Nobody's actually been fined for missing a deletion deadline. Why pay for this?
True, so far. All 11 fines to date were for registration problems, not missed deletion rounds. But the state has a dedicated enforcement team, the law sets $200 per person per day with no grace period, and the audits that start in 2028 will read the records you're building right now. What you're buying is a file that can't be recreated later, not fine-panic.
My IT person can script the matching. Why would I need you?
The matching script is the easy part, and we'll say so on the call. Ask your IT person about the rest: the same customer spelled three different ways across five systems, the six separate lists the state publishes, the notices you're required to send every vendor, and where the proof lives so it's still findable in six years. We'd rather be their backup than their replacement.
There's software for $49-499/month. Why pay more?
Matching software is fine. We sell it ourselves: that's Match Engine, $500 a month. What no software does: delete anything from your systems, write and send the vendor notices the law requires, handle the judgment calls that need your lawyer, or leave a record of who did what when. The higher plans are the work and the paper trail, not the software.
Is $750 a month a lot for this?
Compare it to the alternatives. A privacy lawyer bills $400-600 an hour, so $750 buys under two hours of advice a month, and most owners burn more than that just reading the rules. The $6,000 you send the state each year buys you nothing but permission to operate. This is the work itself, done and documented.
Who is this for, and who is it not for?
For 3-40 person firms that resell consumer data and have no privacy staff. Not for background-check companies covered by the federal FCRA (this law exempts them), not for enterprises with an in-house privacy team, and not for very small shops. If you're under about $500k in revenue, a cheap self-serve tool is honestly the right answer, and we'll tell you so.
How does our lawyer fit in?
Your lawyer (or a privacy attorney we can introduce, who stays your lawyer, not ours) approves the policy once: whether you're covered, and which records other laws force you to keep, like tax or fraud rules. For everything else the default is simple: when in doubt, delete. One exception can't be pre-approved: if a lawsuit puts records on legal hold, tell us the moment it happens and we pause those records. We carry out the policy exactly as written and send anything new back to them. We never give legal advice.
What happens if you miss a deadline?
We redo the work and credit the fee, and that remedy is spelled out in the contract before you pay anything. We don't cover fines; nobody legitimate does, and anyone who offers to should worry you.
What's your refund policy?
For the service plans, your deposit is fully refundable until your first cycle runs. After that it's month to month, with a 60-day out. Match Engine is billed yearly and comes with a 14-day money-back window instead.
Are you lawyers?
No. OptOutReady does compliance operations, not law. Nothing we produce is legal advice, and legal decisions belong to your lawyer. That split is deliberate. It's also why we cost a fraction of what a law firm bills.
Do you need access to our raw customer data?
By default, no. Matching runs in your browser using one-way codes (hashes), and what we see is match results and the state's request numbers, never names or emails. If you'd rather hand the whole thing off, that's a priced option under a signed data agreement.
If one John Smith opts out, do all my John Smiths get deleted?
No. Matching never uses a name alone. The state's list matches exact identifiers: an email, a phone number, or first name, last name, birthday, and ZIP code all together. Two people collide only if all four line up. On the rare day that happens, the state's own rules say to opt them all out, so you lose one sellable record, not every John Smith on your list.