Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.
In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow.
The ruling followed a major Ninth Circuit decision reviving the case on personal jurisdiction grounds, with the court finding that Shopify’s alleged use of geolocation technology supported California-specific contacts because Shopify could know when a consumer’s device was in California. See Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc) (personal jurisdiction); see also Briskin v. Shopify, Inc., No. 4:20-cv-06940-PJH (N.D. Cal.) (post-remand order addressing statutory and privacy claims).
According to the complaint, these tools collect user activity and identifying information for advertising, marketing, analytics, and cross-platform tracking purposes. The plaintiff’s main theory is that the NBA’s cookie opt-out banner gives users a false sense of control because trackers allegedly deploy as soon as a user lands on the site before privacy preferences can be selected and because technologies such as session recording, canvas fingerprinting, pixels, and other scripts may continue operating even after a user opts out of cookies.
The complaint brings claims under statutes and legal theories including the California Invasion of Privacy Act, the federal Wiretap Act, California’s Computer Data Access and Fraud Act, the California Constitution’s privacy provision, and California’s Unfair Competition Law.
Together, the cases are a reminder that checkout flows, pixels, cookies, SDKs, hosted content, session replay, analytics tags, and embedded vendor tools should be treated as part of the privacy compliance perimeter, not as invisible background infrastructure.
Businesses should understand what each technology collects, when it fires, where the user is located, whether collection begins before notice or choice, and whether opt-out or consent signals fundamentally change website behavior. They should also review privacy notices, consent-management settings, tag deployment rules, vendor configurations, and historical records together, because plaintiffs are increasingly focused on the gap between user-facing privacy promises and technical reality. In this environment, a cookie banner is not a universal fix; it is only as defensible as the data flows and controls behind it.