Know what’s on your site before a plaintiff’s firm does
A free privacy audit shows which cookies, pixels and trackers are running — and which ones commonly appear in privacy claims.
For the last several years, businesses have been learning an uncomfortable lesson about the modern web. A website does not need to suffer a traditional data breach to create privacy litigation risk.
The problem may already be sitting inside the page.
A Meta Pixel fires when the visitor arrives. Google Analytics receives a search term. Microsoft Clarity records interactions. A chat widget sends information to its vendor. A session-replay tool observes clicks and form activity. An advertising platform receives an IP address, URL, device identifier or other information before the visitor has made a privacy choice.
Plaintiffs’ lawyers increasingly argue that some of those ordinary website transmissions amount to unlawful interceptions under decades-old wiretapping statutes.
That legal theory has produced thousands of lawsuits, arbitration demands and pre-suit letters. Now the enforcement model itself is becoming automated.
Presenting: Privacy Resolve
PrivacyResolve.com is an unusually clear example. Privacy Resolve describes itself not as a law firm, but as a technology platform that scans websites, captures evidence of alleged privacy violations, prepares pre-litigation matters and gives businesses an online portal through which they can examine the evidence, negotiate a resolution, make payment and obtain a signed release.
Its stated objective is remarkably direct:
resolve the matter before it becomes a lawsuit.
Privacy Resolve says its goal is a signed mutual release rather than a court docket. It performs technical scans, packages the evidence, prepares pre-litigation documents and operates the portal through which recipients respond.
The development is significant because it shows how far website privacy litigation has evolved.
The first generation was a plaintiff discovering a tracking technology and hiring a lawyer.
The second was law firms systematically testing websites and sending large numbers of nearly identical claims.
Privacy Resolve points toward a third generation:
software infrastructure built specifically to discover, document and resolve privacy claims at scale.

What Privacy Resolve actually is
Privacy Resolve’s public website is primarily designed for one audience: a business that has already received a privacy demand letter.
The homepage begins with:
“Received a letter about your website?”
A recipient is given a unique access code in certified correspondence. That code opens a secure case portal containing the alleged technical evidence, statutes, claimant information and pre-litigation demand.
Privacy Resolve expressly says it is not a law firm.
According to its About page, the claimant controls the matter, while the recipient is free to hire its own attorney at any point. Privacy Resolve says its functions include technical website scanning, evidence packaging, pre-litigation document preparation, operating the resolution portal, preparing mutual releases and collecting signatures.
That distinction is important.
This is not simply legal lead generation.
The company appears to be building the infrastructure between the technical discovery of an alleged privacy problem and the eventual filing of litigation.
Its own description captures the thesis:
“The work was already happening. It just needed better technology.”
That may be the most important sentence on the entire website.
Privacy Resolve turns a demand letter into a software workflow
Traditionally, a website privacy claim might proceed something like this:
Plaintiff visits website
↓
Potential tracking issue discovered
↓
Attorney reviews issue
↓
Demand letter prepared
↓
Business forwards letter to counsel
↓
Counsel requests evidence
↓
Emails and phone calls
↓
Settlement negotiations
↓
Agreement drafted
↓
Payment
↓
Release
Privacy Resolve attempts to compress most of the middle of that process into a single platform.
Its published process has five stages.
First, an automated scan identifies what Privacy Resolve characterizes as a violation. The company says the scan captures third-party trackers, the information transmitted, timestamps and packet captures.
Next, the business receives a certified letter containing a unique portal code.
Inside the portal, the recipient can examine the technical findings, claimant identity, asserted statutes and settlement demand.
The recipient can then accept the proposed resolution, make a counteroffer, request remediation information or grant its own lawyer access to the matter.
If terms are reached, Privacy Resolve says the claimant has already executed the relevant agreement under a standing authorization. The business or its lawyer signs, ACH payment becomes available following server verification, and the mutual release is delivered electronically.
That is a remarkably different model from conventional litigation.
The claim itself has become structured data.
