Skip to main content

Pipl Privacy Policy

Last updated: May 26, 2026

legal-hero

Pipl Privacy and Information Security Center

At Pipl, our mission is to provide easy access to true identity information for businesses and make sure people are who they say they are when interacting with our Customers. We do that by finding the real person behind the online identity so that trustworthy people could be trusted. In doing that, we maintain high standards of privacy, compliance and ethics.

We strive to provide you with as much visibility and control of your identity data, it starts with providing transparency around our data collection practices, sourcing our data from publicly available information and making sure that our customers use our solution for permissible purposes.

In addition, we take privacy compliance very seriously, we are certified for the EU-US Data Privacy Framework ("DPF"), UK Extension to the EU-US DPF, and Swiss-US DPF to ensure that our services support GDPR compliance and we comply with applicable laws and regulations, including the California Consumer Privacy Act (CCPA).

In this Privacy and Information Security Center you will find:

  • Pipl’s comprehensive Privacy Policy disclosing how Pipl collects, uses, shares, and handles consumer information;
  • Information and Security Standards demonstrating the rigorous measures by which Pipl secures all information we handle;
  • Specific notices for EU, UK, and California residents regarding the information we collect and how they may exercise their rights under applicable privacy law;
  • Pipl’s Data Collection Practices further explained and described; and
  • Pipl’s Permissible Use Policy for its Customers that access and utilize its Services.

Pipl Privacy Policy

Pipl brand is owned and operated by Pipl, Inc., and Pipl’s (“Pipl”, “Pipl”, “we”, “our” or “us”) privacy policy was built with both its usefulness and your privacy in mind. This privacy policy applies when you visit or use our website and/or our Services. This privacy policy may be updated and will be posted on Pipl’s website (pipl.com/privacy-center).

1. Personal Information We May Collect

“Personal Information” means any information relating to an identified or identifiable individual. We may collect the following types of Personal Information:

  • Personal Information Provided by You
  • Personal Information Provided by Customers
  • Personal Information Derived from Customer Data
  • Third parties
  • Personal Information Automatically Obtained from Your Interaction with the Services or our web sites.

For the purpose of this Privacy Notice, unless otherwise specified, “Personal Information” means any information relating to an identified or identifiable individual. In connection with the provision of the Services, we obtain Personal Information relating to you in the situations described below.

