ConsentPixel – Privacy · Verified

⚠ Mixed result · Claims survived, class denied

Ingraham v. Capital One Financial Corp.

The most important financial-data CIPA case of 2026 has two faces. The claims survived dismissal because the data at issue — credit outcomes, income, FICO segments — was genuinely sensitive. Then the class was denied because tracking harms are inherently individual. Here's the full breakdown, and why both halves matter for your site.

ConsentPixel Research Published July 6, 2026 11 min read CIPA §631 · sensitive financial data
⚖️ Case snapshot
Court
U.S. District Court, N.D. California (Judge Trina L. Thompson)
Case No.
3:24-cv-05985-TLT (docketed as Shah v. Capital One)
Filed
August 26, 2024
Status (as of Jul 2026)
Claims survived (May 2026) · class certification denied (Jun 16, 2026)
Tracking tech
Meta Pixel, Google & Adobe Analytics, DoubleClick, Tealium, BioCatch, Snowplow, New Relic, Skai
Defendant
Capital One Financial Corp. — credit-card application & pre-approval site

What the case is about

In August 2024, a group of Capital One customers and credit-card applicants — the case is captioned Shah v. Capital One on the docket, but is widely known by co-plaintiff Gary Ingraham's name — sued the bank over the tracking technology on its credit-card application and pre-approval website.[5] The allegation wasn't that Capital One suffered a data breach. It was that the bank had quietly built third-party tracking into the most sensitive pages a consumer can visit: the ones where you type in your income, your employment, and apply for credit.

According to the complaint, Capital One's application pages ran a deep stack of third-party tools — the Meta Pixel, Google Analytics, Adobe Analytics, DoubleClick, New Relic, Skai/Kenshoo, Snowplow, BioCatch, and Tealium — that did more than measure traffic. They allegedly transmitted, to outside advertising and analytics companies, information including employment status, bank account type, citizenship and dual-citizenship status, credit-card pre-approval and approval/denial outcomes, FICO score segments, income bands, names, email addresses, and phone numbers.[1]

The human detail that anchored the case: plaintiff Gary Ingraham allegedly applied for a Capital One card, was denied — and then began seeing credit-card ads from Discover, Chase, and Chime in his Facebook feed. Co-plaintiff Deia Williams described the same pattern, saying she was "constantly bombarded" with credit-card ads after her own denial.[4] To the plaintiffs, that was proof their financial circumstances had been broadcast to the ad-tech ecosystem. None of them, they said, had signed any authorization to send that data to third or fourth parties.

Why this case stands out. Most 2026 CIPA cases involve routine analytics and behavioural pixels on ordinary pages. Ingraham is different in kind: the pages are credit applications, and the data is financial eligibility information. That single fact — sensitivity — is what drives every important ruling in the case.

The legal theory — §631 and the "sensitive data" injury

The plaintiffs brought a stack of claims, but the ones that matter here are under the California Invasion of Privacy Act (CIPA) §631 — the wiretapping/interception provision — alongside the federal Electronic Communications Privacy Act (ECPA) and the California Consumer Privacy Act (CCPA). Unlike the pen-register theory driving many other 2026 cases, §631 targets the interception and unauthorized disclosure of the contents of a confidential communication to a third party.[7]

Capital One moved to dismiss on the arguments defendants usually win with: that visitors consented via the posted privacy policy, that no third party read anything "in transit," and that the plaintiffs hadn't suffered any concrete injury. The bank's strongest card was Article III standing — the doctrine that has quietly become the most powerful defense in tracking litigation. Courts increasingly refuse to treat the mere presence of a pixel as a real-world harm; a plaintiff has to show something private was actually disclosed and that a reasonable person would object.[3]

The standing question that decides these cases

Across 2026, courts have drawn a sharp line between routine behavioural metadata (which pixels collect all the time, and which increasingly fails to establish a concrete injury) and genuinely sensitive data — medical, financial, or highly personal information — whose disclosure a reasonable user would find "highly offensive." Where a case falls on that line usually determines whether it survives.

Why the claims survived

On the motion to dismiss — decided in May 2026 — Judge Trina L. Thompson let the core privacy claims proceed. The CIPA §631, ECPA, CCPA, negligence, and unjust-enrichment claims all survived.[5] The reason was exactly the sensitivity point: this wasn't vague "we collected personal information" pleading. The plaintiffs identified specific, sensitive financial data — approval/denial outcomes, income bands, FICO segments — allegedly disclosed to advertisers. On the consent argument, the court followed the Javier v. Assurance IQ line, holding that whether visitors actually consented through a privacy policy is a fact question that can't be resolved on a motion to dismiss.[4]

"Courts are increasingly unwilling to treat every cookie, pixel, beacon, SDK, or session-replay tool as a constitutional injury. But Ingraham shows that the analysis changes when the alleged data involves financial eligibility, employment, citizenship, income, FICO segments, [or] application denial..."

— Security Boulevard analysis of the Ingraham dismissal order

The one plaintiff who lost — and why

In the same order, the court delivered a sharp lesson in how standing actually works. It dismissed Gary Ingraham himself from the case — not because his data was less sensitive, but because of what he did after filing suit: he submitted two more credit-card applications on Capital One's website.[3] You cannot credibly claim a reasonable expectation of privacy in data you keep voluntarily handing to the same company you're suing. Co-plaintiff Deia Williams, who did not do this, retained standing and carried the case forward.[8]

A quietly important detail: the court dismissed Ingraham's claims on his own conduct, not on the merits of the tracking. Standing is not abstract — courts look at what the plaintiff actually did. But note the flip side: Williams survived, which means the underlying tracking claims against Capital One are very much alive.

The turning point: surviving dismissal isn't winning

Here is what makes Ingraham genuinely important, and why it's more than "another pixel case." Surviving a motion to dismiss is the stage most defendants fear — it's the point where settlement pressure becomes enormous, because a class-wide judgment in a financial-data wiretapping case can reach eight or nine figures.[6] Plaintiffs' firms bank on that pressure. But in June 2026, the case reached the next stage — class certification — and the story reversed.

On June 16, 2026, Judge Thompson denied class certification for both the proposed nationwide class and the California subclass.[2] To certify a class under Rule 23(b)(3), plaintiffs must show that common questions "predominate" over individual ones. In tracking cases, that is proving very hard to do — and the court identified three independent reasons the individual questions overwhelmed the common ones:

Why the class was denied — three independent predominance problems 1 Data varied Different tools captured different data for different users. No single class-wide proof. 2 Consent varied Whether each user consented needs an individual look at what they saw and understood. 3 Injury varied One plaintiff had standing, another didn't. That same check is needed for every class member. Any one of these was enough on its own to defeat "predominance" under Rule 23(b)(3) — so no class could be certified.
The class-certification firewall. The very thing that makes tracking claims survive dismissal — fact-specific questions about data, consent, and harm — is what makes them nearly impossible to try as a single class.

The deep irony is that the plaintiffs' claims survived dismissal because the questions of consent and sensitive-data disclosure were fact-specific — and then failed certification for the same reason: fact-specific questions can't be answered class-wide.[2] What helps a plaintiff at the pleading stage sinks them at certification.

Where it stands (as of July 2026)

As of July 2026, the litigation is in an unusual posture. The individual claims survive — named plaintiff Deia Williams cleared standing and her CIPA §631, ECPA, and CCPA claims against Capital One remain live. But there is no class: the June 16, 2026 order means the case can no longer be pursued on behalf of the thousands of applicants whose data was allegedly shared, only on behalf of the individual plaintiff(s) who remain.[2] That transforms the economics — from a potential nine-figure class exposure to an individual dispute.

A note on sourcing and naming. The case is docketed as Shah v. Capital One Financial Corp., No. 3:24-cv-05985 (N.D. Cal.), before Judge Trina L. Thompson, but is commonly cited as Ingraham v. Capital One in legal commentary. Facts here are drawn from the court's orders as reported by Fisher Phillips, Fenwick, Benesch, Bloomberg Law, Law360, and the public docket — all listed in Sources. Litigation status can change; this reflects the record as of July 6, 2026.

How Ingraham fits the 2026 landscape

Ingraham sits at the intersection of two of the most important trends in 2026 tracking litigation. On the merits, it's the flagship "sensitive data changes everything" case — the clearest illustration that financial and eligibility data is treated very differently from routine browsing metadata. On procedure, it's now a leading example of the emerging "class certification firewall." Read alongside its siblings, the pattern is unmistakable:

CaseCourtWhat it held
Ingraham v. Capital One (this case)N.D. Cal.Sensitive financial data kept CIPA §631 claims alive; class certification then denied — individualized data, consent, and injury.
Calhoun v. GoogleN.D. Cal. (Jun 2025)Class certification denied on consent grounds — individualized questions about user knowledge predominated.[2]
In re Meta Pixel Tax Filing CasesN.D. Cal. (Mar 2026)Certification denied — individualized standing and statute-of-limitations issues predominated.[2]
Torres v. PrudentialN.D. Cal. (Apr 2025)Summary judgment for defendant — §631 needs real-time reading of contents, not post-hoc data capture.[9]

The through-line: even when a website-tracking claim is strong enough to survive dismissal — especially on sensitive data — the individualized nature of consent, data flow, and injury makes class treatment increasingly hard to obtain in the Northern District of California. For plaintiffs, that removes much of the settlement leverage. For businesses, it's a reason to defend rather than fold.[6]

But read it honestly. A denial of class certification is not a ruling that the tracking was lawful. Williams's individual claims survive, and the court never held that Capital One's data-sharing was permissible — only that the case couldn't be tried as a class. A business relying on "we'll just beat certification" is betting on procedure, not fixing the underlying exposure.

Why this case matters for website operators

For most website owners, the single most useful takeaway is the sensitivity gradient. If your site collects and could transmit genuinely sensitive data — financial eligibility, health information, application outcomes, income — you are in Ingraham territory, where courts take the alleged injury seriously and claims survive dismissal. If your site collects routine marketing analytics, you're in a very different, much lower-risk position, and standing defenses tend to work.[3] The lesson isn't "tracking is fine now" — it's "the stakes scale with the sensitivity of what your trackers can see."

The second takeaway is subtler and more strategic. Ingraham tells businesses that even a claim that survives dismissal may never become a class — which changes the settle-or-fight calculation. But that is a litigation advantage, available only after you've been sued, spent months in discovery, and paid to brief a certification fight. It is not a substitute for not having the exposure in the first place. The cheapest case is the one that never gets filed because your trackers weren't firing on your application pages before consent.

The trap to avoid: "Courts are denying these classes, so tracking lawsuits are dying." That misreads the case badly. Demand letters and individual suits are still landing every day,[6] financial and sensitive-data claims still survive dismissal, and defeating certification still costs a fortune. Ingraham lowers the ceiling on class exposure — it does nothing to stop the letter arriving.

What this means for your site

The durable lesson from Ingraham is about where your trackers run and what they can see. Capital One's exposure came from third-party tools firing on credit-card application pages — the exact pages where the most sensitive data is entered. The single most protective thing any site can do is ensure that non-essential third-party trackers do not fire on sensitive pages (checkout, application, account, health, or financial forms) before a visitor has consented — and ideally not at all on those pages.

That is precisely what ConsentPixel is built to do: block third-party trackers until a visitor opts in, keep them off the pages where sensitive data lives, and log every consent decision so you have a record if a demand letter arrives. The Javier-style consent question that kept Capital One in court — "did the visitor actually, provably consent before anything fired?" — is exactly the question a proper consent record answers in your favour.

And because this entire dispute began with a stack of third-party tags on the defendant's pages — nine separate tools, several of which a site owner might not even realise were transmitting form data — the first, cheapest step is simply seeing what actually runs on your pages, and whether any of it fires before consent on the pages that matter most.

Worried your site has this exposure?

Scan free in about 10 seconds to see every third-party tracker firing on your site — including the ones loading on sensitive pages before consent, exactly the pattern at the heart of this case. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What was Ingraham v. Capital One about?
Credit-card applicants alleged that Capital One's application and pre-approval website used third-party trackers (Meta Pixel, Google and Adobe Analytics, Tealium, BioCatch and others) that transmitted sensitive financial data — credit approval/denial outcomes, income bands, FICO segments, employment and citizenship status — to advertisers and analytics firms without consent, in alleged violation of CIPA §631, ECPA, and the CCPA. It's docketed as Shah v. Capital One, No. 3:24-cv-05985 (N.D. Cal.).
Did Capital One win or lose?
Both, in different ways. In May 2026 the court let the core CIPA, ECPA, and CCPA claims survive dismissal because the data was genuinely sensitive — a loss for Capital One on the merits. But in June 2026 the court denied class certification, meaning the case can't proceed on behalf of thousands of applicants, only the individual named plaintiff. That's a major practical win for Capital One, because it removes the class-wide exposure that drives large settlements.
Why was one plaintiff (Gary Ingraham) dismissed?
The court dismissed Ingraham for lack of standing because, after filing the lawsuit, he submitted two more credit-card applications on Capital One's website. The court reasoned that you can't claim a reasonable expectation of privacy in data you keep voluntarily providing to the company you're suing. Co-plaintiff Deia Williams, who didn't do this, kept her standing and the case continued.
Does denying class certification mean the tracking was legal?
No. The court did not rule that Capital One's data-sharing was lawful. It ruled only that the case couldn't be tried as a class because individual questions about data, consent, and injury predominated. The individual named plaintiff's claims survive. This is general information, not legal advice.
What's the practical takeaway for website owners?
Sensitivity drives risk. If your site collects financial, health, or eligibility data, keep non-essential third-party trackers off those pages and don't let them fire before consent — that's the exact pattern that kept Capital One in court. Maintain a record of consent decisions so you can answer the "did they actually consent?" question. Don't rely on beating class certification later; it's expensive and only available after you've been sued.

Sources

  1. Security Boulevard — "Give a Mouse a Cookie: California Court Partially Dismisses Cookie Tracking Case Against Capital One". Lists the nine tracking tools and the sensitive-data categories; summarises the standing analysis.
  2. Fisher Phillips LLP — "California Federal Court's Denial of Class Certification May Reshape Website Tracking Litigation" (June 16, 2026 decision; predominance analysis; Calhoun and Meta Pixel Tax comparisons).
  3. Fisher Phillips LLP — "What 7 Recent Court Decisions Tell You About Today's Website Privacy Liability" ("Ingraham v. Capital One: Financial Data Changes Everything"; the post-filing reapplication standing point).
  4. FindLaw — Shah v. Capital One Financial Corporation, Order on Motion to Dismiss (N.D. Cal.). Primary order text; plaintiff allegations and the Javier consent analysis.
  5. Benesch Law — "Tracking Technology Trouble: Shah v. Capital One Deepens Legal Risk Under CCPA and CIPA". Which claims survived and which were dismissed (CRA/SCA/CFAA).
  6. CyberAdviser (Blank Rome) — "Another Internet Tracking Class Action Failed at Certification — Here's Why It Matters". Settlement-pressure economics and the defend-vs-settle calculus.
  7. IAPP — "Beyond data breaches: Court ruling signals broader CCPA liability for tracking technologies". Background on CIPA §631 and ECPA as applied to website trackers.
  8. Bloomberg Law — "Capital One Fails to Escape Suit Over Meta, Google Data Sharing" (Williams retained standing; Ingraham dismissed; Judge Thompson, May 2026).
  9. Fenwick — "California Federal Court Denies Class Certification in CIPA Pixel-Tracking Case". The N.D. Cal. class-certification-denial trend.
  10. CourtListener — Shah v. Capital One Financial Corporation, No. 3:24-cv-05985 (N.D. Cal.). Public docket; filing date and case history.

Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the case is docketed as Shah v. Capital One Financial Corp., No. 3:24-cv-05985 (N.D. Cal.), before Judge Trina L. Thompson. Status is stated as of July 6, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top