CRANDALL CONSULTING
HomeWebsite Tracking Cases › In Re: BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation

In Re: BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

United States Court of Appeals for the Third Circuit
Court
Federal
Jurisdiction
2026-05-11
Decision Date
Lawsuit
Matter Type

Docket / citation: No. 23-3235

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Summary

A CaseMine commentary summarizes the Third Circuit's May 11, 2026 decision in In re: BPS Direct, LLC: the court held that plaintiffs who plausibly alleged session-replay capture of complete payment-card credentials have Article III standing under an intrusion-upon-seclusion analogue, while plaintiffs alleging only non-sensitive browsing captures do not. The opinion rejected a public-disclosure analogue because alleged sharing with session-replay providers was "functionally internal," and it remanded after reversing as to the purchaser-plaintiffs.

Litigation Status

Decided
Current Status
Plaintiff-favorable (as reported)
Reported Outcome Direction
Standing
Ruling Stage
Binding
Precedential Weight

Status, direction, and weight describe how tracked public sources characterize this matter as of our last review — they are informational classifications, not legal assessments.

Procedural Posture

Appeal from a district-court dismissal for lack of Article III standing; Third Circuit reversed dismissal as to two plaintiffs, modified other dismissals to be without prejudice, affirmed as modified, and remanded.

Reported Holding

The Third Circuit held that two plaintiffs who alleged session-replay code captured their complete payment-card credentials during checkout sufficiently pleaded a concrete injury closely analogous to intrusion upon seclusion and therefore have Article III standing. Six other plaintiffs who only alleged capture of routine browsing interactions lacked standing. The court also ruled that sharing data with session-replay vendors, as alleged, was "functionally internal" and did not satisfy a public-disclosure-of-private-facts analogue, and it instructed that dismissals for lack of standing should generally be without prejudice.

What the Court Decided

That plaintiffs who plausibly alleged session-replay capture of complete payment-card credentials (including full card number and associated credentials) had Article III standing via a common-law analogue to intrusion upon seclusion; that plaintiffs who only alleged non-sensitive browsing captures did not have standing; and that the public-disclosure theory failed because the alleged sharing with session-replay providers was 'functionally internal.' The court reversed dismissal as to the two purchasers, modified the remaining dismissals to be without prejudice, affirmed as modified, and remanded.

What the Court Did Not Decide

The court did not decide the merits of the underlying statutory or common-law claims (e.g., whether the Wiretap Act, CFAA, or the privacy torts were violated on the facts), nor did it find that the session-replay providers in fact aggregated or de-anonymized data on these sites (it characterized the 'fingerprinting' theory as speculative as pleaded).

Significance

Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.

What This Page Does and Does Not Say

This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.

Technologies at Issue

Third parties named or identified in tracked sources: Microsoft, Quantum Metric, Mouseflow, Bass Pro Shops (website operator), Cabela's (website operator), third-party session replay providers (unnamed).

Statutes Invoked

Claims Asserted

Claims identified in tracked public sources; pleadings may include additional or amended claims.

What This Matter May Mean for Website Operators

Federal Wiretap Act (ECPA Title I) is a one-party consent statute with a private right of action; California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.

For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice. Our scanner tests these behaviors empirically.

The reported outcome direction at the standing stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.

Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.

Related Intelligence

Sources

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website