Know what’s on your site before a plaintiff’s firm does
A free privacy audit shows which cookies, pixels and trackers are running — and which ones commonly appear in privacy claims.
Did you receive a lawsuit from the Saad & Andrews firm? Most likely you have a faulty cookie banner running on the site and your software provider is not working to keep you compliant. Captain Compliance provides software tools to stay compliant with privacy regulations. If you’d like a free privacy audit to see if you are at risk book a complimentary audit above.
Saad & Andrews playbook is a useful example of where plaintiffs’ privacy litigation is heading. The Mobile, Alabama firm does not present itself as a traditional privacy boutique focused on regulatory counseling or compliance. Its public-facing practice is built around consumer harm: data breaches, privacy violations, payment and PIN-related claims, and class litigation involving allegedly systemic corporate conduct. The firm says it evaluates not only whether information was exposed or collected, but whether the underlying behavior appears to be part of a broader practice affecting groups of consumers.
What makes Saad & Andrews particularly interesting in 2026, however, is what appears outside the firm’s own website. The firm is currently associated with a growing group of mass-arbitration investigations involving website tracking and alleged disclosures of consumer information to companies such as Meta, Google, TikTok and other advertising platforms.
That places it directly inside one of the most consequential changes occurring in privacy litigation: plaintiffs’ lawyers are no longer relying exclusively on class actions. They are increasingly assembling thousands of individual consumer claims around the same underlying technology.
From data breaches to tracking technology
Saad & Andrews’ own website emphasizes several areas of privacy-related litigation. The firm identifies data breaches involving unauthorized access, ransomware, allegedly inadequate security and delayed notification; alleged misuse of payment-related information; and class actions involving practices affecting large groups of consumers.
Those categories represent two very different types of privacy claim.
A traditional breach case usually begins with an unauthorized outsider obtaining data. The dispute may focus on whether a company used reasonable security, whether notice was timely and whether affected consumers suffered compensable injury.
Website tracking litigation can involve the opposite factual situation. The company’s systems may never have been hacked. Instead, plaintiffs allege that the company itself intentionally installed software that caused consumer information to be transmitted to third parties without sufficient consent.
The basic architecture might be:
Consumer visits website
↓
Consumer searches, purchases or logs in
↓
Tracking technology observes the event
↓
Information travels to an advertising platform
↓
Plaintiffs allege the transmission violated privacy law
There may be no cyberattack at all.
That distinction is important because organizations accustomed to treating privacy litigation as an incident-response problem can miss the risk already embedded in normal marketing technology.
Saad & Andrews appears to be moving aggressively into mass privacy arbitration
Current consumer-claim listings show Saad & Andrews administering or jointly administering several privacy-related mass-arbitration campaigns.
One involves Duolingo users and allegations that personal information was improperly shared with Meta or Google through tracking technologies. Another investigates Kelley Blue Book over alleged website tracking. A separate Marriott matter concerns alleged transmission of customer information to advertising platforms including Meta, Google, TikTok, Pinterest and others. Saad & Andrews is also identified as administering a privacy investigation involving WWE users.
These are described as investigations or claims, not court findings that the companies violated privacy law. The defendants may dispute the allegations, and the ultimate legal merit of each matter will depend on facts, contractual terms, applicable statutes and the technology involved.
But the pattern itself matters.
The same plaintiffs’ infrastructure can potentially be applied to many websites because the underlying technological questions recur:
What third-party tracking technology is installed?
What information does it transmit?
Does the visitor have an account?
Is the information associated with Meta, Google or another external identifier?
Did the transmission happen before consent?
What statute or contract potentially applies?
Once those questions can be answered programmatically or through repeatable testing, a claimant pool can potentially be built around them.
Mass arbitration changes the economics
For years, corporations inserted arbitration clauses and class-action waivers into consumer terms largely because they could reduce class-action exposure.
Plaintiffs’ firms adapted.
Instead of asking one named plaintiff to represent 500,000 consumers, counsel can potentially sign up thousands of clients and pursue each person’s claim individually through arbitration.
That creates a very different economic problem.
The model becomes:
Large affected population
↓
Digital claimant intake
↓
Thousands of individual representation agreements
↓
Pre-arbitration demands
↓
Individual arbitrations or group resolution
If a company’s arbitration provision requires it to pay significant filing or administrative costs, large volumes of claims can create meaningful expense even before the underlying merits are decided.
This is why the rise of firms such as Saad & Andrews matters even to businesses that believe their arbitration clause protects them from class litigation.
The clause may prevent a class action.
It does not necessarily prevent thousands of individual consumers from asserting substantially identical claims.
The current investigations show how broad the targeting can become
The companies connected with current Saad & Andrews privacy investigations are not all in one industry.
Duolingo is an education technology platform.
Kelley Blue Book operates an automotive information marketplace.
Marriott is a global hospitality company.
WWE operates sports-entertainment and media properties.
The common denominator is the website or application, not the underlying business.
Almost every significant consumer business now uses some combination of:
analytics
advertising pixels
conversion tracking
attribution technology
customer-data platforms
retargeting
social-media integrations
That means the potential defendant universe is enormous.
A plaintiffs’ firm does not need a new legal theory for hotels, language-learning applications, automotive marketplaces and entertainment companies if the alleged technical conduct is substantially the same.