The evidence is the product
Privacy Resolve repeatedly emphasizes that its cases are supposed to be based on technical evidence rather than generic allegations.
Its homepage says case files identify the scan timestamp, vendors found, destinations receiving traffic and fields captured. Its How It Works page says packet captures are attached to the matter.
That matters because website wiretap litigation has become increasingly technical.
A plaintiff does not necessarily need internal corporate documents to begin constructing a claim.
The browser exposes much of what happens.
Open Developer Tools.
Load the website.
Watch the Network panel.
Enter something into a search field.
Start a chat.
Navigate to a product page.
Reject the cookie banner.
Then observe what requests leave the browser.
A technically sophisticated tester can ask:
Which third parties received requests?
Did the request fire before consent?
What URL was transmitted?
Was a search term included?
Was a unique identifier included?
Did the request contain form information?
Did tracking continue after Reject All?
Was session replay active?
Privacy Resolve has essentially turned that type of inspection into the front end of an enforcement workflow.
The rise of plaintiffs’ firms changed the economics of website privacy
Privacy Resolve did not emerge in isolation.
It sits on top of a litigation trend that has been developing for several years.
The California Invasion of Privacy Act was enacted in 1967, long before websites, pixels or JavaScript analytics existed.
Yet plaintiffs have increasingly used CIPA to challenge modern website technology.
Barnes & Thornburg described the 2026 environment as a multistate, multi-statute litigation campaign targeting routine website instrumentation including pixels, session replay, analytics SDKs, chat widgets and advertising tags. Claims increasingly invoke not only CIPA but the federal Electronic Communications Privacy Act, Florida’s Security of Communications Act, Pennsylvania’s wiretap statute, the Video Privacy Protection Act and related privacy theories.
The attraction is obvious.
CIPA’s civil-remedy provision can provide the greater of $5,000 per violation or three times actual damages for qualifying violations.
A technical event that costs essentially nothing to reproduce can therefore support a demand with potentially significant statutory exposure.
And the factual investigation can often be performed from outside the company.
A small group of plaintiffs and firms learned how scalable this could be
Website privacy litigation increasingly developed characteristics of an industrial process.
Certain firms became closely associated with high-volume CIPA claims.
Recent legal commentary has identified firms including Tauler Smith, Pacific Trial Attorneys, Manning Law, Potter Handy and Victims Advocacy Group among firms active in website-tracking litigation.
Tauler Smith, for example, has publicly described its own claims involving technologies such as TikTok tracking software and alleged collection of browser, geographic, referral and URL information.
Then the demand-letter model expanded beyond conventional plaintiffs’ firms.
One of the most notable examples has been Vivek Shah.
Fisher Phillips estimated that between fall 2025 and June 2026 Shah sent thousands of letters to businesses and nonprofits alleging CIPA violations. The targets reportedly extended far beyond traditional consumer companies and included organizations with questionable connections to California.
Privacy insurer and claims analysts later reported that Shah-related matters grew so rapidly during the first half of 2026 that his demand volume exceeded the volume associated with law firms in their dataset.
In July 2026, a federal judge in the Central District of California declared Shah a vexatious litigant and entered a prefiling order applying to new CIPA and related digital-privacy cases he sought to file in that district.
But that did not end the broader phenomenon.
The underlying technical theories, other plaintiffs and other law firms remained.
California changed CIPA, but the litigation did not simply disappear
California’s 2026 CIPA reform materially changed one part of this ecosystem.
Governor Gavin Newsom signed legislation that removes the private right of action from CIPA’s pen-register and trap-and-trace provision beginning January 1, 2027, with retroactive effect reaching back two years.
Reuters reported that the amendment could eliminate thousands of claims built specifically around that provision. Fisher Phillips estimated that more than 4,700 tracking-related suits had been filed, with additional demand letters and arbitration claims outside the courts.
But companies should not conclude that California ended website privacy litigation.
The reform does not erase every CIPA theory.
Section 631 remains relevant.
