Johnson v. Blue Nile, Inc.

District Court, N.D. California·Decided April 8, 2021·No. 3:20-cv-08183·Unknown

Opinion

San Francisco Division SUSAN JOHNSON, individually and on Case No. 20-cv-08183-LB behalf of all others similarly situated, Plaintiff, ORDER GRANTING MOTION TO v. Re: ECF No. 37 BLUE NILE, INC., et al., Defendants. Blue Nile sells jewelry online through its website. It uses FullStory’s software (called “session replay”) to record what visitors are doing on the Blue Nile website, such as their keystrokes, mouse clicks, and page scrolling, thereby allowing a full picture of the user’s website interactions. The plaintiff — on behalf of a putative California class — claims that FullStory is illegally wiretapping her communications with Blue Nile (and Blue Nile is aiding and abetting that eavesdropping) in violation of California’s Invasion of Privacy Act (CIPA). The defendants moved to dismiss the claims, in part on the ground that FullStory — as Blue Nile’s vendor for analyzing its website traffic — was a party to the communication (and not an eavesdropper). The defendants also contend that the court lacks personal jurisdiction because there is no forum-related conduct. The plaintiff does not plausibly plead that FullStory eavesdropped on her communications with Blue Nile and pleads only that FullStory is Blue Nile’s vendor for software services. She thus does not meet her prima facie burden to establish specific jurisdiction over the defendants, and she does not plausibly plead wiretapping in violation of California law. The next sections describe how FullStory’s software works, how the plaintiff used Blue Nile’s website (and what information FullStory’s software captured), and the case’s procedural history. 1. FullStory’s Software FullStory is a Delaware corporation headquartered in Atlanta, Georgia.1 It provides software to its clients (including Blue Nile) to capture and analyze data so that the clients can see how visitors to their websites are using the sites.2 The clients put FullStory’s code on their websites to capture the data, and then they can review the data, which is stored in the cloud on FullStory’s servers.3 The software records visitor data such as keystrokes, mouse clicks, and page scrolling. Through a function called Session Replay, FullStory’s clients can see a “playback” of any visitor’s session. If the visitor is still on the site, the clients can see the session live.4 2. The Plaintiff’s Use of Blue Nile’s Website The plaintiff is a resident of California, and Blue Nile is a Delaware company headquartered in Seattle, Washington.5 Between January and May 2020, the plaintiff visited Blue Nile’s website on a monthly basis to browse its jewelry selection but did not buy anything. FullStory’s Session Replay 1 First Am. Compl. (FAC) – ECF No. 34 at 3 (¶ 8). Citations refer to material in the Electronic Case File (ECF); pinpoint citations are to the ECF-generated page numbers at the top of documents. 2 Id. at 6–7 (¶¶ 25–28). 3 Id. at 3 (¶ 9), 10 (¶ 41), 16 (¶ 72). 4 Id. at 6–7 (¶¶ 26–28), 8 (¶ 31). function “created a video capturing each of Plaintiff’s keystrokes and mouse clicks on the website . . . [and] also captured the date and time of the visit, the duration of the visit, Plaintiff’s IP address, her location at the time of the visit, her browser type, and the operating system on her device.”6 “When users access [] [Blue Nile’s] Website and make a purchase, they enter their PII [personally identifiable information],” and FullStory’s software “captures these electronic communications . . . [e]ven if users do not complete the form” for the purchase. The captured PII includes — in addition to the information in the last paragraph — the user’s payment card information such as card number, expiration code, and CVV security code.7 3. Relevant Procedural History The plaintiff’s amended complaint has three claims: (1) wiretapping, in violation of Cal. Penal Code § 631(a); (2) the sale of eavesdropping software, in violation of Cal. Penal Code § 635(a); and (3) invasion of privacy under California’s Constitution.8 The plaintiff withdrew claim three.9 The putative class is “all California residents who visited [Blue Nile’s] Website, and whose electronic communications were intercepted or recorded by FullStory.”10 The case is related to Graham v. Noom, Inc., No. 3:20-cv-06903-LB (N.D. Cal.) and raises the same issues.11 All parties consented to magistrate jurisdiction.12 The parties do not dispute that there is subject-matter jurisdiction under the Class Action Fairness Act, 28 U.S.C. § 1332(d)(2)(A).13 The defendants moved to dismiss the case.14 The court held a hearing on April 8, 2021.

6 Id. at 10–11 (¶¶ 44–45). 7 Id. at 11 (¶¶ 47–48). 8 Id. at 14-18 (¶¶ 65–93). 9 Opp’n – ECF No. 39 at 9 n.1. 10 FAC – ECF No. 34 at 13 (¶ 58). 11 Order – ECF No. 34 (relating cases). 12 Consents – ECF Nos. 29–31. 13 FAC – ECF No. 34 at 34 (¶ 11). The reasoning in Graham v. Noom controls here: (1) for the section 631(a) claim, the plaintiff does not plausibly plead FullStory’s wiretapping, and Blue Nile thus is not liable as an aider and abettor; (2) there is no section 635(a) claim because there is no wiretapping; and (3) there is no personal jurisdiction over FullStory or Blue Nile. 1. Section 631(a) Claim First, for the reasons stated in Graham v. Noom, FullStory is not a third-party eavesdropper. As a result, Blue Nile is not liable for aiding and abetting FullStory’s wrongdoing because there is no wrongdoing.15 Second, the plaintiff predicates her claim in part on information — such as IP addresses, locations, browser types, and operating systems — that is not content.16 The plaintiff does not meaningfully dispute that this information is not content but contends that other website interactions are content.17 For the reasons in Noom, the court dismisses the claim to the extent that it is predicated on non-content information.18 In any amended complaint, the plaintiff can delineate content from non-content records. Third, the defendants contend that Blue Nile’s privacy policy discloses the possibility of data collection and analysis.19 The plaintiff counters — as her counsel did in Noom — that she could not consent to wiretapping that happened when she accessed the website and before she could read the policy, notice was insufficient, and the policy in any event did not disclose wiretapping.20 The privacy policy discloses that Blue Nile may collect user data such as (1) information gathered through cookies and other tracking technology, (2) device and browser information, (3)

Free access — add to your briefcase to read the full text and ask questions with AI

Johnson v. Blue Nile, Inc., (N.D. Cal. 2021).

Johnson v. Blue Nile, Inc. (Johnson v. Blue Nile, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related