Last updated: May 26, 2026
At Pipl, our mission is to provide easy access to true identity information for businesses and make sure people are who they say they are when interacting with our Customers. We do that by finding the real person behind the online identity so that trustworthy people could be trusted. In doing that, we maintain high standards of privacy, compliance and ethics.
We strive to provide you with as much visibility and control of your identity data, it starts with providing transparency around our data collection practices, sourcing our data from publicly available information and making sure that our customers use our solution for permissible purposes.
In addition, we take privacy compliance very seriously, we are certified for the EU-US Data Privacy Framework ("DPF"), UK Extension to the EU-US DPF, and Swiss-US DPF to ensure that our services support GDPR compliance and we comply with applicable laws and regulations, including the California Consumer Privacy Act (CCPA).
In this Privacy and Information Security Center you will find:
Pipl brand is owned and operated by Pipl, Inc., and Pipl’s (“Pipl”, “Pipl”, “we”, “our” or “us”) privacy policy was built with both its usefulness and your privacy in mind. This privacy policy applies when you visit or use our website and/or our Services. This privacy policy may be updated and will be posted on Pipl’s website (pipl.com/privacy-center).
1. Personal Information We May Collect
“Personal Information” means any information relating to an identified or identifiable individual. We may collect the following types of Personal Information:
For the purpose of this Privacy Notice, unless otherwise specified, “Personal Information” means any information relating to an identified or identifiable individual. In connection with the provision of the Services, we obtain Personal Information relating to you in the situations described below.
Web Beacons: We may also use web beacons, small graphic images, or other web programming code which may be included in our Web pages and e-mail messages. We may use Web beacons (or similar technologies) to count visitors to our web pages, and to monitor how users navigate our web pages, among other legitimate business purposes.
Log files, IP addresses, URLs, embedded scripts, and similar data: We gather certain information automatically to administer the Services and analyze trends in the aggregate. This information may include IP addresses (or the proxy server a business Customer uses to access the Services), device and application identifiers, browser type, Internet service provider, the pages and files viewed, searches conducted, operating system and system configuration information, and date/time stamps associated with usage. Also, Pipl automatically receives the URL of the Web site from which a business Customer came. This information is used to analyze overall trends, and to provide and improve the Services. For example, Pipl collects IP addresses from Customers when they log into the Services as part of security features to confirm identity or detect compromised accounts. Pipl may also use embedded scripts, which are programming code designed to collect information about an interaction with a Web site, such as the links clicked on. The code is temporarily downloaded onto a device from our Web server or a third-party service provider, is active only while you are connected to the Web site containing the embedded script, and is deactivated or deleted thereafter.
Fraud Prevention SDKs and Device Technologies: Certain Customers may deploy third-party SDKs, device intelligence technologies, or similar embedded tools in connection with their use of the Services for fraud prevention, account security, identity verification, and abuse detection purposes. These technologies may automatically collect technical and device-related information such as device identifiers, operating system information, browser characteristics, IP address, network attributes, device telemetry, application interaction data, and indicators associated with fraudulent or automated activity. Information collected through these technologies may be shared with Pipl solely to support fraud prevention, cybersecurity, identity verification, risk mitigation, and related security functions. Such technologies are not used by Pipl for targeted advertising or unrelated consumer profiling activities.
2. How We May Use Your Personal Information
We may use your Personal Information to:
We set out below the purposes for which we process Personal Information. We indicate the categories of Personal Information per processing purpose. We will only process your Personal Information when we have a valid legal ground for the processing in accordance with applicable law, depending on the country in which you are located. However, please note that even though the chart below may not list consent as a legal basis for each processing activity, in some countries consent is the only or most appropriate legal basis for the processing of Personal Information, and in those countries we rely on consent for all processing activities. In certain cases, this consent may be obtained on our behalf from our Customers.
