In Re: BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation
Summary
A CaseMine commentary summarizes the Third Circuit's May 11, 2026 decision in In re: BPS Direct, LLC: the court held that plaintiffs who plausibly alleged session-replay capture of complete payment-card credentials have Article III standing under an intrusion-upon-seclusion analogue, while plaintiffs alleging only non-sensitive browsing captures do not. The opinion rejected a public-disclosure analogue because alleged sharing with session-replay providers was "functionally internal," and it remanded after reversing as to the purchaser-plaintiffs.
Litigation Status
Procedural Posture
Appeal from a district-court dismissal for lack of Article III standing; Third Circuit reversed dismissal as to two plaintiffs, modified other dismissals to be without prejudice, affirmed as modified, and remanded.
Reported Holding
The Third Circuit held that two plaintiffs who alleged session-replay code captured their complete payment-card credentials during checkout sufficiently pleaded a concrete injury closely analogous to intrusion upon seclusion and therefore have Article III standing. Six other plaintiffs who only alleged capture of routine browsing interactions lacked standing. The court also ruled that sharing data with session-replay vendors, as alleged, was "functionally internal" and did not satisfy a public-disclosure-of-private-facts analogue, and it instructed that dismissals for lack of standing should generally be without prejudice.
What the Court Decided
That plaintiffs who plausibly alleged session-replay capture of complete payment-card credentials (including full card number and associated credentials) had Article III standing via a common-law analogue to intrusion upon seclusion; that plaintiffs who only alleged non-sensitive browsing captures did not have standing; and that the public-disclosure theory failed because the alleged sharing with session-replay providers was 'functionally internal.' The court reversed dismissal as to the two purchasers, modified the remaining dismissals to be without prejudice, affirmed as modified, and remanded.
What the Court Did Not Decide
The court did not decide the merits of the underlying statutory or common-law claims (e.g., whether the Wiretap Act, CFAA, or the privacy torts were violated on the facts), nor did it find that the session-replay providers in fact aggregated or de-anonymized data on these sites (it characterized the 'fingerprinting' theory as speculative as pleaded).
Significance
Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- Session Replay Code
- JavaScript
- fingerprinting
- video replay
- session-replay
- pixel
- tracking-technology
- consent management platform (CMP)
- pixel tracking
- JavaScript-based session replay
- session replay
- form input capture / keystroke capture
- user fingerprinting (alleged)
- session replay (JavaScript-based session-replay code)
- keystroke/text-entry capture
- browser/device fingerprinting (alleged/speculative)
Third parties named or identified in tracked sources: Microsoft, Quantum Metric, Mouseflow, Bass Pro Shops (website operator), Cabela's (website operator), third-party session replay providers (unnamed).
Statutes Invoked
- Wiretap Act, 18 U.S.C. § 2510 et seq.; Computer Fraud and Abuse Act, 18 U.S.C. § 1030 et seq.
- Wiretap Act; Computer Fraud and Abuse Act; CIPA § 631; CIPA § 638.51; Pennsylvania WESCA; Florida FSCA; VPPA
- 18 U.S.C. § 2510 et seq.; 18 U.S.C. § 1030
- Federal Wiretap Act; Computer Fraud and Abuse Act; California Invasions of Privacy Act (CIPA) § 631 and § 638.51; Pennsylvania WESCA; Florida FSCA; Video Privacy Protection Act (VPPA) (as referenced)
- 18 U.S.C. § 2510 et seq. (Wiretap Act); 18 U.S.C. § 1030 (Computer Fraud and Abuse Act)
- Federal Wiretap Act; Computer Fraud and Abuse Act; various state-law and common-law causes of action (public disclosure of private facts; intrusion upon seclusion)
- Wiretap Act; Computer Fraud and Abuse Act (as alleged); state common-law privacy theories (intrusion upon seclusion and public disclosure of private facts)
Claims Asserted
- Wiretap Act (18 U.S.C. § 2510 et seq.)
- Computer Fraud and Abuse Act (18 U.S.C. § 1030)
- State and common-law privacy claims (including intrusion upon seclusion)
- Federal Wiretap Act (as alleged in complaint)
- Computer Fraud and Abuse Act (as alleged in complaint)
- State-law and common-law claims including public disclosure of private facts and intrusion upon seclusion (as alleged in complaint)
- Wiretap Act (alleged)
- Computer Fraud and Abuse Act (alleged)
- Intrusion upon seclusion (state common-law privacy analogue)
- Public disclosure of private facts (state common-law privacy analogue)
What This Matter May Mean for Website Operators
Federal Wiretap Act (ECPA Title I) is a one-party consent statute with a private right of action; California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice. Our scanner tests these behaviors empirically.
The reported outcome direction at the standing stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
- In Re: BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation (No. 23-3235)
- In re: BPS Direct LLC (Third Circuit judgment)
- Session-Replay Capture of Complete Payment Card Data Confers Article III Standing Under Intrusion Upon Seclusion
- Where to Stand and Fight: How the New Circuit Split In Session-Replay Class Actions Reshapes Defense Strategy
- Third Circuit Draws a Standing Line in Session Replay Cases with Browse-Only Claims Dismissed, Checkout Payment-Data Claims Revived
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website