Chien v. Bumble Inc.

District Court, S.D. California·Decided November 17, 2022·No. 3:22-cv-00020·Unknown

Opinion

RYAN CHIEN, individually and on behalf Case No.: 3:22-cv-00020-GPC-NLS of all others similarly situated, JUDGMENT AND ORDER: Plaintiffs, v. (1) GRANTING IN PART DEFENDANTS’ MOTION TO BUMBLE INC., BUZZ HOLDINGS L.P., DISMISS FOR LACK OF PERSONAL and BUMBLE TRADING LLC, JURISDICTION Defendants. (2) GRANTING DEFENDANTS’ MOTION TO COMPEL ARBITRATION [ECF No. 24]

Before the Court is a Motion to Dismiss, or in the alternative to Compel Arbitration, Plaintiff Ryan Chien’s First Amended Complaint, filed by Defendants Bumble Inc., Buzz Holdings L.P., and Bumble Trading LLC (collectively referred to as “Bumble” except where otherwise indicated). (ECF No. 24.) For the reasons set forth below, the Court GRANTS IN PART Defendants’ motion to dismiss for lack of personal jurisdiction and GRANTS Defendants’ motion to compel arbitration.

Plaintiff Ryan Chien filed his putative class action complaint against Bumble Inc. and Buzz Holdings L.P. (Buzz Holdings) on November 24, 2021 in the Superior Court of California. (ECF No. 1-2 at 7.1) Defendants Bumble Inc. and Buzz Holdings removed the action to this Court on January 6, 2022. (ECF No. 1.) Chien amended his complaint in April to include Bumble Trading LLC (Bumble Trading) as a defendant, (ECF No. 18), after Bumble Inc. and Buzz Holdings challenged this Court’s jurisdiction in March. (ECF No. 16.) Chien’s operative First Amended Class Action Complaint (“Complaint” or “FAC”) concerns several privacy-related torts. (See FAC ¶¶ 152-224.) The causes of action arise from the allegedly unauthorized collection, use, and disclosure of users’ personally identifiable information (“PII”) and biometric information. (Id. at ¶ 1.) The medium through which these data were collected and used was an internet-based dating application called Bumble (“App”). (See FAC ¶ 2.) The App is free to download on mobile or desktop devices but has premium features available for purchase via subscription or in-app purchases. (FAC ¶ 24; ECF Nos. 30-1 at 31; 16-3 at 2.) “Bumble Trading . . . is responsible for decision making and marketing the . . . [A]pp in the United States.” (ECF No. 30-1 at 6; see also ECF No. 24-2 at 2 (“Bumble Trading LLC operates the Bumble App globally . . . .”).) Chien alleges that “Bumble Inc. directs and controls the operations of [Bumble Trading],” (FAC ¶ 27), whereas Bumble denies that either Bumble Inc. or Buzz Holdings have ever “owned, operated, or controlled the app, or collected, stored, managed, used or disclosed Bumble app user information,” (ECF Nos. 24-1 at 12, 16; 24-2 at 3). Bumble instead alleges that Bumble Inc. and Buzz Holdings “are holding companies that do not conduct any operational activities in the United States.” (ECF No. 24-1 at 16.)

