Hyatt Hotels faced legal claims that its website booking platform allowed Meta and Adobe tracking pixels to collect detailed guest information, including names, contact details, and reservation data entered during the booking process. In May 2026, a federal court dismissed the primary Federal Wiretap Act claim brought by plaintiff Juhyun So, ruling that Hyatt’s website terms and privacy disclosures provided adequate legal protection—even though the tracking was occurring.
The dismissal means that despite evidence Hyatt was sharing booking information with third-party advertising platforms, guests did not have a viable claim under federal wiretapping laws. This case highlights a critical gap in privacy protections: companies can legally track your personal information through invisible pixels on their websites as long as they disclose it somewhere in their terms of service, even if most users never read those disclosures. For Hyatt customers who believed their hotel reservation details were private, the ruling came as a significant disappointment.
Table of Contents
- How Hyatt’s Website Tracking Shared Guest Booking Information
- The Juhyun So Lawsuit: What the Federal Wiretap Act Claim Alleged
- Why the Court Dismissed the Privacy Tracking Claims
- The Data Breach Connection: Separating Tracking Claims from Breach Liability
- What the Texas Settlement Reveals About Hyatt’s Deceptive Practices
- What You Should Know If You Stayed at Hyatt
- The Future of Tracking Pixel Litigation and Guest Privacy
- Conclusion
How Hyatt’s Website Tracking Shared Guest Booking Information
Meta and Adobe operate tracking pixels—small lines of code embedded on websites—that follow users’ behavior and collect data about what they do online. When you visited Hyatt’s booking website to search for hotels, check prices, and enter your personal information, these pixels captured that activity and sent it to Meta and Adobe’s servers. This allowed the technology companies to build profiles of your interests, which they then use for targeted advertising across the internet.
The allegation in the So v. Hyatt case was that guests entered sensitive information—including their names, email addresses, phone numbers, dates of travel, and payment card details—while these pixels were actively transmitting data to third parties. Unlike a data breach where hackers steal information, this tracking happens transparently through the normal website experience, though most guests are unaware it’s occurring. For example, if you visited Hyatt.com to book a room for a medical conference, the Meta pixel could capture that information and use it for advertising purposes, even though you never explicitly consented to Meta receiving your booking details.

The Juhyun So Lawsuit: What the Federal Wiretap Act Claim Alleged
Juhyun So filed suit in U.S. District Court in Illinois in 2025, arguing that Hyatt violated the federal Wiretap Act by allowing Meta and Adobe pixels to intercept booking information. The Wiretap Act is a 1968 federal law designed to protect communications privacy by prohibiting the unauthorized interception of phone calls, emails, and electronic communications. The theory was that when Hyatt allowed these tracking pixels to capture booking data, it was effectively intercepting guest communications without consent.
The case number was 25 C 10483, and it raised novel questions about whether advertising technology constitutes illegal “interception” under modern privacy law. The plaintiff’s legal theory was straightforward: guests enter sensitive personal information on Hyatt’s website with the expectation that only Hyatt (and its necessary service providers like payment processors) will receive that data. By secretly routing that information to Meta and Adobe for advertising purposes, Hyatt crossed the line from normal website operation into unlawful interception. This is different from merely collecting data yourself—it’s about sharing data you don’t want shared with companies you never agreed to do business with.
Why the Court Dismissed the Privacy Tracking Claims
On May 5, 2026, the Northern District of Illinois dismissed the Federal Wiretap Act claim, finding that Hyatt’s website terms and privacy policy provided adequate legal cover. The court applied Illinois law based on choice-of-law provisions in Hyatt’s website and loyalty program terms, ruling that because Hyatt technically disclosed the tracking (somewhere in its terms), guests could not claim they were intercepted without consent. This is a crucial limitation of privacy law: disclosure, even in fine print or obscure terms of service, can shield companies from liability.
The ruling reveals how outdated privacy law struggles with modern advertising technology. The Federal Wiretap Act was written before the internet existed and requires proof of intentional interception “without the consent of any party to the communication.” Courts have interpreted this to mean that if a company discloses in its terms of service that tracking occurs, consent is deemed given—even if you never read those terms or actively understood what you were agreeing to. A warning: this sets a precedent that companies can continue tracking guest information as long as they mention it somewhere in their legal agreements, a burden that clearly favors large corporations over individual consumers.