More importantly, plaintiffs have already begun shifting toward other statutes.
Jeffer Mangels & Mitchell observed in September 2026 that plaintiffs were increasingly pairing or replacing CIPA theories with the federal Wiretap Act, the VPPA and statutes such as Florida’s Security of Communications Act.
That adaptability is one of the defining characteristics of this litigation market.
The technology stays mostly the same.
The legal theory changes.
Privacy Resolve is designed for that environment
Privacy Resolve’s public materials repeatedly reference both CIPA and the federal Wiretap Act.
The company says its purpose is to operate in the enforcement gap created by private rights of action.
Its mission statement is unusually candid:
“Privacy law only works when someone enforces it.”
Privacy Resolve argues that regulators lack the resources to investigate every individual website and that legislatures intentionally created private rights of action so enforcement does not depend entirely on regulatory agencies. The company says it occupies that gap.
Its worldview is essentially:
Tracking occurs
↓
Consumer data reaches a third party
↓
Consumer has a statutory claim
↓
Technical evidence documents it
↓
Business receives demand
↓
Business remedies site
↓
Consumer receives compensation
↓
Matter ends without litigation
Privacy Resolve says the result benefits three constituencies.
The visitor gets a remedy.
The website operator gets a private and comparatively fast way to resolve the matter.
And, according to the company, the internet becomes more privacy protective because enforcement forces websites to remove nonconsensual tracking.
That is the company’s mission as it describes it.
Whether courts agree that a particular transmission actually establishes liability is a separate question.
That distinction matters because the law remains unsettled
Privacy Resolve’s website occasionally states the legal theory too categorically.
Its homepage says, for example, that “[n]o allegation of intent is needed; the transmission itself is the violation.”
Elsewhere, its materials describe trackers as intercepting electronic communications and suggest that the federal Wiretap Act applies when a tracker transmits visitor information without affirmative consent.
Businesses should not interpret those statements as settled law.
The actual litigation is much more complicated.
Defendants have prevailed on arguments involving whether information was intercepted “in transit,” whether the third-party technology could contemporaneously read the communication, whether the website operator was itself a party to the communication, whether consent existed, whether the information constituted contents rather than routing data, Article III standing and other issues.
Barnes & Thornburg noted in April 2026 that California federal courts and state courts had reached different conclusions in some CIPA disputes and highlighted a significant defense decision where a session-replay provider could not read the information while it was in transit.
Spencer Fane similarly described the law in July 2026 as genuinely unsettled, noting conflicting results in cases involving substantially similar website-tracking theories.
So the accurate statement is not:
Tracker fired, therefore wiretap violation.
It is:
Tracker fired, therefore there may be facts supporting a privacy or wiretap claim that must be evaluated under the applicable statute, jurisdiction, technology architecture, consent record and case law.
That difference can determine whether a claim is worth settling or fighting.
Interestingly, Privacy Resolve tells recipients to verify its claims
One of the more responsible parts of the site appears in its own guidance for recipients.
Privacy Resolve tells businesses not to assume a demand is valid merely because it looks official.
It recommends independently verifying the sender, claimant, domain, phone number and mailing address. It says businesses should determine whether the notice identifies the website, dates, pages, technology, legal theory and evidence supporting the allegation.
Its guidance also explicitly says:
“A demand is a claim by a sender—not a court judgment, proof of liability, or guarantee that a lawsuit will follow.”
That is an important qualification and a considerably more nuanced formulation than some of the stronger marketing language elsewhere on the site.
It also tells companies to consult qualified counsel before making a payment.
In other words, Privacy Resolve is simultaneously a platform facilitating claims and a platform telling recipients to independently assess whether those claims are legally valid.
It also appears engineered around evidentiary integrity
The underlying application architecture is revealing.
Privacy Resolve says portal sessions are audited and timestamped.
Its privacy notice says the platform keeps case information, demand amounts, evidence, correspondence, authentication records, security information, settlement documents and payment status.
