A roofer in San Jose opened his mailbox and found a thick lawsuit. The claim: a bit of code on his website sent a visitor’s clicks to Facebook without asking first. He settled for $2,500 and paid another $5,000 in lawyer fees.
That roofer is Paul Fowler, who has run Westshore Roofing for 34 years. Homepros reported his story on October 2, 2026. He told them he was frustrated his marketing company had not put the right protections in place. As a marketing company, we took that personally.

What these lawsuits claim
Most of the suits use a California law from 1967. It was written to stop people from listening in on phone calls. Lawyers now argue that common website tools do the same thing to your visitors.
The tools they name are ones most business websites already run:
- The Meta Pixel (Facebook’s tracking code for ads)
- Google Analytics
- Chat boxes on your site
- Tools that record how visitors scroll and click
- Online booking forms run by another company
The California law lets a plaintiff ask for $5,000 per violation without proving they lost a dime. One lawyer told Homepros the math they use: visit a site 20 times, call each visit a violation, and ask for $100,000.
Homepros, citing a tracker kept by the law firm Fisher Phillips, reports more than 5,800 of these suits filed across the country since 2022. That does not count the demand letters that ask you to pay before anyone files anything.
It is not just contractors
Home service companies are the newest group to get hit. They are far from the only one.
- HVAC: Folsom Lake Heating and Air was sued and settled, according to CapRadio.
- Solar: Element Electric is fighting its suit. The owner said a lawyer wanted at least $30,000 just as a deposit.
- Health care: Doctors’ offices and patient portals were some of the first targets. Health information raises the stakes.
- Restaurants and retail: Fisher Phillips reports a restaurant brand class action and a suit against Nike in Florida.
- Newspapers: The Los Angeles Times settled one of these cases for $3.85 million in 2026.
- Banks and insurance: The law firm Barnes and Thornburg lists financial services among the main targets.
One law firm put the list as “manufacturers, retailers, service providers, technology companies.” If you have a website, you are on it.
You do not have to be in California
The man who sued Fowler said he visited the site from Orange County, hundreds of miles outside Fowler’s service area. Your customers do not need to be in California. A visitor does.
California lawyers have mailed demand letters to businesses in Pennsylvania and Texas. On September 17, 2026, the Texas Attorney General put out a consumer alert warning businesses about them.
Other states have their own versions. Florida’s law allows up to $1,000 per violation. Pennsylvania and Massachusetts have seen cases too, and law firms are watching Illinois, Maryland, and Washington.
What the new California law does and does not fix
On September 30, 2026, Governor Newsom signed SB 690. Starting January 1, 2027, only the state attorney general can bring one type of these claims, the kind that says your site tracks a visitor’s IP address like a phone tap.
Here is the catch. The main wiretap claim, the one about sharing what visitors do with Facebook or Google, is still open to private lawsuits. Law firms already report plaintiffs moving to other laws.
A federal bill, the Halt Abusive Internet Lawsuits Act, was introduced in September 2026. It has not passed. Do not plan around it.

Five ways to lower your risk
None of this makes you lawsuit-proof. It does make your site a much harder target. Every step below comes from what privacy law firms are telling their own clients.
1. Know what is running on your site. Ask your web person for a written list of every tracking code, chat tool, and booking form on your site. Get it in writing.
2. Ask before you track. Put a clear consent banner on your site. The key part: tracking codes must stay off until the visitor clicks yes. Courts look at whether the banner actually works, not just whether it shows up.
3. Make your privacy policy match the truth. If the policy says you do not share data but your site runs the Meta Pixel, that gap is what plaintiffs look for.
4. Tell people about the chat box. If a chat tool on your site saves or shares conversations, say so in plain words before the visitor types.
5. Ask your software companies. Folsom Lake’s owner told CapRadio she contacted Housecall Pro, and they were able to settle the suit. If Jobber, ServiceTitan, Housecall Pro, or any other company puts a form or widget on your site, ask them how they handle consent.
If a letter shows up
Do not pay it. Do not reply to it yourself. The Texas Attorney General said the same thing: talk to a lawyer before you respond or send money.
- Take screenshots of your website as it is today.
- Save your privacy policy and any banner settings.
- Call your business insurance agent and ask whether your policy covers this.
- Call a lawyer who handles privacy cases.
Also know this: settling does not protect you from the next law firm. As one attorney told Homepros, a company can settle one day and get sued by a different firm the next.
![]()
How to start this week
Do one thing. Open your website in a private browser window on your phone. If nothing asks for your permission before the page loads, send your web person one question: “What tracking tools are on our site, and do any of them run before a visitor says yes?”
That answer tells you how much work you have. Clarity beats complexity.
Common questions
Can I be sued if my business is not in California?
Yes. These claims are based on where the website visitor is, not where your business is. California lawyers have sent demand letters to businesses in Pennsylvania and Texas, and other states such as Florida have their own laws.
Does a cookie banner make me safe?
Not by itself. The banner has to actually stop tracking codes from running until the visitor agrees, and your privacy policy has to match what your site really does. A banner that only shows a message while the tracking runs anyway does not help much.
Did the new California law end these lawsuits?
No. SB 690, signed September 30, 2026 and effective January 1, 2027, stops private lawsuits over one type of claim. The main wiretap claims are still allowed, and plaintiffs are using other state and federal laws.
This post is general information, not legal advice. If you get a demand letter or a lawsuit, talk to a lawyer who handles privacy cases.
Not sure what is running on your website? Take the free Website Privacy Check. Twelve quick questions, about two minutes. You get a risk score on the spot and a 30-day fix-it roadmap you can hand to your web person. It is not legal advice. It is a place to start.











0 Comments