Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Embedded Tech, Real Privacy Risk: Courts Scrutinize Shopify Checkout Tools and NBA Tracking Practices

By Kathryn Rattigan on August 6, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow.

The ruling followed a major Ninth Circuit decision reviving the case on personal jurisdiction grounds, with the court finding that Shopify’s alleged use of geolocation technology supported California-specific contacts because Shopify could know when a consumer’s device was in California. See Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc) (personal jurisdiction); see also Briskin v. Shopify, Inc., No. 4:20-cv-06940-PJH (N.D. Cal.) (post-remand order addressing statutory and privacy claims).

The NBA case raises a related but distinct issue about whether privacy banners and cookie opt-outs actually stop the tracking they appear to control. Yee v. NBA Props., Inc., No. 4:26-cv-07919 (N.D. Cal. removed July 29, 2026). The proposed class action alleges that visitors to nba.com are tracked by tools from Google, Amplitude, and others when they browse schedules, tickets, player information, game highlights, and related content.

According to the complaint, these tools collect user activity and identifying information for advertising, marketing, analytics, and cross-platform tracking purposes. The plaintiff’s main theory is that the NBA’s cookie opt-out banner gives users a false sense of control because trackers allegedly deploy as soon as a user lands on the site before privacy preferences can be selected and because technologies such as session recording, canvas fingerprinting, pixels, and other scripts may continue operating even after a user opts out of cookies.

The complaint brings claims under statutes and legal theories including the California Invasion of Privacy Act, the federal Wiretap Act, California’s Computer Data Access and Fraud Act, the California Constitution’s privacy provision, and California’s Unfair Competition Law.

Together, the cases are a reminder that checkout flows, pixels, cookies, SDKs, hosted content, session replay, analytics tags, and embedded vendor tools should be treated as part of the privacy compliance perimeter, not as invisible background infrastructure.

Businesses should understand what each technology collects, when it fires, where the user is located, whether collection begins before notice or choice, and whether opt-out or consent signals fundamentally change website behavior. They should also review privacy notices, consent-management settings, tag deployment rules, vendor configurations, and historical records together, because plaintiffs are increasingly focused on the gap between user-facing privacy promises and technical reality. In this environment, a cookie banner is not a universal fix; it is only as defensible as the data flows and controls behind it.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Kathryn RattiganEmail
Show more Show less
  • Posted in:
    Class Action & Mass Torts, Privacy and Cybersecurity, Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo