ACompliance

First-party data.
Consent on file. Auditable.

Piplead is a B2B SaaS that resells pseudonymous trader signal — not a list broker, not a scraper, not an aggregator of third-party feeds. Every record we ship traces back to a trader who consented at signup on Piplead's own trade automation platform.

Last updated · 13 May 2026

What Piplead actually is

Piplead is a B2B SaaS platform operated by Finnect, LLC (701 Tillery Street #2589, Austin, TX 78702, United States). The platform delivers verified, consent-based trader signal to licensed financial businesses — brokers, prop firms, IBs, banks, insurers, fintech, research.

We are not a marketing-list vendor, not a people-finder, not a data broker selling consumer profiles, and not an aggregator of third-party tracking pixels. We do not buy or sell email lists. We do not scrape websites or social networks for personal data.

Where the data comes from

The signal we resell originates from one source we own and operate ourselves: the Piplead Trade Automation Platform. Retail traders sign up on our platform directly, agree to our Terms of Service, and during signup provide explicit consent that pseudonymous trading metadata — broker, platform, volume bands, recency, country — may be shared with vetted broker, prop firm, and IB partners.

Every record we ship has a traceable consent on file. We can produce the consent timestamp and the version of the consent language for any record on request.

What we collect (and never collect)

What we collect
  • Pseudonymous trader identifier
  • Name, work email, work phone (where the trader provided them)
  • Country of residence (region-coarse)
  • Trading platform(s) used (e.g., MT4, MT5, cTrader)
  • Broker / prop firm relationships
  • Volume bands and recency of activity
  • Funding status (yes / no)
  • Strategy fit and intent score (derived)
What we never collect
  • Account passwords or API keys
  • Government-issued IDs
  • Bank account numbers or IBANs
  • Card numbers or full payment data
  • Trade-by-trade P&L tied to identity
  • Health, biometric, or special-category data
  • Children's data (under 18)
  • Browsing history outside our own platform

What customers may do with it

Customers must have a lawful basis to contact each lead under their applicable law — typically consent or legitimate interest under GDPR / UK GDPR, and the B2B exemption where it applies. Our Acceptable Use Policy is binding.

Customers must:

  • Honour every opt-out we propagate, within 24 hours of receipt.
  • Identify themselves clearly in any outbound communication.
  • Provide an unsubscribe / opt-out path on every message.
  • Comply with all applicable telemarketing, anti-spam, and financial-promotion rules in their jurisdiction.
  • Use the data only for the purposes disclosed in their workspace.

Customers must not:

  • Resell, sublicense, or republish raw lead data.
  • Send unsolicited bulk messaging or spam.
  • Combine our data with consumer datasets bought from list brokers.
  • Re-identify pseudonymous traders by joining with external datasets.
  • Contact traders outside the regions, products, and use-cases agreed with us.

Read the full Acceptable Use Policy.

Trader rights

Traders whose data is shared via Piplead can exercise the following rights at any time, regardless of where they live:

  • Access — receive a copy of the data we hold.
  • Deletion — request erasure from our platform and from every customer downstream.
  • Correction — fix inaccurate fields.
  • Portability — receive their data in a machine-readable format.
  • Opt-out — withdraw consent for further sharing at any time.
  • Complaint — escalate to their local data protection authority.

The fastest route is the privacy request form. You can also email privacy@piplead.com. We respond within 30 days; usually within 7.

Opt-outs propagate within 24h

When a trader opts out — through us, through a customer's CRM unsubscribe, or through an authority — we suppress that record within Piplead immediately and push the suppression to every customer who received it via webhook and via the Suppressions API. Customers are contractually required to apply suppressions within 24 hours.

We log suppression delivery per customer and can produce evidence on request.

Audits & evidence

  • Internal data-handling review performed at least annually.
  • Sub-processor list maintained and updated; see /legal/sub-processors.
  • DPIA available to enterprise customers under NDA.
  • Vulnerability disclosure: security@piplead.com.
  • Incident response: customers notified within 72 hours of confirmed personal-data breach.

We do not currently hold a SOC 2 certification. Our security posture is described honestly on the Security page.

Region & residency

Default processing region is the European Union. EU/UK data-residency is available on request. US-only routing for US-bound campaigns is available on request. Cross-border transfers are governed by the Standard Contractual Clauses referenced in our Data Processing Addendum.

Need more?

We'll walk you through it on a call.

Compliance, legal, security review — we have the documents and the people to answer. Pick a slot and we'll bring our DPO, our security lead, or both.