It identifies Google Cloud Platform for infrastructure, Supabase for database and private evidence storage, Stripe for ACH processing, DocuSeal for electronic agreements, Resend for transactional email, Telnyx for SMS and Anthropic for an optional case-support assistant.
The company says case records, messages, signed agreements, evidence, payment status and integrity records may be retained for seven years or longer in circumstances involving litigation holds, disputes or other legal requirements.
This is not the architecture of a basic website scanner.
It looks like a matter-management system.
The evidence must survive.
The communication history must survive.
The signatures must survive.
The payment record must survive.
The identity of the claimant must survive.
If the matter does not resolve and later reaches litigation, those records potentially become part of the evidentiary history.
Privacy Resolve also practices the tracking restraint it advocates
There is an interesting detail on every public Privacy Resolve page reviewed.
The site declares that its public pages use no advertising trackers.
Its privacy notice says it does not use tracking pixels, session recording, browser fingerprinting, behavioral analytics or third-party advertising. It says fonts and static assets are served from its own Google Cloud infrastructure rather than from a public font CDN.
The authenticated portal uses what Privacy Resolve describes as an essential first-party session cookie rather than advertising technologies.
That appears deliberate.
A company built around alleging unlawful third-party website tracking would create an obvious credibility problem if its own marketing pages were covered in advertising pixels.
The remediation side is also part of the model
Privacy Resolve is not merely telling businesses to pay.
Its resources include detailed instructions for identifying trackers, examining browser network traffic, disabling session-replay software, implementing consent controls and aligning privacy notices with actual website behavior.
The site specifically instructs businesses to open browser Developer Tools and inspect requests to familiar domains associated with Meta, Google Analytics, Microsoft Clarity, Hotjar, Segment, Mixpanel, Intercom, Amplitude, DoubleClick and Mouseflow.
That is notable because it gives defendants essentially the same basic investigative method that can be used against them.
Look at what the browser actually does.
Privacy Resolve’s own self-check says finding a tracker is not automatically a violation. It focuses instead on questions such as whether it fires before consent, whether disclosures accurately describe the technology and whether sensitive form or keystroke information is captured.
Again, that portion of the site is more nuanced than the homepage.
The demand-letter economy exists because litigation is expensive even when the defendant may win
To understand why Privacy Resolve’s model could work, it is necessary to understand the economics.
A company can believe a privacy demand is legally weak and still decide to settle.
Why?
Because litigation has transaction costs.
Outside counsel needs to investigate the technology.
Engineers need to reconstruct old website behavior.
Tag-manager histories need to be preserved.
Consent records have to be located.
Insurance carriers may become involved.
Motions must be prepared.
Discovery can begin.
Executives spend time on the matter.
And uncertainty remains.
A demand for a relatively modest amount can therefore become economically rational to resolve even when the defendant disputes the underlying theory.
Plaintiffs’ firms have understood this for years.
Privacy Resolve appears designed to reduce the friction on both sides enough that more matters can reach that economic decision before litigation expenses accumulate.
Its product is therefore not simply enforcement technology.
It is transaction-cost technology.
The portal could make privacy enforcement substantially more scalable
Consider what happens when each step becomes standardized.
Technical scans can be repeated.
Evidence can be collected in a common format.
Demand letters can be generated from structured case information.
The recipient logs into the same interface.
Counteroffers use the same workflow.
Settlement agreements use standardized fields.
Signatures are electronic.
Payments are ACH.
Releases are automatically delivered.
One person can theoretically manage far more matters than would be possible if every case required independent email correspondence and manually negotiated paperwork.
That scalability is important.
Privacy litigation traditionally faced a natural limiting factor: legal labor.
Automation weakens that constraint.
This resembles what happened to other high-volume legal claims
Privacy enforcement is not the first legal field to become operationalized.
Debt collection became heavily automated.
Mass tort intake became software driven.
TCPA litigation developed standardized testing and demand practices.
ADA website-accessibility claims became highly repeatable.
Arbitration platforms handle huge numbers of standardized disputes.
