Evidence and testimony
Abstract stepped block illustration representing Website and Conversion

EvidenceParty-heldThe record sits in the parties' own systems, and its completeness is itself contested.

Website and Conversion

The record
Server logs, tag manager versions, CMS revisions, experiment and form logs
Who holds it
The site operator, and its vendors under contract
What it establishes
What was deployed on a site, when, by whom, and what it captured
What it cannot settle
A log records a request, not what a visitor perceived or understood

The website record a party already holds is usually better than the platform record it is trying to subpoena

The most reliable website record is the one nobody asks for

Server logs are the strongest and least used evidence in this field. Each entry records the request time, the requesting IP address, the user agent string, the requested address, the referrer, the response code and the bytes served. They are a first-party record on the operator's own infrastructure. They are not subject to an advertising platform's retention schedule, they are not gated by a consent banner, and they are not suppressed by an ad blocker. In an environment where analytics data is consent-gated, thresholded and partly modeled, server logs are frequently the only complete record of what was actually requested.

They are also, routinely, already discarded, because log retention is a cost decision nobody revisits when a dispute appears. Establish that early and in writing: the difference between never keeping them and rotating them out last March matters later.

An attorney looking for a website expert witness usually wants someone who can say what a site did and when. That answer is assembled from party-held records — good news for obtainability, and the reason their completeness becomes a contested question of its own.

The full inventory, and what each item is good for

  • Server logs — requests, responses and timing; the best evidence of what was served and whether the site was reachable.
  • Analytics — sampled above volume thresholds, consent-gated, partly modeled, and subject to retention limits that delete the granular layer on a schedule.
  • Tag manager version history — a versioned, timestamped, attributed record of every container publish. It shows exactly what tracking was live, on what pages, from what date, published by which account. It is excellent evidence and it is routinely overlooked.
  • Content management revision history — page and post revisions with author and timestamp.
  • Form and checkout logs — submission timestamps, field-level validation failures, abandonment points, payment gateway request and response pairs, and the version of the form that was displayed.
  • Session recordings and heatmaps — the closest thing to a record of one visitor's experience, with the caveats below.
  • A/B testing records — which variant a visitor was assigned, when the experiment ran, how traffic was split, and what the platform computed.
  • Third-party archives — the Internet Archive, with irregular crawls, historic robots exclusions, and poor coverage of dynamic pages.

In a dispute about a build or a services engagement, the first four establish the sequence of work: what was deployed, when, by whom, and what broke. That is usually more probative than the correspondence, because it is contemporaneous and was not written for an audience.

Experiment records are unusually good evidence, and their results are not

An experiment configuration is pre-registered evidence. It records what the operator changed, what it expected, how traffic was split, and when the test started and stopped — all fixed before the outcome was known. In a dispute about whether a developer or agency did what it said it would, or about whether a change preceded a decline, that is direct evidence of intent and sequence rather than reconstruction.

Experiment results are a different matter, and an opposing expert will raise all of these: peeking, where stopping a test once it looks good inflates false positives; multiple comparisons; insufficient power for the effect claimed; sample ratio mismatch; novelty and primacy effects; and the gap between a significant lift on a small on-page action and any effect on revenue. A result offered as proof that a design change drove a business outcome has to survive all six, and often cannot.

There is also a trap that catches page-content claims. If a test was running during the disputed period, "what the website said" has no single answer, and any screenshot-based claim has to be checked against the experiment log for the same dates.

Session replay, and the litigation wave that now surrounds it

Session replay tools capture page changes, mouse movement, scrolling, clicks and keystrokes, and reconstruct a video-like playback of a visit, typically by injecting a third-party script that streams event data to the vendor. For the operator, that capture is close to the best possible evidence of what a specific user experienced: what was on screen, in what order, what was clicked, whether a disclosure was visible. In a disclosure-adequacy dispute it beats a static image.

The same capture is the subject of a very large volume of litigation, on three recurring theories. Under the California Invasion of Privacy Act, § 631(a) — the wiretap theory — the vendor is cast as an unauthorized eavesdropper on the communication between visitor and site, with statutory damages of $5,000 per violation under Cal. Penal Code § 637.2. Under § 638.51 — the pen register theory, which emerged around 2023 and 2024 — a script that captures identifiers and routing information is characterized as a pen register installed without a court order, and that theory reaches ordinary analytics and advertising tags, not only session replay. Separately, video content on publisher sites has generated its own wave under the Video Privacy Protection Act.

