Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

PayPal Secretly Transmits Venmo Users' Private Transaction Info to Third Parties, Class Action Lawsuit Alleges

A proposed nationwide class action lawsuit (Borquez, et al. v. PayPal, Inc.) filed in California federal court accuses PayPal, Inc. of secretly sharing Venmo users’ private payment data with third-party marketing and analytics firms.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

When you transfer money to a friend, pay rent, or send a personal note using Venmo, you expect those transactions to stay private—especially if you actively set your account settings to “Private.” However, a new proposed nationwide class action lawsuit alleges that PayPal, Inc., the owner and operator of Venmo, has been surreptitiously intercepting and transmitting sensitive financial data to third-party marketing and data analytics companies.

The lawsuit charges that PayPal intentionally embedded invisible tracking code inside the Venmo application. Rather than honoring its public commitments to guard user privacy, PayPal allegedly allowed third-party companies to capture unanonymized payment amounts, recipient names, contact details, and personal transaction notes detailing the intimate specifics of users’ daily lives.

How Venmo Allegedly Discloses Private Financial Details

Venmo generates a detailed digital record for every transaction completed on its platform. Beyond the numerical payment amount, each record lists the sender’s full name, email address, phone number, advertising ID, recipient information, and a text memo where users describe the purpose of the transfer.

According to court documents, PayPal promises users that setting a transaction or profile to “Private” ensures the transaction remains strictly confidential between sender and recipient. Venmo’s official privacy statement further reassures consumers that the platform does not share personal information with third parties for marketing or promotional purposes.

Despite these clear representations, the complaint charges that PayPal chose to install background tracking tools—such as software kits operated by mParticle and Kochava—directly into the app. When users send money, these tracking scripts automatically execute in the background, copying and sending raw transaction logs to external commercial servers without the account holder’s knowledge or authorization.

What Information Was Exposed to Third Parties?

The lawsuit emphasizes that financial transaction history is among the most valuable types of consumer data for commercial advertisers because it shows real consumer spending behavior instead of rough estimates. The complaint alleges that the data transmitted by PayPal was neither aggregated nor anonymized.

Instead, the tracking software allegedly transmitted personal identifiers tied to individual users, including:

  • Senders’ full legal names, email addresses, and phone numbers

  • Device advertising IDs and persistent tracking numbers

  • Recipient identities and financial account details

  • Exact dollar amounts transferred

  • Personal transaction notes written in the memo field

Transaction notes frequently contain deeply personal information, such as payments for medical treatments, therapy sessions, rent, political donations, or personal relationship expenses. The lawsuit argues that once PayPal transmitted these details to third parties, it relinquished control over how the sensitive records are used or repurposed.

Legal Rights Under Privacy Laws and Consumer Safeguards

The lawsuit alleges that PayPal’s background data collection violates multiple federal and state privacy statutes designed to protect consumer financial records. The complaint claims violations of the federal Electronic Communications Privacy Act (ECPA), the Gramm-Leach-Bliley Act (GLBA), the California Invasion of Privacy Act (CIPA), and California’s Unfair Competition Law.

Federal and state consumer protection laws mandate that financial institutions must handle personal records transparently. Under these legal standards, companies cannot make explicit representations that data is secure and private while operating covert tracking technologies that intercept consumer communications behind the scenes.

Who May Be Eligible to Join the Venmo Class Action?

You may be eligible to join this class action lawsuit if you reside in the United States, used the Venmo platform, and took steps to protect your privacy by doing either of the following:

  • Set your overall Venmo account privacy settings to “Private.”

  • Sent or received at least one transaction marked as “Private.”

The lawsuit seeks to represent all affected U.S. residents whose personally identifiable information and transaction details were intercepted, transmitted, or made accessible to third-party tracking companies without consent. If the case proceeds and results in a monetary settlement or verdict, class members may be eligible to claim financial compensation.

What Steps You Can Take Next

If you are a Venmo user and are concerned that your personal financial transactions and private memos were shared with third parties, here is what you can do right now:

  • Review Your Privacy Settings: Open your Venmo app, navigate to your settings, and review your default transaction privacy controls.

  • Keep Record of Private Transactions: Retain digital receipts or account statements showing your history of private transactions on the platform.

  • Stay Updated on Case Progress: Follow ongoing legal developments to learn when class notices or claim forms become available.

At ClassActionU.org, our mission is to empower everyday people with the information they need to protect their rights. Don’t stand alone—stay informed about active consumer litigation and take action when corporate entities fail to honor your privacy.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: September 2026 (dark web claim date; underlying incident date not confirmed)
Date of Breach: September 2026 (dark web claim date; underlying incident date not confirmed)
Date of Breach: Notification issued September 18, 2026 (exact breach date not disclosed)
Latest News