๐Ÿณ๏ธโ€โšง๏ธ trans rights are human rights ๐Ÿณ๏ธโ€โšง๏ธ
Theme

Did Brooklinen illegally track its customers to different websites?

TL;DR

  • Brooklinen, Inc. was hit with a federal class action on June 18, 2026 in the Eastern District of New York, accused of secretly tracking users who explicitly told the site not to.
  • The complaint alleges the Brooklinen website loads tracking pixels from at least eight companies including Facebook, TikTok, Google, Microsoft, Pinterest, Reddit, and Snapchat the moment a page loads and keeps tracking even after users hit “Reject All.”
  • These tracking tools allegedly harvest browsing activity, device identifiers, email addresses, and IP-based location, then transmit that data to the tech giants in real time for profit.
  • The suit claims violations of the federal Wiretap Act, California’s Invasion of Privacy Act, and California consumer protection laws, seeking statutory damages of up to $10,000 per violation.
  • The plaintiff, a California resident, says she rejected non-essential cookies and was tracked anyway; had she known the opt-out was fake, she says she never would have used the site.
One tracking pixel allegedly starts harvesting your data before the cookie banner even finishes loading on your screen.

The Non-Financial Ledger

According to the lawsuit, a shopper looking at robes and sheets believed she had privacy because the website offered her a button that said “Reject All.” She pressed it. She trusted it. That trust was apparently worthless from the start.

The complaint describes a betrayal of the most basic expectation people have online: that when a company gives you a control, the control does something. The plaintiff says she rejects tracking on every website she visits as a matter of personal practice. Brooklinen allegedly honored that choice on the screen while ignoring it in the code, transmitting her browsing behavior to Facebook, TikTok, and six other tracking companies as she clicked.

The dignity loss is being watched without knowing it, and being told you are safe while you are being recorded. The complaint states that had the plaintiff known she could not rely on Brooklinen’s promises, she would not have browsed the site at all. She was, in the words of the filing, “lulled into a false sense of security, privacy, and control.”

Legal Receipts

“Defendant’s assurances are false. The Website begins placing and transmitting cookies and other third-party tracking technologies (the ‘Tracking Tools’) capable of transmitting users’ data the moment users visit the Website, before they can interact with the Cookie Banner or select their preferences in the Cookie Settings.”
  • This is the core accusation: tracking allegedly begins before any consent is possible, making the opt-out mechanism meaningless from the first second.
  • It establishes that the alleged harm occurs even for users who never touched the “Accept” button.
“Worse still, even after users affirmatively reject all non-necessary cookies, the Website continues to utilize and deploy Tracking Tools which transmit users’ data to the advertising, social media, and analytics companies that designed and operate the Tracking Tools, including Facebook, TikTok, Google, Microsoft, Pinterest, Snapchat, and Reddit.”
  • This alleges the opt-out is not just delayed but ignored entirely, with tracking continuing after an active rejection.
  • It names all seven of the corporate tracking entities receiving the data, showing the scale of the alleged disclosure.
“Defendant lulls users into a false sense of security, privacy, and control while simultaneously enabling third parties to monitor, intercept, and transmit users’ online behavior in real time.”
  • This frames the conduct as active deception, not a passive technical oversight.
  • It ties the privacy interface directly to the alleged real-time surveillance it was supposed to prevent.
“These cookies do not store any personally identifiable information.”
  • This is Brooklinen’s own quoted description of its “Strictly Necessary Cookies” from the Cookie Settings.
  • The complaint places this claim against its allegation that the site transmitted IP addresses, email addresses, and persistent identifiers even to users who rejected everything.

“Users were told they could disable tracking, attempted to do so, and the Defendant continued tracking them regardless.”

Public Deception

The complaint centers on a gap between what Brooklinen’s interface promised and what the site’s code allegedly did.

  • The Cookie Banner offered “Manage Preferences,” “Reject All,” and “Accept Cookies,” which the complaint says led users to believe rejecting would stop non-necessary tracking. The complaint alleges tracking continued regardless.
  • The Cookie Settings described “Strictly Necessary Cookies” as storing no personally identifiable information. The complaint alleges the site transmitted IP addresses, email addresses, and persistent cross-session identifiers even after rejection.
  • The Privacy Policy stated data partners “may” associate site activity with personal information. The complaint alleges this active real-time transmission happened to users who explicitly opted out.
What You Were Told vs. The Reality What You Were Told The Reality (Alleged) Press “Reject All” to stop non-necessary cookies Tracking tools continued transmitting after rejection Necessary cookies store no personally identifiable info IP addresses, emails, and device IDs allegedly sent You control what data the site shares Tracking began before the banner could be clicked Data used for browsing “smoothness” Data monetized to build marketing profiles

Regulatory Gray Zones

The complaint frames Brooklinen’s alleged conduct as an exploitation of the gap between a compliant-looking consent interface and the surveillance laws that interface was supposed to satisfy.

