▼
Allegations Only · No Settlement Yet
This article describes a class action complaint. The statements below are unproven
allegations. WeWork has not been found liable, has not yet responded to the complaint,
there is no certified class, and nothing to claim at this time. LiveRamp is described in
the complaint but is not a defendant in this case. This page is informational and is not
legal advice.
A proposed class action accuses WeWork of letting a data broker identify visitors to its website who never gave it their name, email address, or anything else. The complaint, Price v. WeWork Inc. (Case No. 1:26-cv-06436, U.S. District Court for the Southern District of New York), was filed on July 28, 2026 by a California resident who says she visited wework.com on October 5, 2025.
The allegation is that wework.com ran code supplied by LiveRamp Holdings, Inc., a registered California data broker, which captured signals sent by her browser and device the moment the page loaded. Those signals, the suit says, were used to work out who she was through browser fingerprinting and match her to a permanent identifier the broker keeps for advertising and tracking. The complaint says WeWork never obtained a court order or her consent, which it argues makes the code an unlawful trap and trace device under California law. WeWork has not yet responded, and the allegations are unproven.
Status
Complaint Filed · July 28, 2026
Price v. WeWork Inc. · U.S. District Court, Southern District of New York
Core Allegation
Data-broker code fingerprinted and identified anonymous visitors
Claims under California's trap and trace law (Penal Code § 638.51) and intrusion upon seclusion
Damages Sought
$5,000 per violation
Statutory damages under CIPA, plus punitive damages, restitution, disgorgement, and an injunction
Proposed Class
California visitors to wework.com
All persons who, while located in California, visited the site during the limitations period and were subjected to the code
Can I Claim?
No — nothing to claim yet
No settlement, no fund, no claim form; class not certified
The mechanism at the center of this case is worth understanding, because it does not depend on cookies and does not require the visitor to type anything.
Every browser tells a website a long list of technical details so the page can render correctly. On its own, none of it identifies anyone. The complaint lists the categories it says are captured:
• Device type and configuration, device memory, and CPU class
• Browser type and version, and installed plugins or extensions
• Operating system and version
• Screen resolution and color depth
• System language, time zone, and keyboard layout
• Installed fonts
• Canvas, WebGL, and AudioContext rendering characteristics
• Touch support and input capabilities, and network connection type
Bundled together, the complaint alleges, those details form a combination distinctive enough to single out one person's device. The suit draws a line it says matters: a website operator legitimately needs some of this to display a page correctly on a visitor's screen. What it challenges is that data being handed to a third party that plays no role in operating the site or rendering it, and that wants it only to identify, profile, and track the visitor.
The complaint cites 2025 research from Texas A&M and Johns Hopkins that it says provided evidence of websites using browser fingerprints for online tracking tied to advertising behavior, along with a 2025 Wired article explaining how the individual data points combine into a unique fingerprint.
LiveRamp is named throughout the complaint but is not a defendant in this case. The allegations about it are the plaintiff's description of how she says the code works, and LiveRamp has not answered them here.
According to the complaint, the code runs in three steps. When it loads on a page, it captures the identifiers available in that moment, including any first-party cookie ID the page passes along with standard request information such as IP address and user-agent. It sends that to LiveRamp's servers, where the suit alleges it is combined with other data the broker already holds about the individual from online and offline sources, potentially including name, postal address, email address, cookie IDs, and mobile device IDs. The visitor is then matched to a pre-existing identifier the complaint calls a RampID.
The suit describes that identifier as permanent and designed to follow a person across thousands of websites, alleging it does not reset when someone clears cookies or switches devices, and that it is shared with ad-tech partners who pay for access. It also alleges the matching happens in real time, so a site can identify a visitor at the moment an ad impression is served. The complaint quotes LiveRamp's own marketing language describing impressions matched to a persistent people-based ID and data stitched across devices.