  • Personal Information Provided by You
      • General Communication Information. When you contact us (for example via email, phone or online web forms), we will collect Personal Information provided by you, such as your first and last name, telephone number, email address, physical address, employer name, as well as any other content that you provide (“General Communication Information”). If you do not provide certain General Communication Information, we may not be able to answer your requests or queries.
      • Account Information. We may collect usernames, passwords, and other details of account-level information from representatives of business Customers when they correspond with us by phone or email, or request support for the Services (“Account Information”). If they do not provide certain Account Information, such as usernames and passwords, they may not be able to use the Services or take advantage of certain features of the Services.
      • Billing Information. We may collect billing information from representatives of our business Customers when they purchase our Services, such as billing name and address, ACH, or credit card number.
      • Identity Verification. In certain circumstances, we may request or receive personal information directly from a consumer interacting with our Customer’s platform or other web service if necessary to verify a consumer’s identity and prevent potential fraud. We only collect such information when reasonably necessary for these purposes, and we do not use it for unrelated purposes.
  • Personal Information Provided by Customers
      • Customer Data. We collect information in the form of queries submitted to the Services by business Customers for identity verification and fraud prevention and detection purposes. Such queries may contain the name, e-mail address, physical address, phone number, and IP address of the business Customer’s consumers (“Customer Data”). When a Customer submits Customer Data to the Services, Pipl may analyze Customer Data in conjunction with Pipl Data (see below) and other Customers’ data, to create Metadata (see below) to provide results to the Customer’s query.
      • Device and Fraud Prevention Signals. In connection with fraud prevention, identity verification, account security, and abuse prevention activities, certain Customers may utilize third-party software development kits (“SDKs”), device intelligence tools, or similar technologies within their applications, websites, or platforms. These technologies may collect and transmit device-related and network-related information to Pipl or to Customer-authorized third parties acting on the Customer’s behalf, including device identifiers, browser and operating system characteristics, IP address, network and connection attributes, application telemetry, and signals associated with device integrity, fraud risk, or suspicious activity. Pipl processes such information solely for fraud prevention, identity verification, cybersecurity, and account protection purposes and not for advertising, or marketing.
    1. Personal Information Derived from Customer Data
      • Metadata. We derive information from our analysis of Customer Data, such as the number of times a data element has been queried in a period of time (velocity) or the last time a data element has been seen (recency) (“Metadata”) to identify behavioral patterns and insights for our fraud prevention and identity verification services (e.g., patterns confirming that a provided address is genuine).
  • Third parties
      • Third party data. To enable us to provide our Services, we obtain Personal Information from publicly available sources and from third party data providers, who may collect the information from publicly available sources or directly from individuals. This data collection includes the mapping of IP addresses to non-precise location data (e.g., city, state), and the collection of the following data elements: name, e-mail address, physical address, phone number, and IP address. Pipl includes such third-party data together with Metadata (collectively “Pipl Data”) in its own databases.
  • Personal Information Automatically Obtained from Your Interaction with the Services
    • Usage Information (such as cookies and similar technologies). When you interact with our ads, websites, apps or other digital assets, we or our service partners may collect certain information by automated means such as cookies, web beacons, and embedded scripts. This Usage Information may include standard information from a web browser (such as browser type and browser language), an IP address, device identifier numbers, and the actions a website visitor or Customer takes on our web pages (such as how a visitor/Customer interacts with the web pages and the links clicked).
      Cookies: Pipl may use cookies, pixels, beacons, local storage and similar technologies (“Tracking Technologies”) in an effort to improve the quality of our Services and your interactions with our web sites. A Cookie is a small data file that is sent to your computer when you first visit a website. Cookies usually include an identification number that is unique to the computer you are using. Such identifiers can help us better understand our users and how they are using the website and the Services, and track affiliate referrals. Cookies can improve the quality of our service (e.g. recognizing a user when they visit the site, displaying the site according to the user’s chosen user settings for language, and maintaining the security of the user’s account); and help us provide relevant information and offers to our customers and prospects. If you prefer, you can reset your browser so that it refuses all cookies or notifies you when a cookie is being sent. In such a case, your browser will send us a special signal to stop tracking your activity. You can learn more and turn off certain third party targeting and advertising cookies by visiting the following third-party webpages:

Web Beacons: We may also use web beacons, small graphic images, or other web programming code which may be included in our Web pages and e-mail messages. We may use Web beacons (or similar technologies) to count visitors to our web pages, and to monitor how users navigate our web pages, among other legitimate business purposes.
Log files, IP addresses, URLs, embedded scripts, and similar data: We gather certain information automatically to administer the Services and analyze trends in the aggregate. This information may include IP addresses (or the proxy server a business Customer uses to access the Services), device and application identifiers, browser type, Internet service provider, the pages and files viewed, searches conducted, operating system and system configuration information, and date/time stamps associated with usage. Also, Pipl automatically receives the URL of the Web site from which a business Customer came. This information is used to analyze overall trends, and to provide and improve the Services. For example, Pipl collects IP addresses from Customers when they log into the Services as part of security features to confirm identity or detect compromised accounts. Pipl may also use embedded scripts, which are programming code designed to collect information about an interaction with a Web site, such as the links clicked on. The code is temporarily downloaded onto a device from our Web server or a third-party service provider, is active only while you are connected to the Web site containing the embedded script, and is deactivated or deleted thereafter.

Fraud Prevention SDKs and Device Technologies: Certain Customers may deploy third-party SDKs, device intelligence technologies, or similar embedded tools in connection with their use of the Services for fraud prevention, account security, identity verification, and abuse detection purposes. These technologies may automatically collect technical and device-related information such as device identifiers, operating system information, browser characteristics, IP address, network attributes, device telemetry, application interaction data, and indicators associated with fraudulent or automated activity. Information collected through these technologies may be shared with Pipl solely to support fraud prevention, cybersecurity, identity verification, risk mitigation, and related security functions. Such technologies are not used by Pipl for targeted advertising or unrelated consumer profiling activities.

