got pixels?
Audit Complete
Website: https://www.gymshark.com
Consent Flow: Composer:Pixels
Post-Consent Flow: Reload only
Pages visited: 4
Agent: browser-use (7 steps)
Location: Pennsylvania (US-PA)
Completed: 2026-09-18T21:06:26.218455+00:00
Checkpoints: 3 phases captured
Pixel Litigation Assessment
Pennsylvania WESCA Matrix
| Category | Result | Risk | Evidence & Authority |
|---|---|---|---|
| All-party consent | Mixed | High | The initial-load banner was visibly presented and described “Cookies and Tracking Pixels,” but the tested user selected “Accept only essential cookies”; after reload, Google Analytics, Google Ads, mParticle, Intercom, and Datadog traffic still appeared. The banner’s browsewrap-style language may support an implied-consent defense, but the express reject action materially weakens it. Popa v. Harriet Carter Gifts, Inc. held that the adequacy of notice that communications were sent to a third party is a fact-sensitive consent question. (www2.ca3.uscourts.gov) |
| Contents interception | Elevated | High | Before any choice and again after rejection, GA/Ads requests transmitted persistent IDs, URLs, page titles, scroll activity, product identifiers, selected size, cart event, value, and SKU. The post-reject add-to-cart payload identified the Black Medium joggers and $33.60 value. That is stronger than a bare tracker-load theory, though this run did not show user-entered checkout fields or a replay recording. 18 Pa. C.S. § 5703; compare Popa (third-party routing of website interactions may constitute interception). (www2.ca3.uscourts.gov) |
| Civil private right of action / damages | Elevated | Critical | If interception, disclosure, or use is established, WESCA supplies a private claim with actual damages or at least $100 per day/$1,000, whichever is greater, plus potential punitive damages, fees, and costs. The class-exposure signal is real, although this run lacks proof of typed sensitive data. 18 Pa. C.S. § 5725. As calibration, the Philadelphia Inquirer settlement included a $1.125 million fund and Meta Pixel practice changes tied in part to Pennsylvania Wiretap Act requirements; its video-pixel facts are not identical to this ecommerce flow. (legis.state.pa.us) |
ECPA Wiretap Matrix
| Category | Result | Risk | Evidence & Authority |
|---|---|---|---|
| Contents interception in transit | Elevated | High | The tested flow shows contemporaneous third-party transmissions of browsing and purchase-intent content—not merely a static script load—including product page, product name/SKU, chosen size, add-to-cart event, and value after rejection. No email, address, phone, or payment fields were typed, so this is not a form-content capture finding. 18 U.S.C. § 2510; compare Price v. Carnival Corp., where alleged session-replay capture of information entered into fields was treated as alleged “contents.” (law.justia.com) |
| Party vs third-party interceptor | Mixed | High | Gymshark is plainly a party to the shopper-site exchange, but Google, Meta/Facebook, Datadog, mParticle, Intercom, Riskified, and Shopify-related endpoints are separate entities. The evidence most strongly supports third-party receipt by Google Analytics/Ads; whether each vendor functioned only as the site’s extension or independently processed captured data needs vendor/configuration discovery. 18 U.S.C. § 2511(2)(d); Price treated alleged heatmapping and fingerprinting beyond a tape-recorder function as potentially outside the party shield. (law.justia.com) |
| One-party consent | Mixed | High | Gymshark may invoke its participation in the web exchange and the displayed banner. But the tested session had a visible banner on initial load, an affirmative “Accept only essential cookies” selection, and continued GA/Ads traffic marked pscdl=denied; those facts may undercut an argument that the visitor consented to the observed nonessential transmissions. 18 U.S.C. § 2511(2)(d); compare Piedmont Healthcare (party exception can defeat an ECPA pixel theory where the website is the intended recipient). (govinfo.gov) |
| Crime-tort exception § 2511(2)(d) | Unclear | Medium | The record supports marketing/analytics collection after rejection, but does not itself show that any party intercepted communications for the purpose of committing a separate crime or tort. Marketing motive alone is not a clean shortcut around the party exception; this theory would need materially stronger purpose evidence. 18 U.S.C. § 2511(2)(d); a recent pixel-tracking dismissal required facts showing the requisite criminal or tortious purpose, not merely knowing collection. (govinfo.gov) |
| Contents vs metadata | Mixed | High | Browser/device attributes, consent flags, and pseudonymous IDs are metadata-like; the selected product, size, cart status, SKU, price, page path, and add-to-cart event are more plausibly substantive website-communication content. The absence of typed checkout data caps the factual fit. 18 U.S.C. § 2510(8); compare In re BPS Direct, which found standing for alleged surreptitious session-replay capture of payment/billing information but not for generalized browsing allegations alone. (law.justia.com) |
Key Takeaway
The sharper litigation theory is not that trackers merely loaded: it is that, after an express essential-only selection, Google endpoints continued receiving persistent identifiers plus product, size, cart, and value data. WESCA presents the more consequential exposure path for a Pennsylvania session; the federal ECPA claim is more vulnerable to party/consent and crime-tort defenses.