The complaint alleges WeWork installed this code on its site and allowed the broker to access, use, and monetize the resulting visitor data in ways not disclosed to the public. Its theory of WeWork's motive is commercial: knowing who an anonymous visitor is lets a company that rents desks and offices target that person with specific marketing.
The first count uses a provision most people associate with law enforcement surveillance. California Penal Code section 638.51 says a person may not install or use a trap and trace device without first obtaining a court order. Section 638.50(c) defines such a device as one that captures the incoming electronic impulses identifying the source of a wire or electronic communication, but not the contents of that communication.
The complaint's argument is that a visit to a website is an electronic communication, that the visitor and her device are its source, and that code capturing the incoming signals in order to identify that source fits the statutory definition. It cites a long line of California state and federal decisions from 2024 through 2026 that it says have allowed this theory to proceed against website operators. The California Invasion of Privacy Act allows a private lawsuit with statutory damages of $5,000 per violation, which is what makes these cases financially significant even without proof of out-of-pocket loss.
The complaint also heads off a defense in advance. Section 638.51(b)(5) contains a consent exemption, but the suit argues that exemption is available only to a provider of electronic or wire communication service, and that WeWork is not one. Courts have not uniformly accepted the trap-and-trace theory, and defendants in these cases routinely argue that ordinary web analytics are not a surveillance device and that visitors consented. WeWork has not yet filed a response.
For background on the statute and the technology, see our glossary entries on pen registers and trap and trace devices and the California Invasion of Privacy Act.
The second count is a common-law privacy claim. Under California law, a defendant can be liable for intruding into a private place, conversation, or matter in a way that would be highly offensive to a reasonable person.
The complaint frames the plaintiff's visit to wework.com as that private matter, alleges the intrusion was intentional because deploying the code required configuring the site, and says it was done for WeWork's economic benefit. It asks for compensatory damages plus punitive damages, arguing the conduct was malicious, oppressive, and willful, and for an injunction stopping the practice along with disgorgement of profits. Whether a routine website visit qualifies as a private matter is one of the contested questions these cases turn on.
A recurring problem in website-tracking cases is explaining what a visitor actually lost. This complaint answers that in a few ways.
It argues the data has market value, pointing to the existence of the industry built to collect it and citing an estimate that the global data brokerage industry was worth roughly $270 billion in 2024. The theory is that a visitor who is tracked without knowing it loses the ability to decide whether to withhold, limit, or trade her own data on informed terms.
It also argues the consequences run past advertising. The complaint cites a 2025 Federal Trade Commission finding that some websites use consumer characteristics and behavior, including location, demographics, browsing patterns, and shopping history, to tailor individual pricing. It raises the possibility of broker data reaching government agencies, citing reporting on federal immigration and homeland security agencies obtaining commercially available data and user records. And it quotes the California Attorney General's 2022 enforcement complaint against Sephora, which made the point that browsing data can support inferences about sensitive matters such as health conditions. These are the plaintiff's arguments about why the tracking matters, not findings about WeWork.
The complaint proposes a single class:
All persons who, while located in California, visited wework.com during the applicable limitations period and were subjected to the operation of the data broker code running on the site.
The plaintiff says she does not know the exact number but believes it runs into the thousands. Note the geography: the case was filed in New York because that is where WeWork is headquartered, but the class is limited to people who were physically in California when they visited, because the statute at issue is a California one. No class has been certified, so the definition could change as the case proceeds — or the case could be dismissed.
No. This is a lawsuit at the complaint stage, not a settlement.
That means:
• There is no settlement fund.
• There is no claim form.
• There is no payout and no deadline to act.
• wework.com visitors do not need to sign up or register for anything.
The $5,000-per-violation figure is what the complaint asks for, not what anyone is owed. For money to reach anyone, the case would have to survive WeWork's expected motion to dismiss, win class certification, and then settle or prevail at trial. That takes years and often does not happen. Be cautious of any site claiming you can file a WeWork claim today.
