Insight

Vivek Shah CIPA Claims: The Tracking Gaps Behind Demand Letters

Insight Published 13 min read
Cover image for a blog about CIPA claims and demand letters, featuring a judge's gavel, scales of justice, and a legal document, with the title "CIPA Claims" and presenter Vivek Shah from Melurna.

Vivek Shah has sent thousands of demand letters to businesses, accusing their websites of illegally wiretapping visitors under the California Invasion of Privacy Act (CIPA). The letters say that common website tools like analytics tags, ad pixels, and session scripts collect visitor data without proper consent. They also demand payment to avoid a lawsuit.

Courts are starting to push back. In July 2026, a judge even called Shah a vexatious litigant. Even so, the letters keep coming, and others have started employing similar tactics.

Even if the legal claims fail, the letters point out real data problems. For privacy leaders and legal teams, these letters serve as a warning. Your website might be leaking information, and fixing those tracking gaps is what you can actually do.

Key takeaways

  • Vivek Shah is a serial self-represented CIPA plaintiff.
  • The demands are based on CIPA’s $5,000-per-violation damages, which are added up for each third-party tracker and can total about $50,000 per letter.
  • Your website’s own tools are what trigger these claims.
  • A cookie banner does not automatically protect you.
  • Courts are pushing back, but copycats and the broader pixel wave continue.
  • The best defense is to know exactly what your site sends and to whom, before someone else finds out.

Who is Vivek Shah?

Vivek Shah is a California serial pro se litigant blasting businesses with CIPA “digital wiretapping” demand letters to businesses from Fall 2025 to June 2026, filing about 29 lawsuits. His claims often involve unauthorized data sharing through a website’s search bar. If a business does not pay, he escalates by filing a lawsuit or by bringing an arbitration claim under the website’s terms of use, which can lead to high filing fees for the business.

Courts have pushed back: in May 2026, a federal court dismissed one of his cases for lack of standing, and on July 20, 2026, another judge declared him a vexatious litigant, requiring court permission before he can file a new CIPA suit in that district. Some companies, like Lofty and the Ovadia law firm, have gone further and sued him first.

None of that makes the problem go away because it was never about one person. Copycat filers are pressing similar wiretapping and trap-and-trace claims in states like Florida, Texas, Michigan, and Pennsylvania. The wider wave of session-replay and pixel litigation affects retail, finance, healthcare, publishing, and education.


What is CIPA (California Invasion of Privacy Act), and how does it apply to a website?

CIPA is a 1967 California wiretapping statute that plaintiffs have repurposed against routine website technology. It was written for telephone eavesdropping, but it includes a private right of action, meaning any person can sue, not just prosecutors.

Under CIPA, wiretapping occurs when someone intentionally taps into, connects to, or tries to access a phone line or other communication device without permission.

The money is the draw. Section 637.2 sets statutory damages at $5,000 per violation for unauthorized data interception, or three times actual damages if greater, with no proof of harm required (Cal. Penal Code § 637.2). A claimant does not need to show any real-world injury to demand payment, and the letters stack the number by pleading each transmission to a distinct tracker as a separate violation (Jeffer Mangels, April 1, 2026).

Under California law, two provisions carry these claims. Section 631(a), the wiretap clause, prohibits reading the contents of a communication while it is in transit without all parties’ consent (statute text). Section 638.51, the pen register and trap and trace provision, bars using a device or process that records dialing, routing, or addressing information without a court order (statute text); the campaign pivoted to this theory in 2026, mirroring the broader plaintiffs’ bar. 

Because a site is a party to its own conversation with a visitor, it is accused of aiding and abetting the vendor’s interception by embedding the script, and a privacy policy accepted after data is already flowing does not count as prior consent (Javier v. Assurance IQ, 9th Cir. 2022, opinion).

AspectSection 631(a) wiretap theorySection 638.51 pen register theory
StatuteCal. Penal Code § 631(a), enacted 1967 (text)Cal. Penal Code § 638.51, added by AB 929, effective January 1, 2016 (text)
What it prohibitsReading or learning the contents of a communication while in transit without all parties’ consent; aiding or abetting that interceptionInstalling or using a pen register or trap and trace device without a court order, subject to provider and consent exceptions
Theory applied to websitesA pixel or replay script “reads” search terms or form entries in real time; the site aids and abetsTrackers collecting IP addresses, device IDs, and cookies are a “process” recording addressing information
Where courts splitWhether post-transmission processing counts as reading “in transit”; whether generic inputs are “contents”Federal district courts in California mostly let the theory past the pleading stage; California Superior Courts repeatedly hold that it covers telephone surveillance only

Any public website can be targeted. If a California resident visits your site, that alone can lead to a claim. Letters have been sent to manufacturers, schools, and business-to-business firms across the country, even those with no presence in California. Being out of state is a defense to discuss with your lawyer, but it will not stop a letter from coming.


How does the search-bar “wiretap” playbook work? 

