What two new US tracking lawsuits mean for your store
Key Takeaways
- On September 15, 2026, two federal courts issued motion-to-dismiss rulings in website-tracking cases involving Meta Pixel, Google Analytics, Google Tag Manager, and LinkedIn Insight Tag.
- In Wehrle v. McLaren Health Care Corp., a Michigan federal court let federal Wiretap Act (ECPA) and unjust-enrichment claims proceed to discovery on allegations that health-related site activity was shared with third parties.
- In Felsen v. The Vanguard Group, a Pennsylvania federal court dismissed the federal Wiretap Act claim without prejudice but kept Pennsylvania WESCA and California CIPA claims alive, and refused to treat a footer privacy-notice link as proven consent at the pleading stage.
- These are early-stage decisions, not final verdicts.
- They still underscore a practical point for website operators: know which trackers run on your site, what they send, and whether visitors actually saw and could act on your consent choices, especially on pages that handle sensitive activity.
What happened on September 15, 2026
Two U.S. district courts issued orders the same day in putative class actions about third-party tracking code on consumer-facing websites and apps.
Wehrle v. McLaren Health Care Corporation (E.D. Mich.)
Patients alleged that McLaren and the Karmanos Cancer Institute embedded tracking tools on their websites, including Meta Pixel, Google Analytics, Google Tag Manager, and LinkedIn Insight Tag.
They claimed those tools collected and sent information tied to health conditions, treatment interest, facility and physician searches, search queries, and appointment booking activity to Meta, Google, and LinkedIn without consent.
Judge Matthew F. Leitman granted the motion to dismiss in part and denied it in part. The court:
- Allowed the federal Electronic Communications Privacy Act / Wiretap Act claim (Count II) to proceed
- Allowed the unjust enrichment claim (Count V) to proceed
- Dismissed breach of fiduciary duty, intrusion upon seclusion, breach of implied contract, and negligence claims
The court stressed that the ECPA ruling reflects its view of the pleadings and current case law, that courts nationwide still disagree on the crime-tort exception in pixel cases, and that it will revisit the issue with an open mind.
Felsen v. The Vanguard Group, Inc. (E.D. Pa.)
Brokerage customers alleged that LinkedIn Insight Tag, Google Analytics, and Meta Pixel on Vanguard’s website and app captured account-related activity and investment behavior, including search queries, ticker symbols, and buy/sell activity, and that third parties used that information for marketing.
Claims included the federal Wiretap Act, Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA), California’s Invasion of Privacy Act (CIPA), and California constitutional/common-law privacy claims.
Judge John F. Murphy held that the plaintiffs had Article III standing. On the pleadings, the court:
- Dismissed without prejudice the federal Wiretap Act claims (and certain California common-law and constitutional claims)
- Allowed the Pennsylvania WESCA claim to continue
- Allowed the California CIPA claims to continue past the motion stage (after addressing choice-of-law and merits arguments in the memorandum)
Two points in Felsen matter for operators of any high-intent website, not only brokerages.
1. “Contents” of a communication can include search terms and trading activity.
WESCA defines “contents” to include information concerning the substance, purpose, or meaning of a communication. The court treated that definition as aligned with federal Wiretap Act case law holding that a search for information on a particular topic can reveal the substance and meaning of a communication. On the facts pleaded, search terms for financial products and trading activity could qualify as “contents.”
2. A privacy-notice link in the footer is not automatic proof of consent at the motion-to-dismiss stage.
Vanguard argued that a plaintiff consented because a privacy notice was linked at the bottom of every page. The court declined to find consent on that basis at this stage. Even if the notice itself were considered, Vanguard would still need to establish additional facts, including that the hyperlink was functional and conspicuous enough that the user could reasonably have seen it.
That second holding is the one many Shopify merchants should read carefully. A policy page that exists is not the same as consent the user actually received and could act on.
Why the two courts reached different results on the federal Wiretap Act
Both cases sit in the same broader wave of pixel and tag litigation. The federal outcomes still diverged for doctrinal reasons tied to how each circuit and district treats the Wiretap Act’s “party” rules and the crime-tort exception.
Under the federal Wiretap Act, a private party who is a party to the communication is generally not liable for interception, unless the interception is for the purpose of committing a criminal or tortious act. In the Third Circuit, that criminal or tortious purpose must be independent of the interception itself, not simply the alleged wiretapping restated as another privacy tort. In Felsen, the court found the plaintiffs had not adequately pleaded that independent crime or tort under binding Third Circuit authority, so it dismissed the federal claim without prejudice.
In Wehrle, the Michigan court allowed the ECPA claim to proceed on the pleadings. Plaintiffs alleged intentional transmission of HIPAA-protected information to third parties without consent. The court found those allegations enough, at this stage, to engage the crime-tort exception theories other courts have accepted in healthcare pixel cases, while expressly noting the unsettled national split and reserving the right to revisit after discovery.
