ConsentPixel – Privacy · Verified

Plaintiff firms scan thousands of sites a day

For US businesses

Your website is being watched — by the people who sue over it.

CIPA demand letters go out by the thousands, auto-generated from free scans that check whether your trackers fire before a visitor consents. Small businesses are the prime target. ConsentPixel blocks those trackers first — one pixel, any platform, live in ten minutes.

No credit card · From $8.99/mo · Or scan first — the same way plaintiff firms do, in 10 seconds

4,700+
Wiretap-style lawsuits filed against websites since 2022 — and climbing
$15K–40K
Typical demand-letter ask — priced as a nuisance you'll settle to make go away
3,000+
Businesses sued under CIPA, per the Stop CIPA Shakedowns coalition
Any state
You can be sued wherever a California visitor lands on your site — location is no shield
"

Sometimes it's "are we going bankrupt?" and sometimes "are we buying that house?" That's just how it is running a small business.

A husband-and-wife HVAC business in Folsom, California — started May 2025, sued under CIPA in February 2026, six months in, for the same analytics tools they used to track their own ad performance.

This isn't a big-company problem

The targets aren't who you'd think

It's tempting to assume these lawsuits chase the Forbes and CNN-sized names. They don't. Small and mid-sized businesses are the prime targets — precisely because they're least likely to have a lawyer on retainer or a technical team watching what their website loads.

The tools in question aren't exotic. They're the Meta Pixel, Google Analytics, a Hotjar session recorder, a chat widget — the exact stack running on almost every business website in America, usually installed once and forgotten. You don't have to have done anything unusual to get a letter. You just have to have a website.

How the demand-letter machine runs

It's automated, and it's aimed at your site

Plaintiff firms and pro se litigants have turned this into a volume business. Understanding the four steps is the fastest way to see where it breaks — and where ConsentPixel steps in.

1

Automated scan

Crawlers visit thousands of sites a day with a fresh, zero-cookie session — watching which trackers fire before any consent is given.

2

Templated letter

A near-identical demand letter goes out, citing CIPA and often stacking ECPA and CDAFA claims, with a draft complaint attached.

3

Nuisance demand

The ask lands around $15K–$40K — calibrated to be cheaper than hiring a defense lawyer, so you settle just to end it.

4

Repeat

The same boilerplate is filed against the next site, and the next. It scales because most sites fail the very first step: trackers firing pre-consent.

🔍
See your site the way a plaintiff firm does Free scan — fresh session, zero cookies. Ten seconds, no account.
Scan your site free →

Why the usual assumptions don't protect you

Four things business owners get wrong about this

Most owners believe one of these — and each one is the reason a solvable problem turns into a settlement cheque.

📍

"I'm not in California."

Doesn't matter. CIPA reaches any site a California resident visits. Businesses across the US — and even Canada — have been targeted. Your location is not a defense.

🍪

"I already have a cookie banner."

A banner that appears while trackers are already firing is exactly the failure these scans catch. What matters is whether tags actually wait for consent — most banners don't enforce that.

🛡️

"My insurance covers it."

Often it doesn't. General liability and cyber policies frequently exclude private privacy-violation claims like these — leaving the demand, and the defense costs, on you.

"A law will fix this soon."

SB 690, the bill that would exempt routine commercial tracking, stalled in the California Assembly. Even if revived, it couldn't take effect before 2027. The exposure is live right now.

💸

"I'll just fight it."

Defending is usually more expensive than the demand — which is the entire point of the pricing. Even a meritless claim costs real money to investigate and answer.

🔁

"I settled once, I'm done."

Settling without fixing the underlying tracking invites the next claim — including allegations you're now misrepresenting your compliance. The only durable fix is technical.

The fix is technical, not legal

One pixel closes the gap they scan for

Every one of these lawsuits turns on the same fact: trackers ran before the visitor consented. ConsentPixel makes that impossible — and gives you the record to prove it.

🚫

Blocks trackers before consent

Hotjar, FullStory, the Meta Pixel, Google Analytics, chat widgets — all held until your visitor opts in. The pre-consent firing that scans flag simply doesn't happen.

The core fix

Live in 10 minutes

One script tag in your site's header. No plugins to wrangle, no developer to hire, no platform migration. Paste it and you're covered across every page.

🌐

Works on any platform

WordPress, Shopify, Wix, Squarespace, Webflow, WooCommerce — anything that lets you add a script. One approach, every stack.

🗄️

Keeps a consent record

Every consent is logged with a timestamp — an immutable, exportable record of who agreed to what and when, so you can show trackers waited.

Your evidence
🔍

Watches for drift

Websites change — a new marketing tag appears and quietly reopens your exposure. ConsentPixel keeps scanning so a Friday-afternoon pixel doesn't become Monday's demand letter.

