Court filing
Exhibit B - Complaint in Evans v. Plaid, No. 20-cv-4804 — In re Plaid Inc. Privacy Litigation (Dkt. 52-3, N.D. Cal. No. 4:20-cv-03056)
Filed July 17, 2020 in In re Plaid Inc. Privacy Litigation; one of 174 filings from this case.
Record facts
| Court | U.S. District Court for the Northern District of California |
|---|---|
| Filed | 2020-07-17 |
U.S. District Court for the Northern District of California · No. 3:20-cv-04804-JSC · Doc. 1 · 2020-07-17 · Docket on CourtListener
Full text
CLASS ACTION COMPLAINT
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Jon A. Tostrud (CA Bar No. 199502)
TOSTRUD LAW GROUP, P.C.
1925 Century Park East, Suite 2100
Los Angeles, CA 90067
Telephone: (310) 278-2600
Fax: (310) 278-2640
Email: jtostrud@tostrudlaw.com
Email: acarter@tostrudlaw.com
Brian P. Murray (Pro Hac Vice to be filed)
Lee Albert (Pro Hac Vice to be filed)
GLANCY PRONGAY & MURRAY LLP
230 Park Avenue, Suite 530
New York, NY 10169
Telephone: (212) 682-5340
Fax: (212) 884-0988
Email: bmurray@glancylaw.com
Email: lalbert@glancylaw.com
Attorneys for Plaintiffs
UNITED STATES DISTRICT COURT
NORTHERN DISTRICT OF CALIFORNIA
DAVID EVANS, PATRICK LENAHEN,
ADAM SMOTKIN, and OSWALDO
HERRERA, Individually and On Behalf of
All Others Similarly Situated,
Plaintiffs,
v.
PLAID INC., a Delaware corporation,
Defendant.
Case No. 20-cv-4804
CLASS ACTION COMPLAINT
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 1 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 1 of 62
CLASS ACTION COMPLAINT
1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Plaintiffs David Evans, Patrick Lenahen, Adam Smotkin, and Oswaldo Herrera
(“Plaintiffs”), individually and as representatives of a class of similarly situated persons, by their
undersigned counsel, alleges as follows against Defendant Plaid Inc. (“Plaid”):
I.
INTRODUCTION
1.
Among the most valuable and sensitive of all consumer data is the personal
financial information maintained in consumers’ banking and other financial accounts. The
common law of privacy, as well as many federal and state laws, safeguard such information.
2.
Contrary to these laws and societal norms, Plaid takes consumers’ financial
account login credentials, accesses their banking and other financial accounts several times per
day, and then sells and otherwise misuses the highly personal and private information it has
wrongfully obtained. Plaid discloses none of this to consumers.
3.
Plaid gathers all this data through software embedded in widely-used financial
technology (fintech) apps such as Venmo, Coinbase, Square’s “Cash App,” and Stripe. Plaid’s
stated mission is to make it “easy” for consumers to “connect” their bank accounts to these
fintech apps, but Plaid conceals its conduct and true intentions from consumers. Indeed, Plaid for
years has exploited its position as middleman to acquire app users’ banking login credentials and
then use those credentials to harvest vast amounts of private transaction history and other
financial data, all without consent. Plaid has perpetrated this scheme to amass what it touts as
“one of the largest transactional data sets in the world.” First, Plaid induces consumers to
hand over their private bank login credentials to Plaid by making it appear those credentials are
being communicated directly to consumers’ banks. Consumers are informed the connection is
“private” and “secure,” and their banking credentials will “never be made accessible” to the app.
They are then directed to a login screen that looks like it is coming from their bank, complete
with the bank’s logo and branding. In reality, however, though Plaid does not disclose this, the
login screen is created by, controlled by, and connected to Plaid. Plaid executives have
acknowledged this process was “optimized” to increase “user conversions”—in other words, to
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 2 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 2 of 62
CLASS ACTION COMPLAINT
2
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
provide a false sense of comfort to consumers by concealing Plaid’s role as an unaffiliated third
party.
4.
Second, Plaid uses consumers’ login credentials to obtain direct and full access to
consumers’ personal financial banking information for Plaid’s own commercial purposes wholly
unrelated to consumers’ use of the apps. For each consumer, Plaid downloads years’ worth of
transaction history for every single account they have connected to that bank (such as checking,
savings, credit card, and brokerage accounts), regardless of whether the data in any of the
accounts bears any relationship to the app for which the consumer signed up. Thus, a consumer
who makes a single mobile payment on an app from a checking account unwittingly gives Plaid,
years’ worth of private, granular financial information from every account the consumer
maintains with the bank, including accounts maintained for others such as relatives and children.
To date, Plaid has amassed this trove of data from over 200 million distinct financial accounts.
5.
Plaid exploits its ill-gotten information in a variety of ways, including marketing
the data to its app customers, analyzing the data to derive insights into consumer behavior, and,
most recently, selling its collection of data to Visa as part of a multi-billion dollar acquisition.
Plaid has unfairly benefited from the personal information of millions of Americans and
wrongfully intruded upon their private financial affairs.
6.
Accordingly, Plaintiffs, on behalf of themselves and similarly-situated consumers,
bring this action to seek declaratory and injunctive relief requiring Plaid to cease its misconduct,
purge the data it has unlawfully collected, notify consumers of its misconduct, and inform
consumers of the steps they can take to protect themselves from further invasions. Plaintiffs also
seek economic redress for Plaid’s violations of consumers’ dignitary rights, privacy, and
wellbeing caused by Plaid’s unethical and undisclosed invasions into their financial affairs.
II.
JURISDICTION AND VENUE
7.
Pursuant to 28 U.S.C. § 1331, this Court has original subject matter jurisdiction
over the claims that arise under the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, and the
Stored Communications Act, 18 U.S.C. § 2701.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 3 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 3 of 62
CLASS ACTION COMPLAINT
3
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
8.
This Court also has supplemental jurisdiction over the asserted state law claims
pursuant to 28 U.S.C. § 1367.
9.
This Court has diversity jurisdiction pursuant to 28 U.S.C. § 1332(d) under the
Class Action Fairness Act because the amount in controversy exceeds $5,000,000, exclusive of
interest and costs, and at least one Class member is a citizen of a state different from Plaid.
10.
This Court has personal jurisdiction over Defendant because Plaid has conducted
business in the State of California, and because Plaid has committed acts and omissions
complained of herein in the State of California.
11.
Venue is proper in this District pursuant to 28 U.S.C. § 1391 because Plaid does
business in and is subject to personal jurisdiction in this District. Venue is also proper because a
substantial part of the events or omissions giving rise to the claims occurred in or emanated from
this District.
III.
INTRADISTRICT ASSIGNMENT
12.
Pursuant to Civil L.R. 3-2(c), assignment to the San Francisco Division of this
District is proper because a substantial part of the conduct which gives rise to Plaintiffs’ claims
occurred in the City and County of San Francisco. Plaid markets and deploys its products
throughout the United States, including in San Francisco. Additionally, Plaid is headquartered in
San Francisco and developed the software at issue in this action in this District.
IV.
THE PARTIES
13.
Plaintiff David Evans is a citizen of California.
14.
Plaintiff Patrick Lenahen is a citizen of the Commonwealth of Pennsylvania.
15.
Plaintiff Adam Smotkin is a citizen of New York.
16.
Plaintiff Oswaldo Herrera is a citizen of New York.
17.
Defendant Plaid Inc. is a financial technology company. Plaid is a Delaware
corporation with its principal place of business at 85 Second Street, Suite 400, San Francisco,
California 94105.
V.
FACTUAL BACKGROUND
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 4 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 4 of 62
CLASS ACTION COMPLAINT
4
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
A. Founding of Plaid
18.
In 2012, two former Bain & Co. consultants named William Hockey and Zach
Perret began collaborating on a mobile app designed to help consumers track their finances.
Looking back six years later, after Plaid had become a company valued at over a billion dollars,
Hockey told a meeting of fintech software developers “how and why we started Plaid.”1 Initially,
he said, he and Perret intended to help consumers “better control their finances,” but soon
realized, “[w]e weren’t really consumer guys.” Hockey and Perret determined that because
“there wasn’t a good way . . .to get consumers’ transaction history, account data, or anything like
that,” they would instead develop Plaid as a “back-end, developer-focused infrastructure
company.” Hockey and Perret decided that the planning and financial management (or “PFM”)
tools they were building were less interesting to them than “decisioning analysis” and “risk
modeling”—in other words, taking from users years of their transaction history and mining that
data to make predictions about purchases they might make. As Hockey and Perret described it at
an insular gathering of fintech software developers,2 “[w]e wanted to know habits and how
people were spending,” and then “target people based on how they were spending.” But Hockey
and Perret learned that “[t]he problem with existing data sources is you can look back 30 days,
60 days, maybe 90 days. We wanted to look back 5 years.” So they designed Plaid such that, as
Hockey put it, “[t]he moment a user comes on we can look 2, 3, 4, 5 years back. So the amount
of transactions we can actually hold is immense for an individual. That’s 5-6,000 transactions.”
Thus, even with just “a couple of users,” Hockey said, “the amount of transactions we can look
at is immense and the potential applications are awesome.”
19.
Plaid’s product offering thus evolved from a consumer-facing app aimed at
helping users plan their financial lives to largely invisible plumbing designed to amass a huge
1 Deep Dive w/Plaid—William Hockey, Co-Founder & CTO, Cambrian (Sept. 26, 2018),
https://www.youtube.com/watch?v=9D5Rwt3DvGg. In his opening remarks, Hockey asked if anyone had heard of
Plaid. Nearly everyone in the room, consisting of fintech software developers, raised their hands. This shows how
well known Plaid is among a small coterie of experts, even while it remains almost completely anonymous to the
2 Zach Perret and William Hockey, Plaid.io // NYC Data Business Meetup // Feb 2013, DataDriven NYC (Dec. 5,
2013), https://www.youtube.com/watch?v=_I8DRbFmLKM.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 5 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 5 of 62
CLASS ACTION COMPLAINT
5
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
mountain of data at consumers’ expense. Even the goal of providing the infrastructure that
connects users’ financial accounts to fintech apps, which enabled Plaid to accumulate that
mountain of sensitive user data in the first place, has since evolved to a new goal: mining that
mountain of data for profit. Plaid’s website reveals the shift in the company’s focus. According
to the “About Us” page on its website, Plaid “started out by building the technical infrastructure
APIs that connect consumers, traditional financial institutions, and developers. Today, we add
key insights to the data access we provide with our suite of analytics products.”
20.
Subsequently, the company developed relationships with some of the most
popular fintech apps. This included apps that allow people to transfer money or make consumer
purchases, such as Venmo, Square’s Cash App and Stripe; buy and sell cryptocurrencies, such as
Coinbase; or invest in equities, options and other investment assets, such as Robinhood (together,
the “Participating Apps”). Plaid is not an app that a user downloads directly. It does not appear
on the Apple or Android app stores that most mobile phone users visit to download apps. Instead,
Plaid is embedded in the Participating Apps, adding a functionality that the Participating Apps
don’t provide themselves. Plaid persuaded the Participating Apps to allow Plaid to be the data
plumbing connecting users to their bank accounts, thus enabling them to make ACH transfers to
and from those accounts using the apps.
21.
By partnering with the Participating Apps, Plaid gained access to hundreds of
millions of consumers. Venmo (now owned by PayPal) has over 52 million active user accounts;
Coinbase reportedly has more than 30 million;3 and Cash App reportedly has more than 24
million.4 Stripe’s payment service reportedly is used by millions of businesses, and thus a
commensurate number of consumers.5 Many of those users utilize Plaid to connect their bank
accounts to the Participating Apps. Plaid itself claims that it connects to 11,000 financial
3 About Us, Coinbase (last visited June 23, 2020), https://www.coinbase.com/about.
4 Daniel Keyes, Square’s Cash App User Base Surges to a Massive 24 Million Monthly ActiveCustomers, Business
Insider (Feb. 28, 2020), https://www.businessinsider.com/squares-cash-appreached-24-million-users-and-
monetization-surge-2020-2.
5 Customers, Stripe (last visited June 23, 2020), https://www.stripe.com/customers.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 6 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 6 of 62
CLASS ACTION COMPLAINT
6
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
institutions; that 1 in 4 Americans have provided their bank login credentials to Plaid; and that it
has gathered data from and retains credentials for as many as 200 million distinct financial
accounts.
22.
Plaid now describes itself as an “infrastructure” company, but even that
description conceals Plaid’s true purpose: invading consumers’ privacy for profit. In a 2019
interview, Perret revealed that the name Plaid refers to an algorithm he and Hockey devised to
conduct “cross-user comparisons”: comparing users’ transaction patterns to those of other users
against the backdrop of Plaid’s database of merchants. The overlapping patterns resembled a
crosshatch pattern—hence the name.6
B.
Plaid Deliberately Undermines Industry Standard Security Protocols
In Order to Trick Users Into Giving Plaid Their Bank Login Credentials
23.
Plaid has acquired its mountain of consumer data by deceiving consumers into
giving Plaid the key to their financial lives: their bank usernames and passwords.
24.
Historically, in order to allow a third party access to a bank account, a user had to
submit his bank routing and account numbers; transfer a small trial deposit (usually a few cents);
and then return to the bank to verify the amount transferred.7 This could take several days and, in
the fast moving world of fintech, that delay would cause many potential customers to abandon
their adoption of a fintech app. In the terminology of the software world, this reduced new user
conversions.
25.
One alternative to this arduous process is “OAuth.” Users are likely familiar with
this procedure because it has become the industry-standard protocol for users who wish to grant
a website or app permission to access certain information from another website or app. Crucially,
OAuth “enables apps to obtain limited access (scopes) to a user’s data without giving away a
user’s password.” For instance, consider an example in which a user wishes to grant Facebook
6 Fireside Chat: Zach Perret, Founder & CEO of Plaid (FirstMark’s Data Driven NYC) at 10:45to 11:45, Data
Driven NYC (May 13, 2019), https://www.youtube.com/watch?v=sgnCs34mopw (“Perret Interview”).
7 DEEP DIVE with Plaid: Fintech’s Super-Connector, FinTechtris (Oct. 24, 2018),
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 7 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 7 of 62
CLASS ACTION COMPLAINT
7
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
permission to access his Twitter account so that he can integrate his social media accounts
together. Before he can do so, the user will be redirected from Facebook to Twitter, where he
must login to ensure he is authorized to grant those permissions.8 Then, a dialogue box pops up,
asking which permissions he is granting and which he is denying. The dialogue box might look
something like this:
9
26.
In this example, note that the user grants Facebook permission to update his
Twitter profile and even post to the user’s Twitter account (“This application will be able to: . . .
Update your profile; Post Tweets for you”), but denies Facebook permission to see the user’s
Twitter password (“This application will not be able to: . . . See your Twitter password”).