Key Observations
- The Initial Cookie Banner Visual Check was “Yes”; the initial screenshot and post-scroll privacy-interface screenshots show a conspicuous “Cookies and Tracking Pixels” banner before the reject action.
- After “Accept only essential cookies” and reload, the run still recorded 16 tracker hits across Google Ads, Google Analytics, and Amazon-related endpoints.
- Post-reject shopping transmitted product-page and add-to-cart data to GA/Ads, including the joggers, Black color, Medium size, SKU, and $33.60 value.
- The checkout screenshot shows contact, delivery, and payment fields were visible but untouched; this run does not establish capture of typed personal, shipping, or payment data.
Authorities & Litigation Signals
- Popa v. Harriet Carter Gifts, Inc. is the closest Pennsylvania authority: undisclosed third-party routing of website interactions can support a WESCA interception theory, while notice and consent remain fact-intensive. (www2.ca3.uscourts.gov)
- In re BPS Direct is useful downside calibration: session-replay allegations tied to captured payment data supported standing, whereas ordinary browsing allegations did not. The present run falls between those poles because it shows cart/product content but no entered checkout data. (law.justia.com)
- Price v. Carnival Corp. is factually analogous on third-party session-replay processing and weak cookie-banner consent arguments, but it involved alleged capture of materially more sensitive information than this run. (law.justia.com)
- Braun v. Philadelphia Inquirer signals Pennsylvania settlement pressure around pixel deployment: final approval covered a $1.125 million fund and prospective Meta Pixel restrictions/disclosure measures, although its video-page facts differ from this retail journey. (docs.justia.com)
Screenshots
Agent Steps
| Time | Step | Message |
|---|---|---|
| 21:06:36 | Configure geo proxy | |
| 21:07:13 | Capture the page before scrolling | |
| 21:07:26 | Check whether a cookie banner is visible | |
| 21:07:35 | Scroll to bottom (reveal footer privacy choices) | |
| 21:07:36 | Capture checkpoint 'pre consent' | |
| 21:07:43 | Look for privacy choices | |
| 21:07:52 | Click reject all button | |
| 21:08:11 | Check for internal preference modal | |
| 21:08:33 | Reload page | |
| 21:08:35 | Capture checkpoint 'post reject' | |
| 21:10:51 | Post-consent workflow step 1.1: Click element 3753 | |
| 21:10:51 | Post-consent workflow step 2.1: Click element 7915 | |
| 21:10:51 | Post-consent workflow step 3.1: Click element 14067 | |
| 21:10:51 | Post-consent workflow step 3.2: Click element 14099 | |
| 21:10:51 | Post-consent workflow step 4.1: search page | |
| 21:10:51 | Post-consent workflow step 4.2: Scroll True | |
| 21:10:51 | Post-consent workflow step 5.1: Click element 18309 | |
| 21:10:51 | Post-consent workflow step 6 | |
| 21:10:51 | Post-consent workflow step 7.1: done | |
| 21:10:53 | Capture checkpoint 'post checkout journey' |
Tracking Audit Summary
Pre Consent