Shared report — read-only. Anyone with this link can view it.
Audit

got pixels?

Audit Complete

Website: https://www.gymshark.com
Consent Flow: Composer:Pixels
Post-Consent Flow: Reload only
Pages visited: 4
Agent: browser-use (7 steps)
Location: Pennsylvania (US-PA)
Completed: 2026-09-18T21:06:26.218455+00:00
Checkpoints: 3 phases captured

Pixel Litigation Assessment

This assessment focuses on pixel-litigation theories that apply to this geo and the evidence captured in this audit.

Pennsylvania WESCA Matrix

CategoryResultRiskEvidence & Authority
All-party consent Mixed High The initial-load banner was visibly presented and described “Cookies and Tracking Pixels,” but the tested user selected “Accept only essential cookies”; after reload, Google Analytics, Google Ads, mParticle, Intercom, and Datadog traffic still appeared. The banner’s browsewrap-style language may support an implied-consent defense, but the express reject action materially weakens it. Popa v. Harriet Carter Gifts, Inc. held that the adequacy of notice that communications were sent to a third party is a fact-sensitive consent question. (www2.ca3.uscourts.gov)
Contents interception Elevated High Before any choice and again after rejection, GA/Ads requests transmitted persistent IDs, URLs, page titles, scroll activity, product identifiers, selected size, cart event, value, and SKU. The post-reject add-to-cart payload identified the Black Medium joggers and $33.60 value. That is stronger than a bare tracker-load theory, though this run did not show user-entered checkout fields or a replay recording. 18 Pa. C.S. § 5703; compare Popa (third-party routing of website interactions may constitute interception). (www2.ca3.uscourts.gov)
Civil private right of action / damages Elevated Critical If interception, disclosure, or use is established, WESCA supplies a private claim with actual damages or at least $100 per day/$1,000, whichever is greater, plus potential punitive damages, fees, and costs. The class-exposure signal is real, although this run lacks proof of typed sensitive data. 18 Pa. C.S. § 5725. As calibration, the Philadelphia Inquirer settlement included a $1.125 million fund and Meta Pixel practice changes tied in part to Pennsylvania Wiretap Act requirements; its video-pixel facts are not identical to this ecommerce flow. (legis.state.pa.us)

ECPA Wiretap Matrix

CategoryResultRiskEvidence & Authority
Contents interception in transit Elevated High The tested flow shows contemporaneous third-party transmissions of browsing and purchase-intent content—not merely a static script load—including product page, product name/SKU, chosen size, add-to-cart event, and value after rejection. No email, address, phone, or payment fields were typed, so this is not a form-content capture finding. 18 U.S.C. § 2510; compare Price v. Carnival Corp., where alleged session-replay capture of information entered into fields was treated as alleged “contents.” (law.justia.com)
Party vs third-party interceptor Mixed High Gymshark is plainly a party to the shopper-site exchange, but Google, Meta/Facebook, Datadog, mParticle, Intercom, Riskified, and Shopify-related endpoints are separate entities. The evidence most strongly supports third-party receipt by Google Analytics/Ads; whether each vendor functioned only as the site’s extension or independently processed captured data needs vendor/configuration discovery. 18 U.S.C. § 2511(2)(d); Price treated alleged heatmapping and fingerprinting beyond a tape-recorder function as potentially outside the party shield. (law.justia.com)
One-party consent Mixed High Gymshark may invoke its participation in the web exchange and the displayed banner. But the tested session had a visible banner on initial load, an affirmative “Accept only essential cookies” selection, and continued GA/Ads traffic marked pscdl=denied; those facts may undercut an argument that the visitor consented to the observed nonessential transmissions. 18 U.S.C. § 2511(2)(d); compare Piedmont Healthcare (party exception can defeat an ECPA pixel theory where the website is the intended recipient). (govinfo.gov)
Crime-tort exception § 2511(2)(d) Unclear Medium The record supports marketing/analytics collection after rejection, but does not itself show that any party intercepted communications for the purpose of committing a separate crime or tort. Marketing motive alone is not a clean shortcut around the party exception; this theory would need materially stronger purpose evidence. 18 U.S.C. § 2511(2)(d); a recent pixel-tracking dismissal required facts showing the requisite criminal or tortious purpose, not merely knowing collection. (govinfo.gov)
Contents vs metadata Mixed High Browser/device attributes, consent flags, and pseudonymous IDs are metadata-like; the selected product, size, cart status, SKU, price, page path, and add-to-cart event are more plausibly substantive website-communication content. The absence of typed checkout data caps the factual fit. 18 U.S.C. § 2510(8); compare In re BPS Direct, which found standing for alleged surreptitious session-replay capture of payment/billing information but not for generalized browsing allegations alone. (law.justia.com)

Key Takeaway

The sharper litigation theory is not that trackers merely loaded: it is that, after an express essential-only selection, Google endpoints continued receiving persistent identifiers plus product, size, cart, and value data. WESCA presents the more consequential exposure path for a Pennsylvania session; the federal ECPA claim is more vulnerable to party/consent and crime-tort defenses.

