June 08, 2026|Franchise Frontlines

De Ayora v. Inspire Brands: Federal court lets pen-register, common-law privacy, fraud, and unjust-enrichment claims over post-opt-out cookies proceed against a multi-brand franchisor

June 8, 2026  |  United States District Court for the Northern District of California  |  Slip Copy — Not Yet Reported (2026 WL 1653483)

Executive Summary

In this slip-copy order, United States Magistrate Judge Alex G. Tse of the United States District Court for the Northern District of California granted in part and denied in part a second motion to dismiss brought by Inspire Brands, Inc. and its restaurant-brand subsidiaries — Arby’s Restaurant Group, Inc.; Jimmy John’s Franchisor SPV, LLC; Sonic Industries Services, LLC; and Dunkin’ Brands, Inc. (alleged to operate both the Dunkin’ and Baskin Robbins sites). The plaintiffs, four individual website users, alleged that the brand websites deployed tracking cookies even after users declined consent through cookie-consent banners, and asserted common-law invasion-of-privacy claims (Claims One and Two), California Invasion of Privacy Act (CIPA) wiretapping (Claim Three) and pen-register (Claim Four) claims, fraud (Claim Five), and unjust enrichment (Claim Six). The defendants argued that the parent, Inspire, should be dismissed because the complaint did not allege that Inspire itself collected data, that certain CIPA claims were time-barred, and that plaintiffs failed to plead the elements of their CIPA, fraud, and unjust-enrichment theories; the plaintiffs responded that they had adequately pleaded each claim at the pleading stage. The court held that plaintiffs had standing to sue the parent Inspire on the basis of its alleged shared, enterprise-wide technology infrastructure, dismissed certain plaintiffs’ time-barred CIPA claims (with prejudice as to one plaintiff and without prejudice as to another), dismissed the CIPA wiretapping claim without prejudice for failure to allege interception of the “contents” of a communication, and otherwise denied the motion — sustaining the CIPA pen-register, common-law privacy, fraud, and unjust-enrichment claims and granting leave to amend by July 10, 2026.

Relevant Background

The plaintiffs are four individuals — Benjamin Paul de Ayora, Christine Wiley, Mikhail Gershzon, and George Nino — who used consumer-facing websites associated with restaurant brands. The defendants are Inspire Brands, Inc. and four brand subsidiaries: Arby’s Restaurant Group, Inc.; Jimmy John’s Franchisor SPV, LLC; Sonic Industries Services, LLC; and Dunkin’ Brands, Inc., which the opinion states is alleged to operate both the Dunkin’ and Baskin Robbins websites. The plaintiffs alleged that Inspire owns and is directly and substantially involved in operating each website, providing “shared technology infrastructure and services related to user data collection and privacy compliance” and operating its brands via “integrated, enterprise-wide, technology-enabled platforms,” and that each website’s privacy policy directs users to an Inspire email address.

According to the complaint, each brand website presented visitors with a cookie-consent banner that allowed users to decline tracking. The plaintiffs alleged that, after they declined consent, the defendants continued to deploy cookies that tracked information including browsing history, website interactions, device information, referring URLs, session information, user identifiers, geolocation data, and IP addresses. On that factual basis, the plaintiffs asserted common-law invasion of privacy (Claims One and Two), CIPA wiretapping (Claim Three), CIPA use of a pen register (Claim Four), fraud (Claim Five), and unjust enrichment (Claim Six).

This was the defendants’ second motion to dismiss. In an earlier order, the court had found no standing to sue Inspire and had dismissed all claims for failure to satisfy Rule 9(b)’s heightened pleading standard, granting leave to amend. The plaintiffs then filed an amended pleading (which the court, addressing a captioning irregularity, treats as the operative Second Amended Complaint), and the defendants again moved to dismiss.

Decision

Applying the ordinary plausibility pleading standard, the court first addressed standing to sue the parent, Inspire. The defendants argued that the complaint did not plausibly allege that Inspire itself engaged in the misconduct, and the court distinguished Briskin v. Shopify, Inc., on which the plaintiffs relied. The court acknowledged that “there is no allegation that Inspire collects any data,” but found that because each website’s privacy policy refers to Inspire’s email address, it is “plausible that a plaintiff knows Inspire participated in the privacy policy and the information or data governed by that policy.” On that basis, and coupled with the allegations of shared, enterprise-wide technology infrastructure, the court held that at the pleading stage the plaintiffs had standing to sue Inspire.

On the CIPA theories, the court treated wiretapping and pen register as distinct causes of action with different elements. A wiretapping claim requires interception of the “contents” of a communication; quoting In re Zynga Privacy Litigation, the court explained that “contents” refers to “the intended message conveyed by the communication” and “does not include record information regarding the characteristics of the message.” The court agreed with the defendants that the plaintiffs alleged only record information and “don’t allege engaging in any communications with the websites or otherwise generating any content,” so the wiretapping claim (Claim Three) failed for want of a contents allegation. The court dismissed that claim without prejudice, with leave to amend.