The data itself can make the claim more interesting
Not all tracking events are equal.
A basic pageview containing only a generic URL can present one level of risk. A transmission that combines a logged-in consumer, an identifier, a search query, purchase information or account activity can present another.
ClassAction.org, which is facilitating some investigations associated with Saad & Andrews, currently describes one Guitar Center investigation as involving allegations that search terms and information about items placed into shopping carts may be transmitted to third parties such as Meta or TikTok.
That kind of allegation is important because the privacy analysis becomes increasingly fact-specific as richer data enters the request.
Consider:
Pageview
versus:
Account identifier
+
Product searched
+
Cart contents
+
Advertising identifier
+
Third-party destination
The second transmission gives plaintiffs considerably more factual material to work with.
This is why packet-level privacy testing matters
Companies often evaluate tracking by asking what vendors are installed.
That is only the first question.
The more important analysis is what those vendors actually receive.
A meaningful website assessment should reproduce the user’s experience and inspect network traffic during events such as account creation, login, search, checkout and consent rejection.
The company should be able to determine:
Destination
Request timing
Identifiers transmitted
Page or content information
Form values
Search terms
Purchase information
Consent state
If plaintiffs’ counsel can determine those facts from outside the company, the company itself should certainly know them.
Saad & Andrews is also positioning around data breaches
The firm should not be understood solely as a tracking-litigation operation.
Saad & Andrews’ primary website strongly emphasizes data breaches and specifically identifies exposure of medical, payroll, financial and other personal information as potential matters. The firm describes its approach as determining what information was affected, what the company disclosed and whether the underlying conduct appears systemic.
That gives the firm access to another expanding privacy-litigation market.
Large breaches routinely generate populations of tens of thousands or millions of affected consumers. The technical incident itself produces the claimant universe.
Unlike an ordinary negligence claim, where counsel must locate people who were individually injured, a breach notification can effectively identify the entire pool of prospective plaintiffs.
Privacy litigation therefore has unusually scalable economics on both sides of the field.
Website tracking provides repeatable technical conduct.
Data breaches provide large affected populations.
Mass arbitration and class actions provide mechanisms for aggregating claims.
Payment privacy is another potentially important niche
Saad & Andrews also prominently advertises “PIN & Payment Privacy” litigation involving alleged collection, storage, sharing or misuse of payment-related information.
That is worth watching because payment flows combine several categories that plaintiffs’ lawyers increasingly scrutinize: financial information, identifiers, checkout tracking, advertising pixels and third-party processors.
The checkout page can become a particularly sensitive location for unnecessary tracking.
A retailer might appropriately send information to a payment processor while simultaneously allowing unrelated advertising technology to observe events around the same transaction.
The question is not simply whether a tracking vendor exists somewhere on the site. It is whether the vendor receives data from sensitive parts of the customer journey that it does not need.
A modern plaintiffs’ privacy firm is partly a technology operation
The larger story surrounding Saad & Andrews is not really about one Alabama law firm.
It is about the infrastructure developing around privacy claims.
Consumer recruitment can happen online.
Technical investigators can scan websites remotely.
Claimant qualification can be standardized.
Representation agreements can be electronic.
Thousands of similarly situated users can be organized into arbitration cohorts.
Different plaintiffs’ firms can collaborate on the same investigations.
The legal work is still performed by lawyers, but technology dramatically increases the number of matters those lawyers can identify and administer.
That means the privacy plaintiffs’ bar is beginning to resemble other mature mass-claims industries.
Companies should expect more firms to follow this model
The economics are attractive enough that Saad & Andrews is unlikely to be unusual for long.
There are millions of consumer-facing websites and applications, many running substantially similar advertising and analytics stacks. There are dozens of privacy statutes and consumer-protection theories that plaintiffs can test. Arbitration agreements can produce individualized claims rather than eliminate them. Digital intake platforms allow firms to recruit clients nationally.
The barrier to launching a privacy investigation has therefore become much lower.
A firm can identify a technical pattern, advertise the investigation, qualify users and potentially assemble a meaningful claimant population without waiting for a regulator to take action.
That changes the compliance calculus.
Businesses should no longer ask only whether a regulator is likely to investigate their tracking practices.
They should assume that plaintiffs’ lawyers can test those practices themselves.
The practical lesson is to find the evidence first
The companies most exposed to the next generation of privacy claims will often be the ones that do not know what their own technology is transmitting.
A privacy notice alone will not solve that problem.
Neither will an arbitration clause.
Neither will a cookie banner if the underlying tags ignore it.
Organizations need to continuously understand the actual behavior of their websites and applications: what technologies are present, what data leaves, whether tracking fires before consent, whether Reject All works and whether sensitive customer interactions are exposed to advertising platforms.
Saad & Andrews’ growing presence in tracking investigations is another indication that privacy litigation is moving toward a repeatable, mass-claims model.
The question for businesses is no longer merely whether one consumer could bring a claim.
It is whether the same technical behavior could support ten thousand of them.
Put this into practice
Turn privacy guidance into working controls.
Captain Compliance helps teams discover tracking technologies, enforce consent, manage privacy requests and document the evidence behind every decision.