Key Observations

  • The Initial Cookie Banner Visual Check was “Yes”; the initial screenshot and post-scroll privacy-interface screenshots show a conspicuous “Cookies and Tracking Pixels” banner before the reject action.
  • After “Accept only essential cookies” and reload, the run still recorded 16 tracker hits across Google Ads, Google Analytics, and Amazon-related endpoints.
  • Post-reject shopping transmitted product-page and add-to-cart data to GA/Ads, including the joggers, Black color, Medium size, SKU, and $33.60 value.
  • The checkout screenshot shows contact, delivery, and payment fields were visible but untouched; this run does not establish capture of typed personal, shipping, or payment data.

Authorities & Litigation Signals

  • Popa v. Harriet Carter Gifts, Inc. is the closest Pennsylvania authority: undisclosed third-party routing of website interactions can support a WESCA interception theory, while notice and consent remain fact-intensive. (www2.ca3.uscourts.gov)
  • In re BPS Direct is useful downside calibration: session-replay allegations tied to captured payment data supported standing, whereas ordinary browsing allegations did not. The present run falls between those poles because it shows cart/product content but no entered checkout data. (law.justia.com)
  • Price v. Carnival Corp. is factually analogous on third-party session-replay processing and weak cookie-banner consent arguments, but it involved alleged capture of materially more sensitive information than this run. (law.justia.com)
  • Braun v. Philadelphia Inquirer signals Pennsylvania settlement pressure around pixel deployment: final approval covered a $1.125 million fund and prospective Meta Pixel restrictions/disclosure measures, although its video-page facts differ from this retail journey. (docs.justia.com)
Disclaimer: This AI-generated summary is for informational purposes only and does not constitute legal advice.

Screenshots

Initial Before Scroll
Initial Before Scroll
1789765633
Cookie Banner
Cookie Banner
1789765664
Checkpoint: Post Checkout Journey
Checkpoint: Post Checkout Journey
1789765853
Checkpoint: Post Reject
Checkpoint: Post Reject
1789765715
Checkpoint: Pre Consent
Checkpoint: Pre Consent
1789765656

Agent Steps

Time Step Message
21:06:36 Configure geo proxy Browser session created with proxy geolocation for US-PA.
21:07:13 Capture the page before scrolling Captured the loaded page before scrolling.
21:07:26 Check whether a cookie banner is visible Cookie banner visible on initial load.
21:07:35 Scroll to bottom (reveal footer privacy choices) Scrollto on /html[1]
21:07:36 Capture checkpoint 'pre consent' Snapshotted 178 requests, 5 tracking domains, 10 cookies.
21:07:43 Look for privacy choices Checked the page for privacy choices.
21:07:52 Click reject all button Click on /html[1]/body[1]/div[10]/div[2]/div[1]/div[1]/div[2]/div[2]/div[1]/div[2]/button[1]
21:08:11 Check for internal preference modal No internal modal detected from screenshot
21:08:33 Reload page Page reloaded for fresh tracking capture.
21:08:35 Capture checkpoint 'post reject' Snapshotted 136 requests, 4 tracking domains, 11 cookies.
21:10:51 Post-consent workflow step 1.1: Click element 3753 Clicked a "Shop now" (https://www.gymshark.com/)
21:10:51 Post-consent workflow step 2.1: Click element 7915 Clicked a "Training Fleece Straight Leg R..." aria-label=Training Fleece Stra (https://www.gymshark.com/collections/last-chance/womens?banner id=sw-mss-stat-camp-set-dark-black-cta1)
21:10:51 Post-consent workflow step 3.1: Click element 14067 Clicked label "m (6-8)" (https://www.gymshark.com/products/gymshark-training-fleece-straight-leg-joggers-black-ss25)
21:10:51 Post-consent workflow step 3.2: Click element 14099 Clicked button "Add to bag" (https://www.gymshark.com/products/gymshark-training-fleece-straight-leg-joggers-black-ss25)
21:10:51 Post-consent workflow step 4.1: search page Searched page for "Checkout": 32 matches found. (https://www.gymshark.com/products/gymshark-training-fleece-straight-leg-joggers-black-ss25)
21:10:51 Post-consent workflow step 4.2: Scroll True Scrolled down element 18552 0.5 pages (https://www.gymshark.com/products/gymshark-training-fleece-straight-leg-joggers-black-ss25)
21:10:51 Post-consent workflow step 5.1: Click element 18309 Clicked a "Checkout securely" (https://www.gymshark.com/products/gymshark-training-fleece-straight-leg-joggers-black-ss25)
21:10:51 Post-consent workflow step 6 Https://us.checkout.gymshark.com/checkouts/cn/hWNGzHe6IYreIa4UZTsqAdhC/en-us? r=AQABMBg-cIX wxYu7oO0EA3RI0ocZePKfTXga7ZBc fp NM&auto redirect=false&edge redirect=true&skip shop pay=true
21:10:51 Post-consent workflow step 7.1: done Task completed: True - Completed your request and stopped at the checkout page without entering any personal, shipping, or - 1110 more characters (https://us.checkout.gymshark.com/checkouts/cn/hWNGzHe6IYreIa4UZTsqAdhC/en-us? r=AQABMBg-cIX wxYu7oO0EA3RI0ocZePKfTXga7ZBc fp NM&auto redirect=false&edge redirect=true&skip shop pay=true)
21:10:53 Capture checkpoint 'post checkout journey' Snapshotted 643 requests, 18 tracking domains, 27 cookies.

Tracking Audit Summary

Pre Consent

4
Tracking Companies
0
Third-Party Cookies
178
Requests (segment)
16
Tracker hits
Loading...