Most of these demands focus on one everyday feature. The tactic is simple, repeatable, and requires only a standard web browser. It runs in four steps:

  1. The sender visits your website with the browser’s developer tools (DevTools) open, recording all network traffic.
  2. He types “VIVEK” into your search bar.
  3. Third-party trackers on the page, such as Google Analytics or the Meta Pixel, transmit that search term in real time.
  4. Screenshots of the transmission become Exhibit A in a demand packet.
Infographic showing how a CIPA demand letter claims third-party trackers capture search terms without consent, leading to alleged statutory damages.

A website cannot wiretap its own conversation with a visitor. The packets cast trackers like Google Analytics, Meta Pixel, and HubSpot as uninvited interlopers and accuse the owner of aiding, agreeing with, employing, or conspiring with them under Section 631(a). Nor is the method limited to search bars: the allegations and the wider wave extend to forms, chat widgets, and ad pixels such as TikTok and Reddit.

The theory also has a legal anchor: a July 19, 2024 federal ruling in Heerde v. Learfield Communications held that search terms can be the protected “contents” of a communication and let the theory proceed, though it was a motion-to-dismiss ruling, not a final merits decision (741 F. Supp. 3d 849 (C.D. Cal. July 19, 2024).

The packet is engineered to look like a ready-to-file lawsuit. It contains a cover letter requesting “Informal Dispute Resolution” (some letters are titled “Explanation of Dispute”) for alleged violations of the CIPA, specifically Cal. Code § 631(a), a draft complaint formatted for the Los Angeles Superior Court, and screenshots; his demands also seek injunctive relief to make the site “dismantle and remove” the tracking scripts.

The letters stress that no banner or consent opportunity appeared before typing. The packets allege that in at least one test, he clicked Decline on the cookie banner and the site transmitted his search term anyway. Packets are mailed to companies’ registered agents nationwide. He sues businesses in court when websites ignore his arbitration demands.

The amounts demanded are usually less than what it would cost to defend against the claim, so paying often seems cheaper than fighting. This approach is profitable because of the volume.


Where does the campaign stand?

The campaign took its first real losses in mid-2026 but is far from over. On May 28, 2026, a federal judge dismissed Shah’s case against Talentbridge for lack of standing, the constitutional requirement of a concrete injury, because generic search terms are not tied to a searcher’s identity. Defense counsel called it the first decision of its kind against Shah (Glaser Weil, July 8, 2026). Shah appealed to the Ninth Circuit (PacerMonitor docket; Justia, Appeal No. 26-3514).

Weeks earlier, an arbitrator dismissed his claims against Pashion Footwear (PacerMonitor docket). Three businesses then sued him first. On July 20, 2026, a federal judge declared him a vexatious litigant, requiring court permission before he files new privacy suits in the Central District of California (PacerMonitor, Crain docket).

The broadest countersuit is Lofty’s: it seeks a declaratory judgment covering an analytics configuration that runs on more than 30,000 websites for over 91,000 customers (Glaser Weil, July 8, 2026). 

Letter volume surged in June and July 2026. The severity matters too. CIPA class actions routinely settle in the high six or seven figures. A $3.85 million pen register class settlement against the Los Angeles Times won final approval on June 26, 2026 (Spencer Fane, July 14, 2026).

Campaign timeline

Timeline of the Vivek Shah CIPA campaign from 2024 to 2026, showing the emergence of CIPA wiretapping claims, the rise of mass demand letters, key court dismissals, and the legal backlash culminating in a federal pre-filing order against Vivek Shah.

Is your website exposed?

If your site has a public input field and uses third-party tags, you fit the profile these letters target. See how many of these apply to your site:

  1. A visible search bar or forms that accept typed input.
  2. Google Analytics or Google Ads tags.
  3. The Meta (Facebook) Pixel.
  4. Live chat or a chatbot widget.
  5. Session-replay or heatmap scripts.
  6. No consent banner, or one that loads trackers before the visitor chooses.

If four or more apply, your site is likely exposed. This does not mean you have broken the law, since the law is still being debated. But it does mean your site probably sends data in the way these letters describe, so it is worth checking carefully instead of guessing.


Having a consent banner does not guarantee protection. Many banners and consent management platforms (CMPs) are set up once but can fall out of sync with what the site actually does. Four common gaps often appear.

  • Scripts fire before consent: For a banner to work as a defense, it has to block tracking scripts until the visitor agrees. If your tags fire the moment the page loads, the data has already left.
  • Geo-targeting gaps: Some setups only show a banner to visitors in certain states. If IP geolocation lags or the state list is out of date, trackers can fire unchecked for the very visitors who can bring a claim.
  • No input protection: A standard banner does not stop a third-party script from scraping what someone types into a search box or form. That is the exact behavior these letters describe.
  • Configuration drift: Marketing adds a new pixel for a campaign; the consent rules never catch up; the exposure you thought you fixed returns quietly.

The only way to be sure is to check what actually leaves the browser at the network level, not just what your settings are supposed to do. A banner shows your intent, but the network shows what really happens.


What to do if you receive a Vivek Shah or similar demand letter?

