Demand letter response · Free scan · No signup
Received a CIPA demand letter?
You’re one of thousands of businesses that got one this year. Before you respond — or pay — see the evidence the letter is built on: a free scan shows every tracker your site fires before visitors consent, graded in 90 seconds.
Letter in hand and need to move fast?
Book a 20-min call — we’ll walk your scan results and show what a fix looks like.
Why you got this letter
CIPA — the California Invasion of Privacy Act — carries $5,000 per violation in statutory damages with no proof of harm required. Plaintiffs’ firms and individual claimants run automated tooling that scans websites for trackers firing before consent, then send templated letters in batches. More than 800 CIPA suits were filed in 2025 alone, and pen-register (“trap and trace”) filings under § 638.51 grew from roughly 600 to over 4,000. Your site was almost certainly found by a scanner, not an investigator.
- $5,000statutory damages per violation, no harm required
- 4,000+pen-register / trap-and-trace claims and counting
- 800+CIPA suits filed in 2025 alone
Recognize the letterhead?
A handful of senders account for most of the volume. If your letter matches one of these, you are one of hundreds of recipients of a template campaign — which changes how your counsel will price it. Everything below is drawn from court records and legal-industry reporting.
Vivek Shah
Pro se claimantThe highest-volume individual sender of 2025–26, with thousands of letters over search bars, cookies, and analytics under § 638.51. In July 2026 a federal judge declared him a vexatious litigant, restricting his future filings in the Central District of California.
Swigart Law Group, APC
Law firm (San Diego)A leader of the CIPA mass-arbitration wave: batches of individual arbitration demands over Meta/TikTok pixels, session replay, and chatbots, with demands reported as high as $900,000 and the same claimants recycled across many targets.
Pacific Trial Attorneys, APC
Law firm (Newport Beach)Pioneered the chat-widget wiretapping theory under § 631 and has filed hundreds of cases through a stable of repeat "tester" plaintiffs, later pivoting to § 638.51 pen-register arbitration demands.
Tauler Smith LLP
Law firm (Los Angeles)Sent pen-register demand letters over Google Analytics, Hotjar, and the Meta pixel to hundreds of businesses. In an earlier demand-letter campaign, a federal jury found the firm liable under RICO, with roughly $895,000 in fees awarded against it.
Srinivas Rangam
Individual claimantMass pre-litigation demand letters across ecommerce, healthcare, and SaaS sites, mostly CIPA-based with parallel claims under Pennsylvania, Florida, and Illinois wiretap statutes.
Manning Law, APC
Law firm (Newport Beach)Dozens of website-tracking suits across California courts, often combining CIPA claims with ADA accessibility claims, through repeat plaintiffs who have individually filed 100+ cases in a year.
↗ Buchanan Ingersoll: the next wave of web-wiretapping claims
What to do in the first 48 hours
- 1
Don’t ignore it — but don’t pay it today either
These letters usually carry a response deadline and settle for four to five figures precisely because that is cheaper than a defense. Ignoring one can turn a letter into a filed complaint or arbitration demand; paying immediately marks you as a soft target. You have time to understand your actual exposure first.
- 2
Find out what your site actually exposes
Every one of these claims is built on the same evidence: trackers that fire before a visitor consents. The free scan above loads your site from a California IP without touching the consent banner and records every pixel, cookie, session-replay script, and chat widget that fires — the same picture the sender’s tooling captured. Knowing whether the claim is accurate changes every decision that follows.
- 3
Stop the pre-consent tracking now
CIPA claims accrue per violation, so trackers that keep firing while you deliberate keep adding theoretical damages. Blocking pixels, analytics, and session replay until after consent doesn’t erase past exposure, but it caps it — and a documented fix date is something your counsel will want.
- 4
Bring the letter and the scan report to defense counsel
Whether to respond, negotiate, or contest is a legal call — CIPA defense outcomes vary a lot by claim theory, letterhead, and forum, and several pen-register theories have been rejected outright by California courts. A defense attorney who has handled these letters can price yours quickly. PieEye is not a law firm and nothing on this page is legal advice.
CIPA demand letter FAQ
- Is a CIPA demand letter legitimate? Can they really sue over a chat widget or pixel?
- The legal theory is real: CIPA carries $5,000 per violation in statutory damages with no proof of harm required, and courts have allowed claims over chat widgets, session replay, and tracking pixels to proceed. But outcomes vary widely — several courts have rejected the pen-register (§ 638.51) theory, and in 2025 one court dismissed a serial "tester" plaintiff for lack of standing. Most letters are templates sent in bulk, not the product of an investigation into your business specifically.
- What do CIPA demand letters settle for?
- Defense-side publications report typical individual settlements in the four-to-low-five-figure range, with mass-arbitration campaigns demanding far more before negotiating down. The senders’ economics rely on settlements being cheaper than defense costs. What a specific letter is worth depends on the claim theory, the sender’s track record, and what your site actually does — which is why the scan matters.
- If I fix my website, does the claim go away?
- No — fixing pre-consent tracking stops new violations from accruing but does not extinguish claims about past conduct. It does materially improve your position: it caps exposure, removes the ongoing-violation leverage from any follow-up letter, and takes you off the target list these campaigns rescan.
- What is a "pen register" or "trap and trace" demand letter?
- CIPA § 638.51 prohibits installing a device that captures dialing or routing information without consent. Since a 2023 ruling that software can qualify as a pen register, plaintiffs have applied it to analytics scripts, pixels, and search bars that capture visitor identifiers like IP addresses. It is now the highest-volume CIPA theory — filings grew from roughly 600 to more than 4,000 — though several California courts have rejected it as applied to ordinary web analytics.
- I got a similar letter about a Florida statute (FSCA). Is that the same thing?
- It is the same playbook under Florida’s wiretap statute, the Florida Security of Communications Act. A March 2025 federal ruling opened the door, and hundreds of FSCA suits and small-claims actions have followed. The same scan covers FSCA — or use the dedicated Florida scanner.
- Will PieEye tell me whether to pay or fight?
- No. PieEye is not a law firm and does not give legal advice. What we give you is the factual record: exactly which trackers fire on your site before consent, graded against CIPA, FSCA, and three other regimes — the evidence baseline you and your attorney need to evaluate the letter. Fixing what the scan finds is what our consent platform does.
Go deeper
PieEye is a privacy-compliance software company, not a law firm. Nothing on this page is legal advice, and reading it does not create an attorney–client relationship. Statements about specific senders are drawn from the cited court records and legal-industry publications. If you have received a demand letter or arbitration demand, consult a licensed attorney about your specific situation.