🇺🇸

CIPA-first, US-built

This is what ConsentPixel was made for. Not a GDPR tool with a US bolt-on — a platform built around the American wiretap-litigation problem, with CCPA and state laws covered too.

Purpose-built

From exposed to protected

Covered before the end of the day

No procurement, no project. Four steps from a free scan to trackers that wait for consent.

1

Scan your site — see what a plaintiff firm would

Run the free scanner. In ten seconds you get the same view the crawlers get: every tracker firing before consent, ranked by risk. No account, no card.

2

Add one pixel

Paste a single script tag into your <head> — five minutes on WordPress, Shopify, or any platform. It covers every page automatically.

3

Publish your consent banner

Match it to your brand in the visual builder and publish. From that moment, non-essential trackers are held until each visitor opts in — and the consent log starts recording.

4

Rescan and confirm

Run the scan again. The flags that were red are now blocked. You've closed the exact gap the demand-letter machine is built to find.

Why owners install it

Peace of mind in ten minutes

★★★★★

"I had no idea Hotjar was recording keystrokes on my checkout page without consent. The scanner found it in 30 seconds. This should be mandatory for every store."

RM
Ryan M.Shopify store owner
★★★★★

"We got a demand letter in the mail and I panicked. Scanned the site, saw exactly what they saw, installed the pixel that afternoon. Rescan came back clean. Ten minutes, done."

TG
Tara G.Service business owner · California
★★★★★

"I'm not technical and I don't have a developer. One script tag, pasted where they told me, and my trackers finally wait for consent. That's the whole thing I was scared I couldn't fix."

DP
Devin P.WordPress site owner

Close the gap before the next letter goes out

One pixel, any platform, live in ten minutes — from $8.99/mo. Start your 14-day free trial and stop being the easy target.

Business-owner questions

What owners ask first

I just got a CIPA demand letter. What do I do?
First, don't ignore it — these letters are designed to prompt a quick response, and ignoring one can lead to a lawsuit being filed. Talk to a qualified attorney about the letter itself; that part is a legal decision, and ConsentPixel isn't a law firm. What you can do immediately on the technical side is close the underlying gap: scan your site to see which trackers are firing before consent, then block them so the same problem can't be found again. Fixing the tracking is the step that stops you being an easy repeat target.This is general information, not legal advice. Consult an attorney about any demand letter you receive.
I'm not based in California. Am I actually at risk?
Yes. CIPA can apply wherever a California resident visits your website — you don't have to be located in California to be targeted. Businesses across the US, and even in Canada, have received demand letters and lawsuits. If you get any meaningful traffic from California (most US sites do), this is relevant to you.Not legal advice.
I already have a cookie banner. Isn't that enough?
Often not. The problem these scans catch is trackers firing before anyone interacts with your banner. If your Meta Pixel or session recorder loads the moment someone lands on the page, a banner shown afterward doesn't undo it. What matters is whether your tags actually wait for consent — and most default banners don't enforce that. ConsentPixel blocks non-essential trackers until the visitor opts in, which is the part that closes the gap.
Which tools get sites flagged?
The common ones: the Meta (Facebook) Pixel, Google Analytics, TikTok pixel, session-replay tools like Hotjar and FullStory, chat widgets, and heatmaps — especially on checkout, search, or form pages where they can capture what someone types. The free scan inventories exactly which of these are on your site and which fire before consent.
How much does it actually cost, and how long to set up?
Plans start at $8.99/month per domain, with a 14-day free trial and no credit card to start. Setup is one script tag in your site's header — about five minutes on WordPress, Shopify, Wix, or Webflow — and it covers every page automatically. Most owners go from scan to protected in well under an afternoon.
Won't blocking trackers break my analytics and ads?
No — it changes when they fire, not whether they work. Once a visitor consents, your tags run normally, and ConsentPixel signals consent to Google and other platforms so measurement continues for consenting visitors. What you lose is the pre-consent data you weren't supposed to be collecting anyway — the exact data that creates the exposure.
Isn't a law coming that makes this go away?
Not soon. SB 690 — the California bill that would carve out routine commercial tracking — stalled in the Assembly and was reclassified as a two-year bill. Even in the best case it couldn't take effect before 2027, and the litigation is very active in the meantime. Waiting for a law to rescue you leaves you exposed through the period when the demand letters are actually being sent.Not legal advice.
Do I need to be technical to use this?
No. If you can paste a line of code into your site's header — or ask whoever built your site to do it once — you're set. There are no plugins to configure and no developer required. The banner is built visually in your dashboard, and everything runs from that single pixel.

Stop being the easy target

Scan your site the way plaintiff firms do, then close the gap with one pixel. Ten minutes today beats a demand letter tomorrow.

No credit card · From $8.99/mo · Any platform · Live in 10 minutes

CIPA · CCPA · state privacy laws Any platform Blocks 2,000+ trackers before consent Used by 500+ websites
Scroll to Top