Privacy claims have many of the same characteristics.
A website can be tested remotely.
The underlying technologies recur across thousands of companies.
The statutes can provide fixed or statutory damages.
Evidence can often be captured electronically.
The claims share enough common structure to be processed through standardized workflows.
Privacy Resolve takes that logic another step by placing the settlement infrastructure itself online.
This could fundamentally change how businesses experience privacy litigation
Historically, a company’s first indication of privacy risk might have been a lawsuit.
Then it became a demand letter.
The next version may be:
“We scanned your website. Here is your case code.”
That is psychologically and operationally different.
The claim arrives already packaged.
The evidence is available immediately.
The settlement mechanism is already built.
The claimant has already authorized the agreement.
Payment rails are waiting.
A business can theoretically go from receiving certified mail to obtaining a release without ever entering a courthouse.
Privacy Resolve explicitly says that is the point.
The rise of this model makes technical privacy compliance more important
For businesses, arguing about the philosophy of plaintiffs’ litigation misses the practical issue.
The website can be tested by outsiders.
The browser provides the evidence.
If a business deploys:
Meta Pixel
Google Analytics
TikTok Pixel
Microsoft Clarity
Hotjar
chat widgets
session replay
advertising tags
customer-data platforms
it needs to understand what those technologies actually transmit.
Not what the marketing department thinks they transmit.
Not what the vendor’s sales presentation says.
Not merely what the privacy policy says.
What leaves the browser.
That is the relevant technical fact.
Pre-consent transmission is particularly dangerous
One recurring theme throughout the current litigation wave is timing.
The visitor arrives.
Before the visitor clicks anything, requests begin leaving the browser.
The consent banner may appear half a second later.
From a design perspective, the difference looks trivial.
From a litigation perspective, it can be the entire case.
If the challenged communication occurred before the visitor made a choice, the defendant may have a much harder time relying on the banner as evidence of consent.
This is the “millisecond problem” that privacy lawyers increasingly discuss: the user interface appears compliant while the underlying trackers fire before the interface has any practical effect. Loeb & Loeb has described pre-consent tracking as a central part of the 2026 CIPA plaintiffs’ playbook.
That is why blocking needs to occur technically.
A privacy policy does not stop a packet
This litigation wave has also exposed the limitations of document-first privacy programs.
A company can have an excellent privacy notice.
Its website can still send data to ten vendors before the visitor reads it.
The policy does not control JavaScript.
It does not reconfigure Google Tag Manager.
It does not prevent a session-replay library from initializing.
It does not stop an image pixel.
It does not honor Reject All unless somebody implemented that behavior.
That is why website privacy has increasingly become an engineering discipline.
Plaintiffs’ firms will continue moving to the next available theory
The CIPA pen-register reform demonstrates another reason companies should not chase one statute at a time.
When courts narrow one argument, plaintiffs adapt.
When legislatures remove one private cause of action, another statute may become more attractive.
The September 2026 analysis from Jeffer Mangels described precisely this migration from CIPA’s pen-register provisions toward ECPA, VPPA and statutes in states such as Florida.
Healthcare tracking litigation provides another route.
Video viewing provides another.
Mobile SDKs provide another.
Connected TV provides another.
Chat transcripts provide another.
Form tracking provides another.
The common denominator is not CIPA.
It is unauthorized or inadequately disclosed data transmission.
Privacy Resolve may be more important as a signal than as a single company
The most interesting thing about Privacy Resolve may ultimately not be Privacy Resolve itself.
It is what the platform says about the maturation of the privacy-enforcement market.
The ingredients now exist for highly scalable enforcement:
Automated detection
Technical evidence capture
Private rights of action
Standardized legal theories
Digital case management
Electronic negotiations
Electronic signatures
Integrated payments
Repeatable remediation
Put those together and privacy enforcement begins to look less like bespoke litigation and more like a technology-enabled claims operation.
Whether that development is viewed as efficient consumer enforcement or industrialized litigation will depend heavily on where someone sits.
