CRANDALL CONSULTING
HomeWebsite Tracking Cases › In re BPS Direct, LLC; Cabela's, LLC Wiretapping Litig.

In re BPS Direct, LLC; Cabela's, LLC Wiretapping Litig.

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

United States Court of Appeals for the Third Circuit
Court
Federal
Jurisdiction
2026-05-11
Decision Date
Lawsuit
Matter Type

Docket / citation: F.4th, 2026 WL 1280969

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Summary

A Covington & Burling blog post summarizes the Third Circuit's May 11, 2026 decision in In re BPS Direct and Cabela's litigation on website wiretapping standing. The court held that ordinary browsing data (clicks, scrolls, searches) and theoretical third-party de-anonymization do not establish Article III standing, but found standing where session-replay tools allegedly captured names and full payment card numbers.

Litigation Status

Decided
Current Status
Mixed
Reported Outcome Direction
Standing
Ruling Stage
Binding
Precedential Weight

Status, direction, and weight describe how tracked public sources characterize this matter as of our last review — they are informational classifications, not legal assessments.

Procedural Posture

Eight plaintiffs sued online retailers alleging use of session-replay code violated the Wiretap Act, the CFAA, and state privacy laws. The Third Circuit reviewed dismissal rulings and affirmed dismissal for six plaintiffs for lack of standing while reviving the claims of two plaintiffs.

Reported Holding

The Third Circuit affirmed dismissal for lack of Article III standing for six of eight plaintiffs who merely browsed websites and did not provide sensitive information, holding that disclosure of clicks, scrolls, and searches does not constitute a concrete injury and that theoretical third-party de-anonymization is insufficient. The court found two plaintiffs had standing because session-replay code allegedly captured their names and full credit/debit card numbers, which the court treated as highly sensitive and analogous to intrusion upon seclusion.

What the Court Decided

The court held that (1) disclosure of clicks, scrolls, and searches without sensitive identifying data does not create a concrete injury for Article III standing; (2) allegations that third parties could theoretically aggregate data into browser fingerprints do not establish standing; and (3) capture of highly sensitive payment and identifying information by third-party session-replay tools can confer standing.

What the Court Did Not Decide

The court did not adopt a rule that all collection via third-party tools establishes standing and limited its finding of standing to the alleged capture of highly sensitive identifying/payment information; it did not expand standing to users who only had non-identifying browsing data captured.

Significance

Neutral / mixed significance. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.

What This Page Does and Does Not Say

This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.

Technologies at Issue

Statutes Invoked

Claims Asserted

Claims identified in tracked public sources; pleadings may include additional or amended claims.

What This Matter May Mean for Website Operators

For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field. Our scanner tests these behaviors empirically.

Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.

Related Intelligence

Sources

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website