
Two new federal class actions say prediction market Kalshi quietly fed people’s identities and bets to big tech trackers, reviving fears that sensitive political wagering doubles as data mining.
Story Snapshot
- California and New York lawsuits allege Kalshi sent user identities, browsing, and bet details to Google and LinkedIn.
- Plaintiffs say users did not consent, raising wiretap and privacy claims under federal and state laws.
- Kalshi’s public pages tout encryption and data controls, but do not directly answer the new claims.
- The cases join a larger wave testing whether common web trackers violate old wiretap statutes.
What the complaints say Kalshi sent to third parties
California filings in June 2026 allege Kalshi used embedded code that transmitted user identities, browsing histories, confidential financial details, and specific bets to Google and LinkedIn. Reporting on the Manhattan case says the platform placed third-party scripts and pixels on its sites, despite the sensitive nature of the information handled there. Plaintiffs claim they did not consent to such sharing and that the LinkedIn Insight tag gave secret instructions to users’ browsers that caused the transfers of personal and financial data.
The California suit invokes the federal Electronic Communications Privacy Act and the California Invasion of Privacy Act, signaling a wiretap theory, not just a general consumer complaint. A named California plaintiff says he placed numerous bets on the site this year, which supports user standing rather than abstract concern. Bloomberg’s summary adds that tracking pixels allegedly covered particular bet choices, a detail that, if proven, could heighten risk because it links identity to specific political or market views.
What Kalshi says elsewhere about data, and the current gaps
Kalshi’s security page says the company uses encryption across the platform, along with masking and anonymization, and stores data in ways designed to avoid a single point of failure. Its help materials say it retains addresses, phone numbers, encrypted Social Security numbers, and emails for compliance, and that a third-party “know your customer” partner, not Kalshi, holds ID images. The privacy policy outlines California Consumer Privacy Act request rights for access and authorized agents. These pages, however, do not directly address the claimed transfers to analytics firms.
The current record is mostly complaint-driven reporting. The public materials do not include packet captures, server logs, or vendor records showing exactly what fields went to which recipient and when. The articles do not specify whether the shared data was truly identified, pseudonymous, or aggregated in each instance, which matters for wiretap and consent analysis. No court ruling has tested the claims yet. That means the key questions about scope, intent, and consent terms remain open at this early stage.
How these suits fit the larger privacy-litigation wave
These cases land in a crowded field where plaintiffs recast common pixels and tags as unlawful interceptions, while companies argue consent, anonymization, or that wiretap laws do not fit website telemetry. Recent rulings have cut both ways. Some courts have dismissed tracker suits on consent grounds or narrow readings of wiretap statutes, while others let claims proceed, especially when plaintiffs plausibly allege sensitive data exposure like health or finance details. Outcomes often turn on granular facts about what was sent and how it was identified.
For prediction markets, the stakes feel higher. Users track political odds, economic events, and sometimes disclose employers for certain higher-risk markets to fight insider trading, according to prior reporting on Kalshi’s rules. If a platform ties identity and job details to specific bets, then sends event data to ad-tech partners, many people will see that as a step too far. That fear crosses party lines: nobody wants their financial choices or political wagers turned into marketing profiles without clear, informed consent.
Why both right and left may see the same warning sign
Conservatives recall how big tech tracking often expanded with few checks. Liberals fear growing data gaps between powerful firms and regular people. Both groups suspect that institutions profit while citizens lose control of private choices. These suits strike at that nerve. If a regulated exchange let third-party code watch users place sensitive bets, it would look like another case where convenience and growth beat duty and disclosure. If the facts prove weaker, courts can toss the claims. But the concern is real.
What to watch next: discovery. Vendor logs from Google and LinkedIn, tag-manager exports, and versioned privacy policies could show exactly which scripts fired and which fields moved. That evidence will decide whether this was routine analytics with consent or a bridge too far. Until then, users should review account settings, clear trackers, and demand plain-language notices. In a year packed with high-stakes elections and markets, trust will hinge on what companies share, and with whom.
Sources:
washingtontimes.com, mediapost.com, ag.ny.gov, law.com, predictionnews.com, bloomberg.com