|
Processing activity |
Legal Basis for Processing (where required under applicable law) |
Categories of Personal Information |
|
Provide Services to our customers for fraud and incident prevention and servicing customer accounts, including activities such as facilitate payments for the Services, communicate with our customers, connect third party services for customers, personalize the services at customers’ requests, and audit interactions with customers. |
We, and our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services. We may also rely on the “performance of a contract” legal ground when we process Personal Information to fulfill individuals’ requests e.g., to respond to individuals’ inquiries. |
Account Information Customer Data Usage Information (such as cookies and similar technologies) Billing Information Pipl Data Metadata |
|
Maintain the Services in good working order, and to manage cyber threats, risk exposure, and franchise quality with respect to the integrity and security of our Services and internal systems. |
We have a legitimate interest in ensuring the safety, security and performance of our Services. |
Account Information Customer Data Usage Information (such as cookies and similar technologies) Pipl Data Metadata |
|
Operate, evaluate, and improve our business (including developing new products and services). |
We have a legitimate interest in improving and developing our business, products, and services. |
Account Information Customer Data Usage Information (such as cookies and similar technologies) Billing Information Pipl Data Metadata |
|
Provide tailored business communication and marketing. |
We have a legitimate interest in promoting our business. When we send electronic direct marketing communications, or when we tailor our advertising, we will obtain individuals’ prior consent if required in accordance with applicable laws. |
General Communication Information Account Information We do not use Customer Data for marketing purposes. |
|
As may be required by applicable laws and regulations, including for compliance with Know Your Customers, Anti-Money Laundering, anti-corruption and sanctions screening requirements, or as requested by any judicial process, law enforcement, or governmental agency having or claiming jurisdiction over Pipl or Pipl’s affiliates. |
Compliance with legal obligations |
General Communication Information Account Information Customer Data Usage Information (such as cookies and similar technologies) Billing Information Pipl Data Metadata |
|
Protect against and prevent fraud and cyber threats, unauthorized transactions, claims and other liabilities, and manage risk exposure and franchise quality with respect to the integrity and security of our Services. |
We, or a third party, have a legitimate interest in protecting against legal claims. |
General Communication Information Account Information Customer Data Usage Information (such as cookies and similar technologies) Billing Information Pipl Data Metadata |
|
Perform due diligence reviews, accounting, auditing, billing, reconciliation and collection activities. |
We have a legitimate interest in managing our Customer, vendor and partner relationships as necessary to operate our business. |
Account Information Billing Information |
|
Protect our Customer and others against fraud, cyber incidents and strengthen the cyber resilience of our Customer’s operations. |
We, or our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services. |
Account Information Customer Data Usage Information (such as cookies and similar technologies) Pipl Data Metadata |
3. How We Share Your Personal Information
We may share Personal Information with:
Pipl may provide your Personal Information to the following third parties for the purposes set out below:
4. Commitment to Children’s Privacy
We are committed to protecting the privacy of minors. To comply with various privacy regulations, at this time, Pipl is not directed or otherwise intended to be used by users under the age of 18. Therefore, our Services are only available to users who are at least 18 years old and should only be used by users in that condition, in accordance with our terms of service. If you are under 18, please do not use Pipl’s Service.
Furthermore, Pipl never knowingly sells or publicly discloses personal information that is associated with a minor individual.
5. Third Party Websites
Pipl Services contain links to third party websites and embedded elements from third party web services such as Google Maps; likewise, your query information might be relayed to third party data feeds for additional results. If you use Pipl’s Services or follow a link to a third-party website, some information about you and your query will be visible to subsequent services. Even if the third-party website or service is affiliated with us, we have no control over linked sites, services or data feeds, each of which has a separate privacy and data collection practices independent of Pipl. As such, we are not responsible for, nor have any control over, the content or privacy policies of those third-party websites or services, and encourage all users to read the privacy policies of each and every website linked from or embedded in Pipl.com. In addition, Customers utilizing the Services may independently implement third-party fraud prevention or device intelligence SDKs, scripts, or embedded technologies within their own applications, websites, or services. The collection and processing of information by such Customer-authorized technologies is governed by the applicable Customer’s privacy practices and agreements, except to the extent Pipl receives or processes such information solely in support of fraud prevention, identity verification, or cybersecurity services.