Where the courts have actually split, stated precisely

Counsel is regularly handed a summary of this area that is wrong in one specific way, so precision pays.

Javier v. Assurance IQ, LLC, No. 21-16351 (9th Cir. 31 May 2022), is cited most often for the proposition that consent must be prior: the panel reversed dismissal, reading § 631(a) to require the prior consent of all parties, so consent obtained after recording began does not satisfy the statute. It is an unpublished memorandum disposition, expressly marked not for publication, and under Ninth Circuit Rule 36-3 such dispositions are not precedent, though they are citable under FRAP 32.1. Describing Javier as binding authority is an easy error to correct on cross.

Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 16 Aug. 2022), is precedential. Applying the Pennsylvania wiretap act, the Third Circuit found no direct-party exception to liability under that statute, held that the vendor and the retailer could not avoid liability merely by showing the visitor communicated directly with the vendor's servers, and located the interception "at Popa's browser" rather than at the vendor's servers. It vacated summary judgment for the defendants and remanded, principally on whether the privacy policy disclosed the third-party tracking well enough to establish consent.

The Massachusetts Supreme Judicial Court went the other way on its own statute in Vita v. New England Baptist Hospital, SJC-13542 (Mass. 24 Oct. 2024), holding that the Massachusetts wiretap act does not unambiguously reach web browsing, that "communication" is ambiguous as applied to interactions with a website, and — applying the rule of lenity, the act carrying criminal penalties — reversing the denial of motions to dismiss the wiretap claims, over a dissent by Justice Wendlandt. Popa and Vita are not in conflict; they construe different statutes, which is itself the point.

On the pen register theory, Greenley v. Kochava, Inc., 684 F. Supp. 3d 1024 (S.D. Cal. 2023), denied a motion to dismiss the § 638.51 claim, reading the statute's reference to "a device or process" to reach software that identifies consumers, gathers data and correlates it through fingerprinting, and directing that the analysis focus less on the form of the collector and more on the result. Reported federal decisions since have run substantially, though not uniformly, toward allowing that theory past the pleading stage, and there is no controlling appellate authority on it. The main defense to the § 631(a) theory is the party exception — that a vendor serving the operator is an extension of the operator rather than an eavesdropper — and courts have divided on it, with outcomes turning on the vendor contract and on whether the vendor uses the data for its own purposes. California has repeatedly considered, and as of this writing has not enacted, legislation narrowing private claims of this kind against website analytics and tracking technology.

What the technical expert supplies in a tracking case, and what it stops short of

The marketing and website expert does not opine on whether a statute was violated. That is the court's question and counsel's argument. What is answerable, and almost entirely from the operator's own systems, is the factual predicate underneath it:

  • which scripts were present on which pages, on which dates
  • what each script captured, at what granularity
  • where the captured data was sent, and whether it left the operator's control
  • what the consent interface said, and when it appeared relative to the script firing
  • who deployed each tag and when, from the tag manager's version history

That last item is the most probative artifact in these cases and it is frequently not collected. A container's version history attributes each publish to an account and a timestamp, converting "nobody knows when that script went on the site" into a documented sequence. It is equally useful to a defendant, because it often shows that a script was removed, or was never live on the pages at issue.

Development and services disputes, where the argument is about sequence

In a dispute over a website build or an ongoing services engagement, the contract sets the obligations and the technical record sets what happened. Deployment and version history establish what was delivered and when. Server logs establish availability, error rates and response codes across the period. Form and checkout logs establish whether the things a site was supposed to capture were in fact captured, and from what date. Tag history establishes whether measurement was ever correctly installed — which matters when a party's damages theory depends on numbers produced by tracking that was misconfigured for part of the period.

Conversion claims deserve particular care, because four systems count four different things: analytics counts sessions, the order table counts orders, the payment processor counts settled transactions, and the advertising platform counts conversions it attributed to itself. Those figures will not match, and a party treating the mismatch as evidence of bad faith has usually not read the platforms' own documentation. Reconciling them and documenting why they differ frequently resolves the dispute without anyone having to characterize anyone's conduct.