2. How We May Use Your Personal Information

We may use your Personal Information to:

  • Provide Services to our customers for fraud and incident prevention and servicing customer accounts, including activities such as to facilitate payments for the Services, communicate with our customers, connect third party services for customers, personalize the services at customers’ requests, and audit interactions with customers. Maintain the Services in good working order, and to manage cyber threats, risk exposure, and franchise quality with respect to the integrity and security of our Services and internal systems. This may include the use of device intelligence, SDK-generated signals, network telemetry, and related technical data provided by Customers or Customer-authorized third-party technologies solely for fraud prevention, identity verification, account security, cybersecurity, and abuse prevention purposes.
  • Operate, evaluate, and improve our business (including developing new products and services).
  • Provide tailored business communication and marketing.
  • As may be required by applicable laws and regulations, including for compliance with Know Your Customers, Anti-Money Laundering, anti-corruption and sanctions screening requirements, or as requested by any judicial process, law enforcement, or governmental agency having or claiming jurisdiction over Pipl or Pipl’s affiliates.
  • Protect against and prevent fraud and cyber threats, unauthorized transactions, claims, and other liabilities, and manage risk exposure and franchise quality with respect to the integrity and security of our Services.
  • Perform due diligence reviews, accounting, auditing, billing, reconciliation and collection activities.
  • To protect our Customer and others against fraud, cyber incidents and strengthen the cyber resilience of our Customer’s operations.

We set out below the purposes for which we process Personal Information. We indicate the categories of Personal Information per processing purpose. We will only process your Personal Information when we have a valid legal ground for the processing in accordance with applicable law, depending on the country in which you are located. However, please note that even though the chart below may not list consent as a legal basis for each processing activity, in some countries consent is the only or most appropriate legal basis for the processing of Personal Information, and in those countries we rely on consent for all processing activities. In certain cases, this consent may be obtained on our behalf from our Customers.


Processing activity

Legal Basis for Processing (where required under applicable law)

Categories of Personal Information

Provide Services to our customers for fraud and incident prevention and servicing customer accounts, including activities such as facilitate payments for the Services, communicate with our customers, connect third party services for customers, personalize the services at customers’ requests, and audit interactions with customers.

We, and our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services.


We may also rely on the “performance of a contract” legal ground when we process Personal Information to fulfill individuals’ requests e.g., to respond to individuals’ inquiries.

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Billing Information

Pipl Data

Metadata

Maintain the Services in good working order, and to manage cyber threats, risk exposure, and franchise quality with respect to the integrity and security of our Services and internal systems.

We have a legitimate interest in ensuring the safety, security and performance of our Services.

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Pipl Data

Metadata

Operate, evaluate, and improve our business (including developing new products and services).

We have a legitimate interest in improving and developing our business, products, and services.

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Billing Information

Pipl Data

Metadata

Provide tailored business communication and marketing.

We have a legitimate interest in promoting our business. When we send electronic direct marketing communications, or when we tailor our advertising, we will obtain individuals’ prior consent if required in accordance with applicable laws.

General Communication Information

Account Information

We do not use Customer Data for marketing purposes.

As may be required by applicable laws and regulations, including for compliance with Know Your Customers, Anti-Money Laundering, anti-corruption and sanctions screening requirements, or as requested by any judicial process, law enforcement, or governmental agency having or claiming jurisdiction over Pipl or Pipl’s affiliates.

Compliance with legal obligations

General Communication Information

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Billing Information

Pipl Data

Metadata

Protect against and prevent fraud and cyber threats, unauthorized transactions, claims and other liabilities, and manage risk exposure and franchise quality with respect to the integrity and security of our Services.

We, or a third party, have a legitimate interest in protecting against legal claims.

General Communication Information

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Billing Information

Pipl Data

Metadata

Perform due diligence reviews, accounting, auditing, billing, reconciliation and collection activities.

We have a legitimate interest in managing our Customer, vendor and partner relationships as necessary to operate our business.

Account Information

Billing Information

Protect our Customer and others against fraud, cyber incidents and strengthen the cyber resilience of our Customer’s operations.

We, or our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services.