Instead, the user provides his Twitter username and password only to Twitter. Twitter then sends
a “token” to Facebook, essentially confirming to Facebook that the user’s login to Twitter was
legitimate. Scopes are one of the “central components” and perhaps even “the first key aspect” of
OAuth.
27.
But as with the old-fashioned way of authorizing a bank account by providing
account and routing numbers and waiting for a small deposit, OAuth purportedly undermines an
8 Redirection from the app the user is currently using to the app where it retains the data to which
it is granting permission is a hallmark of OAuth. See OAuth 2.0, OAuth (last visited June 23,
2020), https://oauth.net/2/.
9 See Matt Raible, What the Heck is OAuth?, Okta (June 21,
2017),https://developer.okta.com/blog/2017/06/21/what-the-heck-is-oauth.
1111$ .,- wlll bll .abl• ta
- Pnst T t!I. \Ql' 'J'OU
f
ffljijQj.]ij
ij Cance l
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 8 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 8 of 62
CLASS ACTION COMPLAINT
8
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
app’s user conversion rate. Because it requires a user to leave the app and be redirected to
another app, OAuth supposedly drives consumers away who decide it isn’t worth the trouble.
28.
So Plaid devised an alternative to traditional bank verification or even OAuth:
“Managed OAuth,” which it also calls “Screenless Exchange,” the technology underlying the
“Plaid Link” software that Plaid embeds in each of the Participating Apps. Plaid co-founder
Perret has described Managed OAuth as “kind of like OAuth, where the OAuth is embedded in
the application. It’s not technically OAuth, but it behaves very similarly.”10
29.
Plaid claims that Managed OAuth is “technically” different from OAuth in that it
eliminates the need to redirect a user to his bank’s website.11 But there are several other
important distinctions between industry-standard OAuth and Plaid’s Managed OAuth. First,
Plaid does not provide a clear dialogue box outlining the scopes of the permissions that the user
is granting to Plaid or the permissions the user is denying to Plaid (indeed, the user has no option
to deny Plaid any permissions at all).
30.
Second, and more importantly, the core principle of OAuth—and what has made
it the industry-standard authorization protocol—is that an app like Plaid can obtain limited
access to a user’s data without accessing the user’s password. But Plaid designed Managed
OAuth specifically to circumvent this precaution and to deceive users into giving up their bank
usernames and passwords to Plaid. Plaid achieves this fraud by erecting a sophisticated edifice
of deceit to trick users into thinking that they are logging into their financial institutions, when in
fact they are turning over their credentials to Plaid.
C.
Plaid Deceives Users By Representing Itself To Be Their Financial
Institutions
10 Perret Interview at 17:30-17:45.May 13, 2019 interview with Zach Perret at Data Driven NYC event at 17:30-
17:45, https://www.youtube.com/watch?v=sgnCs34mopw.
11 Eric Showen, Demystifying Screenless Exchange, Fin (Nov. 15, 2016), https://fin.plaid.com/articles/demystifying-
screenless-exchange/. (“Screenless Exchange combines the security advantages of OAuth—such as tokenization—
with the design elements offered by solutions like Plaid. Specifically, Screenless Exchange is different because it
allows a user to permission access to personal financial data without ever leaving the original app.”)
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 9 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 9 of 62
CLASS ACTION COMPLAINT
9
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
31.
Consider the following hypothetical user experience of Plaid Link. A user
downloads Venmo and creates an account, with the intent of sending money to a friend. Because
it is his first time using the app, he has no balance in his Venmo account, and needs to connect
his checking account in order to have funds to transfer. After clicking on “Add bank or card...,”
the user will see the below message pop up:
( Back Bank Verification
1.
Instant Verification
Sign in to your bank to instantly verify your >
bank account.
2.
Manual Verification
Use your bank's routing and account number. >
Verification can take up to 3 business days.
32.
The user sees two options: “instant verification” or “manual verification.” Manual
verification refers to the process of using a bank’s routing and account number and sending a
small deposit. As the dialogue box indicates, this can take up to 3 business days.
33.
If the user selects instant verification, Venmo will display the following dialogue
box:
Instant Verification
Venmo uses Plaid to verify your bank account information and, periodically, your bank
account balance to check you have enough funds to cover certain transactions.
You can turn off Venmo's use of Plaid by simply removing the bank account. You can
always use our manual verification process to add a bank account, which doesn't use
Plaid.
Continue
34.
The dialogue box states, “Venmo uses Plaid to verify your bank account
information and, periodically, your bank account balance to check you have enough funds to
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 10 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 10 of 62
CLASS ACTION COMPLAINT
10
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
cover certain transactions.”12 The screen contains no description of what Plaid is or does, or even
the fact that it is a distinct entity with no corporate affiliation with Venmo. It gives the
misleading impression that Plaid is only collecting balance information. It does not disclose that
Plaid will (as discussed below) download years of the user’s transaction history for purposes
entirely unrelated to connecting the user’s bank account.
35.
The dialogue box then states, “[y]ou can turn off Venmo’s use of Plaid by simply
removing the bank account.” This statement misleads users by omitting the fact that once Plaid
has obtained a user’s credentials, removal of the bank account from Venmo has no effect on
Plaid’s retention and use of those credentials to collect, retain and sell the user’s sensitive
personal data going forward.
36.
If the user clicks “continue,” a dialogue box comes up that indicates that use of
Plaid is both “Secure” and “Private”:
12 Although the precise language that each Participating App uses to describe Plaid varies, Plaid has admitted that it
plays a direct role in shaping those disclosures. See Perret Interview at 25:45-26:10 (“[O]ur customers are the ones
that build the consumer apps. But there are certain elements of the consumer experience that are really important,
such as making sure that a consumer understands data privacy. Where it’s going, how it’s going.”) But in reality,
Plaid either negligently fails to exercise this oversight or willfully sanctions the Participating Apps’ failure to make
adequate disclosures. For instance, if a user is attempting to link her bank account to Cash App, he will not even see
the messages like the ones in the Venmo dialogue boxes described here. Instead, he proceeds directly to the Plaid
Link iframe requesting user credentials as displayed in ¶50. Whether in Venmo (with its minimal and misleading
disclosures), Cash (which makes no reference to Plaid at all) or otherwise, at no time are users of the Participating
Apps informed in the app that Plaid will take their bank login credentials, retain them, and use them to collect
extraordinarily detailed data about their financial lives, going back five years and going forward in perpetuity.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 11 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 11 of 62
CLASS ACTION COMPLAINT
11
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
37.
These representations are false.
38.
First, the transfer of information is not secure. Plaid sends login credentials in
plain text under only a single level of encryption. This leaves the credentials open to interception
by a hacker with even a minimal level of experience. Further, after Plaid has collected and
retained a user’s information, including sensitive personal data, Plaid packages it into various
products that it sells to the Participating Apps and other third parties. Plaid exercises no control
or oversight over those third parties after it has sold it. Although it requires such customers to
“handle End User Data securely” and adhere to best practices, Plaid has no enforcement or
tracking mechanisms in place to ensure that developers do so.
39.
The statement about the security of Plaid is not only false but also misleading. By
stating that a user’s information is encrypted end-to-end, Plaid gives the user the false impression
that no entity other than Venmo and his bank will be able to access the user’s bank balances, let
alone the vast quantity of other sensitive personal data that Plaid collects. In fact, Plaid obtains
this data for use by itself and its third party customers.
40.
Second, the transfer of information is not private. Plaid deceives the user into
thinking that he is providing credentials only to his bank, using Plaid merely as a link. But it is
misleading to say that the user’s credentials will never be made accessible to Venmo. The user’s
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 12 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 12 of 62
CLASS ACTION COMPLAINT
12
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
credentials are made accessible to Plaid, which keeps the credentials for itself, using them to
extract reams of sensitive personal data. Further, even if Venmo never obtains the user’s
credentials, Venmo may later obtain the data that the credentials protect—after Plaid has
packaged it into analytics products that Plaid sells to the Participating Apps and others, as
discussed below.
41.
At the bottom of the dialogue box reproduced in ¶ 13 is a large blue button
labeled “Continue.” Above that, in small gray print is the language, “By selecting ‘Continue’ you
agree to the ‘Plaid End User Privacy Policy.’” That text is deemphasized in several ways. For
instance, the text is smaller than other text on the screen and it appears in a light gray color that
is more difficult to read than the other text on the screen. Although that text is underlined,13 it
does not appear in the blue color normally indicating a hyperlink. A user would not know that
this text contains a link to Plaid’s privacy policy unless he were to actually click on it. Nothing
else on the screen directs the user to do so. The screen contains no requirement that the user must
review (or even scroll through) the privacy policy before clicking “Continue.”
42.
This disclosure is known in the tech world as a “fine-print click-through”
disclosure. This disclosure is inadequate to put a user on actual or constructive notice that if he
proceeds, Plaid will gather information on every financial transaction he has made going back
five years and going forward in perpetuity.14 Plaid itself has admitted that such disclosures are
inadequate. In a 2019 letter to the United States Senate Committee on Banking, Housing, and
Urban Affairs, Plaid wrote, “[a]ffirmative permission (not fine-print click-through) should be
required in order to sell account data, even in aggregated form, to any parties the consumer
doesn’t have a direct permissioning relationship with. To do otherwise would breach the trust
13 The underlining is a recent addition that was not present as recently as a few months ago.
14 As described more fully below, even if a user realizes that the gray language contained a hyperlink to the Privacy
Policy, clicked through to that policy and reviewed it—as few if any users actually do—the Privacy Policy is riddled
with so many misrepresentations and omissions that any consent to that Policy is invalid.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 13 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 13 of 62
CLASS ACTION COMPLAINT
13
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
consumers place in fintech providers.”15 Yet, as discussed below, Plaid does sell Plaintiffs and
Class Members’ data—in aggregated form and otherwise—to the Participating Apps and other
third party customers, despite the fact that Plaintiffs and Class Members never consented to such
sale of their data.
43.
After the user clicks “continue,” the app asks a user to “select your bank” from a
list of approximately 16 of the nation’s largest financial institutions. After selecting a bank, the
screen on the app appears to slide to the left, mimicking the visual a user would see if the app
redirected his to his bank’s website.
44.
Plaid designed the next steps of the process with the explicit intent of deceiving
the user into thinking that he is in the secure environment of his trusted financial institution.
Plaid Link presents the user with a login screen that mimics the look and feel of the user’s bank,
including by imitating its distinctive color scheme, font and logo. For example, if the user selects
Chase, he will be directed to a login screen as depicted in this screenshot:
15 See John Pitts, Plaid Submission to the U.S. Senate Committee on Banking, Housing and Urban Affairs (Mar. 15,
2019), available at https://www.banking.senate.gov/imo/media/doc/Data%20Submission_Plaid1.pdf.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 14 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 14 of 62
CLASS ACTION COMPLAINT
14
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
45.
This interface features the word “Chase” in the bank’s characteristic font; the
Chase logo; and a background color in Chase’s distinct navy blue. The same is true for Bank of
America, Wells Fargo, Citibank, and thousands of other financial institutions.
46.
Plaid has designed this entire process—including the “sliding” animation as well
as the look and feel of the page asking for input of credentials—to mislead the user into thinking
that he is being redirected to his bank’s website, as would happen if Plaid deployed a true OAuth
procedure. Plaid deliberately creates the false impression that the user is sharing his credentials
only with his bank directly. In fact, the user has never left the Plaid Link interface within the
Participating App and is sharing his login credentials with Plaid—not just temporarily and for the
purposes of connecting his account but permanently and for whatever purposes Plaid chooses.
47.
Plaid has admitted and even boasted that it designed its interface to give the user
the false impression that he is dealing directly with his bank. In April 2016, a Plaid engineer
bragged that Plaid had “completely optimized our drop-in module used for onboarding bank
accounts.”16 Plaid attributed this success to its use of “design elements” that mirror the “look and
feel of permissioning access” for the financial institutions, thus “increasing user conversion.”17
Plaid has admitted that it designed this approach to give users “a greater sense of security and
familiarity.”18
48.
Various members of the developer community—including members of Plaid’s
own team—have called out the company for this misleading conduct. In late 2018, a poster on a
nowdeleted thread on the developer website GitHub called out the fact that a third party website
was using a Plaid iframe to “render[] my bank’s logo to fool me into thinking I’m accessing my
bank’s site.”19 Plaid engineer Michael Kelly responded:
16 See Fintech Firm Plaid Raises $44M, Y Combinator Hacker News (Jun. 20, 2016),
https://news.ycombinator.com/item?id=11939103.
17 Shown, supra n. 11.
18 See Baker Shogry, Improving Search for 9,600+ Banks, Plaid (Dec. 13, 2017), https://blog.plaid.com/improved-
search/ (“This means you’ll see logos and brand colors for even more institutions in Link so that end-users feel a
greater sense of security and familiarity when they recognize their institution’s look-and-feel.”).
19 Privacy/Security Concerns #68, GitHub (Feb. 11,
2016),http://web.archive.org/web/20190415103059/https:/github.com/plaid/link/issues/68.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 15 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 15 of 62
CLASS ACTION COMPLAINT
15
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
[W]e appreciate your concerns, which is why our compliance team vets anybody
who uses Link. As to malicious knock offs, this is a matter that most successful
companies lookout [sic] for and deal with -- as we and our security team do. If
you see someone impersonating Link in such a way, please drop us a note at
security@plaid.com. It’s also worth noting that, in addition to the security we
provide, banks protect their users from credential based attacks via multi factor
authentication.
Kelly did not deny that Plaid was impersonating major financial institutions, or that others might
try to use Plaid’s code to do the same. Indeed, he indicated Plaid’s awareness that precisely that
kind of malicious conduct does take place.
49.
In May 2018, a poster to the site Y Combinator Hacker News warned others
against using the stock-trading app Robinhood because of concerns about Plaid: “I would really
caution connecting your bank account through Plaid on RH. It’s really unclear what data they are
collecting but their privacy policy suggests they are collecting your bank account transaction
history using Plaid’s API. 100% a dealbreaker for me.” The poster was right that someone was
collecting his entire bank account transaction history, but he was mistaken that the malfeasor was
Robinhood rather than Plaid. Plaid co-founder Hockey responded, “I can’t give the rationale on
why RH wrote the privacy policy the way they did, but I can guarantee you that they are not
pulling transactional data. They’re only using Plaid for the ACH authentication.”20 Notably,
Hockey did not deny that Plaid was collecting Plaid’s full transaction history; only that
Robinhood was not. This deflection echoes the language noted above in the Venmo disclosure,
“[y]our credentials will never be made accessible to Venmo.” The credentials are, of course,
made accessible to Plaid. This linguistic sleight of hand does not justify Plaid’s deceitful
conduct, particularly where that conduct leads to invasions of privacy on a massive scale.
50.
