Lineberry v. AddShopper, Inc.
- Vince Chhabria
- 3:23-cv-01996
- U.S. District Court · Northern District of California
- 6
In Lineberry v. AddShopper, Inc., Judge Chhabria granted in part and denied in part a motion to dismiss, ending some claims while allowing other privacy claims to continue.
The plaintiffs’ CDAFA claims, Cook’s CIPA claim against Peet’s, and the plaintiffs’ discontinued UCL claims were dismissed without leave to amend. The remaining CIPA claims continue.
What happened
In Lineberry v. AddShopper, Inc., the plaintiffs alleged that AddShopper and others collected and combined their browsing activity with personal information to send targeted emails. The defendants argued that the plaintiffs lacked a sufficiently concrete privacy injury and that some California statutes did not apply to the claims.
The court rejected the defendants’ arguments that the plaintiffs lacked federal standing, reasoning that the alleged long-term collection and aggregation of browsing activity across many retailers could constitute a concrete privacy injury. But it dismissed the California computer-access claims because the complaint did not explain concretely how the alleged misuse reduced the value of the plaintiffs’ data. It also dismissed Cook’s claims against Peet’s under those California statutes because the complaint did not allege that the relevant conduct occurred in California. The court concluded that the specific products viewed online could qualify as the contents of a communication, so the remaining California privacy claims were not dismissed.
Judge Vince Chhabria granted in part and denied in part the motion to dismiss. The plaintiffs’ computer-access claims, Cook’s California privacy claim against Peet’s, and the discontinued unfair-competition claims were dismissed without leave to amend. The remaining California privacy claims were not dismissed.
The detailed version
- Lineberry v. AddShopper, Inc. · No. 3:23-cv-01996
- Vince Chhabria
- Feb. 19, 2025
Background
The plaintiffs alleged that AddShopper’s SafeOpt system intercepted and aggregated their browsing activity across many online retailers and connected that activity with personal information disclosed elsewhere. They alleged that the information was used to send targeted emails to people who had not voluntarily provided their email addresses to a member of the data-sharing network. AddShopper and Peet’s Coffee moved to dismiss the first amended complaint.
Federal Standing
The defendants argued that the plaintiffs had not suffered an injury-in-fact, which is a concrete injury required to sue in federal court. The court rejected that argument. It explained that the alleged aggregation of browsing activity across many retailers and over several years could constitute a concrete privacy injury. The court also held that Cordero did not need to allege that he received a targeted email. Tracking and acquiring his browsing activity could be enough to support a privacy injury.
California Computer-Access Claims
The plaintiffs brought claims under the California Comprehensive Computer Data Access and Fraud Act, or CDAFA. The defendants argued that the plaintiffs lacked statutory standing because they had not alleged the required “damage or loss.” The court held that CDAFA does not limit that phrase to damage to a computer system, network, program, or stored data. In principle, economic loss from the alleged misappropriation of personal data could qualify.
The court nevertheless held that the complaint did not allege that loss concretely. The plaintiffs asserted that their data lost economic value whenever it was used or shared, but they did not allege facts about a market for individual browsing activity, the data’s actual value, whether the data could still be sold after AddShopper obtained it, or how the alleged misappropriation reduced its value. The court therefore dismissed the CDAFA claims for lack of CDAFA statutory standing.
Cook’s Claims Against Peet’s
Peet’s argued that CDAFA and the California Invasion of Privacy Act, or CIPA, did not apply outside California. The court noted that both statutes contain language indicating a focus on protecting privacy within California. A California statute can apply to a non-California resident when the alleged wrongful conduct occurred in California, but the court found no such allegations for Cook.
The complaint alleged that SafeOpt intercepted Cook’s browsing activity from the Peet’s website and sent it to AddShopper, which the opinion says is based in North Carolina. The complaint did not allege that the relevant conduct occurred in California or that Peet’s made relevant business decisions in California. The court therefore dismissed Cook’s CDAFA and CIPA claims against Peet’s.
CIPA Claims
The defendants also argued that the information intercepted was not the “contents” of communications, as required by CIPA. The court declined to dismiss the remaining CIPA claims on that basis. It concluded that browsing activity identifying the specific products viewed, rather than only an internet address or the date of website access, should be treated as communication content. The court compared viewing a specific product online to calling a store to ask about that product.
Disposition
The court granted in part and denied in part the motion to dismiss. It dismissed the plaintiffs’ CDAFA claims and Cook’s CIPA claim against Peet’s. The plaintiffs had stated that they were no longer pursuing their UCL claims, and the court dismissed those claims as well. The dismissals were without leave to amend because of the case schedule and the plaintiffs’ prior opportunity to amend. The remaining CIPA claims were not dismissed. The court also authorized supplemental briefing on class certification.
Read the full 6-page opinion on CourtListener, the free public archive maintained by the Free Law Project.