What website evidence cannot establish

A log records a request; it does not record perception. A server log entry supports a finding that a resource was requested and a response sent. It does not establish that the page rendered as intended, that the visitor read anything, or that any of it was understood. Where client-side rendering, personalization or an experiment assignment sits between the response and the screen, the log is upstream of what the visitor saw.

A session recording is one visit on one device, with fields masked by design. It cannot establish that the experience was typical, and it certainly cannot establish what a class of users saw.

A screenshot establishes almost nothing on its own — not the date, not the server's response, not whether personalization or an experiment applied.

The Internet Archive has known gaps: irregular crawl frequency, historic robots exclusions that removed content retroactively, poor capture of dynamic and personalized pages, and embedded resources sometimes pulled from different crawl dates than the page itself. It is useful. It is not a complete archive, and absence from it is not evidence of absence.

Frequently Asked Questions

What website records should be preserved first when a dispute appears?

Server access logs, because retention is a cost setting somebody rotates without thinking about it. Tag manager container versions, which are the most probative artifact in any tracking dispute and are almost never collected. Content management and theme version history, before a redesign overwrites it. Experiment configuration and assignment data. Form and checkout logs, including the displayed version of each form. Analytics exports at the finest granularity still available, with the retention setting and reporting identity recorded at the time of the export. Date every extract and note the exact path or query that produced it.

Is Javier v. Assurance IQ binding authority on consent for session replay?

No. Javier is an unpublished memorandum disposition of the Ninth Circuit, expressly marked not for publication, which under Ninth Circuit Rule 36-3 means it is not precedent, though it remains citable under FRAP 32.1. Its substance — that section 631(a) requires prior consent of all parties, so consent obtained after recording began does not satisfy the statute — is cited constantly as though it were controlling. It is not. By contrast, the Third Circuit's decision in Popa v. Harriet Carter Gifts, applying the Pennsylvania statute, is precedential, and the two are frequently conflated in briefing.

Can an expert say whether a tracking script violated a wiretapping statute?

That is not the expert's question and offering it invites exclusion. What the expert establishes is the factual predicate: which scripts were on which pages on which dates, what each captured, where the data went, what the consent interface said, and when it appeared relative to the script firing. The tag manager's version history supplies who deployed what and when. Those facts, drawn from the operator's own systems, are what the legal argument is built on, and they are equally useful to a defendant who needs to show a script was never live on the pages at issue.

How reliable are A/B test results as evidence that a change caused a business outcome?

The configuration is strong evidence; the result usually needs qualification. An experiment record is pre-registered, so it establishes what was changed, when, and what the operator expected before the outcome was known. The result faces the standard objections: peeking, multiple comparisons, insufficient power for the claimed effect, sample ratio mismatch, novelty and primacy effects, and the gap between a lift on a small on-page action and any movement in revenue. A test offered as proof that a design change drove sales generally has to answer all of them, and many cannot.

Why do analytics, orders and platform conversions never match on a website?

Because they measure different things. Analytics counts sessions and is sampled above volume thresholds, gated by consent, and partly modeled. The order table counts orders. The payment processor counts settled transactions. Each advertising platform counts conversions it attributed to itself, under its own window and model, so those figures cannot even be summed across platforms. Discrepancies are the expected condition, not an anomaly requiring an explanation of bad faith. What matters is that the reconciliation is done and documented, with each definitional difference identified, before anyone characterizes the gap.

What can a rebuttal engagement do when the opposing report relies on a screenshot?

Quite a lot, and cheaply. A screenshot does not fix the date, the server response, the visitor's logged-in state, the personalization applied, or the experiment variant assigned. If a test was running in the disputed period, different visitors were shown different pages, and the assignment log determines whether the version in the exhibit was even reachable by the population described. Checking the exhibit against the tag manager history, the content version history and the experiment log frequently shows that the page in the image existed for a narrower audience or a shorter period than the report assumes.
Keep reading

Read the guides

An entry names the record that exists for one channel or one claim. A guide covers what is done with it, and how long there is before a retention window closes.

Top