Temu Tracking Pixel Lawsuit: Trap and Trace Claim
Website Privacy · CIPA Trap and Trace · Lawsuit Filed

Temu Tracking Pixel Lawsuit: Suit Says Temu.com Watched Visitors With Trap and Trace Code

Published July 17, 2026
Updated August 6, 2026

A California class action says Temu.com did not wait for permission before it started watching. The complaint alleges tracking pixels captured every visitor's device and routing signals the moment the page loaded — before any cookie banner appeared — and asks for $5,000 per violation under California's trap and trace law. The case has since moved to federal court, and there is nothing to claim.

Temu tracking pixel class action lawsuit over trap and trace surveillance of Temu.com visitors under the California Invasion of Privacy Act
Pottish v. WhaleCo, Inc. alleges pixels on Temu.com operated as trap and trace devices under Penal Code § 638.51, installed without a court order or consent.
Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Whaleco Inc. (Temu) has not been found liable, had not filed a public response as of August 6, 2026, there is no certified class, and there is nothing to claim at this time. Amplitude, Fastly and Meta are described in the complaint but none of them is a defendant in this case. This page is general information, not legal advice.

Is There a Temu Tracking Settlement Yet?

There is no settlement and no claim form. Pottish v. WhaleCo, Inc. is a proposed class action against the operator of Temu.com, brought by a California resident. The complaint is dated April 27, 2026 and was filed in Los Angeles County Superior Court; the case was removed to federal court on May 27, 2026 and is docketed as Case No. 2:26-cv-05657 in the U.S. District Court for the Central District of California. As of August 6, 2026, no class has been certified and no court has ruled on the merits.

This page covers the privacy half of the case — the tracking code the complaint says ran on Temu.com, and the claims under the California Invasion of Privacy Act. The same complaint also alleges the marketing email that brought the plaintiff to the site violated California's anti-spam statute, with a false subject line and a spoofed sender domain; that side of the case, and the complaint PDF itself, are covered in our Temu spam email lawsuit breakdown.

Status Complaint Filed · Removed to Federal Court Pottish v. WhaleCo, Inc., No. 2:26-cv-05657 (C.D. Cal.) · removed May 27, 2026
Core Allegation Pixels on Temu.com captured visitors' device and routing signals Claims under California's trap and trace law (Penal Code § 638.51) and common-law intrusion upon seclusion
Damages Sought $5,000 per violation Statutory damages under Penal Code § 637.2, plus punitive damages and an injunction
Proposed Class Visitors to Temu.com tracked without consent No purchase or account required — the definition turns on visiting the site
Can I Claim? No — nothing to claim yet No settlement, no fund, no claim form; class not certified

What Does Temu.com Allegedly Do to Visitors?

The allegation is about timing as much as technology. The complaint says the tracking code begins collecting information the moment a visitor lands on the site — before any pop-up or cookie banner tells them tracking is happening or asks them to agree to it. By the time a consent dialog appears, on this account, the collection has already occurred.

The complaint names three sources of the code it calls Tracking Pixels: Amplitude, Fastly and Facebook Domain Insights. It describes them as capturing routing, addressing and signaling information from each visitor, then requesting and transmitting further identifying information that links the visitor's behavior on Temu.com to their social media accounts and other devices. None of those three companies is a defendant, and none of this has been tested by the court.

How Does Browser Fingerprinting Identify Anonymous Visitors?

The mechanism the complaint describes does not depend on a visitor typing anything, and it is worth understanding because it is the same theory driving a large wave of California filings.

The complaint alleges the code runs algorithms over internet and device data to predict whether two or more devices belong to the same person, drawing on cookie IDs, operating system identifiers, IP addresses, online registrations and data from partner publishers to build a probability score. Its example: an Android phone that visits a site shortly after a desktop computer on the same home network gets scored as likely the same person, and both devices then see the same advertising. The complaint calls this fingerprinting and says the point is to attach an identity to otherwise anonymous visitors by matching them against information already accumulated about hundreds of millions of Americans.