The most important and simplest step is to give the letter to your legal team before you do anything else. Nothing here substitutes for a qualified attorney who can review your specific situation. Only your counsel should decide how to respond, settle, or push back. The next steps explain how you can help them act quickly.

  1. Send it to your legal team first and do not reply to the sender yourself. Forward the complete package to in-house counsel or an outside privacy attorney and let them handle the response.
  2. Give your counsel the full record. Hand over the cover letter, the draft complaint, the exhibit screenshots, and the envelope. The more complete the record, the faster they can assess it.
  3. Do not ignore the letter or change the website yet. Preserve evidence first: HAR files (HTTP Archive logs of your site’s network requests), tag manager exports, consent logs, and current versions of your banner, privacy policy, and terms of use.
  4. Map what your trackers actually transmit. Document which scripts fire on your search bar and forms, what data they send, and to which vendors. This factual picture is what your counsel needs and the fastest way to understand your exposure. A privacy risk intelligence platform can produce that map automatically and keep it current (see the next section).
  5. Get the right people in the room. Marketing, web/IT, and security each hold part of the story: know what cookies, pixels, analytics tools, and session replay software you’re using, who operates them, and when they start collecting data. Aligning them early with legal saves time later.
  6. Check your insurance and internal notice obligations. Ask whether a cyber or media-liability policy may apply; many carry notice deadlines. Your legal and finance teams can confirm what’s triggered.
  7. Keep a clean paper trail and stay current. Log dates and actions, and watch how similar cases and reform efforts (such as SB 690) evolve, sharing what you find with your counsel.

Your legal team weighs the options; your job before that is to preserve records, understand what your site does, and give them all the information they need to act.


How does Melurna help?

Every one of these demands starts the same way: someone tracing where a search term travels. For insurers and risk teams, outside-in observation of what an insured’s website transmits is becoming a formal input to underwriting and portfolio monitoring.

MELURNA is a privacy risk intelligence platform that traces data from the point of entry through to fourth parties in real time, turning the plaintiff’s one-off developer-tools check into ongoing visibility. In practice, that gives you:

  • Full third-party visibility: an inventory of every tracker and vendor that receives data from your search bar and forms, including the fourth parties your direct vendors pass data to.
  • PII vs non-PII classification: so you can see not just that data is leaving, but what kind, and prioritize the flows that matter most.
  • Framework mapping: your exposure mapped against 30-plus compliance frameworks, including CIPA, HIPAA, GDPR, ISO 27001, and SOC 2.
  • Continuous monitoring: new tags and vendor changes are caught as they happen, so a fresh pixel doesn’t quietly recreate the gap you just closed.
  • Point-in-time evidence: a timestamped record of what your site transmitted and what you changed that your counsel can actually use.

This is the difference between hoping your consent banner works and knowing exactly what your site sends. You can find and fix any exposure before a plaintiff or regulator does.


What does this mean going forward?

The legal future of this campaign is uncertain. Website privacy litigation under CIPA, as well as other federal and state privacy laws, is rapidly evolving. Shah’s Talentbridge appeal is pending in the Ninth Circuit (No. 26-3514). SB 690 must pass by August 31, 2026, to strip private lawsuits from the pen register sections retroactively. The Variety and Reuters appellate writs could undercut that theory statewide. Any of the three could shrink the wave, and none would affect the wiretap theory under Section 631.

The telemetry question, by contrast, is permanent. Whatever the Legislature or Ninth Circuit does, what a website transmits to third parties is observable from the outside. That observation is becoming a formal insurance input.

If you have received a letter, give it to your legal team today and save your site’s current configuration. If you want to get ahead of the risk, map your third-party data flows and close any gaps now.

Not sure what your site is leaking? Book a Melurna demo.


FAQs

Is a Vivek Shah demand letter a scam?

No, it is not a scam in the legal sense. The letter refers to a real law with a real private right of action, and the sender has filed actual lawsuits and arbitrations. However, a federal judge found that his pattern of seeking out violations and dropping cases when challenged suggests he aims to pressure defendants into settlements. Treat the letter as a real legal threat that needs investigation. Do not treat it as spam or just a bill to pay.

Does the vexatious litigant order mean Shah can never sue again?

No. The July 20, 2026 order requires pre-filing permission only for new privacy suits in the Central District of California. It does not touch demand letters, arbitration, state-court filings, other federal districts, or his pending cases.

We are not in California. Can we still be targeted?

Yes. Letters have gone to businesses nationwide, including companies with no California offices, employees, or clients. But out-of-state status is a defense as well as a grievance: a Florida firm sued first precisely to test whether CIPA can reach a company with no California presence at all.

How do I know if my website is exposed? 

If you run a search bar or forms alongside Google Analytics, the Meta Pixel, chat, or session-replay tools without clear, up-front consent, your site may transmit data the way these letters describe. Mapping your third-party data flows confirms it.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information. We are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “Vivek Shah CIPA Claims: The Tracking Gaps Behind Demand Letters.” Melurna, August 25, 2026. https://www.melurna.com/blog/vivek-shah-cipa-claims/