Dawson v. Porch.com Inc

District Court, W.D. Washington·Decided August 17, 2021·No. 2:20-cv-00604·Unknown

Opinion

1 2 3 4 5 UNITED STATES DISTRICT COURT WESTERN DISTRICT OF WASHINGTON 6 AT SEATTLE 7 BOB DAWSON, et al., Cause No. C20-0604RSL 8 Plaintiffs, 9 v. ORDER DENYING DEFENDANTS’ MOTION FOR SANCTIONS 10 PORCH.COM, INC., et al., 11 Defendants. 12 13 This matter comes before the Court on defendants’ “Motion for Sanctions.” Dkt. # 41. 14 Defendants seek terminating sanctions or, in the alternative, the disqualification of plaintiffs’ 15 counsel pursuant to the Court’s inherent authority and/or 28 U.S.C. § 1927. Having reviewed the 16 memoranda, declarations, and exhibits submitted by the parties, and having heard the arguments 17 of counsel, the Court finds as follows: 18 In early 2019, Thomas Alvord, the founder and managing partner of the law firm 19 20 representing plaintiffs in the above-captioned matter, developed a smartphone application 21 through which users could report spam and, if warranted, initiate suit against those responsible. 22 One such user reported receiving hundreds of spam text messages from defendant GoSmith. 23 While communicating with GoSmith’s lawyers about the reports, Mr. Alvord was told that the 24 user had agreed to GoSmith’s terms of service, which authorized the communications about 25 26 which he was complaining. The user denied having created a GoSmith account or having agreed 27 ORDER DENYING DEFENDANTS’ 1 to its terms of service. Mr. Alvord and the user went through the process of creating an account 2 on May 31, 2019, “to see what an account contained.” Dkt. # 61 at ¶ 11. Mr. Alvord used his 3 name, address, and email, but adopted the service the user provided (pool services) and used a 4 fake company name to create a provider account on GoSmith’s website. In order to complete the 5 process, Mr. Alvord had to affirmatively indicate his consent to GoSmith’s Terms of Use and 6 7 Privacy Policy. Those terms required that “the information you provide us will be accurate and 8 complete” and required Mr. Alvord’s agreement that he would not: 9 “access, download, monitor, or copy any content or information on the Smith 10 Properties or in the Services through automated or artificial means (including, but not limited to, screen and database scraping, spiders, robots, crawlers, deep-link, or 11 any similar or equivalent automatic or manual process);” 12 13 “otherwise obtain or attempt to obtain any content or information through any 14 means that Smith does not intentionally [make] available through the Smith Properties and the Services;” 15 16 “harvest information about Consumers or Service Providers from the Smith 17 Properties or the Services;” 18 “use, or attempt to use, the Smith Properties or the Services through any means 19 not explicitly and intentionally made available, provided or intended;” or 20 “engineer, decompile, disassemble or otherwise attempt to derive the source 21 code or architectural framework fo the Smith Properties of the Services.” 22 23 Dkt. # 44-1 at 6, 8-9. 24 By the end of 2019, Mr. Alvord had incorporated LawHQ, LLC, and was investigating 25 the numerous reports he was receiving regarding GoSmith’s spamming activities. As part of this 26 27 ORDER DENYING DEFENDANTS’ 1 investigation, he clicked on the unique URL links contained in the messages his clients received 2 from GoSmith and found that the clients’ names, phone numbers, and other identifying 3 information were easily accessible. If he changed the last digit of a given URL, another 4 provider’s profile page would open and, again, that provider’s personal information was 5 disclosed. None of the pages was password protected, no sign in or authentication was required, 6 7 and his clients (and he) could use the text message link to go to GoSmith’s website without 8 having an account. 9 Once on a provider’s profile page, Mr. Alvord could use his browser’s “Developer Tools” 10 to see bits of information that the webpage loaded into the browser but were not otherwise 11 visible. Where the “Developer Tools” disclosed a URL, Mr. Alvord visited the designated 12 webpage. In this way, he could tell whether a provider had created a password for GoSmith 13 14 and/or accepted GoSmith’s Terms of Use: a value of “null” in those fields indicated to him that 15 the provider had not created a GoSmith account and had not, therefore, consented to the spam 16 messages they received from GoSmith. The URL also disclosed where GoSmith had obtained 17 the provider’s information, such as the webpages for the Better Business Bureau, Yelp, and the 18 Yellow Pages. Anyone who visited a provider’s page and ran “Developer Tools” could access 19 20 the information described above: no account, password, or sign-in was needed. 21 Mr. Alvord concluded that GoSmith had scraped other websites for contact information, 22 spammed the identified service providers with text messages offering to sell them leads to 23 consumers, and required the providers to create an account and accept the Terms of Use before 24 viewing the lead. During his investigation, he saved the data he viewed that related to his clients. 25 On December 26, 2019, Rebecca Evans, a lawyer at LawHQ, filed a lawsuit in the Northern 26 27 ORDER DENYING DEFENDANTS’ 1 District of California against GoSmith on behalf of two individuals alleging violations of the 2 Telephone Consumer Protection Act (“TCPA”). LawHQ continued to receive complaints 3 regarding GoSmith’s spam. 4 In mid-January 2020, GoSmith announced that it would be shutting down its operations at 5 the end of the month. Mr. Alvord had his staff save approximately 3% of the profiles on 6 7 GoSmith’s website (totaling 340,000 webpages) and hired an internet security expert to verify 8 and document that the information Mr. Alvord was copying was publicly accessible. See Dkt. 9 # 62.1 The expert captured the information from another 100,000 GoSmith webpages just before 10 the company ceased operations. In authorizing these data captures, Mr. Alvord considered 11 various factors before determining that “there was nothing improper in doing so,” including the 12 absence of any viable claim of trade secret in information that had been scraped from third-party 13 14 websites, GoSmith’s unclean hands in scraping information from websites that prohibited 15 scraping, and case law suggesting that scraping public web content that is not password 16 protected is not a violation of the Computer Fraud and Abuse Act. Dkt. # 61 at ¶¶ 49-53. 17 At the end of January 2020, GoSmith attempted to convince plaintiffs’ counsel that the 18 text messages sent to her clients had been sent manually and did not violate the TCPA. Ms. 19 20 Evans was unpersuaded and filed a second lawsuit in the Northern District of California, this 21 time on behalf of 330 individuals. Having learned that GoSmith had been acquired by Porch.com 22 and that its clients were reporting spam from both entities, LawHQ sued not only GoSmith, but 23 24 1 Dale Rowe, a cybersecurity consultant, confirmed that all of the information Mr. Alvord 25 reviewed and saved was available to the public, could be accessed without circumventing security 26 controls, did not require an account with GoSmith, and did not involve any reverse engineering of compiled code, binaries, or executables. Dkt. # 62 at ¶¶ 27-29; Dkt. # 62-1 at 25. 27 ORDER DENYING DEFENDANTS’ 1 also Porch.com and the corporate officers allegedly responsible for the spam.2 Ms. Evans 2 notified defendants of the new filing via email and inquired whether they “would like to 3 seriously discuss a settlement.” Dkt. # 42-1 at 2. Efforts to reach a global settlement were 4 unsuccessful, however.

Free access — add to your briefcase to read the full text and ask questions with AI

Dawson v. Porch.com Inc, (W.D. Wash. 2021).

Dawson v. Porch.com Inc (Dawson v. Porch.com Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related