An audit went out to the privacy consultant for PacSun and it was ignored. Now a California shopper has sued Pacific Sunwear the same day the state narrowed one privacy statute and left this theory standing. On September 30, 2026, Sarah Paiva filed a class action in Santa Clara County Superior Court against Pacific Sunwear of California, LLC, the company behind pacsun.com. Case No. 26CV504846. Counsel is Bursor & Fisher. She bought clothing on the site in April 2026, from California, on a device where she was logged into Facebook and TikTok. The complaint says Meta’s pixel and TikTok’s pixel intercepted that session, including checkout, and tied it to identifiers those platforms already held.
This is not a pen-register case. It is pleaded under the federal wiretap statute, California’s wiretap and recording statutes, the state computer-crime law, and the California Constitution. Those claims survived the signing of SB 690.
The promise on the banner
PacSun’s cookie notice, quoted in the complaint, told visitors that advertising cookies “do not store directly personal information, but are based on uniquely identifying your browser and internet device.” Paiva’s lawyers treat that sentence as the case. They allege the pixels did the opposite: they captured IP addresses, Facebook IDs, the c_user cookie, other cookie and device IDs, names, emails, phone numbers, and purchase details, then sent them to Meta and TikTok.
The exhibits are network logs, not inferences. One Meta call, labeled initiateCheckout, left pacsun.com/checkout on June 18, 2026, carrying a product name, “Boston Soft Footed Clog Taupe,” a price of $169.95, quantity, and currency. A TikTok call the same day posted to analytics.tiktok.com with a hashed email and a hashed phone number, a product value, and a payment-step event. The complaint cites the Federal Trade Commission’s July 2024 warning that hashing does not anonymize data. The same input always produces the same hash, so a platform that already has the email or phone can match it.

Who is in the class
Two proposed classes. A nationwide class of U.S. residents who bought on pacsun.com during the class period. A California subclass of California residents who did the same. The class period runs from the applicable statute of limitations, after any tolling, to judgment. Paiva says the classes are at least thousands of people. She reserved the right to add subclasses.
PacSun is a California LLC headquartered in Anaheim. Venue is Santa Clara because that is where Paiva says the conduct reached her. The complaint demands a jury.
The five counts, and why SB 690 does not touch them
Count I is the Electronic Communications Privacy Act, 18 U.S.C. § 2511, for the nationwide class. The claim is intentional interception of the contents of an electronic communication, with a private right of action under § 2520. Statutory damages there can reach $10,000 per violation or $100 a day, whichever is greater.
Counts under CIPA §§ 631 and 632 are the California wiretap and confidential-communication claims. Section 631 is the eavesdropping provision. Section 632 covers recording a confidential communication without consent. SB 690, signed the same day this case was filed, stripped the private right of action only for pen-register claims under Penal Code § 638.51 arising on websites and apps. It did not amend § 631 or § 632. A pixel case pleaded as interception of contents, not as a pen register, is the case the new law left open.
The complaint also pleads the Comprehensive Computer Data Access and Fraud Act, Penal Code § 502, and a privacy claim under the California Constitution for the California subclass. Common questions listed in the filing are whether the pixels violated the ECPA, § 631, § 632, § 502, and the state constitution, and what damages follow.
These are allegations. PacSun has not answered in this filing. Nothing here is a finding that the banner was false or that the pixels fired as described for every purchaser.
The Bursor and Fisher attorney on the complaint is Philip L. Fraietta (State Bar No. 354768). While it’s a California complaint there are ties to New York as there is a New York address and number on the public filing:
50 Main Street, Suite 475
White Plains, NY 10606
Telephone: (914) 874-0708
Facsimile: (914) 206-3656
Email: pfraietta@bursor.com
Where a banner-only vendor fails
The failure mode in this complaint is a mismatch, not a missing policy page. A consent tool told shoppers that advertising cookies do not store directly personal information. The tags behind that banner sent a Facebook user ID and a hashed phone number at checkout, with the product and the price. A vendor that drops a banner and calls the job done never compares the sentence on the banner to the request leaving the browser. They were using OneTrust which has been a frequent target of these lawsuits lately and even caught the attention of Scott Ferrel of Pacific Trial Attorneys.
That gap shows up in four places.
- The banner describes the wrong object. “Does not store directly personal information” is a claim about the cookie. The pixel is a script that posts an event. A scan that inventories cookie names and ignores network calls will bless the banner and miss the payload.
- Checkout is a different page. Product views and initiateCheckout are not the same event. Tags are often added by a media agency on the confirmation and payment steps, outside the template the privacy vendor reviewed.
- Hashing was treated as a control. A hashed phone is still a phone to the platform that issued the hash match. The FTC has said so. A vendor that labels hashed identifiers “anonymous” is writing the plaintiff’s exhibit.
- Consent never gated the tag. If the pixel fires before a choice, or fires after a reject, the banner is evidence for the plaintiff. Logging the choice is not the same as blocking the request.
What stops the claim
Captain Compliance treats this as a tag-and-disclosure problem, not a policy rewrite. The work is to make the banner true.
- A tag audit against the live site, including checkout. Capture the calls to facebook.com, analytics.tiktok.com, and any server-side equivalent. Record the event name, the identifiers, and whether a reject stopped them.
- Consent that blocks, not just records. Advertising and analytics tags stay unloaded until the matching category is allowed. A reject has to kill the pixel, the CAPI call, and the tag-manager fallback.
- Copy that matches the payload. If a tag sends a user ID, a hashed email, or a hashed phone, the notice cannot say the cookie does not store directly personal information. Either the sentence changes or the field is stripped.
- No checkout events in the advertising pipe by default. Product, price, and payment-step events are the contents the ECPA and § 631 theories are built on. They do not ship to an ad platform unless the notice says so and the shopper opted in.
- A record. Timestamp of the choice, version of the banner, tags that were allowed to fire. That is the defense exhibit. A screenshot of a cookie panel is not.
Retailers running Meta and TikTok on a storefront should assume a plaintiff’s firm can reproduce Figure 2. The banner language in this complaint is common. The network log is common. The statute this case is pleaded under is the one California did not cut back on September 30.