6. Data Subject Rights
Pipl, Inc. acknowledges the rights of access afforded to EU, UK and/or Swiss individuals. If the European Union’s General Data Protection Regulation, UK Data Privacy Act, California Consumer Privacy Act, or other countries’ privacy regulation is applicable to you, you may have the following rights in respect of your personal data that we hold:
7. Exercising Your Rights
California, EU, Swiss and/or UK residents have the choice to exercise their rights under the CCPA, the GDPR, or the UK-GDPR in the following ways:
For California residents under CCPA, to “Opt-Out” of the sale or sharing of your information with third parties, visit:
DO NOT SELL OR SHARE MY PERSONAL INFORMATION LINK
For California residents, under CCPA, to make a deletion or disclosure request, visit: https://pipl.com/ccpa-disclosure-form
EU, Swiss and/or UK residents may exercise your right to access, delete, rectification, or object to processing as described above you may also submit a request to us via the following methods:
Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Pipl will provide you with a date when the information will be provided. If for some reason access is denied, Pipl will provide an explanation as to why access has been denied.
For questions or complaints about the processing of your personal data, you can email Pipl’s privacy team at privacy@pipl.com. Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation’s data protection authority.
8. International Transfers
Information collected by Pipl may be stored in the United States or any other country in which Pipl or its agents maintain facilities. By using Pipl, you consent to any such transfer outside of your country. With respect to personal information that Pipl receives from its EU based customers, Pipl complies with applicable transfer mechanism(s) in place at such time.
Pipl, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Pipl, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Pipl, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
9. Data Retention
We will retain your personal information for as long as necessary to operate our website or provide services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods shall be determined taking into account the type of information that is collected and the purpose for which it is collected for, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.
10. Data Security
We have implemented administrative, technical, and physical safeguards to help prevent unauthorized access, use or disclosure of your personal information.
While we seek to protect your information to ensure that it is kept confidential, we cannot guarantee the security of any information. You should be aware that there is always some risk involved in transmitting information over the internet and there is also some risk that others could find a way to thwart our security systems. As a result, while we strive to protect your personal information, we cannot ensure or warrant the security and privacy of your personal information or other content you transmit using the Services or Websites, and you do so at your own risk. Thus, we encourage you to exercise discretion regarding the personal information you choose to disclose.
11. California Consumer Privacy Act (“CCPA”) and Related Regulations
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
Annual Report on request to access, delete and opt-out for the calendar year 2025:
|
Requests |
Total Number of Requests |
Numbe of Requests Complied with in Full |
Number of Requests Complied with in Part |
Number of Requests Denied |
Mean Number of Days to Respond* |
Median Number of Days to Respond* |
|
Disclose |
7 |
7 |
0 |
0 |
0.66 |
0.67 |
|
Delete |
19,227 |
19,227 |
0 |
0 |
0.5 |
0.54 |
|
Opt-Out |
507 |
507 |
0 |
0 |
0.66 |
0.5 |
12. How to Contact Us
If you have any questions, concerns or complaints, or would like to exercise your rights, please contact us at:
In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), Pipl, Inc. commits to resolve complaints about our collection or use of your personal information transferred to the U.S. pursuant to the EU-U.S. DPF, the UK extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. EU, UK, and Swiss individuals with inquiries or complaints should first contact Pipl, Inc. at privacy@Pipl.com.
Pipl has further committed to refer unresolved DPF Principles-related complaints to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbbprograms.org/dpf-complaints for more information and to file a complaint. This service is provided free of charge to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction
The Federal Trade Commission has investigatory and enforcement authority regarding Pipl’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and SW-US DPF.