For earlier Consentmo coverage of California-focused tracking risk and CIPA context, see California Tracking Lawsuits Are Rising.
What this tells website operators about trackers
Strip away the procedural labels and both complaints describe a familiar stack:
- marketing and analytics tags embedded sitewide or in apps
- capture of page views, identifiers, search input, and high-intent actions
- transmission to platforms that also sell advertising services
- disputes about whether users knew and agreed
Courts are willing, at least at the pleading stage, to treat some of that activity as more than dry “routing” metadata. Search terms, appointment flows, and product/ticker selections can look like the substance of what the user was communicating to the site.
That does not mean every website must block Meta Pixel or Google Analytics until consent in every jurisdiction. Requirements turn on:
- where your visitors are
- what data the scripts actually send
- whether the data is sensitive under a specific statute (health, financial, or other regulated categories)
- how you present notices and choices
- whether a given law is a consent statute, a wiretap-style interception statute, a consumer privacy statute, or sector rules such as HIPAA
Overclaiming “these cases require X everywhere” helps no one. Under-reading them is also a mistake. They show that plaintiffs and courts will dig into what the pixel fired on, not only whether a privacy policy existed somewhere on the domain.
What Shopify merchants should check on their own sites
Use these two rulings as a prompt for an operational review, not as a panic trigger.
1. Inventory what actually runs
List every marketing, analytics, advertising, social, and session tool on the storefront, checkout-adjacent pages, account area, search, and any embedded apps. Include Meta Pixel, Google tags, LinkedIn Insight, TikTok, Pinterest, review widgets, chat, and personalization scripts. Categorize each as essential or non-essential for your compliance model.
Consentmo’s scanner and Tracker Manager are built for this continuous inventory: scripts change when you install apps, edit theme code, or launch campaigns.

2. Map what each tool can observe
For important pages and actions, check what third-party trackers can learn from things like the URL, search terms, products viewed, form steps, or event names. In Felsen, the court said search and transaction-related activity could count as the “contents” of a communication.
In Wehrle, health-related searches and appointment activity received even closer scrutiny.
3. Test consent as a user would see it
Ask:
- Is the choice presented before non-essential tags fire in regions where you require prior consent?
- Are accept and reject (or equivalent granular controls) actually usable?
- Is the privacy or cookie policy link easy to find, working, and readable on mobile?
- Do you keep records of what version of the banner and policy applied when consent was given?
Felsen refused to assume consent from a bottom-of-page privacy link without proof that the link was functional and conspicuous. That is a UX and evidence problem as much as a legal theory problem.
4. Align analytics and ads with consent signals
Where you use Google tags, configure Consent Mode and verify behavior after opt-in and opt-out. See Consentmo’s Google Consent Mode V2 guidance.
For Meta and other pixels, confirm load rules match your regional consent settings rather than firing on every first paint worldwide.

5. Rescan on a schedule
Theme edits, app installs, and Black Friday pixels are common ways silent tags return. A one-time audit ages quickly. Build rescans into your release checklist.
6. Get counsel for regulated categories
Health, finance, children’s products, and cross-border sales raise statute-specific issues. These two opinions are district-court pleadings decisions. They are useful signals, not a compliance certificate.
Practical tracking and consent checklist
What Consentmo helps you with
Consentmo is a Shopify-focused consent and tracking control layer. It does not replace your lawyer, and it does not convert a healthcare or financial product site into an automatically compliant one. It does help merchants run the controls these cases keep putting in issue:
- Scan the store for cookies and trackers and classify them
- Block non-essential scripts until the visitor’s consent choice allows them
- Present clear banner and preference-center choices, including region-aware setups
- Document consent where your process requires a record
- Rescan so new pixels from apps and campaigns do not silently reappear
- Support Google Consent Mode and related ad-stack consent signals so analytics and ads respect the choice you collected
If you already run a CMP, use this week’s rulings as a reason to verify real browser behavior on search, product, and account pages, not only the banner screenshot in your brand guidelines.
Conclusion
Wehrle and Felsen, both decided September 15, 2026, are early-chapter opinions in the long-running U.S. fight over website pixels and tags. One healthcare case lets federal Wiretap Act and unjust-enrichment theories proceed into discovery. One financial-services case drops the federal Wiretap Act claim for now but keeps state WESCA and CIPA theories alive, and refuses to treat a footer privacy link as proven consent on the pleadings. Together they push operators toward a simple operational standard: know your trackers, know what sensitive interactions they can observe, and make consent something users can actually see and exercise.
This article is general information for merchants, not legal advice. Outcomes depend on facts, jurisdiction, and counsel’s guidance for your store.



