Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow.

The ruling followed a major Ninth Circuit decision reviving the case on personal jurisdiction grounds, with the court finding that Shopify’s alleged use of geolocation technology supported California-specific contacts because Shopify could know when a consumer’s device was in California. See Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc) (personal jurisdiction); see also Briskin v. Shopify, Inc., No. 4:20-cv-06940-PJH (N.D. Cal.) (post-remand order addressing statutory and privacy claims).

According to the complaint, these tools collect user activity and identifying information for advertising, marketing, analytics, and cross-platform tracking purposes. The plaintiff’s main theory is that the NBA’s cookie opt-out banner gives users a false sense of control because trackers allegedly deploy as soon as a user lands on the site before privacy preferences can be selected and because technologies such as session recording, canvas fingerprinting, pixels, and other scripts may continue operating even after a user opts out of cookies.

The complaint brings claims under statutes and legal theories including the California Invasion of Privacy Act, the federal Wiretap Act, California’s Computer Data Access and Fraud Act, the California Constitution’s privacy provision, and California’s Unfair Competition Law.

Together, the cases are a reminder that checkout flows, pixels, cookies, SDKs, hosted content, session replay, analytics tags, and embedded vendor tools should be treated as part of the privacy compliance perimeter, not as invisible background infrastructure.

Businesses should understand what each technology collects, when it fires, where the user is located, whether collection begins before notice or choice, and whether opt-out or consent signals fundamentally change website behavior. They should also review privacy notices, consent-management settings, tag deployment rules, vendor configurations, and historical records together, because plaintiffs are increasingly focused on the gap between user-facing privacy promises and technical reality. In this environment, a cookie banner is not a universal fix; it is only as defensible as the data flows and controls behind it.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.