The Data Breach Connection: Separating Tracking Claims from Breach Liability
The Hyatt tracking case is separate from but overlapping with a major January 2026 data breach that exposed 48 to 50 gigabytes of Hyatt’s internal data. In January, the NightSpire ransomware group announced it had stolen data from Hyatt Place Chelsea in New York, including employee credentials, invoices, expense reports, and customer management system records. This real breach—where hackers stole information—is more serious than the tracking issue, but it’s worth understanding the difference: the tracking pixels are intentional disclosure to business partners, while the breach was unauthorized theft. A separate class action case, Cuiellette v.
Hyatt Hotels Corporation (Case 2:26-cv-00638) filed in Louisiana Eastern District Court, addresses claims related to the January 2026 breach itself. This is distinct from the So tracking case, though both involve Hyatt’s mishandling of guest information. The limitation here is important to understand: if you were affected by the data breach, you may have stronger legal claims than the tracking case provided, since breach victims can often argue unauthorized access. However, tracking—which is technically authorized by terms of service—creates a weaker legal position.
What the Texas Settlement Reveals About Hyatt’s Deceptive Practices
While the federal tracking case was dismissed, Hyatt did face consequences for privacy-related deception in other contexts. On December 30, 2025, Hyatt agreed to a $1.25 million settlement with Texas Attorney General Ken Paxton for deceptive pricing practices. The core issue was that Hyatt advertised room rates without disclosing mandatory fees upfront, misleading guests about the true cost of their reservations. Although this settlement addresses pricing rather than data privacy directly, it demonstrates Hyatt’s pattern of misleading customers about important terms of their transactions.
This Texas settlement is instructive because it shows that companies can face enforcement action for incomplete disclosure, but only when regulators actively pursue it. The tracking pixels issue might have been similarly addressable through state attorney general enforcement if the plaintiffs had pursued that avenue rather than relying on federal wiretap law. A comparison: in the tracking case, Hyatt technically disclosed the pixels in its terms (though most guests missed it), while in the Texas case, Hyatt failed to disclose fees at all. Yet both involved hiding material information from customers.

What You Should Know If You Stayed at Hyatt
If you have stayed at Hyatt or booked a reservation through their website, your booking information may have been shared with Meta and Adobe for advertising targeting. The So v. Hyatt dismissal means you likely do not have a viable federal Wiretap Act claim, but you should be aware that this tracking probably occurred.
Check your email for any notices from Hyatt about the January 2026 breach; if your data was exposed in that incident (rather than just tracked), you may have claims related to inadequate data security. Review your Hyatt account settings and consider adjusting your privacy settings in Meta’s Ad Preferences and Adobe’s privacy portal if you want to limit targeted advertising. While the dismissal suggests tracking was legal, it doesn’t mean you have to accept it passively. Additionally, if you were charged unexpected fees at a Hyatt property or your reservation had hidden resort fees not clearly disclosed, you may still have grounds for a complaint with your state attorney general.
The Future of Tracking Pixel Litigation and Guest Privacy
The So v. Hyatt dismissal raises important questions about the future of privacy litigation in the era of ubiquitous website tracking. As more cases challenge tracking practices, courts may develop clearer standards about what constitutes adequate disclosure and whether terms of service buried in legal documents truly constitute meaningful consent.
The travel and hospitality industry—where guests share sensitive information including payment methods, home addresses, and travel dates—is particularly vulnerable to tracking abuse. Looking forward, state legislatures and the FTC may become more active in regulating advertising pixels and requiring clearer, upfront consent for data sharing. The California Consumer Privacy Act and similar state laws have already begun shifting the burden away from companies’ fine-print disclosures toward explicit opt-in requirements. Hyatt customers should monitor whether hospitality industry standards evolve to limit tracking, and whether state regulators pursue enforcement action against the practice even if federal courts won’t intervene.
Conclusion
Hyatt Hotels’ website tracking practices were the subject of a federal privacy lawsuit that alleged Meta and Adobe pixels on Hyatt’s booking site improperly intercepted guest information. The court’s May 2026 dismissal of the Federal Wiretap Act claim reflects the current state of privacy law: companies can track and share your information with third parties as long as they disclose it in their terms of service, even if that disclosure is obscure or unread. If you stayed at Hyatt and are concerned about your booking information being tracked, understand that this particular federal claim is no longer available, but you may have other options.
Check whether you were affected by the January 2026 data breach, monitor your accounts for suspicious activity, and consider contacting the Louisiana court handling the Cuiellette v. Hyatt breach case if you have damages to report. As privacy law evolves, clearer protections for guest information may emerge, but for now, reading the fine print and understanding what websites track is the most practical protection available.
You Might Also Like
- Venmo Privacy Class Action Claims User Transaction Data Was Shared Improperly
- MGM Resorts Data Breach Class Action Claims Guest Information Was Exposed
- U-Haul Data Breach Class Action Claims Customer Driver’s License Information Was Exposed
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase: