For US businesses
Your website is being watched — by the people who sue over it.
CIPA demand letters go out by the thousands, auto-generated from free scans that check whether your trackers fire before a visitor consents. Small businesses are the prime target. ConsentPixel blocks those trackers first — one pixel, any platform, live in ten minutes.
No credit card · From $8.99/mo · Or scan first — the same way plaintiff firms do, in 10 seconds
Sometimes it's "are we going bankrupt?" and sometimes "are we buying that house?" That's just how it is running a small business.
This isn't a big-company problem
The targets aren't who you'd think
It's tempting to assume these lawsuits chase the Forbes and CNN-sized names. They don't. Small and mid-sized businesses are the prime targets — precisely because they're least likely to have a lawyer on retainer or a technical team watching what their website loads.
The tools in question aren't exotic. They're the Meta Pixel, Google Analytics, a Hotjar session recorder, a chat widget — the exact stack running on almost every business website in America, usually installed once and forgotten. You don't have to have done anything unusual to get a letter. You just have to have a website.
How the demand-letter machine runs
It's automated, and it's aimed at your site
Plaintiff firms and pro se litigants have turned this into a volume business. Understanding the four steps is the fastest way to see where it breaks — and where ConsentPixel steps in.
Automated scan
Crawlers visit thousands of sites a day with a fresh, zero-cookie session — watching which trackers fire before any consent is given.
Templated letter
A near-identical demand letter goes out, citing CIPA and often stacking ECPA and CDAFA claims, with a draft complaint attached.
Nuisance demand
The ask lands around $15K–$40K — calibrated to be cheaper than hiring a defense lawyer, so you settle just to end it.
Repeat
The same boilerplate is filed against the next site, and the next. It scales because most sites fail the very first step: trackers firing pre-consent.
Why the usual assumptions don't protect you
Four things business owners get wrong about this
Most owners believe one of these — and each one is the reason a solvable problem turns into a settlement cheque.
"I'm not in California."
Doesn't matter. CIPA reaches any site a California resident visits. Businesses across the US — and even Canada — have been targeted. Your location is not a defense.
"I already have a cookie banner."
A banner that appears while trackers are already firing is exactly the failure these scans catch. What matters is whether tags actually wait for consent — most banners don't enforce that.
"My insurance covers it."
Often it doesn't. General liability and cyber policies frequently exclude private privacy-violation claims like these — leaving the demand, and the defense costs, on you.
"A law will fix this soon."
SB 690, the bill that would exempt routine commercial tracking, stalled in the California Assembly. Even if revived, it couldn't take effect before 2027. The exposure is live right now.
"I'll just fight it."
Defending is usually more expensive than the demand — which is the entire point of the pricing. Even a meritless claim costs real money to investigate and answer.
"I settled once, I'm done."
Settling without fixing the underlying tracking invites the next claim — including allegations you're now misrepresenting your compliance. The only durable fix is technical.
The fix is technical, not legal
One pixel closes the gap they scan for
Every one of these lawsuits turns on the same fact: trackers ran before the visitor consented. ConsentPixel makes that impossible — and gives you the record to prove it.
Blocks trackers before consent
Hotjar, FullStory, the Meta Pixel, Google Analytics, chat widgets — all held until your visitor opts in. The pre-consent firing that scans flag simply doesn't happen.
The core fixLive in 10 minutes
One script tag in your site's header. No plugins to wrangle, no developer to hire, no platform migration. Paste it and you're covered across every page.
Works on any platform
WordPress, Shopify, Wix, Squarespace, Webflow, WooCommerce — anything that lets you add a script. One approach, every stack.
Keeps a consent record
Every consent is logged with a timestamp — an immutable, exportable record of who agreed to what and when, so you can show trackers waited.
Your evidenceWatches for drift
Websites change — a new marketing tag appears and quietly reopens your exposure. ConsentPixel keeps scanning so a Friday-afternoon pixel doesn't become Monday's demand letter.
CIPA-first, US-built
This is what ConsentPixel was made for. Not a GDPR tool with a US bolt-on — a platform built around the American wiretap-litigation problem, with CCPA and state laws covered too.
Purpose-builtFrom exposed to protected
Covered before the end of the day
No procurement, no project. Four steps from a free scan to trackers that wait for consent.
Scan your site — see what a plaintiff firm would
Run the free scanner. In ten seconds you get the same view the crawlers get: every tracker firing before consent, ranked by risk. No account, no card.
Add one pixel
Paste a single script tag into your <head> — five minutes on WordPress, Shopify, or any platform. It covers every page automatically.
Publish your consent banner
Match it to your brand in the visual builder and publish. From that moment, non-essential trackers are held until each visitor opts in — and the consent log starts recording.
Rescan and confirm
Run the scan again. The flags that were red are now blocked. You've closed the exact gap the demand-letter machine is built to find.
Why owners install it
Peace of mind in ten minutes
"I had no idea Hotjar was recording keystrokes on my checkout page without consent. The scanner found it in 30 seconds. This should be mandatory for every store."
"We got a demand letter in the mail and I panicked. Scanned the site, saw exactly what they saw, installed the pixel that afternoon. Rescan came back clean. Ten minutes, done."
"I'm not technical and I don't have a developer. One script tag, pasted where they told me, and my trackers finally wait for consent. That's the whole thing I was scared I couldn't fix."
Close the gap before the next letter goes out
One pixel, any platform, live in ten minutes — from $8.99/mo. Start your 14-day free trial and stop being the easy target.
Business-owner questions
What owners ask first
I just got a CIPA demand letter. What do I do?
I'm not based in California. Am I actually at risk?
I already have a cookie banner. Isn't that enough?
Which tools get sites flagged?
How much does it actually cost, and how long to set up?
Won't blocking trackers break my analytics and ads?
Isn't a law coming that makes this go away?
Do I need to be technical to use this?
Stop being the easy target
Scan your site the way plaintiff firms do, then close the gap with one pixel. Ten minutes today beats a demand letter tomorrow.
No credit card · From $8.99/mo · Any platform · Live in 10 minutes