Any consent that Plaid claims to have obtained from Plaintiffs and Class
Members is further called into question by the fact that most consumers do not recognize that
Plaid is an entity distinct from the Participating App that they are using, or even—as Plaid
20 See Stock-Trading App Robinhood Was Rejected by 75 Investors, Y Combinator Hacker News (May 13, 2018),
https://news.ycombinator.com/item?id=17060034.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 16 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 16 of 62
CLASS ACTION COMPLAINT
16
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
boasts—that Plaid exists at all. Co-Founder Hockey has said in interviews that “most people will
never know we exist.”21 Perret has stated, “we don’t need every consumer to know what Plaid
is.”22 One of Plaid’s investors at Goldman Sachs Investment Partners told CNBC, “Plaid has
quietly created a very big infrastructure without the consumer knowing that they’re powering
it.”23
51.
If consumers don’t know that Plaid exists, they certainly cannot consent to Plaid
taking their data. Plaid intentionally designs the software interface that a user sees when
connecting his bank account to a Participating App to ensure that the user does not receive actual
or constructive notice of Plaid’s conduct—including that Plaid is collecting the user’s login
credentials and then using them to collect, retain and sell vast quantities of his sensitive personal
data. Plaid knows that if its users were on notice of the massive invasions of privacy in which
Plaid engages, it would never secure consent of any kind.
D.
Plaid Gathers Data Far Beyond What it Needs for the Services It Provides
52.
In response to a 2017 Request for Information from the Consumer Financial
Protection Bureau (the “CFPB RFI”), Plaid wrote, “[m]inimization is a key principle that should
govern data use; it is the concept that permissioned parties should collect only a rational amount
of data to service a product or service, and store such data for the necessary amount of time. Data
collection and retention policies should be clearly displayed in plain English to consumers by
permissioned parties, typically during onboarding – in other words, transparency is critical.”
53.
In practice, Plaid departs from every word of this statement.
54.
First, Plaid collects far more data than it needs. Plaid does not collect only a
rational amount of data to support the service it provides to Plaintiffs and Class Members,
21 See Nick Sommariva, EmoryWire (Aug. 2013),
http://www.alumni.emory.edu/emorywire/issues/2013/august/of_interest/story_1/index.html#.Xk sqMxNKjQg.
22 See Feb. 2019 interview with Zach Perret at 19:08 to 19:37; Louise Lee, the Plaid Story: Integrating with 10,000
Institutions. On the Way to a $5 Billion Acquisition, SaaStr (Jan. 14, 2020), https://www.saastr.com/build-a-
platform-ecosystem/.
23 See Kate Rooney, Meet the Start-Up You’ve Never Heard of that Powers Venmo, Robinhood, and Other Big
Consumer Apps, CNBC (Oct. 4, 2018), https://www.cnbc.com/2018/10/04/meetthe-startup-that-powers-venmo-
robinhood-and-other-big-apps.html (emphasis added).
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 17 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 17 of 62
CLASS ACTION COMPLAINT
17
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
namely, linking their bank accounts to the Participating Apps. Instead, from “[t]he moment a
user comes on” to Plaid’s system, Plaid looks back 5 years into their financial histories and
gathers information regarding “5-6,000 transactions.” In Plaid’s own words, “the amount of
transactions [Plaid] can look at is immense.” In job postings on the influential software
developer forum Y Combinator Hacker News, co-founders Hockey and Perret have repeatedly
described Plaid as “generating one of the largest transactional data sets in the world, and using
machine learning and statistical analysis to draw insights about how consumers spend their time,
money, and attention.”24 The data Plaid collects data extend into every corner of users’ lives,
including their spending and borrowing related to health care, education, transportation, political
contributions, dining, entertainment, and other habits, as well as investment and retirement
savings.
55.
Plaid has claimed that it is entitled to this data under users’ assignments to Plaid
of their rights under the Dodd-Frank Act. See Perret Interview at 23:00-23:30 (“In the early days,
there’s a provision of Dodd-Frank that consumers must have access to a digital copy of their
financial data. We operated under this principle where consumers assigned us that and we then
went and collected the data from the bank.”). Nowhere in Plaid’s statements to users of the
Participating Apps does it disclose that it is gathering data pursuant to Dodd-Frank or that it is
asking users to assign those rights to Plaid.
56.
Because it is largely automated, Plaid’s collection of sensitive personal data is
indiscriminate. It gathers financial data regardless of the protections, described below, that
statutes and public policy ascribe to users’ financial information. It gathers health-related data
regardless of the Health Insurance Portability and Accountability Act (“HIPAA”). And it gathers
all of this information regardless of the age of the account holder, thus gathering extensive
24 Plaid Technologies – plaid.io, Y Combinator Hacker News (Feb. 1, 2013),
https://news.ycombinator.com/item?id=5151764; Plaid Technologies – http://plaid.io/jobs, Y Combinator Hacker
News (Mar. 1, 2013). https://news.ycombinator.com/item?id=5304472; Ask HN: Who is Hiring? (July 2015), Y
Combinator Hacker News (July 1, 2015) https://news.ycombinator.com/item?id=9812245.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 18 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 18 of 62
CLASS ACTION COMPLAINT
18
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
information about minors.25 The scope of the data that Plaid collects is utterly disproportionate to
the services it provides to users of the Participating Apps and is not routine commercial behavior.
57.
Second, Plaid retains user data for far longer than necessary and re-collects it
far more often than necessary. Plaid stores the data that it collects for far longer than is
necessary to connect user bank accounts to the Participating Apps. Plaid collects this data not
only at the time that users of the Participating Apps connect their financial accounts, but on a
constant, rolling basis and then stores it indefinitely. According to Plaid’s Head of Engineering,
Plaid is “effectively caching” the banking data.26 Plaid “update[s] a user[’]s account at set
intervals throughout the day, independent of how many times a client calls the /connect
endpoint”—in other words, regardless of the last time the user actually used the Participating
App.27 This can happen as often as multiple times per day, or every 4-6 hours, going forward in
perpetuity.
58.
Third, Plaid is not transparent about the data it collects. As detailed
throughout this Complaint, Plaid acquires data from Plaintiffs and Class Members only through
an elaborate web of lies, fraud and deceit that it has erected with the express intention of
extracting from them their sensitive personal data. It does not disclose to users in plain English
the data it accesses or the fact that it collects, retains and sells it.
E.
Plaid Sells User Data, Despite Its Explicit Promise to Not Do So
59.
In the privacy overview on Plaid’s website, it claims, “we never sell your data.”
This is false.
60.
In fact, Plaid does sell user data. The Plaid website admits that the company is
pivoting from what its co-founders have called Phase 1—building its “immense” database of
25 Even if the user of the Participating App is an adult, if that adult uses the same login credentials it provides to
Plaid to access the accounts of a minor for whom it acts as a custodian, Plaid will access, collect, retain and sell the
data from that account.
26 See Plaid: Banking API Platform with Jean-Denis Greze, Software Engineering Daily (Dec. 13, 2018),
https://softwareengineeringdaily.com/2018/12/13/plaid-banking-api-platform-withjean-denis-greze/.
27 See Plaid Legacy API, Plaid (last visited June 23, 2020), https://plaid.com/docs/legacy/api/.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 19 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 19 of 62
CLASS ACTION COMPLAINT
19
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
consumer data—to Phase 2: “add[ing] key insights to the data access we provide with our suite
of analytics products.”28
61.
Plaid could not sell those analytics products without the mountain of consumers’
private data that it has amassed. And the data up for grabs is extensive. For example, Plaid
advertises that it offers customers access to “detailed transaction history,” including the
following product features:
The first two categories are aimed at third parties, not users. The first category suggests that
while Plaid collects as much as five years of user data, it offers customers the opportunity to
“[r]etrieve typically 24 months of transaction data, including enhanced geolocation, merchant,
and category information.” The second category highlights Plaid’s ability to constantly ping
Plaintiffs and Class Members’ financial accounts on an ongoing basis by offering, “[c]ontinuous
transaction updates: Stay up-to-date by receiving notifications via a webhook whenever there are
new transactions associated with linked accounts.” In sum, Plaid can only offer these services
because of the enormous amount of data that Plaid takes from users and then updates even more
often than once per day.
62.
In August 2018, a programmer who formerly worked for Plaid confirmed that the
company “perform[ed] huge amounts of analytics on customer data acquired as part of the
28 See Our Vision, Plaid (last visited June 23, 2020), https://plaid.com/company/. See also Perret Interview at 12:30-
13:15 (“We’re continuing to do more analytics on top of the data. It’s an immense pile of data that we have.”); 14:21
to 14:26.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 20 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 20 of 62
CLASS ACTION COMPLAINT
20
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
account verification process.29 Plaid investor Goldman Sachs has explained that Plaid has
developed a “sustainable moat or advantage” against its competitors because the Participating
Apps rely upon Plaid to understand their own users’ behavior.30
F.
Plaid’s Privacy Policy is Misleading
63.
In the unlikely event that a user clicks through to review Plaid’s privacy policy—
which the vast majority of users do not, because nothing requires them to do so—that policy fails
to place Plaintiffs and Class Members on actual or constructive notice of the outrageous
invasions of privacy in which Plaid engages. As a result, any consent to that Policy is not only
questionable but invalid.
64.
The Privacy Policy begins with the phrase, “Privacy and security are very
important to us at Plaid.” It continues, “[o]ur goal with this Policy is to provide a simple and
straightforward explanation of what information Plaid collects from and about end users . . . and
how we use and share that information. We value transparency and want to provide you with a
clear and concise description of how we treat your End User Information.”31 These statements
are false and misleading.32
65.
In California, multiple statutes govern the disclosures that a privacy policy like
Plaid’s must contain. The California Consumer Privacy Act (the “CCPA”) requires that any
“business that collects a consumer’s personal information” must “inform consumers as to the
categories of personal information to be collected and the purposes for which the categories of
29 See Ask HN: What Is the Most Unethical Thing You've Done As a Programmer?, Y Combinator Hacker News
(Aug. 5, 2018) https://news.ycombinator.com/item?id=17692291.
30 See Rooney, supra n.23.
31 Legal, Plaid (last visited June 23, 2020), https://plaid.com/legal/.
32 In addition to its formal privacy policy, Plaid’s website also contains a page offering an overview of its approach
to privacy that is briefer and written in less legal language. See Privacy, Plaid (last visited June 23, 2020),
https://plaid.com/overview-privacy/. This statement also contains misrepresentations and omissions of material fact.
For instance, the page states, “When you connect a financial account to an app or service using Plaid, you allow us
to access your account data so that we can deliver it to the apps you want to use.” It does not state that Plaid also
retains this data for itself, nor does it disclose that the “account data” it captures is deeply invasive details of every
financial transaction from the past five years. The page also states, “We’re committed to handling your data with the
utmost care and respect for your privacy. It’s why we never sell your data.” As noted herein, Plaid does sell user
data and products based off of user data.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 21 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 21 of 62
CLASS ACTION COMPLAINT
21
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
personal information shall be used. A business shall not collect additional categories of personal
information or use personal information collected for additional purposes without providing the
consumer with notice consistent with this section.” Cal. Civ. Code § 1798.100(b). Similarly, the
California Online Privacy Protection Act (“CalOPPA”) requires that “[a]n operator of a[n] . . .
online service that collects personally identifiable information through the Internet about
individual consumers” must “[i]dentify the categories of personally identifiable information that
the operator collects . . . about individual consumers who use or visit its . . online service and the
categories of third-party persons or entities with whom the operator may share that personally
identifiable information.” Cal. Bus. & Prof. Code § 22575.
66.
Plaid violates these statutes because the vague descriptions in its Privacy Policy
do not put consumers on notice of the full scope and extent of its data practices.
67.
First, Plaid’s Privacy Policy omits material facts: Plaid does not disclose that
rather than merely providing a link to Plaintiffs and Class Members’ financial institutions, as it
suggests, Plaid in fact collects and retains users’ bank login information for its own purposes.
Plaid does not disclose that it uses those credentials to access Plaintiffs and Class Members’
accounts. Plaid does not disclose any information about the temporal scope of the data it collects,
including that Plaid accesses at least five years’ worth of transaction history. Plaid does not
disclose that it retains Plaintiffs and Class Members’ login credentials and data indefinitely. Plaid
does not disclose that it continues to access Plaintiffs and Class Members’ accounts and scrapes
their updated transaction history multiple times per day, going forward in perpetuity—regardless
of how often the user uses the Participating App, including if he stopped using it entirely or
never used it at all. Plaid does not disclose that it uses, sells and otherwise benefits from the data
that it collects, including to the Participating Apps and others. Plaid does not disclose that after it
sells Plaintiffs and Class Members’ data to third parties, it exercises no oversight or control over
how that data is stored, used, or secured. Plaid does not disclose that by removing Plaintiffs and
Class Members’ data from the secure banking environment, it is destroying their rights to
indemnification and other important rights and protections.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 22 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 22 of 62
CLASS ACTION COMPLAINT
22
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
68.
Second, the disclosures that Plaid does make are too vague to be sufficient. The
Privacy Policy gives the user the false impression that it collects only the data necessary to link
his account to a Participating App, because it emphasizes basic information such as the user’s
account number and balance.
69.
Third, Plaid’s Privacy Policy states that the information it gathers “varies
depending on the specific Plaid services developers use to power their applications, as well as the
information made available by those providers.” In fact, Plaid’s collection of user data has no
relationship to the Plaid services that developers use. Once Plaid gains a user’s bank login
credentials, it gathers all available transaction history and other data from all accounts linked
with those credentials, regardless of whether the user has sought to connect a particular account
to the Participating App and regardless of any relationship between the data Plaid collects and
the service it is providing. Even the entry level analytics product that Plaid offers for sale to
developers provides two years of user transaction history.
70.
Fourth, under the heading “How We Use Your Information,” Plaid’s Privacy
Policy lists seven highly vague purposes, such as “To operate, provide and maintain our
services” and “To develop new services.” This gives the misleading impression that Plaid is
gathering the data for the benefit of consumers, i.e., to improve users’ experience and provide
them with additional and superior services. In fact, as Plaid’s co-founders have admitted, they
are “not consumer guys.” The data that Plaid collects, for the most part, has nothing to do with
the services it provides to users, but is geared towards supporting the analytics products that it
sells to third parties.
G.
Plaid’s Public Statements Are Misleading
71.
In addition to the misstatements and omissions in Plaid’s Privacy Policy, Plaid
and its co-founders have repeatedly made statements in public that give the impression that it
operates in the best interest of consumers and is committed to the security and privacy of their
data. These statements are false.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 23 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 23 of 62
CLASS ACTION COMPLAINT
23
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
72.
In February 2019, the Senate Banking Committee sought feedback from
stakeholders regarding “the collection, use and protection of sensitive information by financial
regulators and private companies.” Plaid’s response described an aspirational, consumer-centric
view of its business that completely misrepresents its actual practices.
73.
In its letter, Plaid claimed that it “help[s] a consumer access their own data only
when they chose to do so, and sharing it only with the companies they select. This is a consumer-
permissioned model, in which consumers control what they do with their data.”33 Plaid knows
well that Plaid does not allow consumers to share their data only with companies they select,
since Plaid itself collects, retains and sells consumers’ data; of course, a consumer cannot
“select” to share his data with a company like Plaid if he does not know it exists. Likewise, Plaid
knows that the company’s model does not permit consumers to “control what they do with their
data” since, once Plaid takes it, consumers have no control over what Plaid does with it. And
even Plaid exercises no control or oversight over user data after it sells it.
