CRANDALL CONSULTING
HomeWebsite Tracking Cases › Mikulsky v. Bloomingdale’s LLC

Mikulsky v. Bloomingdale’s LLC

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

U.S. Court of Appeals, Ninth Circuit (appeal from U.S. District Court for the Southern District of California, Judge M. James Lorenz)
Court
Federal
Jurisdiction
2025-06-20
Decision Date
Lawsuit
Matter Type

Docket / citation: 9th Cir. 24-3564 / 24-3837; D.C. 3:23-cv-00425 · Filed: 2025-11-14

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Summary

This tracker post summarizes that the Ninth Circuit reversed the dismissal of a California Penal Code § 631(a) claim challenging session-replay code on bloomingdales.com, finding the complaint alleged capture of communication contents rather than mere record data. The case later settled after the appellate revival.

Litigation Status

Settled
Current Status
Plaintiff-favorable (as reported)
Reported Outcome Direction
Settlement
Ruling Stage
Limited (stage- or fact-specific)
Precedential Weight

Status, direction, and weight describe how tracked public sources characterize this matter as of our last review — they are informational classifications, not legal assessments.

Procedural Posture

Plaintiff filed suit in the Southern District of California (filed Mar 2023 per source). The district court dismissed the § 631 claim as alleging only 'record data' and dismissed an intrusion-upon-seclusion claim; the Ninth Circuit reversed the dismissal of the § 631 claim in an unpublished memorandum on June 20, 2025. The matter later settled (reported Nov 14, 2025).

Reported Holding

The Ninth Circuit reversed the district court's dismissal of the plaintiff's claim under California Penal Code § 631(a), holding that the complaint plausibly alleged real-time capture of the contents of communications (not merely characteristics) and that Bloomingdale's allegedly aided a third-party session-replay vendor in accessing those contents.

What the Court Decided

The Ninth Circuit panel found that, at the pleading stage, the complaint sufficiently alleged that session-replay code captured the contents of communications and that Bloomingdale's aided or enabled a third party to read or learn those contents, warranting reversal of the dismissal of the § 631 claim.

What the Court Did Not Decide

The court did not resolve the ultimate merits of whether contents were in fact intercepted or whether defendants were liable on the merits; its decision addressed pleading-stage sufficiency.

Significance

Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.

What This Page Does and Does Not Say

This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.

Technologies at Issue

Third parties named or identified in tracked sources: FullStory, Inc..

Statutes Invoked

Claims Asserted

Claims identified in tracked public sources; pleadings may include additional or amended claims.

What This Matter May Mean for Website Operators

California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.

For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice; what page URLs and query strings analytics tools share with third parties. Our scanner tests these behaviors empirically.

The reported outcome direction at the settlement stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.

Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.

Related Intelligence

Sources

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website