It frames the result as data-broker surveillance, quoting the Brennan Center for Justice's description of data brokers as collecting and analyzing personal information to build detailed profiles that are then sold on. That characterization is the plaintiff's, drawn from a third-party report, and it is contested territory.

What Is a Trap and Trace Device Under California Law?

The legal hook is a statute written decades before the modern web. California Penal Code § 638.50(c) defines a trap and trace device as a device or process that captures the incoming electronic or other impulses identifying the originating number or other dialing, routing, addressing or signaling information reasonably likely to identify the source of a communication — but not the contents of that communication. Section 638.51(a) then makes it unlawful to install or use one without first obtaining a court order.

That definition was aimed at telephone surveillance. The argument in this case, and in dozens like it, is that website code capturing a visitor's device and network signals does exactly what the statute describes. Penal Code § 637.2 supplies the private right of action and statutory damages of $5,000 per violation, which is what gives the theory its force at class scale. Whether the theory holds is genuinely unsettled — California and federal courts have split on it, some allowing trap and trace claims over website pixels past the pleading stage and others rejecting the analogy outright.

The complaint adds a third cause of action for common-law intrusion upon seclusion, arguing the tracking would be highly offensive to a reasonable person. On jurisdiction, it leans on the Ninth Circuit's en banc decision in Briskin v. Shopify, Inc. (April 21, 2025), which held that a company purposefully directs its conduct at a forum when it knowingly collects, processes and monetizes data from users it understands to be located there, even without a physical presence.

OCA covers a number of cases running on this same statute, including the WeWork website tracking lawsuit and the Toyota website tracking lawsuit.

Who Is in the Proposed Temu Tracking Class?

The tracking half of the proposed class, as pleaded, covers people who visited a website owned or operated by the defendant using a web browser or mobile device and whose interactions, communications or personally identifiable information were intercepted, collected or transmitted to data brokers through tracking pixels, cookies or similar technologies without their knowledge or consent. Officers, directors and employees of the defendant, the presiding judge, and class counsel's firm are excluded.

No purchase and no account are required, and the complaint reserves the right to narrow, expand or subdivide the definition at class certification. Class definitions routinely change between a complaint and a certification ruling, so the wording above is a starting position rather than an eligibility test.

How This Differs From the Other Temu Lawsuits

Temu is no stranger to litigation, but this case is distinct from the ones that came before it:

• The 2023–2025 class actions alleging the Temu app over-collected user data were largely sent to individual arbitration — a federal judge in New York ruled that app users had agreed to Temu's terms of service, and dismissed the Ireland-based parent PDD Holdings from the case. We cover that outcome in our Temu class action arbitration update and our Temu class action explainer. This case sidesteps that history: its claims run on website visits and email, not app data collection, and a website visitor has typically never accepted any terms of service.
• Several state attorneys general — including Arkansas, Nebraska, and Texas — have filed their own suits over Temu's alleged data practices and marketing. Those are government enforcement actions, not class actions consumers can join.
• In September 2025, Whaleco agreed to a $2 million civil penalty and injunction with the U.S. Department of Justice over alleged INFORM Consumers Act violations — a separate marketplace transparency matter.

What Happens Next in the Temu Tracking Pixel Lawsuit?

There is nothing to file at this stage — no settlement and no claim form exist. Because the case is newly in federal court, the realistic next step is a responsive pleading from WhaleCo, most often a motion to dismiss that would test whether website pixels can be trap and trace devices at all. That ruling, whenever it comes, will matter well beyond this case. If you want legal advice, consult a consumer-protection attorney licensed in your state. OpenClassActions.com is a consumer news site, not a law firm, and does not provide legal advice or process claims.

Which Temu Lawsuit Is Which?