74.
Plaid’s letter to the Senate Banking Committee also states, “[a]t Plaid, consumer
permission and control are core principles. Unlike many other service providers who rely on
personal or financial data, our account connectivity services require consumers to affirmatively
provide or permission access to their account information to the company they want to share it
with.” As discussed above, Plaid’s permissioning protocol departs from the industry-standard
permissioning protocol, OAuth, in material ways, including because it deceives users into
providing their login credentials directly to Plaid and because it fails to sufficiently disclose or
cabin the scopes of those permissions.
75.
Plaid’s letter to the Senate Banking Committee also states, “consumer permission
should be tied to the services the consumer requests or purposes for which they are specifically
informed when they grant access.” Yet as this Complaint makes clear, Plaid’s collection,
33 See Crapo, Brown Invite Feedback on Data Privacy, Protection and Collection, U.S. Senate Committee on
Banking Housing, and Urban Affairs (Feb. 13, 2019), https://www.banking.senate.gov/newsroom/majority/crapo-
brown-invite-feedback-on-dataprivacy-protection-and-collection.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 24 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 24 of 62
CLASS ACTION COMPLAINT
24
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
retention and sale of Plaintiffs and Class Members’ sensitive personal data are completely out of
proportion to the service Plaid supposedly provides: connecting bank accounts to the
Participating Apps.
76.
In various other statements, Plaid and its co-founders have expressed their
commitment to consumer welfare, even as Plaid’s conduct consistently belies those platitudes.
For instance, Plaid’s website states that it designed its products to “help users manage, budget
and make sense of their money.” It describes its “vision” as “democratizing financial services
through technology,” and that its “mission is to improve people’s lives by delivering access to
the financial system.” It states that “[b]y delivering access to high-quality, usable financial
account data that we’ve translated and standardized, we enable developers to focus on building
experiences that benefit you.”34 Co-founder Perret told an interviewer, “[o]f course, we’re doing
things only that benefit the consumer. . . . It’s a lot of data but we need to make sure that the
products we’re building are in the consumer’s best interest.”35 Perret has also said that that it is
“really important” for consumers using Plaid’s software to understand things like “data privacy,
where their data is going, [and] how it’s going [there].”36
77.
If Plaid were truly committed to building products that are in consumer’s best
interests, it could apply the same standards in the United States that it applies in Europe. On
September 14, 2019, the European Union’s new privacy rule, Payment Services Directive No. 2
(“PSD2”), became effective. One key element of the new regulation is that a company like Plaid
must not gather users’ credentials or accumulate years of their transactional history. In order to
comply with this policy, Plaid implemented a new approach for European users: “Plaid’s PSD2-
compliant European integrations use a protocol called OAuth 2.0 (Open Authorization) that
allows users to share their financial data without giving Plaid access to their bank login
34 See Legal, supra n. 31.
35 Perret Interview at 13:18 to 13:34.
36 Perret Interview at 21:38 to 26:11. See also id. at 29:35-30:00 (“We don’t directly touch consumers. But our goal
is to create an ecosystem where the consumer wins. . . . It’s about the end customer that is getting the value out of
financial services.”).
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 25 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 25 of 62
CLASS ACTION COMPLAINT
25
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
credentials. Users can then revoke access to their data at any time via their bank’s website, or
extend access via Link update mode.” Plaid co-founder Perret has stated that PSD2 “is good for
consumers, so we’re excited.”37 If Plaid were in fact committed to acting in the interest of
consumers in the United States, it would implement OAuth 2.0 in the United States, regardless of
whether it is required by law to do so. Instead, Plaid has continued to pursue its strategy of
collecting Plaintiffs and Class Members’ login credentials and data through a sophisticated
system of fraud and deceit.
H.
Plaid Violates Statutory Standards for Treatment of Financial Data
78.
The Graham Leach Bliley Act (the “GLBA”) and the regulations promulgated
thereunder impose strict requirements on financial institutions regarding their treatment of
consumers’ private financial data and the disclosure of their policies regarding the same. Plaid is
a financial institution subject to those regulations, which include the Privacy of Consumer
Financial Information regulations (the “Privacy Rule”), 16 C.F.R. Part 313, recodified at 12
C.F.R. Part 1016 (“Reg. P”), and issued pursuant to the GLBA, 15 U.S.C. §§ 6801-6803. Plaid
acknowledged as much in its February 2017 responses to the CFPB RFI, in which it conceded
that “[a]n existing legal framework – the Gramm-Leach-Bliley Act (GLBA) – governs the proper
disclosure and use of consumer financial data. Ecosystem participants – both traditional
institutions and newer digital players – should abide by this framework.”38 Plaid also admits that
the data it sells or otherwise transfers to Participating Apps and other third parties is subject to
the GLBA’s “Safeguards Rule” (16 C.F.R. Part 314).
79.
This regulatory scheme has clear requirements for applicable privacy policies.
Under those rules, a financial institution “must provide a clear and conspicuous notice that
accurately reflects [its] privacy policies and practices.” 16 CFR 313.4. Privacy notices must be
37 Perret Interview at 30:50 to 31:20.
38 Response by Plaid to CFPB’s Consumer Data Access RFI (Feb. 21, 2017), available
atchttps://plaid.com/documents/Plaid-Consumer-Data-Access-RFI-Technical-Policy-Response.pdf.cSee also Legal,
Plaid (last visited June 23, 2020), https://web.archive.org/web/20160920005638/https://plaid.com/legal/ (instructing
developers that their “product must maintain a clear and conspicuous link in its privacy policy to Plaid’s Privacy
Policy”).
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 26 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 26 of 62
CLASS ACTION COMPLAINT
26
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
provided “so that each consumer can reasonably be expected to receive actual notice.” 16 C.F.R.
§ 313.9; 12 C.F.R. § 1016.9. “Clear and conspicuous means that a notice is reasonably
understandable and designed to call attention to the nature and significance of the information in
the notice.” 16 C.F.R. § 313.3(b)(1); 12 C.F.R. § 1016.3(b)(1). Ways a company can call
attention to its privacy policy include “[using] a plain-language heading” (16 CFR
§313.3(b)(2)(ii)(A); “[using] a typeface and type size that are easy to read” (16 C.F.R.§
313.3(b)(2)(ii)(B)); (c) “[using] boldface or italics for key words” (16 C.F.R. §
313.3(b)(2)(ii)(D)); or (d) “[using] distinctive type size, style, and graphic devices, such as
shading or sidebars,” when combining its notice with other information. 16 C.F.R. §
313.3(b)(2)(ii)(E). A company must ensure that “other elements on the web site (such as text,
graphics, hyperlinks, or sound) do not distract attention from the notice.” 16 CFR §313(b)(2)(iii).
The notice should appear in a place that users “frequently access.” 16 CFR §313.3(b)(2)(iii)(A),
(B). Privacy notices must “accurately reflect[]” the financial institution’s privacy policies and
practices. 16 C.F.R. §§ 313.4 and 313.5; 12 C.F.R. §§ 1016.4 and 1016.5. The notices must
include the categories of nonpublic personal information the financial institution collects and
discloses, the categories of third parties to whom the financial institution discloses the
information, and the financial institution’s security and confidentiality policies. 16 C.F.R.§
313.6; 12 C.F.R. § 1016.6.
80.
California’s Financial Information Privacy Act (CalFIPA) likewise requires that
the language in privacy policies be “designed to call attention to the nature and significance of
the information” therein, use “short explanatory sentences,” and “avoid[] explanations that are
imprecise or readily subject to different interpretations.” Cal. Fin. Code §4053(d)(1). The text
must be no smaller than 10-point type and “use[] boldface or italics for key words.” Id. In
passing CalFIPA, the California legislature explicitly provided that its intent was “to afford
persons greater privacy protections than those provided in . . . the federal Gramm-Leach-Bliley
Act, and that this division be interpreted to be consistent with that purpose.” Cal. Fin. Code §
4051.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 27 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 27 of 62
CLASS ACTION COMPLAINT
27
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
81.
Another California statute, CalOPPA, also requires that an operator of any online
service, as defined therein, “conspicuously post” its privacy policy. Cal. Bus. & Prof. Code
§22575. It specifically defines “conspicuously post” to require a text hyperlink to the policy that
includes the word “privacy”; is “written in capital letters equal to or greater in size than the
surrounding text”; “is written in larger type than the surrounding text, or in contrasting type, font,
or color to the surrounding text of the same size, or set off from the surrounding text of the same
size by symbols or other marks that call attention to the language.” Cal. Bus. Prof. Code §
22577(b).
82.
Both GLBA and CalFIPA require that privacy policies provide consumers with an
opportunity to opt out of the sharing of their personal data. 16 C.F.R. § 313.10; Cal. Fin. Code.
§4053(d)(2).
83.
Plaid’s Privacy Policy fell short of these requirements in at least 3 ways.
84.
First, Plaid’s Privacy Policy is not clear and conspicuous and is not provided such
that Plaintiffs or Class Members could reasonably be expected to receive actual notice of its
terms. In some iterations of the Plaid Link software, such as the one embedded in Cash App,
there is no reference to Plaid whatsoever—let alone a link to its privacy policy or a disclosure
that Plaid is collecting and retaining a user’s login credentials. In Venmo, there is no notice of
Plaid’s Privacy Policy at all, other than the small, gray hyperlink in the Plaid Link dialogue box.
That language does not appear in a typeface or type size that is easy to read and is not designed
to call attention to the nature and significance of the information in the notice. To the contrary, it
is deliberately hidden. Rather than using a distinctive type size, style or graphic device to draw
attention to the link to the Privacy Policy, the link appears in a gray font smaller than all other
text on the dialogue box. If anything, the dialogue box emphasizes the misleading statements that
use of Plaid is “secure” and “private” to distract attention from the notice, rather than ensuring
that such statements would not distract attention from the notice. Finally, the hyperlink does not
appear on a page that users frequently access; it appears only upon initial sign up.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 28 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 28 of 62
CLASS ACTION COMPLAINT
28
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
85.
Second, Plaid’s Privacy Policy does not accurately reflect its privacy policies and
practices. Neither the Venmo dialogue box containing the hyperlink nor the Privacy Policy itself
sufficiently emphasize—or even disclose—material facts that would be essential to any
meaningful consent to the Privacy Policy, as detailed above. In the Privacy Policy, the vague
description of each category of data Plaid collects and its policies and practices regarding storage
and use of that data violate the rule that Plaid must “[a]void explanations that are imprecise and
readily subject to different interpretations.” 16 C.F.R. § 313.3(b)(2)(i)(F).
86.
Third, Plaid’s Privacy Policy provides an insufficient opportunity to opt out,
including because it fails to use the heading “Restrict Information Sharing With Other
Companies We Do Business With To Provide Financial Products And Services.” Cal. Fin. Code
4053 (d)(1)(A).
87.
In addition to itself being a financial institution governed by the GLBA and
CalFIPA, Plaid also received data from other financial institutions. As such, it violated the
following CalFIPA provision as well:
An entity that receives nonpublic personal information pursuant to any exception
set forth in Section 4056 shall not use or disclose the information except in the
ordinary course of business to carry out the activity covered by the exception
under which the information was received.
Cal. Fin. Code § 4053.5 (emphasis added).
88.
One of the exceptions noted in Section 4056 allows sharing of nonpublic personal
information “with the consent or at the direction of the consumer.” Cal. Fin. Code. § 4056.
Plaintiffs and Class Members did not consent to or direct the release of their sensitive nonpublic
personal information for the reasons described herein. But even if they did, Section 4053.5 still
provides that an entity like Plaid can only use such information to carry out the activity for which
the user provided consent. Plaid’s use of the data for a myriad of reasons that extend far beyond
connection of users’ Participating App accounts to their bank accounts violates this statutory
protection.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 29 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 29 of 62
CLASS ACTION COMPLAINT
29
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
I.
Government and Industry Leaders Agree that Plaid’s Conduct Is
Wrong, Risky, Dangerous and Bad for Consumers
89.
Government and industry leaders agree that Plaid’s conduct runs afoul of basic
standards of decency and proper treatment of consumer data.
90.
The Consumer Financial Protection Bureau has stated that data services like Plaid
should not “require consumers to share their account credentials with third parties”—i.e., anyone
other than the user or the bank. Of course, Plaid does exactly that.39
91.
Likewise, the CFPB’s October 2017 Consumer Protection Principles provide that
the data practices of a company like Plaid must be “fully and effectively disclosed to the
consumer, understood by the consumer, not overly broad, and consistent with the consumer’s
reasonable expectations in light of the product(s) or service(s) selected by the consumer.” Plaid’s
disclosures were not full and effective, as described above. Plaid’s data practices were not
understood by Plaintiffs and Class Members, are overly broad, and are not consistent with
consumers’ reasonable expectations, since they are wildly out of proportion to what is actually
necessary to link a bank account to a Participating App.
92.
The Consumer Protection Principles also provide that data access terms must
address “access frequency, data scope, and retention period.” The Privacy Policy egregiously
omits any mention of how often it accesses consumers’ data, how much data it gathers and how
long it keeps it—perhaps because consumers would be outraged to learn that more than once a
day, Plaid gathers their entire transaction history and retains that information indefinitely.
93.
The Consumer Protection Principles also provide that consumers must be
informed of any third parties that access or use their information, including the “identity and
security of each such party, the data they access, their use of such data, and the frequency at
which they access the data.”40 Plaid does not disclose this information.
39 See Response by Plaid to CFPB’s Consumer Data Access RFI, supra n. 38, at 12.
40 See Consumer Protection Principles: Consumer-Authorized Financial Data Sharing and Aggregation, Consumer
Finance Protection Bureau (Oct. 18, 2017). https://files.consumerfinance.gov/f/documents/cfpb_consumer-
protection-principles_dataaggregation.pdf.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 30 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 30 of 62
CLASS ACTION COMPLAINT
30
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
94.
Major financial institutions and their trade associations have also voiced concerns.
In April 2016, JPMorgan CEO Jamie Dimon said the bank is “extremely concerned” about
“outside parties,” including “aggregators” (like Plaid), for three reasons: first, “[f]ar more
information is taken than the third party needs in order to do its job”; second, “[m]any third
parties sell or trade information in a way customers may not understand, and the third parties,
quite often, are doing it for their own economic benefit – not for the customer’s benefit”; and
third, “[o]ften this is being done on a daily basis for years after the customer signed up for the
services, which they may no longer be using.”41 Dimon recommended that users not share their
login credentials with third parties like Plaid, in part to avoid loss of important indemnification
rights: “When customers give out their bank passcode, they may not realize that if a rogue
employee at an aggregator uses this passcode to steal money from the customer’s account, the
customer, not the bank, is responsible for any loss. . . . This lack of clarity and transparency isn’t
fair or right.” JPMorgan hit the nail on the head in identifying the egregious invasions of privacy
that are not simply incidental to Plaid’s business, but lie at the heart of it.
