Skip to main content
Intempt
Legal

Intempt & the CCPA

Last Modified: August 27, 2026

The California Consumer Privacy Act, as amended by the CPRA, gives California residents control over the personal information businesses hold about them. If you use Intempt to collect that information, you are the business and Intempt is your service provider. This page covers what that means and which controls you have.

Our role

Under the CCPA you are the business and Intempt acts as a service provider. We process personal information only to provide the Services to you, under the terms of our Data Processing Addendum.

Intempt does not sell personal information, and does not share it for cross-context behavioral advertising as those terms are defined by the CCPA and CPRA. Your data stays in your project.

Consumer requests

The CCPA gives consumers the right to know what is held about them, to have it deleted, and to correct it. Intempt gives you the tooling to answer all three.

Right to know. Submit an access request and Intempt compiles everything held about that consumer. The CCPA sets a twelve-month lookback as a minimum; Intempt returns the consumer's full history rather than the minimum, because returning more of a person's own data to them is always compliant.

Right to delete. Submit an erasure request and Intempt removes the data held about that consumer across its active systems. Backup copies expire on their own within the backup window, and records Intempt must keep by law are retained.

Requests can be filed from the Privacy Center in the console or over the API, so you can connect them to your own support workflow rather than handling each one by hand.

Opting consumers out

Deleting data does not stop new data arriving. A consumer who asks not to be tracked needs both: an erasure request for what exists, and an opt-out so nothing further is collected.

Every Intempt SDK includes opt-out methods. Calling optOut() stops collection for that user and persists across sessions. On mobile, anything already queued on the device is discarded, so events captured just before the request are never sent.

Tracking is enabled by default once an SDK is initialized. Where you need collection held until a consumer has chosen, initialize with collection paused and enable it once they do.

Limiting what you collect

The cheapest way to reduce your obligations is to collect less. Intempt lets you choose every event and attribute, identify consumers by an internal identifier rather than an email address, mask sensitive text so autocapture does not read it, and control which parts of your data each of your teams can reach.

You choose what location data you send. The Android SDK can be configured not to derive location from a network address at all.

Our consent documentation is a practical review pass for a tracking plan.

Where your data is processed

Intempt's primary hosting infrastructure is located in the United States, and Intempt does not offer regional data residency. Certain processing activities may take place in other countries where our subprocessors operate. Those subprocessors are listed at intempt.com/subprocessors.

Retention

Data is retained for a maximum of two years, after which it is deleted. Some categories are kept for shorter periods depending on the type of data and your plan. After termination, data stays in active systems for thirty days and is then deleted, and backups are kept for fourteen days. The terms are in our Data Processing Addendum and our privacy policy.

Security

All traffic to Intempt uses TLS 1.2 or higher. Access is controlled by organization and project roles, and a multi-factor authentication policy configurable per organization. Single sign-on through SAML and OIDC, and directory provisioning through SCIM, are available on the Enterprise plan. Enterprise organizations have an append-only audit log retained for 730 days. Further detail is available at intempt.trustshare.com.

Questions

Privacy questions and consumer requests directed at Intempt reach us at privacy@intempt.com.