CRANDALL CONSULTING
HomeTracking Technologies › Session Replay (category)

Session Replay (category): Tracking Behavior & Litigation Context

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 8, 2026

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What Session Replay (category) Is

Session replay is a category of tools (Microsoft Clarity, Hotjar, FullStory, Mouseflow, Lucky Orange, and others) that record a visitor's on-site behavior — mouse movement, clicks, scrolling, and DOM changes — and reconstruct it as a watchable recording.

What It Does

Replay scripts serialize the page and the visitor's interactions in near-real time and stream that data to the vendor's servers, where operators can replay individual sessions. Depending on masking configuration, typed input may be included.

Browser Communications Generally Observed

Continuous batched transmissions to vendor endpoints throughout a visit, beginning at page load in default configurations, containing serialized DOM state, interaction events, page URLs, and persistent visitor identifiers.

How Our Scanner Detects It

Our scanner identifies replay scripts across vendors, verifies when recording begins relative to consent, and types synthetic marker values into forms to empirically test whether keystrokes or field values are transmitted before submission.

Common Implementation Behavior

Deployed via tag managers with defaults that record all pages. Recurring observed issues: recording on checkout/patient/intake pages, incomplete masking for custom components, and consent banners that don't gate the recorder.

Litigation & Risk Context

Session replay is the technology category most consistently named in website 'wiretap' litigation under all-party consent statutes, on the theory that recording visitor interactions captures the contents of a communication without consent. Detection is a meaningful informational risk indicator on any site, and especially on form-heavy or sensitive-category sites — but is not a legal determination.

Tracked Cases Involving This Technology

Greenley v. Kochava, Inc.; Javier v. Assurance IQ, LLC

Southern District of California; Northern District of California; Ninth Circuit (as discussed) · Reported claim

This law-firm blog post summarizes a wave of California Invasion of Privacy Act (CIPA) class actions alleging that website and app trackers, session-replay tools, and chat vendors intercept communications or function as pen registers. The article notes that some federal courts (including a Southern District of California decision in Greenley) have allowed pen-register and interception claims to proceed, while other courts have rejected the pen-register theory, creating a split in California federal courts.

Popa v. Microsoft Corp.

U.S. Court of Appeals for the Ninth Circuit; U.S. District Courts for the Northern, Central, and Southern Districts of California · Lawsuit

This Holland & Knight alert describes conflicting rulings in California over whether web-based tracking technologies (e.g., pixels and IP-address collection) fall within CIPA Section 638.51. It highlights the Ninth Circuit's Popa v. Microsoft decision tightening Article III standing requirements and notes divergent district-court outcomes applying Popa to CIPA claims.

Javier v. Assurance IQ; Greenley v. Kochava

Ninth Circuit; U.S. District Court for the Southern District of California · Reported claim

This industry article summarizes mid-2026 developments in California CIPA litigation alleging website-based wiretapping and pen-register violations. It explains the statutes at issue (including §§631(a) and 638.51), notes key decisions (Javier and Greenley), and outlines common technologies and theories driving a surge in filings and settlements.

Delsignore v. Zazzle, Inc.

Court not identified · Lawsuit

A proposed class action filed Oct. 13, 2022 (Delsignore v. Zazzle, Inc.) alleges Zazzle used session-replay software on www.zazzle.com to record visitors' mouse movements, clicks, keystrokes, search terms and other inputs without disclosure or consent. The complaint asserts this conduct violated the Pennsylvania Wiretapping and Electronic Surveillance Control Act and seeks to represent Pennsylvania residents whose electronic communications were allegedly intercepted.

Birdsall v. PNC Bank NA; Erakat v. PNC Bank, National Association

Court of Common Pleas of Allegheny County, Pennsylvania (Birdsall v. PNC); U.S. District Court for the Eastern District of California (Erakat v. PNC) · 2026-03-23 · Lawsuit

LegalClarity reports that PNC faces two proposed class actions alleging pixel trackers and session-replay/form-capture technologies on its website transmitted browsing data to third-party advertising platforms. One suit was filed in Pennsylvania invoking WESCA and was removed to federal court then remanded back to state court; a second was filed in federal court in California citing state and federal privacy statutes. Both matters were described as pending with no settlements reported as of mid-2026.

Falls v. Blue Cross Blue Shield of Michigan Mutual Insurance Company

United States District Court for the Eastern District of Michigan · Lawsuit

Miller Canfield reports that a putative class action, Falls v. Blue Cross Blue Shield of Michigan, was filed in the Eastern District of Michigan alleging that the defendant used third‑party tracking pixels and session‑replay tools that captured and transmitted visitors' personally identifiable information to outside vendors. The complaint asserts claims under the Federal Wiretap Act and Michigan's eavesdropping statute and is described as one of nearly 4,000 similar suits nationwide since 2022.

Travis Rounds v. Development Dimensions International

United States District Court for the Central District of California (C.D. Cal.) · 2026-03-11 · Lawsuit

A federal district court in the Central District of California dismissed without leave to amend a complaint alleging that cookies and a 6Sense SDK functioned as a CIPA trap-and-trace device, finding the allegations insufficient to establish a statutory violation and thus personal jurisdiction. The decision indicates that such cookie-based theories will not always succeed in that court.

Mikulsky v. Bloomingdale’s LLC

U.S. Court of Appeals, Ninth Circuit (appeal from U.S. District Court for the Southern District of California, Judge M. James Lorenz) · 2025-06-20 · Lawsuit

This tracker post summarizes that the Ninth Circuit reversed the dismissal of a California Penal Code § 631(a) claim challenging session-replay code on bloomingdales.com, finding the complaint alleged capture of communication contents rather than mere record data. The case later settled after the appellate revival.

In re BPS Direct, LLC; Cabela's, LLC Wiretapping Litig.

United States Court of Appeals for the Third Circuit · 2026-05-11 · Lawsuit

A Covington & Burling blog post summarizes the Third Circuit's May 11, 2026 decision in In re BPS Direct and Cabela's litigation on website wiretapping standing. The court held that ordinary browsing data (clicks, scrolls, searches) and theoretical third-party de-anonymization do not establish Article III standing, but found standing where session-replay tools allegedly captured names and full payment card numbers.

Mirmalek v. Los Angeles Times Communications LLC

United States District Court for the Northern District of California · 2026-06-26 · Lawsuit

On June 26, 2026 the Northern District of California entered a final judgment in Mirmalek v. Los Angeles Times Communications LLC granting final approval of a class action settlement. The Court ordered the parties to comply with the Settlement, dismissed all claims related to the litigation with prejudice, retained jurisdiction to implement and enforce the Settlement, and declared the judgment final and appealable.

Remediation Options Operators Commonly Consider

Whether any option is appropriate for a specific website is a decision for the operator and qualified counsel.

Frequently Asked Questions

Which session replay vendors appear in litigation?

Public complaints have named many vendors in the category. Theories target the recording behavior itself, so the specific vendor matters less than configuration: what is captured, when recording begins, and how masking and consent gating are set up.

Related Intelligence

Sources

This page is based on direct technical observation by our scanner and vendor documentation; tracked litigation sources will be listed as the intelligence engine links them to this technology.

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website