Website Privacy · CIPA Trap and Trace · Lawsuit Filed
Temu Tracking Pixel Lawsuit: Suit Says Temu.com Watched Visitors With Trap and Trace Code
PublishedJuly 17, 2026
UpdatedAugust 6, 2026
A California class action says Temu.com did not wait for permission before it started watching. The complaint alleges tracking pixels captured every visitor's device and routing signals the moment the page loaded — before any cookie banner appeared — and asks for $5,000 per violation under California's trap and trace law. The case has since moved to federal court, and there is nothing to claim.
Pottish v. WhaleCo, Inc. alleges pixels on Temu.com operated as trap and trace devices under Penal Code § 638.51, installed without a court order or consent.
This article describes a class action complaint. The statements below are unproven
allegations. Whaleco Inc. (Temu) has not been found liable, had not filed a public response
as of August 6, 2026, there is no certified class, and there is nothing to claim at this
time. Amplitude, Fastly and Meta are described in the complaint but none of them is a
defendant in this case. This page is general information, not legal advice.
Is There a Temu Tracking Settlement Yet?
There is no settlement and no claim form. Pottish v. WhaleCo, Inc. is a proposed class action
against the operator of Temu.com, brought by a California resident. The complaint is dated April 27,
2026 and was filed in Los Angeles County Superior Court; the case was removed to federal court on
May 27, 2026 and is docketed as Case No. 2:26-cv-05657 in the U.S. District Court for the Central
District of California. As of August 6, 2026, no class has been certified and no court has ruled on
the merits.
This page covers the privacy half of the case — the tracking code the complaint says ran on
Temu.com, and the claims under the California Invasion of Privacy Act. The same complaint also
alleges the marketing email that brought the plaintiff to the site violated California's anti-spam
statute, with a false subject line and a spoofed sender domain; that side of the case, and the
complaint PDF itself, are covered in our
Temu spam email lawsuit
breakdown.
StatusComplaint Filed · Removed to Federal CourtPottish v. WhaleCo, Inc., No. 2:26-cv-05657 (C.D. Cal.) · removed May 27, 2026
Core AllegationPixels on Temu.com captured visitors' device and routing signalsClaims under California's trap and trace law (Penal Code § 638.51) and common-law intrusion upon seclusion
Damages Sought$5,000 per violationStatutory damages under Penal Code § 637.2, plus punitive damages and an injunction
Proposed ClassVisitors to Temu.com tracked without consentNo purchase or account required — the definition turns on visiting the site
Can I Claim?No — nothing to claim yetNo settlement, no fund, no claim form; class not certified
What Does Temu.com Allegedly Do to Visitors?
The allegation is about timing as much as technology. The complaint says the tracking code begins
collecting information the moment a visitor lands on the site — before any pop-up or cookie banner
tells them tracking is happening or asks them to agree to it. By the time a consent dialog appears,
on this account, the collection has already occurred.
The complaint names three sources of the code it calls Tracking Pixels: Amplitude, Fastly and
Facebook Domain Insights. It describes them as capturing routing, addressing and signaling
information from each visitor, then requesting and transmitting further identifying information that
links the visitor's behavior on Temu.com to their social media accounts and other devices. None of
those three companies is a defendant, and none of this has been tested by the court.
How Does Browser Fingerprinting Identify Anonymous Visitors?
The mechanism the complaint describes does not depend on a visitor typing anything, and it is worth
understanding because it is the same theory driving a large wave of California filings.
The complaint alleges the code runs algorithms over internet and device data to predict whether two
or more devices belong to the same person, drawing on cookie IDs, operating system identifiers, IP
addresses, online registrations and data from partner publishers to build a probability score. Its
example: an Android phone that visits a site shortly after a desktop computer on the same home
network gets scored as likely the same person, and both devices then see the same advertising. The
complaint calls this fingerprinting and says the point is to attach an identity to otherwise
anonymous visitors by matching them against information already accumulated about hundreds of
millions of Americans.
