California Case Summaries

Song v. Lemonade — Federal Judge Finds Cookie-Tracking Allegations Establish Article III Standing, Denies Remand of CAFA Privacy Class Action

Unreported / Non-Citable

Case
Wedong Song, et al. v. Lemonade, Inc.
Court
U.S. District Court — Northern District of California
Judge
JAMES DONATO (Barack Obama, 2014)
Date Decided
2026-09-29
Docket No.
3:26-cv-04207
Status
Unreported / Non-Citable
Topics
Article III standing, CAFA removal and remand, California Invasion of Privacy Act, Unfair Competition Law, website cookie tracking, data privacy, Ninth Circuit standing precedent

Background

Wedong Song and John Devito sued Lemonade, Inc., an online seller of life and homeowners insurance, in San Francisco County Superior Court. They alleged that when website visitors clicked “Reject All” on Lemonade’s cookie-tracking banner, the company collected and shared their data anyway, in violation of the California Invasion of Privacy Act and the state’s Unfair Competition Law, and in breach of contract. The complaint claimed that Lemonade’s tracking tools captured sensitive details pulled from insurance applications — names, dates of birth, home addresses, email addresses, and phone numbers — and shared them with third parties including Google and Microsoft. The trackers allegedly let those third parties infer even more sensitive facts, such as whether a person had filed a claim for a death, health issue, or property damage, or had missed a premium payment.

Lemonade removed the case to federal court under the Class Action Fairness Act (CAFA), which allows certain large class actions to be heard in federal court. Song and Devito then moved to send the case back to state court (remand), arguing that their own allegations were too abstract to satisfy the “case or controversy” requirement of Article III of the U.S. Constitution — in other words, that they hadn’t shown a concrete enough injury for a federal court to hear the case at all.

That move put U.S. District Judge James Donato in an unusual position: a plaintiff asking a court to find that the plaintiff’s own complaint didn’t allege a real enough harm. The outcome mattered beyond this case, because the answer would decide whether this category of cookie-tracking privacy claims can proceed in federal court or must be litigated only in state court.

The Court’s Holding

Judge Donato denied the motion to remand, holding that the complaint plausibly alleged a concrete and particularized injury sufficient for Article III standing. He relied on the well-established principle, reaffirmed in Frasco v. Flo Health, Inc., 349 F.R.D. 557 (N.D. Cal. 2025), that “the loss of control over one’s personal information is a concrete harm,” and on the Ninth Circuit’s holding in In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020), that failing to give users a meaningful way to control or prevent unauthorized exploration of their private lives can itself constitute a cognizable invasion of privacy.

The court distinguished the plaintiffs’ primary counterargument, Popa v. Microsoft Corp., 153 F.4th 784 (9th Cir. 2025), where the Ninth Circuit found no standing because the tracking technology at issue gathered only a plaintiff’s pet-store shopping preferences and her street name — information the court viewed as neither sensitive nor financial. Judge Donato found that case readily distinguishable: here, the complaint specifically alleged that Lemonade collected and shared sensitive financial and personal information, including data drawn from insurance applications, even after plaintiffs affirmatively denied permission through the “Reject All” option. That combination — sensitive financial data plus an express rejection of tracking — was enough to cross the line that Popa‘s thinner allegations could not.

Because standing was the only ground the plaintiffs raised for remand, and the court found standing satisfied, the case stays in federal court under CAFA jurisdiction.

Key Takeaways

  • Allegations that a company collected and shared sensitive personal or financial information after a user affirmatively opted out of tracking can establish Article III standing, even in a case removed under CAFA.
  • Courts continue to treat “loss of control over one’s personal information” as a concrete injury for standing purposes, following Frasco v. Flo Health and the Ninth Circuit’s Facebook Internet Tracking decision.
  • Popa v. Microsoft does not provide a categorical bar to standing in cookie-tracking cases; it turns on whether the tracked information is sensitive (e.g., financial, medical) versus generic browsing preferences.
  • Defendants seeking to keep privacy class actions in federal court under CAFA can benefit when plaintiffs’ complaints allege detailed, sensitive data collection — the same specificity that supports the underlying claims also supports federal jurisdiction.
  • Plaintiffs sometimes move to remand on standing grounds strategically, hoping for a more favorable state forum; this order shows that approach can backfire if the complaint’s own factual detail satisfies the federal standing bar.

Why It Matters

This order is a useful data point for anyone litigating website cookie-tracking and “Reject All” claims, a fast-growing category of privacy class actions in California. It shows how courts are applying the post-Popa landscape: generic browsing data may not support standing, but allegations tying tracked data to sensitive categories like insurance, health, or financial information can. For defendants facing CAFA removal strategy choices, it also illustrates a tension — plaintiffs who plead highly specific, sensitive-data allegations to support their underlying privacy claims may inadvertently strengthen the federal court’s basis for keeping jurisdiction, undercutting their own remand motion.

More broadly, the ruling reinforces that Article III standing in digital-privacy cases is fact-intensive and turns on the character of the information at issue, not merely on whether tracking occurred. Practitioners drafting or defending against these complaints should pay close attention to how specifically they plead (or attack) the sensitivity of the data collected.

Read the full opinion (PDF) · Court docket

Scroll to Top