95.
In 2017, the American Bankers Association (“ABA”) wrote to the CFPB to
express similar concerns. The ABA stated that “few consumers appreciate the risks presented
when they provide access to financial account data to non-bank fintech companies,” including
the risk of removing such data from the secure bank environment; that “consumers are not given
adequate information or control over what information is being taken, how long it is accessible,
and how it will be used in the future”; that aggregators like Plaid make “little effort to inform
consumers about the information being taken, how it is being used or shared, how often it is
being accessed, and how long the aggregator will continue to access it”; and that “[c]onsumers
assume that data aggregators take only the data needed to provide the service requested,” but in
reality, “too often it is not the case.”
41 See Letter from JPMorgan Chase to Shareholders (Apr. 6, 2016), available at
https://www.jpmorganchase.com/corporate/annual-report/2015/.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 31 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 31 of 62
CLASS ACTION COMPLAINT
31
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
96.
Plaid boasts that many large banks are now its primary customers. But some
banks have refused to allow Plaid to collect, retain and sell their customer’s data. PNC Bank
blocked Plaid and other data aggregators from accessing customer accounts after it identified
attempts to circumvent technical or code-based barriers PNC had erected.42 As PNC’s head of
retail banking told the Wall Street Journal, “When aggregators access account numbers, many
store them indefinitely, often unbeknownst to customers. This puts customers and their money at
risk.” The same PNC executive later explained that the bank implemented special security
measures against Plaid precisely because consumers did not understand that it “can scrape every
piece of information that is in your banking relationships.”43
97.
Some Plaid employees recognized the impropriety of Plaid’s efforts to circumvent
banks’ technical or code-based barriers to Plaid’s conduct. In August 2018, a former Plaid
programmer described his work on such projects in response to a prompt to describe the most
unethical thing he had ever done:
[M]any . . . banks typically forbid scraping and made it explicitly difficult by
implementing JavaScript-based computational measures required on the client
[side] in order to successfully login. I helped [Plaid] develop methodologies for
bypassing the anti-scraping measures on several banking websites. However, I
stopped working on this because 1) I felt uncomfortable with the cavalier way
they were ignoring banks’ refusals . . . and 2) performing huge amounts of
analytics on customer data acquired as part of the account verification process . . .
. I find it dishonest if the company mining that data is doing so without direct user
consent, or in a “backdoored” manner . . . . [P]ersonally, it bothered me that so
much user data would be mined from their financial statements. . . . [I]t seemed
underhanded since most customers aren’t aware of it. . . .But Plaid is not sold to
users, it’s sold to companies.44
VI. INJURY AND DAMAGES TO THE CLASS
42 See Yuka Hayashi, Venmo Glitch Opens Window on War Between Banks, Fintech Firms, Wall Street Journal
(Dec. 14, 2019), https://www.wsj.com/articles/venmo-glitch-opens-window-onwar-between-banks-fintech-firms-
11576319402.
43 See Bill Streeter, PNC Bank Counters ‘P2P War’ Speculation Over Its Venmo App Moves, The Financial Brand
(Jan. 2020), https://thefinancialbrand.com/91550/pnc-bank-p2p-venmo-mobileapp-zelle-plaid-aggregator/.
44 See Ask HN: What Is the Most Unethical Thing You've Done As a Programmer?, supra n. 29.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 32 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 32 of 62
CLASS ACTION COMPLAINT
32
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
98.
Plaintiffs and Class Members have suffered actual harm, injury, damage and loss
as a result of Plaid’s illegal conduct, including but not limited to economic damages and harm to
their dignitary rights. Had Plaintiffs and Class Members known the true nature, significance and
extent of Plaid’s data practices, it would not have used Plaid.
A.
The Named Plaintiffs’ Experiences
99.
Plaintiff David Evans signed up to use the Venmo App in or about the summer
of 2016. via Apple’s App store. When Mr. Evans established his account with Venmo, he did so
for the purpose, consistent with the services offered by Venmo, of being able to send and receive
payments to or from friends, vendors acquaintances, and other consumers.
100.
Mr. Evans does not recall specific details regarding the process of logging into his
bank account in the Venmo app so that he could send and receive money through the app. He does
not recall being prompted to read any privacy policy during the process of logging into his bank
account and does not recall having ever read any privacy policy from Venmo or Plaid when he linked
his bank account. He does not recall being sent any privacy policy after signing up, or subsequently
seeing any updates to a privacy policy related to his Venmo account or its connection to his bank
account.
101.
At the time Mr. Evans established his account with Venmo, he was not aware of the
existence or role of Plaid. When he was prompted in the Venmo app to log into his bank account, he
believed he was doing so through an actual connection with his bank. He was unaware that he was
providing his login credentials to Plaid.
102.
When Mr. Evans was prompted in the Venmo app to log into his bank account, he
was not aware that Plaid: (a) would collect any of his banking information as part of that process; (b)
would collect, receive, or store any of his banking information beyond that which was strictly
necessary to effectuate transfer or receipt of payments from or to his bank account; (c) would collect,
receive, or store any transaction-related banking information beyond the specific transactions he
triggered using the Venmo app; (d) would sell his banking data to Venmo; or (e) would use or
monetize his banking data in any way.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 33 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 33 of 62
CLASS ACTION COMPLAINT
33
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
103.
By logging into his bank account when prompted in the Venmo app, Mr. Evans
intended only to prompt his bank to provide Venmo with access to his account for the limited
purposes of withdrawing funds for transfers he triggered in the Venmo account and depositing funds
for transfers other Venmo users made to him.
104.
If Mr. Evans had learned what he now knows about the existence and role of Plaid, or
the practices of Plaid in collecting, receiving, storing, selling, or using his banking data, he would not
have connected his bank account in the Venmo app the way he did.
105.
Mr. Evans is informed and believes that Plaid: (a) collected his private bank login
credentials; (b) accessed, downloaded, transferred, stored, enriched, and analyzed his private banking
information and data; (c) sold his private banking information to Venmo; and (d) monetized his
private banking data by performing analytics on it and using it to develop value-added products for
Plaid’s customers. Mr. Evans did not and does not consent to these activities.
106.
As a result of Plaid’s actions, Mr. Evans has suffered harm to his dignitary rights and
interests as a human being, and emotional distress, including anxiety, concern, and unease about
unauthorized parties accessing, storing, selling, and using his most private financial information and
intruding upon his private affairs and concerns. He also fears that he is at increased risk of identity
theft and fraud. He regularly monitors his credit, bank, and other account statements for evidence of
identity theft and fraud and anticipates continuing to do so for the foreseeable future.
107.
Mr. Evans fears that Plaid’s misconduct has increased his risk of identity theft
and fraud.
108.
Plaintiff Patrick Lenahen signed up to use the Venmo App in or about 2015
through the internet. When Mr. Lenahen established his account with Venmo, he did so for the
purpose, consistent with the services offered by Venmo, of being able to send and receive
payments to or from friends, vendors acquaintances, and other consumers.
109.
Mr. Lenahen does not recall specific details regarding the process of logging into his
bank account in the Venmo app so that he could send and receive money through the app. He does
not recall being prompted to read any privacy policy during the process of logging into his bank
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 34 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 34 of 62
CLASS ACTION COMPLAINT
34
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
account and does not recall having ever read any privacy policy from Venmo or Plaid when he linked
his bank account. He does not recall being sent any privacy policy after signing up, or subsequently
seeing any updates to a privacy policy related to his Venmo account or its connection to his bank
account.
110.
At the time Mr. Lenahen established his account with Venmo, he was not aware of
the existence or role of Plaid. When he was prompted in the Venmo app to log into his bank account,
he believed he was doing so through an actual connection with his bank. He was unaware that he
was providing his login credentials to Plaid.
111.
When Mr. Lenahen was prompted in the Venmo app to log into his bank account, he
was not aware that Plaid: (a) would collect any of his banking information as part of that process; (b)
would collect, receive, or store any of his banking information beyond that which was strictly
necessary to effectuate transfer or receipt of payments from or to his bank account; (c) would collect,
receive, or store any transaction-related banking information beyond the specific transactions he
triggered using the Venmo app; (d) would sell his banking data to Venmo; or (e) would use or
monetize his banking data in any way.
112.
By logging into his bank account when prompted in the Venmo app, Mr. Lenahen
intended only to prompt his bank to provide Venmo with access to his account for the limited
purposes of withdrawing funds for transfers he triggered in the Venmo account and depositing funds
for transfers other Venmo users made to him.
113.
If Mr. Lenahen had learned what he now knows about the existence and role of Plaid,
or the practices of Plaid in collecting, receiving, storing, selling, or using his banking data, he would
not have connected his bank account in the Venmo app the way he did.
114.
Mr. Lenahen is informed and believes that Plaid: (a) collected his private bank login
credentials; (b) accessed, downloaded, transferred, stored, enriched, and analyzed his private banking
information and data; (c) sold his private banking information to Venmo; and (d) monetized his
private banking data by performing analytics on it and using it to develop value-added products for
Plaid’s customers. Mr. Lenahen did not and does not consent to these activities.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 35 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 35 of 62
CLASS ACTION COMPLAINT
35
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
115.
As a result of Plaid’s actions, Mr. Lenahen has suffered harm to his dignitary rights
and interests as a human being, and emotional distress, including anxiety, concern, and unease about
unauthorized parties accessing, storing, selling, and using his most private financial information and
intruding upon his private affairs and concerns. He also fears that he is at increased risk of identity
theft and fraud. He regularly monitors his credit, bank, and other account statements for evidence of
identity theft and fraud and anticipates continuing to do so for the foreseeable future.
116.
Mr. Lenahen fears that Plaid’s misconduct has increased his risk of identity theft
and fraud.
117.
Plaintiff Adam Smotkin signed up to use the Venmo App on or about August,
2017 and downloaded it from the Apple Store. When Mr. Smotkin established his account with
Venmo, he did so for the purpose, consistent with the services offered by Venmo, of being able
to send and receive payments to or from friends, vendors acquaintances, and other consumers.
118.
Mr. Smotkin does not recall specific details regarding the process of logging into his
bank account in the Venmo app so that he could send and receive money through the app. He does
not recall being prompted to read any privacy policy during the process of logging into his bank
account and does not recall having ever read any privacy policy from Venmo or Plaid when he linked
his bank account. He does not recall being sent any privacy policy after signing up, or subsequently
seeing any updates to a privacy policy related to his Venmo account or its connection to his bank
account.
119.
At the time Mr. Smotkin established his account with Venmo, he was not aware of
the existence or role of Plaid. When he was prompted in the Venmo app to log into his bank account,
he believed he was doing so through an actual connection with his bank. He was unaware that he
was providing his login credentials to Plaid.
120.
When Mr. Smotkin was prompted in the Venmo app to log into his bank account, he
was not aware that Plaid: (a) would collect any of his banking information as part of that process; (b)
would collect, receive, or store any of his banking information beyond that which was strictly
necessary to effectuate transfer or receipt of payments from or to his bank account; (c) would collect,
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 36 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 36 of 62
CLASS ACTION COMPLAINT
36
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
receive, or store any transaction-related banking information beyond the specific transactions he
triggered using the Venmo app; (d) would sell his banking data to Venmo; or (e) would use or
monetize his banking data in any way.
121.
By logging into his bank account when prompted in the Venmo app, Mr. Smotkin
intended only to prompt his bank to provide Venmo with access to his account for the limited
purposes of withdrawing funds for transfers he triggered in the Venmo account and depositing funds
for transfers other Venmo users made to him.
122.
If Mr. Smotkin had learned what he now knows about the existence and role of Plaid,
or the practices of Plaid in collecting, receiving, storing, selling, or using his banking data, he would
not have connected his bank account in the Venmo app the way he did.
123.
Mr. Smotkin is informed and believes that Plaid: (a) collected his private bank login
credentials; (b) accessed, downloaded, transferred, stored, enriched, and analyzed his private banking
information and data; (c) sold his private banking information to Venmo; and (d) monetized his
private banking data by performing analytics on it and using it to develop value-added products for
Plaid’s customers. Mr. Smotkin did not and does not consent to these activities.
124.
As a result of Plaid’s actions, Mr. Smotkin has suffered harm to his dignitary rights
and interests as a human being, and emotional distress, including anxiety, concern, and unease about
unauthorized parties accessing, storing, selling, and using his most private financial information and
intruding upon his private affairs and concerns. He also fears that he is at increased risk of identity
theft and fraud. He regularly monitors his credit, bank, and other account statements for evidence of
identity theft and fraud and anticipates continuing to do so for the foreseeable future.
125.
Mr. Smotkin fears that Plaid’s misconduct has increased his risk of identity theft
and fraud.
126.
Plaintiff Oswaldo Herrera signed up to use the Venmo App on or about
February 23, 2017 and downloaded from the App Store. When Mr. Herrera established his
account with Venmo, he did so for the purpose, consistent with the services offered by Venmo,
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 37 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 37 of 62
CLASS ACTION COMPLAINT
37
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
of being able to send and receive payments to or from friends, vendors acquaintances, and other
consumers.
127.
Mr. Herrera does not recall specific details regarding the process of logging into his
bank account in the Venmo app so that he could send and receive money through the app. He does
not recall being prompted to read any privacy policy during the process of logging into his bank
account and does not recall having ever read any privacy policy from Venmo or Plaid when he linked
his bank account. He does not recall being sent any privacy policy after signing up, or subsequently
seeing any updates to a privacy policy related to his Venmo account or its connection to his bank
account.
128.
At the time Mr. Herrera established his account with Venmo, he was not aware of the
existence or role of Plaid. When he was prompted in the Venmo app to log into his bank account, he
believed he was doing so through an actual connection with his bank. He was unaware that he was
providing his login credentials to Plaid.
129.
When Mr. Herrera was prompted in the Venmo app to log into his bank account, he
was not aware that Plaid: (a) would collect any of his banking information as part of that process; (b)
would collect, receive, or store any of his banking information beyond that which was strictly
necessary to effectuate transfer or receipt of payments from or to his bank account; (c) would collect,
receive, or store any transaction-related banking information beyond the specific transactions he
triggered using the Venmo app; (d) would sell his banking data to Venmo; or (e) would use or
monetize his banking data in any way.
130.
By logging into his bank account when prompted in the Venmo app, Mr. Herrera
intended only to prompt his bank to provide Venmo with access to his account for the limited
purposes of withdrawing funds for transfers he triggered in the Venmo account and depositing funds
for transfers other Venmo users made to him.
131.
If Mr. Herrera had learned what he now knows about the existence and role of Plaid,
or the practices of Plaid in collecting, receiving, storing, selling, or using his banking data, he would
not have connected his bank account in the Venmo app the way he did.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 38 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 38 of 62
CLASS ACTION COMPLAINT
38
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
132.
