Saffron Rewards, Inc. v. Rossie
- Donna Ryu
- 4:22-cv-02695
- U.S. District Court · Northern District of California
- 17
In Saffron Rewards v. Rossie, Judge Ryu denied dismissal of four claims but granted dismissal of the computer-access claim, allowing amendment.
Saffron Rewards, Inc.’s contract, fiduciary-duty, implied-covenant, and conversion claims continued, while its Computer Fraud and Abuse Act claim was dismissed at this stage with permission to amend; Alex Rossie remained the defendant.
What happened
Saffron Rewards, Inc. sued Alex Rossie, alleging that after leaving the company he withheld access to company accounts and confidential information, violating an agreement and his duties as a director.
The court allowed Saffron’s contract, fiduciary-duty, implied-covenant, and conversion claims to continue. It granted Rossie’s motion to dismiss the Computer Fraud and Abuse Act claim because Saffron did not adequately allege the kind of computer damage or loss required by that law, but allowed Saffron to amend.
Judge Donna Ryu therefore granted in part and denied in part Rossie’s motion to dismiss and ordered an amended complaint addressing the identified deficiency.
The detailed version
- Saffron Rewards, Inc. v. Rossie · No. 4:22-cv-02695
- Donna Ryu
- July 25, 2022
Background
Saffron Rewards, Inc. alleged that it was co-founded by Alex Rossie and Saumil Nanavati. Saffron and Rossie entered into a Technology Assignment Agreement under which Rossie assigned intellectual-property rights to Saffron and agreed not to use or disclose assigned property or Saffron’s technical or business information.
Rossie created and controlled online accounts that Saffron used for software development, communications, website development, finance, email, storage, banking, and cloud services. Saffron alleged that these accounts contained confidential information and company property. After Rossie stopped providing services, Saffron alleged that he refused requests to return access and administrator rights. Saffron also alleged that Rossie accessed a Google Workspace account without authorization and falsely stated that he had already returned access.
Saffron asserted claims for breach of contract, breach of the fiduciary duty of loyalty, breach of the implied covenant of good faith and fair dealing, violation of the Computer Fraud and Abuse Act, and conversion. Rossie moved to dismiss.
Court’s Analysis
The court applied the standard for a motion to dismiss for failure to state a claim. At this stage, the court generally accepts the complaint’s factual allegations as true and asks whether they plausibly support a legal claim. The court treated factual disputes—such as whether Rossie had authorization to access the accounts—as inappropriate for resolution at this stage.
Breach of contract
The court held that Saffron plausibly alleged a valid agreement, Rossie’s breach, and resulting damage. Saffron alleged that Rossie violated the agreement by withholding company property and access to the company accounts. Although Saffron’s allegations about damages were not especially clear, the court found them sufficient at the pleading stage.
Fiduciary duty
Saffron alleged that Rossie remained a director after ending his work for the company and that he breached his duty of loyalty by withholding account access and acting in bad faith. The court rejected Rossie’s arguments that he had already returned the accounts and that his status as a director authorized his access, because those arguments raised factual disputes. The court held that the fiduciary-duty claim could proceed.
Implied covenant
Saffron alleged that Rossie breached an implied obligation to avoid depriving Saffron of the benefits of the agreement. The court found that the agreement assigned intellectual-property rights but did not expressly address access to the company accounts after Rossie’s separation or prohibit conduct that deprived Saffron of the agreement’s benefits. The court therefore held that Saffron plausibly pleaded this claim.
Computer Fraud and Abuse Act
The court held that Saffron adequately alleged that Rossie intentionally accessed its computer systems without authorization and obtained information. But Saffron did not adequately allege qualifying “damage” or “loss” under the Act. The complaint did not identify technological harm, an interruption of computer-related services, a damage assessment, or data restoration. Requests that Rossie return property and a demand letter from counsel were not enough.
Conversion
The court held that Saffron plausibly alleged ownership or a right to possess the confidential information and account access, Rossie’s wrongful retention of that access, and damages. The court also found that the conversion claim did not merely repeat the agreement’s obligations because the agreement did not expressly govern access to the company accounts.
Disposition
The court denied the motion to dismiss the breach-of-contract claim, denied the motion to dismiss the fiduciary-duty claim, denied the motion to dismiss the implied-covenant claim, granted the motion to dismiss the Computer Fraud and Abuse Act claim with leave to amend, and denied the motion to dismiss the conversion claim. Overall, the court granted in part and denied in part Rossie’s motion to dismiss. Rossie was ordered to file an amended complaint addressing the deficiency by August 8, 2022. Judge Donna Ryu also vacated and continued the initial case-management conference.
Read the full 17-page opinion on CourtListener, the free public archive maintained by the Free Law Project.