The pen-register claim reached the opposite result. A pen register captures “dialing, routing, addressing, or signaling information … but not the contents of a communication,” so it does not require the interception element that defeated the wiretapping theory. The plaintiffs alleged that their IP addresses were tracked, and the court found that an IP address falls within the statutory “addressing” information, citing Shah v. Fandom, Inc. The court denied dismissal of the pen-register claim (Claim Four) and declined to revisit its earlier ruling that cookies can qualify as pen registers.

On timeliness, the court held that plaintiff Ayora’s CIPA claims (Claims Three and Four) against Baskin Robbins, Dunkin’, and Jimmy John’s were time-barred and dismissed them with prejudice, because Ayora pleaded that he learned of the alleged violations on or about October 15, 2023, the one-year CIPA limitations period ran, and no tolling applied where his demand letter reached only Inspire and his arbitration demand named only Inspire and Arby’s. Plaintiff Nino’s CIPA claim against Arby’s was dismissed without prejudice for lack of delayed-discovery or fraudulent-concealment facts, while his CIPA claims against Baskin Robbins, Dunkin’, Jimmy John’s, and Sonic survived as possibly timely. The court further found that the plaintiffs now satisfied Rule 9(b) and sustained the fraud, unjust-enrichment, and common-law privacy claims, denying the balance of the motion and granting leave to amend by July 10, 2026 (an amended pleading the court directs be captioned the Third Amended Complaint).

Looking Forward

This order is a useful, defense-side illustration of how consumer data-privacy litigation — here CIPA cookie-tracking claims — may reach a multi-brand franchisor even though the franchise relationship itself is not what the case is about. The exposure arose from consumer-facing brand websites and their cookie-consent banners, and California privacy litigation of this kind may inform how courts elsewhere approach comparable tracking claims, though it is persuasive rather than controlling outside its jurisdiction. The central allegation was simply that cookies kept tracking after users declined consent — a gap between what the banner represented and how the site behaved. Franchisors and branded systems that operate brand websites with consent banners may wish to confirm, as a matter of prudence, that declining consent actually stops the tracking and that opt-out mechanisms function as represented.

The most franchise-analogous feature of the order is the standing ruling against the parent. The court allowed claims against Inspire to proceed on allegations that it provided “shared technology infrastructure” and operated its brands via “integrated, enterprise-wide, technology-enabled platforms,” and that the brand privacy policies routed users to an Inspire email address — even though, as the court noted, “there is no allegation that Inspire collects any data.” For a franchisor or brand-holding company that provides shared web infrastructure, consent-management platforms, or centralized privacy policies across a branded portfolio, this reasoning may inform how courts approach whether a parent can be drawn into privacy litigation. That transfer is analogical only — the ruling rests on this record and on a lenient pleading standard, not a merits determination — but it is a reason to consider carefully how centralized technology and privacy-policy functions are structured and documented across a system.

The order is not uniformly adverse, and its defensive lessons are worth noting. Limitations defenses eliminated one plaintiff’s CIPA claims against three brands with prejudice, underscoring the continuing value of scrutinizing the timing of each plaintiff’s claims against each brand and of testing tolling theories — the demand and arbitration papers here reached only two entities, which defeated tolling as to the others. The wiretapping dismissal likewise reflects a viable line of defense: on this record, record information such as IP addresses and browsing history was not the “contents” of a communication. Even so, branded systems should not read that dismissal as a safe harbor, because the same facts supported the surviving pen-register theory, which proved the more durable claim. Coordinating consent-management practices across multiple brands, and documenting what each site discloses and when, may reduce the risk that a single practice generates exposure across an entire portfolio.


Thomas O’Connell is a Partner at Buchalter LLP and Chair of the firm’s Franchise Practice Group. For questions about this article or media inquiries, you can contact Tom at toconnell@buchalter.com.

This article is based solely on the opinion of the Court in this matter. The author has not conducted any independent investigation into the facts. For the avoidance of doubt, each statement related to the law and facts in this article is drawn from the Court’s opinion in this case. It was drafted with the assistance of an artificial intelligence system. AI systems can make mistakes, including in describing legal authority. Readers should independently confirm any legal authority before relying on it.

This communication is not intended to create, and does not create, an attorney-client relationship or any other legal relationship. No statement herein constitutes legal advice, nor should it be relied upon or interpreted as such. This communication is for general informational purposes only and is not a substitute for legal counsel. Readers should not act or refrain from acting based on any information provided without seeking appropriate legal advice specific to their situation. For more information, visit www.buchalter.com.

Practices