Mr. Herrera is informed and believes that Plaid: (a) collected his private bank login
credentials; (b) accessed, downloaded, transferred, stored, enriched, and analyzed his private banking
information and data; (c) sold his private banking information to Venmo; and (d) monetized his
private banking data by performing analytics on it and using it to develop value-added products for
Plaid’s customers. Mr. Herrera did not and does not consent to these activities.
133.
As a result of Plaid’s actions, Mr. Herrera has suffered harm to his dignitary rights
and interests as a human being, and emotional distress, including anxiety, concern, and unease about
unauthorized parties accessing, storing, selling, and using his most private financial information and
intruding upon his private affairs and concerns. He also fears that he is at increased risk of identity
theft and fraud. He regularly monitors his credit, bank, and other account statements for evidence of
identity theft and fraud and anticipates continuing to do so for the foreseeable future.
134.
Mr. Herrera fears that Plaid’s misconduct has increased his risk of identity theft
and fraud.
B.
Plaintiffs and Class Members Have Suffered Economic Damages
135.
Plaid’s illegal conduct caused Plaintiffs and Class Members to suffer economic
damages and loss, including but not limited to (a) the loss of valuable indemnification rights; (b)
the loss of other rights and protections to which they were entitled as long as their sensitive
personal data remained in a secure banking environment; (c) the loss of control over valuable
property; and (d) the heightened risk of identity theft and fraud.
136.
Plaid caused all of these damages when, without actual or constructive notice to
Plaintiffs and Class Members and without their knowledge or consent, Plaid (1) removed their
sensitive personal data from the secure banking environment and (2) sold it to the Participating
Apps and other third parties, without exercising any oversight or control over what those entities
did with the data.
C.
Loss of Valuable Indemnification Rights
137.
Under federal regulations, a consumer is not liable for unauthorized electronic
fund transfers from his financial accounts, subject to certain limits and conditions. See, e.g., 12
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 39 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 39 of 62
CLASS ACTION COMPLAINT
39
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
C.F.R. § 1005.2(m). But Plaid’s conduct eliminates consumers’ rights to indemnification under
these regulations. If Plaid’s fraud and deceit induce Plaintiffs and Class Members to provide
their bank credentials to Plaid, and a malicious user subsequently uses those credentials to access
and improperly transfer funds from Plaintiffs and Class Members’ accounts, banks consider that
transfer to have been authorized because of the initial provision of the credentials to Plaid.45 As
noted above, JPMorgan has expressed concern that consumers do not generally understand that
they will be responsible for any such loss.46 For instance, a theft of $10,000 from a consumer’s
account would ordinarily leave a consumer liable for only $50; but if Plaid’s conduct in any way
contributes to that unlawful access, the consumer may now be liable for the full $10,000, a loss
in value of $9,950. Thus, the destruction of Plaintiffs and Class Members’ indemnification rights
is an economic loss, even if no funds are actually stolen.
D.
Diminished Value of Rights to Protection of Data
138.
Plaintiffs and Class Members enjoy various other rights and protections relating
to their sensitive personal data as long as it remains within a secure banking environment. The
American Bankers Association has opined that when data aggregators like Plaid extract Plaintiffs
and Class Members’ data from their financial institutions, it leaves the “secure bank
environment, where it is accorded longstanding legal protections, and [is] released into the data
services market where it is accorded no more special status than data created through a
consumer’s use of a social media platform.”47 By removing Plaintiffs and Class Members’ data
45 Consumer Bankers Association Comment on Consumer Access to Financial Records (Feb. 21, 2017), available at
https://www.consumerbankers.com/sites/default/files/CFPB%20-%20Docket%20No%20-%202016-0048%20-
%20RFI%20Consumer%20Access%20to%20Financial%20Records.pdf (“If a bank customer gives their account
credentials to a [planning and financial management app] PFM which subsequently initiates an unauthorized transfer
or an unauthorized transfer is initiated by an outside source as a result of a breach of the PFM, the transfer would be
considered authorized by the bank because the client had furnished an access device (i.e. login credentials) to the
PFM, leaving the customer liable for such transfers. Accordingly, the bank would not be liable for these transfers
unless the customer notified them that the transfers by the person, PFM or other vendor were no longer
authorized.”); see also Response by American Bankers Association to CFPB RFI (Feb. 21, 2017),
https://buckleyfirm.com/sites/default/files/Buckley%20Sandler%20InfoBytes%20-
%20American%20Bankers%20Association%202017.02.21%20Comment%20Letter%20to%20CFPB%27s%20RFI
%20CFPB-2016-0048.pdf.
46 Letter from JPMorgan Chase to Shareholders, supra n. 41.
47 American Bankers Association Comment on Consumer Access to Financial Records, supra n. 45.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 40 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 40 of 62
CLASS ACTION COMPLAINT
40
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
from the secure bank environment and storing it in its own computer systems, networks or
servers, Plaid has destroyed the rights and protections to which Plaintiffs and Class Members are
otherwise entitled. That amounts to an economic loss to Plaintiffs Class Members.
E.
Loss of Control Over Valuable Property
139.
The data that Plaid collects, retains and sells has enormous value both to Plaid
itself and to the Plaintiffs and Class Members from whom Plaid illicitly obtains it. First of all, the
data at issue is clearly of value to Plaid. In January 2020, Visa announced an acquisition of Plaid
for $5.3 billion, based in no small part on the universe of consumers that Plaid has accumulated.
Further, Plaid has pivoted its business from aggregating that data to analyzing and packaging it
for the Participating Apps and other third party customers, thus demonstrating that there is an
active market for Plaintiffs and Class Members’ data. The sheer size of this mountain of data, as
well as Plaid’s ability to continue accessing Plaintiffs and Class Members’ transaction histories
on an ongoing basis—as many as 4-6 times a day—creates a competitive advantage that Plaid
may exercise over its competitors. All of these facts indicate that the data Plaid gathers is
valuable. Once Plaid acquires it, however, Plaintiffs and Class Members have no control over
what Plaid does with it, including how it packages it and to whom it sells it. Further, Plaid
exercises no oversight or control over this data after it sells it. Thus, Plaintiffs and Class
Members suffered economic loss from the loss of control over their valuable property.
F.
Increased Risk of Identity Theft and Fraud
140.
Plaid’s conduct not only destroyed Plaintiffs and Class Members’ rights to
indemnification in the event their accounts are compromised, but has also increased the risk of
just such an incident occurring. As the ABA has recognized, the “sheer volume and value of the
aggregated data” warehoused at entities like Plaid makes them “a priority target for criminals,
including identity thieves.” Databases like Plaid’s create a one-stop shop for such malicious
actors to gain access to all of a consumer’s accounts, creating a “rich reward for a single hack.”
Plaid’s consolidation of risk to consumers at a single point of entry creates tangible, economic
injury to Plaintiffs and Class Members, who now must spend time and money closely monitoring
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 41 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 41 of 62
CLASS ACTION COMPLAINT
41
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
their credit report and other financial records for any evidence that their accounts have been
compromised. Plaid’s conduct has permanently impaired the integrity of Plaintiffs and Class
Members’ bank accounts and the banking information and data therein. Plaintiffs and Class
Members now face an expanded and imminent risk of economic harm from unauthorized
transfers, identity theft, and fraud.
G.
Plaintiffs and Class Members Have a Reasonable Expectation of
Privacy in the Data that Plaid Gathers
141.
When Plaid obtains the login credentials for a user, it gains access to a vast trove
of that user’s sensitive personal data, including transaction history going back as much as five
years. Even if a user only connects a single account to one of the Participating Apps, Plaid gains
access to all accounts that a user associates with those login credentials, including checking,
savings, and retirement or other investment accounts, as well credit card and loan accounts. Plaid
thus accesses data about the most intimate facts of Plaintiffs and Class Members’ lives, including
without limitation information about their income, charitable giving, retirement contributions,
healthcare costs and treatment, shopping habits, dining habits, entertainment habits, saving and
spending habits, credit repayment habits, and loan terms, as well as other financial affairs. Plaid
implements no precautions to ensure that it does not capture data that may be protected by
HIPAA, including information regarding medical procedures, doctor’s visits or prescriptions.
Plaid also collects personal identifying information such as a user’s name, address, email address
and phone number, as well as employment information such as the identity of a user’s employer
and his salary. Plaid takes no steps to avoid collecting data about minors, whose accounts Plaid
may well have accessed and about whom Plaid would have collected data as long as a Class
member was a custodian for a relevant account. The data Plaid accesses, collects, and retains is
not only broad—by Plaid’s own estimate, it includes thousands of transactions for every
individual—but also deep, including such details as the amount paid, to whom, and the date and
geographic location of the transaction.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 42 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 42 of 62
CLASS ACTION COMPLAINT
42
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
142.
Plaintiffs and Class Members have a reasonable expectation of privacy in this
data. Various statutes, Constitutional provisions and centuries of common law support this
presumption as to users’ sensitive personal data in general, and as to their financial data or health
data in particular.
143.
A series of surveys by The Clearing House (“TCH”), a banking association and
payments company, confirmed how important it is to most consumers that such data remain
private, as well as the general lack of understanding among consumers of how invasive the data
practices of aggregators like Plaid can be. One such survey concluded that the vast majority of
consumers are unaware of what data companies like Plaid collect or for how long it is accessed.
As many as 89% of consumers are concerned, very concerned or extremely concerned about data
privacy with regard to Fintech apps.
144.
Plaintiffs and Class Members had a reasonable expectation of privacy in the
sensitive personal information discussed herein. Plaid’s collection, retention and sale of that
information invaded Plaintiffs and Class Members’ privacy and harmed their dignitary rights.
H.
Plaid Violates Users’ Reasonable Expectations of Privacy in
Highly Offensive Ways that Amount to Egregious Violations
of Social Norms
145.
Plaid’s collection, retention and sale of Plaintiffs and Class Members’ sensitive
personal data would be highly offensive to the reasonable person. Plaid’s conduct goes far
beyond what would be considered routine commercial behavior, even among other fintech apps.
It violates various social norms as identified in legislative and constitutional provisions, as well
as various expressions of public policy and the common law, for at least the following reasons:
1. Plaid’s collection, storage and use of data is far out of proportion to what Plaid
needs to link users’ accounts to Participating Apps, including because Plaid collects
massive troves of data going back five years and going forward in perpetuity;
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 43 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 43 of 62
CLASS ACTION COMPLAINT
43
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
2. Plaid deceives users into thinking that they are entering their credentials
directly with their trusted financial institutions, when in fact they are providing those
credentials to Plaid for Plaid’s permanent retention and use;
3. Plaid retains the data that it collects indefinitely;
4. Plaid profits from the data it collects in ways that it fails to disclose to Plaintiffs
and Class Members;
5. The nature of the data that Plaid collects reaches into every part of users’ lives;
and
6. Users did not consent to Plaid’s invasion of their privacy because Plaid failed
to disclose the scope and nature of its data practices, thus rendering any consent it
obtained from users ineffective or, at the least, narrower than the conduct in which Plaid
engages.
I.
Other Damages
146.
Plaid’s conduct damaged Plaintiffs and Class Members in other ways, including
because Plaid:
1. impaired the integrity of the Plaintiffs and Class Members’ data by storing it on
its own systems and using it for its own purposes;
2. impaired the integrity of the financial institutions’ protected computers by
increasing the number of entities that have access to such data;
3. failed to monitor or oversee third party customers to whom Plaid sold
Plaintiffs’ and Class Members’ data and/or analytics products based on this data;
4. impaired the integrity of Plaintiffs and Class Members’ smartphones by
installing software within the Participating Apps that captured their bank login
credentials; and
5. caused Plaintiffs and Class Members mental and emotional distress.
VII.
CHOICE OF LAW
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 44 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 44 of 62
CLASS ACTION COMPLAINT
44
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
147.
California’s substantive laws may be constitutionally applied to the claims of
Plaintiffs and the Nationwide Class Members under the Due Process Clause, 14th Amend., § 1,
and the Full Faith and Credit Clause, art. IV., § 1, of the U.S. Constitution.
148.
California has a significant contact, or significant aggregation of contacts, to the
claims asserted by Plaintiffs and the Class, thereby creating state interests that ensure that the
choice of California state law to the common-law claims is not arbitrary or unfair. Plaid’s
headquarters and principal place of business are in California. Plaid conducts substantial
business in California, and upon information and belief the scheme alleged in this Complaint
originated in, was implemented in and emanated from California. Plaid collects and stores
Plaintiffs and Class Members’ data in California, and sells it from California. California has a
stronger interest in regulating Plaid’s conduct under its laws than any other state.
149.
The application of California law to the proposed Nationwide Class is also
appropriate under California’s choice of law rules, namely, the governmental interest test
California uses for choice-of-law questions. California’s interest would be the most impaired if
its laws were not applied.
VIII. TOLLING, CONCEALMENT AND ESTOPPEL
150.
The statutes of limitation applicable to Plaintiffs’ claims are tolled as a result of
Plaid’s knowing and active concealment of its conduct alleged herein. Among other things, Plaid
and its co-founders made a series of misrepresentations and omissions in the software it embeds
in the Participating Apps; in its Privacy Policy; and in its public statements, including in
interviews, in postings on online forums, and in submissions to government agencies and
regulators. Plaid intentionally concealed the nature and extent of its actions and intentions. To
the extent the Participating Apps made statements regarding Plaid’s service or its privacy
policies, Plaid either approved those statements or failed to timely correct them in service of its
ongoing scheme to conceal the true nature of its conduct.
151.
Plaintiffs and Class Members could not, with due diligence, have discovered the
full scope of Plaid’s conduct, due in no small part to Plaid’s deliberate efforts to conceal it. All
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 45 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 45 of 62
CLASS ACTION COMPLAINT
45
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
applicable statutes of limitation also have been tolled by operation of the discovery rule. Under
the circumstances, Plaid was under a duty to disclose the nature and significance of its data and
privacy policies and practices, but did not do so. Plaid therefore is estopped from relying on any
statute of limitations.
152.
Plaid’s fraudulent concealment and omissions are common to Plaintiffs and all
Class Members.
IX.
CLASS ACTION ALLEGATIONS
153.
Plaintiffs incorporate by reference all the foregoing allegations. Plaintiffs bring
this action on behalf of themselves and all others similarly situated pursuant to Rule 23(b)(2) and
23(b)(3) of the Federal Rules of Civil Procedure.
154.
Plaintiffs seek to represent the following Classes:
Nationwide Class: All natural persons in the United States whose accounts at a
financial institution Plaid accessed by using login credentials that Plaid obtained
through software incorporated in a mobile or web-based software application that
enables payments (including ACH payments) or other money transfers, including
without limitation users of Venmo, Square’s Cash App, Coinbase, and Stripe,
from January 1, 2013 to the present.
California Class: All natural persons in California whose accounts at a financial
institution Plaid accessed by using login credentials that Plaid obtained through
software incorporated in a mobile or web-based software application that enables
payments (including ACH payments) or other money transfers, including without
limitation users of Venmo, Square’s Cash App, Coinbase, and Stripe, from
January 1, 2013 to the present.