Account Information

Customer Data

Usage Information (such as cookies and similar technologies)

Pipl Data

Metadata


3. How We Share Your Personal Information

We may share Personal Information with:

  • Affiliates and other entities within Pipl’s group of companies.
  • Our service providers acting on our behalf.
  • Third-party business partners.
  • Customers
  • As required by law.
  • In the event of a sale or transfer of our business or assets.

Pipl may provide your Personal Information to the following third parties for the purposes set out below:

  1. Subsidiaries and Affiliates
    We may share the Personal Information we collect with our subsidiaries and affiliates that are part of the Pipl group of companies, for the purposes described in this Privacy Notice.
  2. Service Providers
    We may share Personal Information with our service providers who perform services on our behalf and in relation to the purposes described in this Privacy Notice. Examples of our service providers include analytics providers, data storage providers and payment processing providers. We require these service providers by contract to only process Personal Information in accordance with our instructions and as necessary to perform services on our behalf or comply with legal requirements. We also require them to have safeguards designed to protect the security and confidentiality of the Personal Information they process on our behalf. These service providers may also include device intelligence, fraud detection, cybersecurity, and SDK technology providers that support fraud prevention, identity verification, and account security functions on behalf of Pipl or its Customers.
  3. Third-Party Business Partners
    We may share Personal Information with third-party data providers in order to supplement our database. For example, we may send an email address to a data provider to see whether and when the data provider may have seen the email address before.
    In addition, we may partner with a variety of businesses to market or sell our products or services. For instance, partners may co-sponsor our events or offerings. We may share General Communication Information that Customers provide when they sign up for events or other offerings with these Partners so they can send marketing communications and other information of interest. See below for how to withdraw your consent at any time.
  4. Customers
    In response to Customers’ queries, we may provide Customers with Metadata and Personal Information regarding their customers.
  5. As required by law
    We may disclose data about you: (i) if we are required to do so by law or legal process; (ii) in response to a request from a court, law enforcement authorities, or government officials; or (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity.
  6. Sale of business
    We reserve the right to transfer Personal Information we have about you in the event we sell or transfer all or a portion of our business or assets. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use Personal Information you have provided to us in a manner that is consistent with this Privacy Notice.

4. Commitment to Children’s Privacy

We are committed to protecting the privacy of minors. To comply with various privacy regulations, at this time, Pipl is not directed or otherwise intended to be used by users under the age of 18. Therefore, our Services are only available to users who are at least 18 years old and should only be used by users in that condition, in accordance with our terms of service. If you are under 18, please do not use Pipl’s Service.

Furthermore, Pipl never knowingly sells or publicly discloses personal information that is associated with a minor individual.

5. Third Party Websites

Pipl Services contain links to third party websites and embedded elements from third party web services such as Google Maps; likewise, your query information might be relayed to third party data feeds for additional results. If you use Pipl’s Services or follow a link to a third-party website, some information about you and your query will be visible to subsequent services. Even if the third-party website or service is affiliated with us, we have no control over linked sites, services or data feeds, each of which has a separate privacy and data collection practices independent of Pipl. As such, we are not responsible for, nor have any control over, the content or privacy policies of those third-party websites or services, and encourage all users to read the privacy policies of each and every website linked from or embedded in Pipl.com. In addition, Customers utilizing the Services may independently implement third-party fraud prevention or device intelligence SDKs, scripts, or embedded technologies within their own applications, websites, or services. The collection and processing of information by such Customer-authorized technologies is governed by the applicable Customer’s privacy practices and agreements, except to the extent Pipl receives or processes such information solely in support of fraud prevention, identity verification, or cybersecurity services.

6. Data Subject Rights

Pipl, Inc. acknowledges the rights of access afforded to EU, UK and/or Swiss individuals. If the European Union’s General Data Protection Regulation, UK Data Privacy Act, California Consumer Privacy Act, or other countries’ privacy regulation is applicable to you, you may have the following rights in respect of your personal data that we hold:

  • Right of Access. You have the right to know about the specific pieces of personal data we have about you.
  • Right to Delete. You have the right to request the erasure of your personal data.
  • Right to Rectification. You have the right to obtain rectification of your personal data without undue delay where that personal data is inaccurate or incomplete.
  • Right to Restrict. You have the right to restrict the processing of your personal data.
  • Right to Object. You have the right to object to the processing of personal information by us.
  • Right to Portability. You have the right to move, copy or transfer personal data easily from one organization to another.
  • Right to Opt-Out of the Sale of Data (CCPA). You have the right to opt out of the sale of your personal data.
  • Right to Opt-Out of Automated Decision Making. You have the right to opt out of automated decision making based on your personal data.
  • Right to Revoke Consent. Where Pipl relies on your explicit consent for the processing of personal data, you have a right to withdraw this consent at any time. You can do so here.

