can old data expire? | Configure retention rules and document backup retention separately. |
| Are service-provider terms needed? | Yes for HitKeep Cloud or any managed infrastructure relationship you rely on. |

HitKeep can reduce the number of analytics vendors in the review. It does not decide whether your broader site, ad stack, CRM, or tag manager triggers sale/share or targeted advertising obligations.

## Service Provider / Processor Positioning

If you self-host HitKeep yourself, there is no HitKeep-hosted analytics vendor in the loop by default.

If you use **HitKeep Cloud**, you should treat the cloud relationship as one that needs the right contractual and privacy documentation before relying on it for regulated production use. In practice that means:

- a DPA / service-provider-style contract
- documented region choice
- documented subprocessors, if any

## Conservative Recommendation

Use HitKeep as one part of your CCPA / CPRA program, not as the whole program.

At minimum:

1. update your privacy notice
2. make sure rights requests have a real intake path
3. decide whether your analytics flow implicates sale/share analysis
4. document your cloud/self-hosted service-provider relationship clearly

## Related

- [Compliance Overview](https://hitkeep.com/compliance/overview/)
- [Privacy Policy](https://hitkeep.com/legal/privacy-policy/)
- [Data Retention and Archiving](https://hitkeep.com/guides/data/retention/)
- [Open Exports and Takeout](https://hitkeep.com/guides/data/takeout/)
- [Privacy-First Web Analytics](https://hitkeep.com/use-cases/privacy-first-web-analytics/)

## Sources

- [CPPA: FAQs](https://cppa.ca.gov/faq)
- [CPPA regulations PDF](https://cppa.ca.gov/regulations/pdf/20230329_final_regs_text.pdf)

[Previous PECR and ePrivacy](https://hitkeep.com/compliance/pecr-eprivacy/)[Next Digital sovereignty](https://hitkeep.com/compliance/sovereignty/)