155.
Excluded from the Classes are Plaid, its current employees, officers, directors,
legal representatives, heirs, successors and wholly or partly owned subsidiaries or affiliated
companies; the undersigned counsel for Plaintiffs and their employees; and the Judge and court
staff to whom this case is assigned.
156.
The Classes and their counsel satisfy the prerequisites of Federal Rule of Civil
Procedure 23(a) and 23(g) and the requirements of Rule 23(b)(3).
157.
Numerosity. Plaintiffs possess no knowledge or information regarding the exact
size of the Classes or the identities of the Class Members. On information and belief, and based
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 46 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 46 of 62
CLASS ACTION COMPLAINT
46
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
on Plaid’s own statements that as many as 1 in 4 natural persons in the United States have used
Plaid and that Plaid has accessed as many as 200 million financial accounts, each Class has
thousands or millions of members. Thus, the number of members in each Class is so numerous
that joinder is impracticable. Plaid possesses information sufficient to identify the Class
Members.
158.
Commonality. Common questions of law and fact exist as to all members of the
Classes. This is particularly true given the nature of Plaid’s conduct, which was generally
applicable to all the members of both Classes, calling for relief for the Classes as a whole. Such
questions of law and fact common to the Classes include, but are not limited to:
1. Whether a reasonable person would have a reasonable expectation of privacy in
the information that Plaid collected from them;
2. Whether Plaid’s conduct was highly offensive to a reasonable person and/or
amounted to an egregious breach of social norms;
3. Whether Plaid violated the federal Stored Communications Act and Computer
Fraud and Abuse Act;
4. Whether Plaid violated California’s Comprehensive Data Access and Fraud
Act, Unfair Competition Law, Anti-Phishing Act, and Civil Code §1709;
5. Whether Plaid unjustly enriched itself to the detriment of Plaintiffs and Class
Members, thereby entitling Plaintiffs and Class Members to disgorgement of all benefits
derived by Defendants;
6. Whether Plaid acted negligently;
7. Whether the conduct of Plaid and its co-conspirators, as alleged in this
Complaint, caused harm, injury, damage or loss to Plaintiffs and Class Members;
8. The appropriate injunctive and equitable relief; and
9. The appropriate class-wide measure of damages.
159.
Predominance. The questions of law and fact common to the members of the
Classes predominate over any questions affecting only individual members, including legal and
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 47 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 47 of 62
CLASS ACTION COMPLAINT
47
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
factual issues relating to liability and damages. The most important questions at issue involve
Plaid’s conduct, which was common to all or nearly all members of the Classes. Questions
relating to the applicability of statutory and common law as well as the scope or presence of
injuries are also common to the Classes.
160.
Typicality. Plaintiffs’ claims are typical of those of all or nearly all members of
the Classes because Plaid’s conduct applied to all or nearly all members of the Classes in
identical or nearly identical ways. Plaintiffs’ claims and those of Class Members arise from the
same operative facts and legal theories. Plaid cannot articulate any defenses that are unique to
Plaintiffs.
161.
Adequacy. Plaintiffs are an adequate representatives of the Classes. Plaintiffs’
claims arise out of the same common course of conduct giving rise to the claims of the other
members of the Classes. Plaintiffs’ interests are coincident with, and not antagonistic to, those of
the other members of the Classes. Plaintiffs are represented by counsel who are competent and
experienced in the prosecution of consumer and class action litigation. Plaintiffs intend to
prosecute this action vigorously. Plaintiffs and their counsel will fairly and adequately protect the
interest of the Classes.
162.
Superiority. Class action treatment is a superior method for the fair and efficient
adjudication of the controversy, in that, among other things, such treatment will permit a large
number of similarly situated persons to prosecute their common claims in a single forum
simultaneously, efficiently and without the unnecessary duplication of evidence, effort and
expense that numerous individual actions would engender. The benefits of proceeding through
the class mechanism, including providing injured persons or entities with a method for obtaining
redress for claims that might not be practicable to pursue individually, substantially outweigh
any difficulties that may arise in the management of this class action. Classwide adjudication
benefits Plaintiffs, Defendant, and the court system by addressing similar or identical claims
related to Plaid’s illicit conduct universally and at once, while avoiding the potential for
inconsistent or contradictory judgments.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 48 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 48 of 62
CLASS ACTION COMPLAINT
48
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
163.
Injunctive Class. Class certification under Rule 23(b)(2) for purposes of
injunctive and declaratory relief is warranted because Plaid acted or refused to act—and
continues to act or refuse to act—in ways that apply generally to the Classes, such that final
injunctive and declaratory relief are appropriate with respect to, and would benefit, the Classes as
a whole.
X.
CLAIMS FOR RELIEF
FIRST CAUSE OF ACTION
Common Law Invasion of Privacy—Intrusion Upon Seclusion
164.
Plaintiffs incorporate the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
165.
Plaintiffs bring this claim on behalf of themselves and the Nationwide Class or, in
the alternative, the California Class, under California law.
166.
Plaid intruded upon Plaintiffs and Class Members’ seclusion by collecting,
retaining and selling data (1) in which they had a reasonable expectation of privacy for the
reasons described herein; and (2) in a manner that was highly offensive to Plaintiffs and Class
Members, would be highly offensive to a reasonable person, and was in egregious violation of
social norms for the reasons described herein.
167.
Plaid’s conduct described herein violations Plaintiffs and Class Members’
interests in avoiding the dissemination of sensitive personal data about their financial and other
affairs (i.e., their informational privacy rights), as well as their interests in making intimate
personal decisions or conducting personal activities without observation, intrusion, or
interference (i.e., their autonomy privacy rights).
168.
Plaintiffs and Class Members suffered actual harm, injury, damage and loss as a
result of Plaid’s conduct as alleged herein.
169.
Plaintiffs and Class Members are entitled to appropriate relief, including
compensatory damages for the harm to their privacy and dignitary interests, loss of valuable
rights and protections, heightened risk of future invasions of privacy, and mental and emotional
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 49 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 49 of 62
CLASS ACTION COMPLAINT
49
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
distress. Plaintiffs and Class Members are entitled to an order requiring Plaid to disgorge profits
or other benefits that Plaid acquired as a result of its invasions of privacy. Plaintiffs and Class
Members are entitled to punitive damages resulting from the malicious, willful and intentional
nature of Plaid’s actions, directed at injuring Plaintiffs and Class Members in conscious
disregard of their rights. Such damages are needed to deter Plaid from engaging in such conduct
in the future. Plaintiffs also seek such other relief as the Court may deem just and proper.
SECOND CAUSE OF ACTION
Violation of the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. §1030
170.
Plaintiffs incorporate the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
171.
Plaintiffs bring this claim on behalf of themselves and the Nationwide Class.
1.
Violations of 18 U.S.C. § 1030(a)(2)
172.
A person violates 18 U.S.C. § 1030(a)(2) if it “intentionally accesses a computer
without authorization or exceeds authorized access, and thereby obtains—(A) information
contained in a financial record of a financial institution . . . [or] (C) information from any
protected computer.” Protected computers include computers “exclusively for the use of a
financial institution . . . or . . . used by . . . a financial institution . . . and the conduct constituting
the offense affects that use by or for the financial institution,” 18 U.S.C. § 1030(e)(2)(A), or
computers “used in or affecting interstate or foreign commerce,” 18 U.S.C. § 1030(e)(2)(B)
173.
The computer systems, data storage facilities, or communications facilities that
Plaintiffs and Class Members’ financial institutions use to store Plaintiffs and Class Members’
data are “protected computers” under the statute because they are exclusively for the use of
financial institutions or, in the alternative, were affected by Plaid’s conduct, or were used in or
affected interstate commerce. Plaid intentionally accessed these protected computers and thereby
obtained information contained in the financial institutions’ financial records. Plaid did so
without authorization because the consent that Plaid purported to receive from Plaintiffs and
Class Members was null, void, invalid and ineffective for the reasons described above. To the
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 50 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 50 of 62
CLASS ACTION COMPLAINT
50
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
extent Plaid received any valid authorization, its conduct exceeded that authorization for the
reasons described above. See 18 U.S.C. 1030(e)(6) (defining the term “exceeds authorized
access” to mean “to access a computer with authorization and to use such access to obtain or
alter information in the computer that the accessor is not entitled so to obtain or alter”).
2.
Violations of 18 U.S.C. § 1030(a)(4)
174.
A person violates 18 U.S.C. § 1030(a)(4) if it “knowingly and with intent to
defraud, accesses a protected computer without authorization, or exceeds authorized access, and
by means of such conduct furthers the intended fraud and obtains anything of value, unless the
object of the fraud and the thing obtained consists only of the use of the computer and the value
of such use is not more than $5,000 in any 1-year period.”
175.
Plaid knowingly accessed protected computers, and did so without authorization
or in excess of authorization, for the reasons described herein.
176.
Plaid acted with intent to defraud because it devised an elaborate scheme to
deceive Plaintiffs and Class Members into thinking that they were providing their banking
credentials directly to their bank, when in fact they were providing those credentials to Plaid.
Through that conduct, Plaid furthered its fraud and obtained things of value, namely, Plaintiffs
and Class Members’ sensitive personal data.
3.
Violations of 18 U.S.C. § 1030(a)(5)(A)
177.
A person violates 18 U.S.C. § 1030(a)(5)(A) if it “knowingly causes the
transmission of a program, information, code, or command, and as a result of such conduct,
intentionally causes damage without authorization, to a protected computer.”
178.
Plaid knowingly caused the transmission of a program, information, code or
command every time it sent Plaintiffs and Class Members’ credentials to their financial
institutions. Plaid did so without authorization for the reasons described herein. Plaid caused
damage for the reasons described herein.
4.
Violations of 18 U.S.C. § 1030(a)(5)(B), (C)
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 51 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 51 of 62
CLASS ACTION COMPLAINT
51
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
179.
A person violates 18 U.S.C. § 1030(a)(5)(B) if it “intentionally accesses a
protected computer without authorization, and as a result of such conduct, recklessly causes
damage.” A person violates 18 U.S.C. § 1030(a)(5)(C) if it “intentionally accesses a protected
computer without authorization, and as a result of such conduct, causes damage and loss.”
180.
Plaintiffs and Class Members’ financial institutions’ computer systems, data
storage facilities, or communications facilities are protected computers under the statute for the
reasons described herein. Plaid acted without authorization for all of the reasons described
herein. Plaid acted not only recklessly but intentionally for all of the reasons herein. Plaid caused
damage or loss for the reasons described herein.
5.
Violations of 18 U.S.C. § 1030(a)(6)
181.
A person violates 18 U.S.C. 1030(a)(6) if it “knowingly and with intent to defraud
traffics . . . in any password or similar information through which a computer may be accessed
without authorization, if—(A) such trafficking affects interstate or foreign commerce.” The term
“traffic” means “transfer, or otherwise dispose of, to another, or obtain control of with intent to
transfer or dispose of.” 18 U.S.C. 1029 (e)(5).
182.
Plaid acted knowingly and with intent to defraud for the reasons described herein.
Plaid acted without authorization for the reasons described herein. Plaid trafficked in passwords
and similar information when it obtained control of banking credentials from as many as 200
million distinct financial accounts with the intent of transferring them to its own massive
database of user information, thus allowing Plaid access to Plaintiffs and Class Members’
financial institutions’ computers. In the alternative, Plaintiffs trafficked in passwords and similar
information when, after acquiring Plaintiffs and Class Members’ login credentials under false
pretenses and using them to login to those individuals’ financial institutions, those institutions
sent access tokens to Plaid, which access tokens Plaid then transferred to the Participating Apps.
183.
On information and belief, because of the locations of Plaid, its servers, the 200
million accounts for which Plaid acquired credentials and data, and the 11,000 financial
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 52 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 52 of 62
CLASS ACTION COMPLAINT
52
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
institutions to which Plaid has access, Plaid’s trafficking activities affected interstate or foreign
commerce.
6.
Plaid Caused Economic Loss in Excess of $5,000, as Well as other Damage
184.
Plaintiffs may bring a private right of action for economic damages resulting from
Plaid’s violation of the CFAA, provided that they caused “loss to 1 or more persons during any
1- year period . . . aggregating at least $5,000 in value.” 18 U.S.C. 1030 (c)(4)(A)(i)(I). The
CFAA defines the term “damage” to include “any impairment to the integrity or availability of
data, a program, a system, or information.” 18 U.S.C. § 1030(e)(8). The CFAA defines the term
“loss” to include “any reasonable cost to any victim, including the cost of responding to an
offense, conducting a damage assessment, and restoring the data, program, system, or
information to its condition prior to the offense, and any revenue lost, cost incurred, or other
consequential damages incurred because of interruption of service.” 18 U.S.C. 1030(e)(11).
185.
Each of the violations detailed above caused economic loss to Plaintiffs and Class
Members that exceeds $5,000 per year individually or in the aggregate. In particular, Plaid
caused losses to Plaintiffs and Class Members by imposing unreasonable costs on them,
including the cost of conducting damage assessments, restoring the data to its condition prior to
the offense, and consequential damages they incurred by, inter alia, spending time conducting
research to ensure that their identity had not been compromised and accounts reflect the proper
balances.
186.
Plaid’s violations damaged Plaintiffs and Class Members in other ways as
described herein. Plaintiffs seek such other relief as the Court may deem just and proper.
187.
Plaintiffs bring this cause of action within two years of the date of the discovery
of their damages. Thus, this action is timely under 18 U.S.C. § 1030(g).
THIRD CAUSE OF ACTION
Violation of the Stored Communications Act (“SCA”), 18 U.S.C. § 2701
188.
Plaintiffs incorporate the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 53 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 53 of 62
CLASS ACTION COMPLAINT
53
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
189.
Plaintiffs bring this claim on behalf of themselves and the Nationwide Class.
190.
The SCA prohibits a person from (1) intentionally accessing without
authorization, or in excess of authorization, a facility through which an electronic
communication service (“ECS”) is provided and (2) thereby obtained, altered, or prevented
authorized access to a wire or electronic communication (3) while it was in electronic storage in
such system. 18 U.S.C. § 2701(a)(1).
191.
The data that Plaid collects from the financial institutions are electronic
communications. The SCA defines “electronic communication” broadly to include “any transfer
of signs, signals, writing, images, sounds, data, or intelligence of any nature transmitted in whole
or in part by a wire, radio, electromagnetic, photoelectronic or photooptical system that affects
interstate or foreign commerce.” 18 U.S.C. 2510(12).48 The data that Plaid illicitly acquired from
Plaintiffs and Class Members’ financial accounts are electronic communications within the
statute.
192.
The bank servers and systems that Plaid accesses are facilities that provided ECS,
within the definition of the statute. An ECS provider is “any service which provides to users
thereof the ability to send or receive wire or electronic communications.” 18 U.S.C. § 2510(15).