Temu faces several unrelated legal matters at once, and they are routinely confused with one another. This page covers exactly one of them — the tracking claim about code on Temu.com. Here is where each question is answered:
Your question The case that answers it
Did Temu.com track me with pixels when I visited — fingerprinting, cross-device matching, data brokers? Pottish v. WhaleCo, trap and trace claim · $5,000 per violation — this page
Was the Temu marketing email itself unlawful — the subject line, header and sender domain? The same complaint's anti-spam claim · $1,000 per email — Temu spam email lawsuit
What happened to the older lawsuits about the Temu app collecting user data? Sent largely to individual arbitration — Temu arbitration update
Is there any Temu settlement or claim form I can file right now? No — see the full history of Temu litigation and enforcement actions in the Temu class action explainer

Temu Tracking Pixel Lawsuit FAQ

What is the Temu tracking pixel lawsuit about?

A proposed class action, Pottish v. WhaleCo, Inc., alleges that tracking pixels installed on Temu.com captured the routing, addressing and signaling information of everyone who visited the site, and did so before any cookie banner asked for consent. The complaint says the code functions as a trap and trace device under California Penal Code section 638.51, which bars installing or using one without a court order. It attributes the pixels to Amplitude, Fastly and Facebook Domain Insights. These are unproven allegations and WhaleCo has not been found liable.

What is a trap and trace device under California law?

California Penal Code section 638.50(c) defines a trap and trace device as a device or process that captures the incoming electronic or other impulses identifying the originating number or other dialing, routing, addressing or signaling information reasonably likely to identify the source of a communication, but not the contents. The definition was written for telephone surveillance. A growing line of California cases argues it also reaches website code that captures a visitor's device and network signals, and section 638.51 makes installing or using such a device without a court order unlawful.

How much does the complaint seek for the tracking claim?

Penal Code section 637.2 provides a private right of action and statutory damages of $5,000 per violation for California Invasion of Privacy Act claims, and the complaint also asks for punitive damages, injunctive relief and attorney's fees. No court has certified a class or awarded anything, and courts remain divided on whether website pixels qualify as trap and trace devices at all.

Who could be covered by the tracking claim?

As pleaded, the second half of the proposed class covers people who visited a website owned or operated by the defendant using a web browser or mobile device and whose interactions, communications or personally identifiable information were intercepted, collected or transmitted to data brokers through tracking pixels, cookies or similar technologies without their knowledge or consent. Buying something is not required — visiting the site is what the definition turns on. The complaint expressly reserves the right to change that definition at class certification.

Is there a Temu settlement or claim form for this case?

No. The case is at the pleading stage and was removed to federal court in May 2026. There is no certified class, no settlement fund, and no claim form, so nothing can be claimed. The same complaint also carries a California anti-spam claim about the marketing email that led the plaintiff to the site, which is covered on a separate page.

Sources

• Class Action Complaint, Pottish v. WhaleCo, Inc., No. 2:26-cv-05657 (C.D. Cal.), filed as Exhibit A to the notice of removal — Complaint PDF
• California Penal Code § 638.51 (trap and trace devices) — California Legislative Information
Briskin v. Shopify, Inc., No. 22-15815 (9th Cir. Apr. 21, 2025) (en banc) — Ninth Circuit opinion
• Brennan Center for Justice, "Closing the Data Broker Loophole" — Brennan Center
• Courthouse News Service, "Californians sue over deceptive Temu spam" — Courthouse News
• U.S. Department of Justice, "Temu Agrees to $2M Civil Penalty and Injunction for Alleged Violations of the INFORM Consumers Act" — Department of Justice



For more class actions keep scrolling below.
Status Complaint filed — removed to federal court; no settlement, no certified class
Case Title Pottish v. WhaleCo, Inc. (d/b/a Temu.com)
Case Number 2:26-cv-05657
Court U.S. District Court, Central District of California
Originally Filed Los Angeles County Superior Court — complaint dated April 27, 2026
Date Removed May 27, 2026
Claims CIPA trap and trace — Penal Code § 638.51 · intrusion upon seclusion
Damages Sought $5,000 per violation (Penal Code § 637.2) · punitive damages · injunction

Related Website Tracking Cases & Settlements