It frames the result as data-broker surveillance, quoting the Brennan Center for Justice's
description of data brokers as collecting and analyzing personal information to build detailed
profiles that are then sold on. That characterization is the plaintiff's, drawn from a third-party
report, and it is contested territory.
What Is a Trap and Trace Device Under California Law?
The legal hook is a statute written decades before the modern web. California Penal Code § 638.50(c)
defines a trap and trace device as a device or process that captures the incoming electronic or other
impulses identifying the originating number or other dialing, routing, addressing or signaling
information reasonably likely to identify the source of a communication — but not the contents of
that communication. Section 638.51(a) then makes it unlawful to install or use one without first
obtaining a court order.
That definition was aimed at telephone surveillance. The argument in this case, and in dozens like
it, is that website code capturing a visitor's device and network signals does exactly what the
statute describes. Penal Code § 637.2 supplies the private right of action and statutory damages of
$5,000 per violation, which is what gives the theory its force at class scale. Whether the theory
holds is genuinely unsettled — California and federal courts have split on it, some allowing trap and
trace claims over website pixels past the pleading stage and others rejecting the analogy outright.
The complaint adds a third cause of action for common-law intrusion upon seclusion, arguing the
tracking would be highly offensive to a reasonable person. On jurisdiction, it leans on the Ninth
Circuit's en banc decision in Briskin v. Shopify, Inc. (April 21, 2025), which held that a
company purposefully directs its conduct at a forum when it knowingly collects, processes and
monetizes data from users it understands to be located there, even without a physical presence.
The tracking half of the proposed class, as pleaded, covers people who visited a website owned or
operated by the defendant using a web browser or mobile device and whose interactions,
communications or personally identifiable information were intercepted, collected or transmitted to
data brokers through tracking pixels, cookies or similar technologies without their knowledge or
consent. Officers, directors and employees of the defendant, the presiding judge, and class
counsel's firm are excluded.
No purchase and no account are required, and the complaint reserves the right to narrow, expand or
subdivide the definition at class certification. Class definitions routinely change between a
complaint and a certification ruling, so the wording above is a starting position rather than an
eligibility test.
How This Differs From the Other Temu Lawsuits
Temu is no stranger to litigation, but this case is distinct from the ones that came before it:
• The 2023–2025 class actions alleging the Temu app over-collected user data were largely sent
to individual arbitration — a federal judge in New York ruled that app users had agreed to Temu's
terms of service, and dismissed the Ireland-based parent PDD Holdings from the case. We cover that
outcome in our
Temu class action arbitration update
and our
Temu class action explainer.
This case sidesteps that history: its claims run on website visits and email, not app data
collection, and a website visitor has typically never accepted any terms of service.
• Several state attorneys general — including Arkansas, Nebraska, and Texas — have filed their
own suits over Temu's alleged data practices and marketing. Those are government enforcement
actions, not class actions consumers can join.
• In September 2025, Whaleco agreed to a $2 million civil penalty and injunction with the U.S.
Department of Justice over alleged INFORM Consumers Act violations — a separate marketplace
transparency matter.
What Happens Next in the Temu Tracking Pixel Lawsuit?
There is nothing to file at this stage — no settlement and no claim form exist. Because the case is
newly in federal court, the realistic next step is a responsive pleading from WhaleCo, most often a
motion to dismiss that would test whether website pixels can be trap and trace devices at all. That
ruling, whenever it comes, will matter well beyond this case. If you want legal advice, consult a
consumer-protection attorney licensed in your state. OpenClassActions.com is a consumer news site,
not a law firm, and does not provide legal advice or process claims.
Which Temu Lawsuit Is Which?
Temu faces several unrelated legal matters at once, and they are routinely confused with one
another. This page covers exactly one of them — the tracking claim about code on Temu.com. Here is
where each question is answered:
Your question
The case that answers it
Did Temu.com track me with pixels when I visited — fingerprinting, cross-device matching, data brokers?
Pottish v. WhaleCo, trap and trace claim · $5,000 per violation — this page
Was the Temu marketing email itself unlawful — the subject line, header and sender domain?