  • The complaint invokes California Penal Code ยง 638.51, which requires a court order to install a pen register or trap and trace device. It alleges Brooklinen deployed tracking tools that function as such devices without any court order.
  • It cites the framework where site operators, not the tracking companies, bear the legal burden of obtaining consent. Each tracking entity’s terms allegedly warned Brooklinen it “must only share” data “in a manner that is transparent and lawful,” pushing liability onto Brooklinen.
  • The Microsoft UET tool provides a “_uetmsdns” cookie that a site can set to stop events from firing when users decline. The complaint alleges Brooklinen “failed to place this cookie” and did not stop UET events from firing after users declined.

Profit-Maximization at All Costs

The complaint alleges the entire tracking apparatus existed for one reason: to make Brooklinen and the tracking companies more money by turning shoppers into marketing data.

  • The complaint states tracking tools “enable Defendant and Tracking Entities to earn more money and enhance marketing effectiveness” by building “detailed marketing profiles of users.”
  • It describes the use of TikTok’s “Advanced Matching” and “lookalike audiences” to retarget users and reduce Brooklinen’s advertising costs, converting private browsing into ad efficiency.
  • Brooklinen allegedly chose the non-encrypted Facebook Pixel method over an available encrypted JavaScript version, a choice the complaint says “makes users’ information visible.”
  • The complaint alleges the data harvesting served “advertising, analytics, and marketing optimization,” and that knowing who NOT to market to is itself valuable, so data is collected whether or not an ad is ever shown.

Legal Minimalism: The Letter but Not the Spirit

The complaint describes a consent interface built to look like compliance while allegedly defeating the purpose of the privacy laws it gestured at.

  • Brooklinen displayed a Cookie Banner and Cookie Settings with toggles and a “Reject All” option, the visible machinery of consent. The complaint alleges the machinery did not actually govern the tracking tools.
  • The California Invasion of Privacy Act (CIPA) was enacted to protect people from secret monitoring by an “unannounced second auditor.” The complaint alleges Brooklinen presented a legal-looking opt-out while continuing exactly the secret third-party monitoring the law targets.
  • The complaint alleges the site’s default settings “permitted tracking to begin as soon as users arrived,” before any choice was possible, so even a perfectly-honored opt-out would have come too late.

Supply Chain Complicity

This case is a data supply chain: Brooklinen sits at the center, and eight third-party tracking vendors are alleged to be the pipeline through which user data flowed out and money flowed back.

  • The implicated tier is the third-party ad-tech vendors: Facebook/Meta, TikTok, Google (Ads and Analytics), Microsoft, Pinterest, Reddit, and Snapchat, each embedded via pixels or tags into Brooklinen’s own site code.
  • Each vendor’s terms allegedly required Brooklinen to obtain user consent and provide transparency notices before sharing data. The complaint alleges Brooklinen ignored these contractual warnings across all vendors.
  • The complaint alleges the corporate structure diffused responsibility: Brooklinen points to vendor terms, vendors point back to Brooklinen’s duty to get consent, and the user is never party to either agreement.
  • Downstream, the complaint alleges tracking entities like Pinterest and Reddit further share the collected data with “third and fourth parties,” extending exposure beyond the vendors the user never agreed to in the first place.
The Data Flow: One Site, Eight Trackers Website Users (who clicked “Reject All”) BROOKLINEN, INC. embeds tracking pixels Meta / FB TikTok Google Microsoft Pinterest Reddit Snapchat

Societal Impact Mapping

Public Health of the Digital Commons

The complaint frames unauthorized tracking as a threat to the basic privacy people expect in their online lives.

  • The complaint alleges interception of “inferred interests, preferences, age, location, or other characteristics based on user behavior,” creating profiles of individuals without consent.
  • It cites reporting that the TikTok Pixel “immediately links to data harvesting platforms that pick off usernames and passwords, credit card and banking information, and details about users’ personal health.”
  • The complaint alleges tracking entities can de-anonymize otherwise anonymous visitors by matching data against profiles built on “hundreds of millions of Americans.”

Economic Inequality

The complaint describes an economy where a person’s private behavior is converted into corporate revenue without payment or consent.

  • The complaint alleges Brooklinen was “unjustly enriched” by collecting and monetizing user data while representing that such practices would stop upon a user’s decline.
  • It alleges users suffered “diminution in the value of their personal data,” meaning value that belonged to individuals was extracted by the corporation.
  • The tracking companies allegedly profit twice: once selling targeted ads to Brooklinen, and again by using the same harvested data to improve products they sell to every other advertiser.

Who Pays? Following the Cost

The complaint describes a transfer where the value of private data moves from ordinary shoppers to Brooklinen and the tracking giants.

  • The cost originates with users, who lose control of their browsing activity, device identifiers, email addresses, and location data.
  • Brooklinen allegedly absorbs the benefit through lower advertising costs and higher conversion rates driven by the harvested profiles.
  • The tracking entities absorb the benefit by refining their own ad-targeting algorithms and reselling those capabilities to other businesses, compounding the value taken from a single shopper’s session.
The Cost-Shift: From Your Browser to Their Balance Sheet USER’S PRIVATE DATA browsing, IP, email, device ID lower ad cost resold targeting data Brooklinen higher conversions Tracking Entities better ad algorithms + resale

The “Cost of a Life” Metric

The complaint attaches a specific price to each alleged act of interception under federal law.

$10,000 The statutory damages the Wiretap Act allows per violation (or $100 per day), sought for each class member whose communications were allegedly intercepted after they pressed “Reject All.” The class is estimated at thousands to millions of people.

The Settlement Isn’t Justice

No settlement or fine has been imposed; this is a newly filed complaint. What the case already exposes is why penalties in privacy cases often fail as deterrence.

  • The complaint pleads statutory damages precisely because individual users have no easy way to prove dollar losses; the harm is diffuse and invisible, which is exactly what lets tracking continue at scale.
  • The complaint seeks an injunction requiring Brooklinen to either “remove the Tracking Tools from the Website” or obtain “appropriate consent,” an admission that money alone would not fix the underlying practice.
  • Because the tracking entities profit independently by improving algorithms they sell to every advertiser, any penalty against Brooklinen alone leaves the broader data-extraction economy untouched.

This Is the System Working as Intended

The complaint documents an interface engineered to satisfy the appearance of privacy law while the underlying business kept running, which is the structural point.

  • The complaint alleges Brooklinen deployed a full consent framework, banner, toggles, “Reject All” button, and still allegedly transmitted data, showing that the compliance interface itself can become the cover for non-compliance.
  • It alleges every tracking vendor contractually shifted the consent burden onto Brooklinen, a structure where each party can point at another while the user, party to no agreement, absorbs the exposure.
  • The complaint notes the tracking begins from default settings “before users could make any choices,” meaning the system’s default state is surveillance and the user’s rejection is treated as an afterthought the code allegedly ignores.

What a Legitimate Fix Looks Like

Editorial analysis. This case exposes a core failure: a privacy control that displayed choice on the screen while the code allegedly ignored it, and a vendor structure that let everyone disclaim responsibility.

Regulatory Track

  • Regulators should require that “Reject All” verifiably block all non-essential tracking scripts from loading, subject to mandatory third-party technical audits of consent-management implementations, not self-attestation.
  • Agencies should mandate that no tracking tool fire before a user has affirmatively acted on a consent banner, closing the “default tracking” gap the complaint describes.
  • Given the vendor structure, regulators should require public disclosure of every third-party tracker a retail site loads and its data recipients, so the eight-vendor pipeline alleged here cannot stay hidden.

Legislative Track

  • Lawmakers should strengthen statutes like the California Invasion of Privacy Act and the federal Wiretap Act so that a fraudulent opt-out is treated as an unauthorized interception with clear statutory penalties.
  • Legislation should require that the party embedding a tracker, not the tracker vendor, carries non-delegable liability for obtaining consent, ending the contractual buck-passing the complaint describes.
  • A functional standard should require that consent be provably honored end to end, with penalties scaled to the number of affected users rather than a flat cap that large firms can absorb.

Corporate Governance Track

  • Brooklinen should be required to implement an internal compliance review confirming that its consent framework actually blocks the tracking tools it lists, with results reported to its board.
  • The company should adopt a policy that any non-encrypted tracking method (like the Facebook Pixel method the complaint alleges it chose) requires documented executive sign-off and a privacy justification.
  • Executive incentives tied to advertising conversion metrics should be reviewed so that marketing performance is not rewarded when it depends on data harvested against users’ expressed choices.

What Now?

Direct your attention to Brooklinen, Inc., its principal place of business at 225 Varick Street, Suite 800, New York, and the eight tracking companies named as receiving user data.

  • Watchlist: The Federal Trade Commission (FTC) has jurisdiction over deceptive data practices and unfair competition of the kind alleged here.
  • Watchlist: The California Privacy Protection Agency and California Attorney General oversee the state privacy statutes (CIPA, UCL, CLRA) invoked in this complaint.
  • Install a tracker-blocking browser extension and audit which pixels load on retail sites you use; the complaint shows “Reject All” cannot always be trusted.
  • Support digital-rights organizations that litigate and lobby for enforceable consent laws, and share this case so others learn opt-out buttons can be theater.
  • Organize locally: push for privacy-literacy sessions in community and student groups so people know how to check what a website is actually sending about them.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2066