1 Page numbers are based on the CM/ECF pagination. The App is primarily used for dating and relationships, (FAC ¶¶ 2-3), though there are different versions intended for establishing new friendships as well as for professional networking, (FAC ¶ 50). Users create an account by providing PII including their name, username, email address, mobile number, gender identity, date of birth, sexual preference, photograph, geographic location, and various social media account information. (FAC ¶ 6.) In addition to uploading photographs to their profiles, users may share other personal information with other users such as personal photographs as well as their “name, age, education, smoking and drinking preferences, voting status, political preference, religious beliefs[,] and zodiac sign.” (FAC ¶ 7.) As of March 2020 Bumble estimates that there were “over 75,000 unique users of the Bumble app . . . associated with registrations in the United States.” (ECF No. 1-3 at 2.) Chien estimates “[u]pon information and belief” that Bumble generates “revenue from thousands of paying users [residing] in California,” including the Southern District of California. (FAC ¶ 41.) The Complaint alleges that Bumble “unlawful[ly] and intentional[ly] collect[ed] and use[d] . . . users’ [PII], including biometric information . . . , without their consent and [had a] subsequent unauthorized disclosure of that information in violation of state law.” (FAC ¶¶ 1, 12.) The Complaint identifies the types of information it alleges Bumble collected and sometimes shared for profit: device and payment information, (FAC ¶¶ 8, 61); click statistics, (FAC ¶ 8, 61); geolocation, (FAC ¶ 10); and PII and biometric information as described above, (see FAC ¶¶ 11, 60-68). The Complaint alleges that much of this information qualifies as “personal information” as defined by the California Consumer Protection Act. (FAC ¶ 62; see also ECF No. 30-1 at 54.) Bumble allegedly “deriv[es] significant benefit from customers’ PII” by “collect[ing], retain[ing], and us[ing] that data to maximize profits through predictive marketing and other targeted marketing practices.” (FAC ¶ 59.) In addition to collecting and using the above-described information allegedly without adequate user consent, (FAC ¶¶ 79-88), the Complaint details a data breach2 from March 2020, (see FAC ¶¶ 101-11). With relative ease a San Diego-based research group3 was able to access “Bumble’s entire user database of nearly 100 million users and bypassed paying for the app’s premium services by finding and exploiting the app’s security vulnerabilities.” (FAC ¶101.) The group “was able to reverse engineer [Bumble’s] web [Application Program Interface (“API”)] to intercept all of its incoming and outgoing” communications. (FAC ¶¶ 102-04.) Because Bumble’s API allegedly did not conduct security checks that are typical in the industry, the group was able to “repeatedly probe the server for information on Bumble users.” (FAC ¶¶ 103-04.) “The leaked data on each user included their public profile descriptions . . . .”; their “activity on the app, . . . sexual orientation and their ‘wish’—the types of people they are looking to date based on their ‘swiping’ record”; as well as their pictures and Facebook account information if connected to their Bumble account. (FAC ¶¶ 106-07.) The Complaint also alleges that whether a user was “online in real-time, and their distance in miles from the person accessing the data” would have been accessible in the breach. (FAC ¶ 108.) The group notified Bumble of the App’s vulnerabilities four times between March 2020 and July 2020 but did not hear back until they asked about publishing the information. (FAC ¶ 109.) At least until November 1 the group reported that all the vulnerabilities still

Free access — add to your briefcase to read the full text and ask questions with AI

Chien v. Bumble Inc., (S.D. Cal. 2022).

Chien v. Bumble Inc. (Chien v. Bumble Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Milliken v. Meyer
311 U.S. 457 (Supreme Court, 1941)
International Shoe Co. v. Washington
326 U.S. 310 (Supreme Court, 1945)
Keeton v. Hustler Magazine, Inc.
465 U.S. 770 (Supreme Court, 1984)
Calder v. Jones
465 U.S. 783 (Supreme Court, 1984)
Helicopteros Nacionales De Colombia, S. A. v. Hall
466 U.S. 408 (Supreme Court, 1984)
Dean Witter Reynolds Inc. v. Byrd
470 U.S. 213 (Supreme Court, 1985)
At&T Technologies, Inc. v. Communications Workers
475 U.S. 643 (Supreme Court, 1986)
First Options of Chicago, Inc. v. Kaplan
514 U.S. 938 (Supreme Court, 1995)
United States v. Patrick
248 F.3d 11 (First Circuit, 2001)
Goodyear Dunlop Tires Operations, S. A. v. Brown
131 S. Ct. 2846 (Supreme Court, 2011)
Al Alwi v. Obama
653 F.3d 11 (D.C. Circuit, 2011)
Mavrix Photo, Inc. v. Brand Technologies, Inc.
647 F.3d 1218 (Ninth Circuit, 2011)
Kathy Keeton v. Hustler Magazine, Inc.
682 F.2d 33 (First Circuit, 1982)
Sher v. Johnson
911 F.2d 1357 (Ninth Circuit, 1990)