Privacy Resolve’s own position is clear.
It sees private enforcement as necessary because regulators cannot inspect every website, and it argues that financially meaningful claims cause companies to actually fix tracking problems.
Defendants and their lawyers may see the same infrastructure very differently, particularly when legal theories remain unresolved or claims are generated at very high volume.
Both perspectives can be true at the same time.
A website can have a genuine privacy problem.
And a particular legal claim can still be contestable.
Businesses should not confuse a technical finding with a legal conclusion
This may be the most important distinction in the entire Privacy Resolve story.
A scanner can establish:
A request was made.
It can potentially establish:
This data was contained in the request.
It can establish:
The request occurred before the visitor clicked Accept.
Those are technical findings.
Whether the event constitutes an “interception,” whether the information is legally protected “contents,” whether the third party qualifies under the relevant statute, whether valid consent existed, whether a plaintiff has standing and whether damages are available are legal questions.
Automation can dramatically improve evidence collection.
It cannot turn disputed statutory interpretation into settled law.
That means companies receiving technologically sophisticated demands need technologically sophisticated defense counsel and privacy engineers, not panic.
The correct corporate response is evidence against evidence
When a company receives a letter from Privacy Resolve, Tauler Smith, another plaintiffs’ firm or an individual claimant, the strongest response begins with preservation and independent verification.
Preserve the website configuration.
Preserve consent logs.
Preserve tag-manager versions.
Preserve privacy notices.
Preserve network evidence.
Then reproduce the alleged behavior.
Determine precisely what fired.
Determine what was transmitted.
Determine whether the claimant’s evidence accurately characterizes the system.
Determine the visitor’s consent state.
Determine the applicable jurisdiction.
Determine whether insurance may respond.
Then counsel can evaluate the claim.
Privacy Resolve itself recommends much of this approach and specifically warns recipients against making unverified payments simply because a demand appears polished or urgent.
The bigger lesson: privacy compliance is becoming adversarially testable
For years, organizations treated privacy as something they documented internally.
That era is ending.
A plaintiff can test your website.
A regulator can test your website.
A competitor can test your website.
A journalist can test your website.
A privacy platform can test your website.
The browser does not care what your policy says.
It shows where the requests actually went.
That is why the emergence of Privacy Resolve matters.
It is another sign that privacy controls are becoming externally verifiable.
The companies that fare best in this environment will not merely have a consent banner.
They will be able to prove:
what technology is deployed
what data it receives
why it receives that data
when it activates
what happens before consent
what happens after Reject All
which third parties receive information
what version of the privacy notice was active
what consent signal existed for the session
whether the system behaved as represented
That is a considerably higher standard than installing a cookie banner and assuming the problem has been solved.
Privacy Resolve is building infrastructure for a world where privacy violations are continuously discoverable
Privacy Resolve’s stated mission is to make enforcement faster and less adversarial.
Its mechanics tell an even larger story.
Website privacy claims are becoming machine-detectable.
Evidence is becoming machine-packaged.
Pre-suit disputes are becoming digitally managed.
Settlements can be electronically negotiated.
Releases can be electronically executed.
Payments can be automatically processed.
The courthouse is becoming the escalation path rather than the default starting point.
That may make legitimate privacy claims cheaper to enforce.
It may also make weak claims cheaper to send.
Both consequences deserve attention.
The defining question for businesses is therefore not whether they approve of the plaintiffs’ bar.
It is whether their technical controls can withstand outside inspection.
Because the next privacy demand may not begin with an attorney manually studying a website.
It may begin with an automated scan.
And the software on the other side may already have the evidence, the claimant, the demand, the settlement agreement and the payment workflow assembled before the company knows anyone was looking.
That is the new environment Privacy Resolve is building for.
And it is a strong indication of where website privacy enforcement is heading.
Put this into practice
Turn privacy guidance into working controls.
Captain Compliance helps teams discover tracking technologies, enforce consent, manage privacy requests and document the evidence behind every decision.