The financial institutions to which Plaid connects provide various economic communications
services to their customers as part of their commercial offerings, including by sending, receiving,
posting and making available for transfer messages, data, images, queries, notifications,
statements, forms, updates, and others. See 18 U.S.C. § 2510(15) (defining “electronic
communication service”).
193.
The electronic communications that Plaid accesses from financial institution
servers and systems are kept in electronic storage by those institutions. The SCA defines
“electronic storage” as “(A) any temporary, intermediate storage of a wire or electronic
48 Notably, the definition “does not include . . . (D) electronic funds transfer information stored by a financial
institution in a communications system used for the electronic storage and transfer of funds.” Id. Thus, this cause of
action does not apply to such electronic funds transfer information, although other causes of action herein may apply
to such information.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 54 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 54 of 62
CLASS ACTION COMPLAINT
54
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
communication incidental to the electronic transmission thereof; and (B) any storage of such
communication by an electronic communication service for purposes of backup protection of
such communication.” 18 U.S.C. § 2510(17). The financial institutions with which Plaid
interacts maintain the electronic communications that Plaid collects both for temporary or
intermediate storage as well as for purposes of backup protection. They are maintained in
systems, servers and databases both for record-keeping as well as for access by consumers.
194.
Plaid intentionally accessed these facilities without authorization from Plaintiffs
and Class Members. Any authorization that Plaintiffs and Class Members may purportedly have
provided to Plaid is null, void, invalid and ineffective because: Plaid obtained any such
authorization by fraud and deceit; Plaid failed to provided Plaintiffs and Class Members with
actual or constructive notice of the nature and significance of Plaid’s data and privacy practices;
Plaid’s Privacy Policy contains material misrepresentations and omissions; Plaintiffs and Class
Members never voluntarily downloaded or installed any application that Plaid offered; and
Plaintiffs and Class Members were not on notice that Plaid was an entity distinct from the
Participating App(s) they signed up to use. To the extent Plaid obtained any valid authorization
at all, Plaid nonetheless accessed these facilities far in excess of the authorization it received by
obtaining data beyond what was needed to validate users’ bank accounts, storing it for longer
than necessary, continuing to collect data as often as once every 4-6 hours even months or years
after users first tried to connect a bank account, and selling that data to undisclosed third parties.
195.
Plaintiffs and Class Members suffered concrete and particularized injury resulting
from Plaid’s violations of the SCA as alleged herein. Plaintiffs and the Class are entitled to
damages, equitable or declaratory relief, and reasonable attorney’s fees, pursuant to 18 U.S.C. §
2707. Plaintiffs also seek such other relief as the Court may deem just and proper.
196.
Plaintiffs and Class Members bring this cause of action within two years after the
date upon which they first discovered or had a reasonable opportunity to discover Plaid’s
violations. Thus, this action is timely under 18 U.S.C. § 2707(f).
FOURTH CAUSE OF ACTION
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 55 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 55 of 62
CLASS ACTION COMPLAINT
55
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Declaratory Judgment that Plaid Wrongfully Accessed, Collected, Stored, Disclosed, Sold,
and Otherwise Improperly Used Plaintiffs’ Private Data and Injunctive Relief
197.
Plaintiffs incorporate the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
198.
Plaintiffs brings this claim on behalf of themselves and the Nationwide Class
(referred to in this claim as “the Class”).
199.
The gravamen of this controversy lies in Plaid’s failure to inform consumers of its
true nature and conduct, and Plaid’s subsequent invasions of their privacy. Plaintiffs and Class
members never consented to sharing their bank login credentials with Plaid, never agreed to
share their private, personal banking history and data with Plaid, never assented to Plaid
gathering, storing, disclosing, selling, or otherwise using their private, personal data.
200.
Plaid’s misconduct has put Plaintiffs’ and Class members’ financial privacy and
security at risk, and violated their dignitary rights, privacy, and economic well-being.
Accordingly, Plaintiffs seek appropriate declaratory relief, and injunctive relief as prayed for
below.
FIFTH CAUSE OF ACTION
Unjust Enrichment
201.
Plaintiffs incorporates the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
202.
Plaintiffs bring this claim on behalf of themselves and the Nationwide Class
(referred to in this claim as “the Class”).
203.
Plaid received benefits from Plaintiffs and Class Members and unjustly retained
those benefits at their expense.
204.
In particular, Plaid received benefits from Plaintiffs and Class Members in the
form of the sensitive personal data that Plaid collected from Plaintiffs and Class Members,
without authorization and as a product of the deceitful conduct described herein. Plaid has
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 56 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 56 of 62
CLASS ACTION COMPLAINT
56
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
compiled that data into an “immense” database, which it has packaged into various products that
have provided Plaid with economic, intangible, and other benefits.
205.
Plaid unjustly retained those benefits at the expense of Plaintiffs and Class
Members because Plaid’s conduct damaged Plaintiffs and Class Members as described herein, all
without providing any commensurate compensation to Plaintiffs and the Class.
206.
The benefits that Plaid derived from Plaintiffs and Class Members rightly belong
to Plaintiffs and Class Members. It would be inequitable under unjust enrichment principles in
California and every other state for Plaid to be permitted to retain any of the profit or other
benefits it derived from the unfair and unconscionable methods, acts, and trade practices alleged
in this Complaint.
207.
Plaid should be compelled to disgorge in a common fund for the benefit of
Plaintiffs and Class Members all unlawful or inequitable proceeds it received, and such other
relief as the Court may deem just and proper.
SIXTH CAUSE OF ACTION
Violation of California Unfair Competition Law (“UCL”), Cal. Bus. & Prof. Code § 17200
208.
Plaintiffs incorporate the substantive allegations contained in all prior and
succeeding paragraphs as if fully set forth herein.
209.
Plaintiffs bring this claims on behalf of themselves and the Nationwide Class or,
in the alternative, the Calisfornia Class.
210.
Plaid’s conduct as alleged herein constitutes unlawful, unfair, and/or fraudulent
business acts or practices as prohibited by the UCL.
1.
“Unlawful”
211.
Plaid’s conduct constitutes an unlawful business practice within the meaning of
the UCL because it violates, without limitation, the following: the CFAA, the SCA, the CDAFA,
the GLBA’s Privacy Rule, CalFIPA, Cal. Pen. Code § 502, California’s Anti-Phishing Act of
2005, the CCPA, CalOPPA, Cal. Civ. Code § 1709 and Article 1, § 1 of the California
Constitution.
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 57 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 57 of 62
CLASS ACTION COMPLAINT
57
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
2.
“Unfair”
212.
Plaid’s conduct separately constitutes an unfair business practice within the
meaning of the UCL because Plaid’s practices have caused and are likely to cause substantial
injury to the Plaintiffs and the members of the Class that is not reasonably avoidable by them.
213.
Plaid’s conduct, as alleged herein, is and was contrary to public policy, immoral,
unethical, oppressive, unscrupulous, and/or substantially injurious to consumers. Among other
things, it is contrary to the public policy in favor of protecting consumer data in general and
consumer financial data in particular. Any purported benefits arising out of Plaid’s conduct do
not outweigh the harms caused to the victims of Plaid’s conduct.
214.
Plaid’s conduct is also unfair because it is contrary to numerous legislatively
declared policies, as set forth in the CFAA, the SCA, the CDAFA, the GLBA’s Privacy Rule,
CalFIPA, Cal. Pen. Code § 502, California’s Anti-Phishing Act of 2005, the CCPA, CalOPPA,
Cal. Civ. Code § 1709 and Article 1, § 1 of the California Constitution, which explicitly
recognizes every individual’s right to privacy. Here, Plaid’s conduct not only violates the letter
of the law, but also contravenes the spirit and purpose of each of those laws.
215.
Plaid’s conduct is unfair because the harm to the victim outweighs any benefits.
Plaid’s deceitful and illicit collection of Plaintiffs and Class Members’ sensitive personal data
are against public policy in a myriad of ways, including the statutes above that explicitly protect
individuals’ privacy interests in their personal data in general and the data they store with their
financial institutions in particular. The conduct alleged herein threatens an incipient violation of
each of those laws and has both an actual and a threatened impact on competition.
216.
Plaid’s conduct is unfair because Plaid’s Privacy Policy contained material
misrepresentations and omitted material facts that were necessary to make the policy not false
and misleading, as described herein.
217.
Plaid’s conduct is unfair because the data it collected and the time for which it
stored that data violate the principle of data minimization to which Plaid itself claims to
subscribe, in particular because Plaid’s collection, storage and sale of Plaintiffs and Class
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 58 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 58 of 62
CLASS ACTION COMPLAINT
58
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Members’ data is wholly disproportionate to that needed to provide the service Plaid ostensibly
provided to Plaintiffs and Class Members—namely, connecting their bank accounts to a
Participating App.
3.
“Fraudulent”
218.
Plaid’s conduct, as described herein, constitutes a fraudulent business practice
within the meaning of the UCL. Plaid has only been able to amass the mountain of data on which
its business is based by deceiving Plaintiffs and Class Members that they were using their login
credentials to access their financial institutions directly, when in fact they were providing those
credentials to Plaid for its own purposes. Plaid deceived Plaintiffs and Class Members into
thinking that the bank login protocol was “secure” and “private,” when it was not. Plaid designed
its interface to deceive—and did deceive—Plaintiffs and Class Members in order to fraudulently
obtain access to their detailed financial histories going back as much as five years and going
forward in perpetuity.
219.
Members of the public would likely have been deceived by Plaid’s actions.
Plaintiffs and Class Members relied on and were harmed by those actions.
4.
Injury
220.
Plaintiffs and Class Members have suffered injury in fact and lost money or
property as a result of Plaid’s conduct as described herein.
221.
Plaintiffs and Class Members are entitled to equitable and injunctive relief
including restitution and restitutionary disgorgement. Plaintiffs are also entitled to an injunction
prohibiting Plaid from collecting, storing and/or selling Plaintiffs and Class Members’ sensitive
personal data on a going forward basis, and requiring Plaid to destroy any login credentials that it
obtained as a result of the conduct described herein. Plaintiffs also seek such other relief as the
Court may deem just and proper.
XI.
PRAYER FOR RELIEF
Plaintiffs request that judgment be entered against Plaid and that the Court grant
the following:
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 59 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 59 of 62
CLASS ACTION COMPLAINT
59
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
1. An order determining that this action may be maintained as a class action under
Rule 23 of the Federal Rules of Civil Procedure, that Plaintiffs is Class Representative,
and that Class notice be promptly issued;
2. Judgment against Plaid for Plaintiffs and Class Members’ asserted claims for
relief;
3. Appropriate declaratory relief against Plaid;
4. Equitable and injunctive relief requiring Plaid to:
a) purge the data it has unlawfully collected, including Plaintiffs’ and all
Class Members’ login credentials and transaction data;
b) cease using any login credentials to access any financial institution;
c) implement a permission protocol that complies with the industry-
standard of OAuth 2.0, including by providing that Plaid shall not obtain or retain
any user credentials;
d) plainly and conspicuously disclose, on the first screen of the Plaid Link
software, as it appears in any Participating App:
1) that Plaid is a third party data aggregator providing connection
services to consumers’ financial institutions for the purpose of collecting
private data from their financial institutions;
2) that Plaid will not collect or retain any data beyond what is
necessary to provide that service to consumers; and
3) that it is not necessary for consumers to use Plaid in order to
connect their banks to the Participating Apps;
e) notify all former, current and future users of Plaid of the full scope and
extent of its previous data practices and its revisions to those practices;
f) obtain, before it connects with a consumer’s financial account,
affirmative permission from the consumer for each action Plaid takes in
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 60 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 60 of 62
CLASS ACTION COMPLAINT
60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
connection with the account, including accessing, copying, selling, storing, and
using data;
g) require, before it connects with a consumer’s financial account, that the
consumer review the full text of Plaid’s Privacy Policy, acknowledge all of the
terms and conditions by checking boxes to indicate consent to all material
provisions, affirmatively agree to any collection, retention or sale of data, and
acknowledge receipt and approval of the notice;
h) obtain a consumer’s affirmative consent each time Plaid accesses that
consumer’s financial account and financial data; and
i) notify consumers of Plaid’s actions to remedy its unlawful conduct
alleged herein, and steps consumers can take to prevent future and additional
privacy invasions by Plaid and other actors to whom Plaid has sold or otherwise
delivered their personal information;
5. Equitable and injunctive relief enjoining Plaid from:
a) accessing, attempting to access, or procuring transmission of any
consumer’s identifying information through their financial accounts;
b) representing that any solicitation, request, or action by Plaid is being
done by a financial institution;
c) retaining any copies, electronic or otherwise, of any identifying
information obtained through the scheme alleged herein;
d) retaining any copies, electronic or otherwise, of any other information
obtained from any of Plaintiffs or Class Members’ financial institutions using
identifying information obtained through the scheme alleged herein; and
e) engaging in any unlawful activities alleged herein;
6. An order awarding Plaintiffs and Class Members actual, compensatory,
statutory, special and/or incidental damages as well as restitution;
7. An order requiring Plaid to pay punitive, dignitary, and exemplary damages;
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 61 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 61 of 62
CLASS ACTION COMPLAINT
61
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
8. An order requiring Plaid to pay pre-judgment and post-judgment interest;
9. Reasonable attorney’s fees and costs reasonably incurred; and
10. Any and all other and further relief to which Plaintiffs and the Classes may be
entitled.
XII.
DEMAND FOR JURY TRIAL
Plaintiffs demand a trial by jury, pursuant to Federal Rule of Civil Procedure
38(b), of all issues so triable.
Dated: July 17, 2020
TOSTRUD LAW GROUP, P.C.
By: /s/ Jon A. Tostrud
TOSTRUD LAW GROUP, P.C.
Jon A. Tostrud (CA Bar No. 199502)
1925 Century Park East, Suite 2100
Los Angeles, CA 90067
Telephone: (310) 278-2600
Email: jtostrud@tostrudlaw.com
GLANCY PRONGAY & MURRAY LLP
Brian P. Murray (Pro Hac Vice to be filed)
Lee Albert (Pro Hac Vice to be filed)
230 Park Avenue, Suite 530
New York, NY 10169
Telephone: (212) 682-5340
Fax: (212) 884-0988
Email: bmurray@glancylaw.com
Email: lalbert@glancylaw.com
LAW OFFICE OF PAUL C. WHALEN, P.C.
Paul C. Whalen (Pro Hac Vice to be filed)
768 Plandome Road
Manhasset, NY 11030
Telephone: (516) 426-6870
Email: paul@paulwhalen.com
Attorneys for Plaintiffs
Case 3:20-cv-04804-JSC Document 1 Filed 07/17/20 Page 62 of 62
Case 4:20-cv-03056-DMR Document 52-3 Filed 07/22/20 Page 62 of 62File and source
- File
- gov.uscourts.cand.359040.52.3.pdf
- Size
- 1,390,617 bytes
- SHA-256
- 4daa85ea0ce9882b7503e5d397f996d52cf9032c4545fc5021718e22afaa3299
- Original
- PACER (login required)