7. Exercising Your Rights

California, EU, Swiss and/or UK residents have the choice to exercise their rights under the CCPA, the GDPR, or the UK-GDPR in the following ways:

For California residents under CCPA, to “Opt-Out” of the sale or sharing of your information with third parties, visit:

DO NOT SELL OR SHARE MY PERSONAL INFORMATION LINK

For California residents, under CCPA, to make a deletion or disclosure request, visit: https://pipl.com/ccpa-disclosure-form

EU, Swiss and/or UK residents may exercise your right to access, delete, rectification, or object to processing as described above you may also submit a request to us via the following methods:

  • Calling us at (877) 616-1115 (phone requests typically require additional steps and take longer to process);
  • Initiate a request for disclosure/deletion using the following link (identity verification required); or
  • Email: privacy@pipl.com

Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Pipl will provide you with a date when the information will be provided. If for some reason access is denied, Pipl will provide an explanation as to why access has been denied.

For questions or complaints about the processing of your personal data, you can email Pipl’s privacy team at privacy@pipl.com. Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation’s data protection authority.

8. International Transfers

Information collected by Pipl may be stored in the United States or any other country in which Pipl or its agents maintain facilities. By using Pipl, you consent to any such transfer outside of your country. With respect to personal information that Pipl receives from its EU based customers, Pipl complies with applicable transfer mechanism(s) in place at such time.

Pipl, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Pipl, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Pipl, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

9. Data Retention

We will retain your personal information for as long as necessary to operate our website or provide services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods shall be determined taking into account the type of information that is collected and the purpose for which it is collected for, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.

10. Data Security

We have implemented administrative, technical, and physical safeguards to help prevent unauthorized access, use or disclosure of your personal information.

While we seek to protect your information to ensure that it is kept confidential, we cannot guarantee the security of any information. You should be aware that there is always some risk involved in transmitting information over the internet and there is also some risk that others could find a way to thwart our security systems. As a result, while we strive to protect your personal information, we cannot ensure or warrant the security and privacy of your personal information or other content you transmit using the Services or Websites, and you do so at your own risk. Thus, we encourage you to exercise discretion regarding the personal information you choose to disclose.

11. California Consumer Privacy Act (“CCPA”) and Related Regulations

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny you goods and services;
  • Charge you a different price or rates for goods or services, including through granting discounts or other benefits or imposing penalties;
  • Provide you a different level or quality of goods or services; nor
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Annual Report on request to access, delete and opt-out for the calendar year 2025:

Requests

Total Number of Requests

Numbe of Requests Complied with in Full

Number of Requests Complied with in Part

Number of Requests Denied

Mean Number of Days to Respond*

Median Number of Days to Respond*

Disclose

7

7

0

0

0.66

0.67

Delete

19,227

19,227

0

0

0.5

0.54

Opt-Out

507

507

0

0

0.66

0.5


12. How to Contact Us

If you have any questions, concerns or complaints, or would like to exercise your rights, please contact us at:

  • privacy@pipl.com or
  • (877) 616-1115

In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), Pipl, Inc. commits to resolve complaints about our collection or use of your personal information transferred to the U.S. pursuant to the EU-U.S. DPF, the UK extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. EU, UK, and Swiss individuals with inquiries or complaints should first contact Pipl, Inc. at privacy@Pipl.com.

Pipl has further committed to refer unresolved DPF Principles-related complaints to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbbprograms.org/dpf-complaints for more information and to file a complaint. This service is provided free of charge to you.

If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction

The Federal Trade Commission has investigatory and enforcement authority regarding Pipl’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and SW-US DPF.