the receipt

Anatomy of a lead record

People picture a name and an email in a spreadsheet. What actually changes hands is richer than that — and roughly half of it is information you never typed.

short answer

A lead record contains what you typed, what was observed around your submission, the consent evidence that makes it sellable, and the commercial fields added afterward — who bought it, how many times, and what was matched onto you later.

What you typed

The part you knew about.

first_name / last_name
Exactly as entered, typos preserved — typos are how duplicate records get spotted across files.
email
The primary key of the whole industry. Almost every match and merge runs off this field.
phone
Normalized and validated. Line type (mobile vs landline) is usually appended, because mobile is worth more.
address / city / state / zip
ZIP drives pricing more than most people expect — it proxies for property value and risk.
qualifying answers
Coverage type, loan amount, age band, homeowner status, credit range. These are what make you a "qualified" lead.

What was observed

You didn't type any of this. It was captured around you.

page_url
The exact page and step. Reveals which funnel you came through, even when the brand on the page is a shell.
submitted_at
Second-level timestamp. The clock the entire resale market runs on.
ip_address
Approximates location and network, and links your submissions together across sites.
user_agent / device
Browser, OS, device class. Used for fraud scoring and for matching you across records.
referrer / campaign
The ad, keyword, or affiliate that delivered you — how the buyer computes cost per acquisition.

What makes it sellable

The compliance layer. This is what turns data into a tradeable asset.

disclosure_text
The consent sentence displayed to you at submission.
consent_certificate
A TrustedForm or Jornaya token, often with a replay of your session. Held by the buyer, never sent to you.
trusted_form_url
Where the buyer retrieves that evidence if challenged in a TCPA dispute.
opt_in_flag
A boolean asserting you agreed. Downstream buyers frequently trust this field without re-verifying it.

What happens next

Appended after the sale — the fields that outlive your interest.

sold_to
The buyer or buyers. Plural far more often than people assume.
sale_type
Exclusive or shared. Shared is cheaper for the buyer and louder for you.
lead_age
Drives resale price. Fresh sells at a premium; aged gets bundled and dumped.
appended_fields
Everything matched onto you afterward from other datasets — often including data you never gave this company.
suppression_status
Whether you asked to be removed. Only enforced within the company holding this copy.

The asymmetry, in one sentence

Every party in that chain gets a copy of this record. You get a phone call. The consent certificate that proves what you agreed to is held by the people who bought you, is never sent to you, and can't be retrieved by you — and the policy governing it can be rewritten afterward without anyone telling you.

That's the specific thing worth fixing. Not the existence of the market — the fact that only one side of it keeps the receipt.

what you can do about it

Knowing how it works is step one. Step two is never typing your details into a form again.

PRYVC is a free profile that fills any form in one click, keeps a receipt of exactly what you shared and what the site's fine print said that day, re-checks those policies every day, and gives you a revoke button with a formal cease-contact notice behind it.

free forever for individuals · no data selling · every claim independently verifiable