- Example active heading
- Example heading
No, Lendio does not sell your data to lead generators or brokers. We never have. If you’ve seen claims suggesting otherwise, we want to address them directly, because transparency is how we operate.
This article explains exactly what we do with your information, what actually caused the concerns some borrowers experienced, and what you can do to protect yourself going forward.
What we do with your data.
Lendio is a SMB lending platform. When you apply for business financing, we collect the information necessary to evaluate your application and match you with lenders. This information is things like business details, financial statements, and contact information.
Matching you with lenders. Your application data is shared with the lenders, brokers, and financing providers in our platform as a core function of the service. This is not the same as selling your data. Matched lenders may retain your information even if you don't move forward with them, but you can contact any matched lender directly if you'd like to be removed from their records, or Lendio at [email protected].
Internal operations. Your data is used internally for fraud detection, security, customer support, and product development. We may also use anonymized or aggregated data for business intelligence. In that form, it can no longer be linked back to you.
What “selling data” actually means.
Selling data refers to a company collecting, aggregating, and monetizing personal information about individuals, usually without their knowledge. For a borrower, this typically means your information being sold to parties you never chose to interact with.
Lendio does not participate in data brokering or third-party data sales, and is not a lead generation company. The instances in which your data is used internally and how (and who) it is shared with as part of the application and underwriting process is outlined in Sections 3 and 4 of Lendio’s Privacy Policy.
So if Lendio doesn’t sell data, why were some borrowers receiving unsolicited calls from lenders they’d never heard of? It’s a fair question, and the answer has nothing to do with Lendio’s data practices. In December 2025, we started hearing from borrowers experiencing exactly this, and we investigated immediately.
- Our Information Security team conducted a full route forensic audit internally of all data exit points and API routes by our Information Security department, and confirmed there was no internal compromise.
- The team then contacted affected borrowers directly to gather more information on the spam calls and also provide details on the results of the audit.
- The team also introduced a “Borrower Security Concern” workflow for our support and account teams in order to be able to flag and escalate borrower feedback directly to the InfoSec team for real-time investigation.
“Our job isn’t just to watch the perimeter, it’s to make sure borrowers can trust what happens on our side of it. We audited every data exit point, contacted affected borrowers directly, and built the workflows to make sure concerns like this reach us fast. We didn’t find a breach because there wasn’t one. But we came out of this with a stronger system regardless.” - Director of Information Security, Lendio.
Our team found no security breaches during the audit, but the Information Security team was able to discover the culprit: a well-known but little-understood industry practice called a credit trigger lead.
Understanding credit trigger leads, and how to avoid them.
A credit trigger lead occurs when major credit bureaus like Equifax, Experian, and TransUnion sell your information to other lenders after you apply for credit. When you apply for a loan and the lender pulls your credit report, this notifies the bureau, who then sells your contact information to other lenders as a “trigger lead”.
Oftentimes, other lending competitors will contact you, sometimes within hours, trying to offer a better deal.
Are credit trigger leads legal?
Yes, they are, and you don’t have to explicitly agree to it. Credit bureaus are legally allowed to release your information to paying members of their network. Recent legislation is taking aim at the practice primarily on the consumer mortgage loan side, rather than business-specific loans. The good news is, there are steps you can take to opt out, which we will cover below.
How to opt out of credit trigger leads.
There are three methods you can use to reduce unwanted pre-screened credit and insurance offers.
- Opt out of credit trigger leads: Visit www.optoutprescreen.com to opt out of offers. This is the official site used by the Consumer Credit Reporting Industry. You can choose whether to opt out for 5 years, or permanently.
- Add your number to the Do Not Call registry: Register your phone numbers with the National Do Not Call Registry. This reduces unwanted sales calls across multiple industries, not just from lenders.
- Stop unsolicited mail offers: Sign up at www.dmachoice.org to reduce direct mail marketing.
Strengthening how we share borrower information.
Separate from this investigation, Lendio has also completed a broader tightening of how borrower information is shared with our lending and service partners. In a limited set of partner relationships, borrower contact information could previously be passed along directly as part of connecting borrowers to financing options, without an additional consent step from the borrower first. We’ve moved away from that model entirely.
Today, your information is only shared with a partner in one of two ways: as part of a financing package submitted to get you an offer, or after you’ve explicitly consented to be connected with a specific partner. This change was driven by our own review of partner data-sharing practices, reinforced by requirements from communication partners, and reflects our broader commitment to reducing unnecessary borrower data exposure.
Our ongoing commitment to privacy.
To be clear about what we do and don’t do: Lendio does not sell your personal financial data (the information you provide as part of a loan application) to third parties. However, like most online platforms, we do share limited information (such as identifiers and browsing activity) with advertising partners for cross-contextual behavioral advertising purposes. This is disclosed in our Privacy Policy, and you have the right to opt out at any time using our online opt-out form.
When it comes to non-advertising third parties, such as tax preparation services or other ancillary partners, your information is only shared after you have actively elected to pursue their services and provided consent. We do not share it without your knowledge.
Our data practices are governed by applicable federal and state privacy laws, including the Gramm-Leach-Bliley Act (GLBA) and the California Consumer Privacy Act (CCPA). If you have questions about how your data is used, or want to exercise your privacy rights, we want to hear from you directly.
Controlling your data at Lendio.
We take safeguarding your data and privacy very seriously at Lendio. Your data belongs to you, and you have real options to manage it.
If at any time you wish to update, access, retain or delete your data from Lendio, you can do so in your account or by contacting our team:
4100 Chapel Ridge Road, Suite 500
Lehi, Utah 84043
Telephone: (855) 853-6346
Email: [email protected]
Our full privacy policy can be found here: https://www.lendio.com/agreements/privacy-policy