A proposed class action, Pottish v. WhaleCo, Inc., alleges that tracking pixels installed on Temu.com captured the routing, addressing and signaling information of everyone who visited the site, and did so before any cookie banner asked for consent. The complaint says the code functions as a trap and trace device under California Penal Code section 638.51, which bars installing or using one without a court order. It attributes the pixels to Amplitude, Fastly and Facebook Domain Insights. These are unproven allegations and WhaleCo has not been found liable.
What is a trap and trace device under California law?
California Penal Code section 638.50(c) defines a trap and trace device as a device or process that captures the incoming electronic or other impulses identifying the originating number or other dialing, routing, addressing or signaling information reasonably likely to identify the source of a communication, but not the contents. The definition was written for telephone surveillance. A growing line of California cases argues it also reaches website code that captures a visitor's device and network signals, and section 638.51 makes installing or using such a device without a court order unlawful.
How much does the complaint seek for the tracking claim?
Penal Code section 637.2 provides a private right of action and statutory damages of $5,000 per violation for California Invasion of Privacy Act claims, and the complaint also asks for punitive damages, injunctive relief and attorney's fees. No court has certified a class or awarded anything, and courts remain divided on whether website pixels qualify as trap and trace devices at all.
Who could be covered by the tracking claim?
As pleaded, the second half of the proposed class covers people who visited a website owned or operated by the defendant using a web browser or mobile device and whose interactions, communications or personally identifiable information were intercepted, collected or transmitted to data brokers through tracking pixels, cookies or similar technologies without their knowledge or consent. Buying something is not required — visiting the site is what the definition turns on. The complaint expressly reserves the right to change that definition at class certification.
Is there a Temu settlement or claim form for this case?
No. The case is at the pleading stage and was removed to federal court in May 2026. There is no certified class, no settlement fund, and no claim form, so nothing can be claimed. The same complaint also carries a California anti-spam claim about the marketing email that led the plaintiff to the site, which is covered on a separate page.
Sources
• Class Action Complaint, Pottish v. WhaleCo, Inc., No. 2:26-cv-05657 (C.D. Cal.), filed as Exhibit A to the notice of removal —
Complaint PDF
• California Penal Code § 638.51 (trap and trace devices) —
California Legislative Information
• Briskin v. Shopify, Inc., No. 22-15815 (9th Cir. Apr. 21, 2025) (en banc) —
Ninth Circuit opinion
• Brennan Center for Justice, "Closing the Data Broker Loophole" —
Brennan Center
• Courthouse News Service, "Californians sue over deceptive Temu spam" —
Courthouse News
• U.S. Department of Justice, "Temu Agrees to $2M Civil Penalty and Injunction for Alleged Violations of the INFORM Consumers Act" —
Department of Justice
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
For more class actions keep scrolling below.
Status
Complaint filed — removed to federal court; no settlement, no certified class
Case Title
Pottish v. WhaleCo, Inc. (d/b/a Temu.com)
Case Number
2:26-cv-05657
Court
U.S. District Court, Central District of California
Originally Filed
Los Angeles County Superior Court — complaint dated April 27, 2026
Date Removed
May 27, 2026
Claims
CIPA trap and trace — Penal Code § 638.51 · intrusion upon seclusion
Temu Spam Email Lawsuit: The other half of this same complaint — the anti-spam claim over the marketing email, with the full complaint PDF. Read more →
$800K Concord Hospital Pixel Settlement: A pixel-tracking case that reached a claims process — no ID needed, open through September 11, 2026. Read more →
Toyota Website Tracking Class Action: A suit says Toyota.com kept fingerprint-tracking visitors who rejected cookies. Read more →
Crocs Website Tracking Class Action: A wiretap suit says the Meta Pixel and Google trackers intercepted shoppers' purchases. Read more →
Temu Class Action Arbitration Update: What happened to the earlier Temu app privacy class actions — and why most went to arbitration. Read more →