Unreported / Non-Citable
Background
A group of online creators who earn commissions by referring customers to merchants through tracked affiliate links sued Rakuten USA and its Ebates Performance Marketing subsidiary, which operates the Rakuten Rewards browser extension. According to the consolidated class complaint, the extension waits until a shopper reaches a merchant’s checkout page and, if the shopper applies a Rakuten coupon, silently opens a hidden browser tab that refreshes the page — replacing the creator’s commission-tracking cookie with Rakuten’s own tracking code. The result, plaintiffs allege, is that creators lose commissions they would otherwise have earned under their contracts with merchants, even though it was the creator’s referral link that brought the customer to the site in the first place.
Rakuten moved to dismiss the consolidated complaint’s eight claims (including unjust enrichment, several business torts, computer fraud statutes, and state unfair-competition laws), arguing the plaintiffs lacked Article III standing and failed to plausibly plead each cause of action.
The Court’s Holding
The court denied the standing challenge, rejecting Rakuten’s argument that plaintiffs failed to plead an actual, traceable injury. Plaintiffs plausibly alleged — through specific contract language and checkout screenshots — that their merchant agreements entitled them to commissions based on which referral link a customer used, and that the extension’s hidden cookie-swap mechanically redirected that credit to Rakuten. The court also rejected a “self-inflicted harm” standing defense, explaining that an injury is not self-inflicted merely because a plaintiff’s conduct (allowing customers to use a coupon extension) was part of the causal chain, so long as the defendant’s conduct remains a but-for cause of the harm.
On the merits, most claims survived. Unjust enrichment, interference with prospective economic advantage, and intentional interference with contract were all adequately pled because the specific contract terms plausibly showed the plaintiffs were entitled to the diverted commissions. The federal Computer Fraud and Abuse Act claim survived too: the extension’s undisclosed cookie-swapping plausibly constituted unauthorized access causing “damage” (destroying tracking data) and “loss” (lost commission revenue through interrupted service), and a prior terms-of-service agreement some plaintiffs signed did not clearly authorize the specific conduct at the pleading stage. California’s and Florida’s unfair-competition and deceptive-practices statutes also survived.
Two claims failed, however: conversion and California’s Comprehensive Computer Data Access and Fraud Act both required plaintiffs to show they owned or possessed the tracking codes themselves — and the complaint instead showed merchants, not creators, controlled and issued those codes, with customers free to delete or overwrite them at will. Those two claims were dismissed with leave to amend.
Key Takeaways
- An injury is not “self-inflicted” for standing purposes merely because the plaintiff’s own voluntary conduct (like allowing a coupon extension to run) is part of the causal chain — what matters is whether the defendant’s conduct remains a but-for cause of the harm.
- Specific, pled contract language defining how commissions accrue (such as a precise definition of the “last click” that earns credit) can establish both Article III standing and the entitlement element of an unjust enrichment claim at the pleading stage.
- A CFAA claim based on undisclosed software behavior can survive even where some plaintiffs signed terms of service referencing the conduct, if a reasonable reading of those terms is consistent with the plaintiffs’ theory that the behavior was not actually authorized.
- Conversion and similar ownership-based claims over digital tracking data require pleading an actual ownership or possessory interest in the data — allegations that data is merely associated with or customized by a plaintiff are not enough when a third party (here, merchants) actually controls and issues it.
Why It Matters
This decision is an early roadmap for a wave of “cookie-stuffing” litigation against browser extensions and coupon tools that intercept affiliate marketing commissions — confirming that creators and influencers have viable claims when an extension’s undisclosed mechanics divert commissions that their merchant contracts specifically promised them.
For companies that operate browser extensions, shopping tools, or coupon plugins, the ruling is a warning that undisclosed cookie or tracking-code manipulation can expose the company to federal computer-fraud liability and state unfair-competition claims, even if the underlying software change seems purely technical from the company’s perspective.