The trap-and-trace theory has produced a steady run of filings against website operators across unrelated industries, which is the point — the claim is about the code on the page, not the business behind it. We have covered versions of it against Crocs, Toyota, JetBlue, and Dolce & Gabbana.
Two are especially close to this one. The Fender website-tracking class action also names LiveRamp among the recipients of visitor data, though its theory is different — that tracking continued after users rejected cookies. And the Apple Safari fingerprinting class action turns on the same identification technique rather than on cookies.
These cases do sometimes reach a payout. The AutoZone website-tracking privacy settlement resolved similar claims and paid class members, though its claim window has since closed.
The near-term steps are procedural. WeWork will respond to the complaint, most likely by moving to dismiss and arguing that ordinary web analytics are not a trap and trace device, that visitors consented, and that a website visit is not the kind of private matter intrusion upon seclusion protects. Judges have split on those questions, which is why the complaint devotes a long footnote-style string of citations to decisions that went the plaintiffs' way. If the case clears that stage it moves into discovery, where the plaintiff would seek to identify the DOE defendants the complaint reserves space for, and then to a class certification motion.
OpenClassActions.com will watch the docket and update this page on a ruling, certification decision, or settlement with a claim form.
Is there a WeWork settlement or claim form?
No. This is a newly filed class action complaint, not a settlement. There is no settlement fund, no claim form, and no payout. WeWork has not been found liable, no class has been certified, and there is nothing to claim at this time.
What does the WeWork lawsuit allege?
That wework.com ran code supplied by the data broker LiveRamp that captured signals from visitors' devices and browsers, used those signals to identify otherwise anonymous visitors through browser fingerprinting, and matched them to a persistent identifier for advertising and tracking. It brings two claims: violation of California's trap and trace law, Penal Code section 638.51, and intrusion upon seclusion. These are unproven allegations.
What is browser fingerprinting?
It is a technique that combines many individually unremarkable details about a device and browser — screen resolution, installed fonts, time zone, operating system version, rendering behavior — into a combination distinctive enough to single out one device. It can work without cookies and without the visitor typing in a name or email address.
Who could be covered by the proposed class?
All persons who, while located in California, visited wework.com during the applicable limitations period and were subjected to the data broker code running on the site. The case was filed in New York because WeWork is headquartered there, but the class is limited to California visitors because the statute at issue is a California one. No class has been certified, so the definition is not final.
Does the $5,000 figure mean I would get $5,000?
No. The $5,000 per violation figure is the statutory damages amount the California Invasion of Privacy Act allows and that the complaint asks for. It is a request, not an entitlement, and it is not what an individual class member would receive. Cases like this typically resolve — if they resolve at all — for a fraction of the theoretical statutory maximum, divided among everyone who files a claim.
What should I do if I visited wework.com?
There is nothing to do and nothing to claim right now. Visitors do not need to sign up or register to be part of a proposed class. If a class is ever certified and a settlement or judgment results, a formal process with its own eligibility rules and deadlines would be announced. This page is informational and is not legal advice.
• Price v. WeWork Inc. — Class Action Complaint, No. 1:26-cv-06436 (S.D.N.Y., filed July 28, 2026).
• CourtListener — WeWork federal docket search
• California Penal Code §§ 637.2, 638.50 and 638.51 (California Invasion of Privacy Act — trap and trace provisions).
• California Attorney General — People v. Sephora USA, Inc. enforcement action
• Federal Trade Commission — surveillance pricing study (January 2025)
• Texas A&M University — research on browser fingerprinting used for online tracking
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
For more class actions keep scrolling below.
Status
Complaint Filed — Allegations Only
Case Title
Price v. WeWork Inc.
Case Number
1:26-cv-06436
Court
U.S. District Court, Southern District of New York
Date Filed
July 28, 2026
Defendants
WeWork Inc.; Does 1 through 10
Claims
California trap and trace law (Cal. Penal Code § 638.51); intrusion upon seclusion