← All Privacy 101 articles

ReclaimInbox Investigates · September 8, 2026

Why Some Companies Don’t Get a ‘Delete My Data’ Button

Unsubscribing works on everyone. Sending a real data-rights request doesn’t, and that’s not a bug. Here’s the actual line between the two.

You unsubscribe from a sender, and if they keep emailing you anyway, you have a real, federal, no-exceptions complaint on your hands (see what CAN-SPAM actually requires). So it’s natural to expect the same thing when you go looking for a “right to know”, “right to delete”, or “do not sell” link on some company’s site. Sometimes those buttons just aren’t there, or ReclaimInbox shows them grayed out with no link at all. That’s not a scraping failure or a gap in the app. It’s usually the honest answer: that specific company may not be legally required to give you anything.

Two different laws, doing two different jobs

CAN-SPAM is federal and it covers every commercial emailer in the country, full stop. No revenue threshold, no exemption for small businesses, no “but we’re only a five-person shop” carve-out. If it’s a marketing email and it landed in your inbox, the opt-out requirement already applies.

Right to know, right to delete, and do-not-sell are a completely different thing. There is no federal version of these rights. They exist only because individual states passed their own comprehensive privacy laws, starting with California’s CCPA and now joined by a growing list of others (Virginia, Colorado, Connecticut, Utah, and more). Each one only protects residents of that state, and each one only obligates companies that clear that law’s own bar for who counts as covered.

Two gates, and a company has to clear both

Gate one: does your state have a comprehensive privacy law at all? Roughly half the country still doesn’t, as of this writing. Check yours on the IRM tab of your dashboard, it has a state picker that tells you plainly.

Gate two, and the one people miss: is this specific company big enough to be covered? Even in a state with a real law, the law usually only binds businesses over a size threshold. California’s CCPA, for example, only covers a business if it clears roughly $25 million in annual revenue, OR buys/sells/shares personal data on 100,000+ people or households a year, OR gets half its revenue from selling personal data. A small shop that emailed you once about a sale can clear gate one (you live in a covered state) and still fail gate two completely, meaning it has zero legal obligation to honor a delete request, no matter how politely you ask.

That’s the actual reason a company’s IRM buttons might be grayed out here. Not that we couldn’t find their page. It’s that there may genuinely be nothing to find.

This trips up people who do it for a living

If this feels like a strange, easy-to-miss distinction, you’re in good company. Anyone who has actually worked with a marketing team on compliance has run into exactly this confusion: a well-meaning team assuming “we have a privacy policy, so we must be covered by these laws,” or the opposite, a team quietly skipping real obligations because they assumed a size exemption applied when it didn’t. The two laws get talked about in the same breath so often that the actual boundary between them gets lost, on both sides of the inbox.

The one other real lever: a consent preference center

Even when a company isn’t legally required to give you anything, plenty of them still run a “Cookie Preferences” or “Privacy Preference Center” link in their site footer, usually powered by a third-party tool like OneTrust, TrustArc, or Osano. These exist for reasons that have nothing to do with US state law, most often because the company also serves EU visitors and has to comply with GDPR there, so they built one preference system and left it open to everyone. It won’t delete what they already have on file, but it can let you opt out of tracking and certain data uses going forward, voluntarily, on a company that owes you nothing under US law. Worth a look on their site even when ReclaimInbox shows no verified IRM link.

Unsubscribing is a right. Getting your data deleted is a privilege that depends on where you live and how big they are. They only sound like the same kind of request.