Acceptable Use Policy 

1. Scope and Application
This Acceptable Use Policy (the "Policy") governs how you may use the Tomba website, applications, browser extensions, integrations, and API (together, the "Service"), and how you may use any data obtained through them.
This Policy expands on Section 5 of the Terms of Service and forms part of your agreement with us. Where the API is concerned, the API Terms also apply. If this Policy and the Terms of Service ever appear to conflict, the Terms of Service take precedence. Capitalised terms not defined here have the meaning given there.
Violating this Policy is a material breach of your agreement. If you do not agree to this Policy, do not use the Service.
2. Who This Policy Applies To
This Policy applies to everyone who accesses the Service, including:
- Account owners, administrators, and every individual using a seat on your account
- Developers and systems integrating through the API, SDKs, or MCP server
- Users of our browser extensions, spreadsheet add-ons, and other integrations
- Anyone acting on your behalf, including contractors, agencies, and affiliates
You are responsible for the acts and omissions of everyone using the Service through your account, and for ensuring they understand and follow this Policy.
3. Prohibited Uses
You must not, and must not permit any third party to, use the Service to:
Communications and outreach
- Send unsolicited bulk email, spam, or any commercial message that fails to meet applicable anti-spam law
- Send phishing, pretexting, social engineering, fraud, or any deceptive or misleading communication
- Harass, threaten, stalk, dox, defame, or intimidate any person
- Continue contacting a person who has opted out, unsubscribed, or asked not to be contacted
Data and resale
- Reproduce, sell, resell, sublicense, rent, lease, or redistribute the Service or its data
- Build, train, or contribute to a competing product, dataset, or lookup service
- Expose Service data through a public endpoint, free tool, open dataset, or scraped mirror
- Retain a persistent shadow copy of our database beyond what your permitted use requires
Targeting and sensitive data
- Compile data about individuals for purposes unrelated to legitimate business-to-business outreach
- Target individuals in their personal capacity, or seek personal (non-business) contact details
- Collect or infer special categories of personal data, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation
- Use the Service for any purpose regulated by the Fair Credit Reporting Act (FCRA), including eligibility determinations for credit, insurance, employment, housing, or tenancy
- Use the Service to discriminate against any person on a basis prohibited by law
Technical
- Use bots, crawlers, or scrapers against the Service outside of the documented API
- Circumvent, disable, or exceed rate limits, credit allowances, usage quotas, or access controls
- Distribute requests across multiple accounts, keys, or IP addresses to evade limits
- Reverse engineer, decompile, or attempt to derive source code, algorithms, or underlying data structures
- Transmit malicious code, or content designed to interrupt, damage, or limit the Service
- Probe, scan, or test the vulnerability of the Service except under our Security Policy
- Share, sell, or transfer login credentials or API keys, or allow multiple individuals to use a single seat
- Modify, hack, or misrepresent your association with Tomba, or remove any proprietary notice
Legal
- Violate any applicable law, including data protection, anti-spam, marketing, export control, and sanctions law
- Infringe the intellectual property, privacy, or publicity rights of any person
4. Outreach and Anti-Spam Obligations
You are solely responsible for every message you send to a contact discovered through the Service. Tomba does not send your outreach and is not the sender, controller, or author of it.
In connection with any such communication, you must:
- Establish and maintain a valid lawful basis for processing under the GDPR, UK GDPR, and any other applicable data protection law, and complete any legitimate interests assessment required
- Comply with all applicable marketing and anti-spam law, including the CAN-SPAM Act (US), CASL (Canada), the ePrivacy Directive and its national implementations (EU), and the PECR (UK)
- Provide accurate sender identification, a valid physical postal address, and a truthful subject line
- Include a functioning, conspicuous unsubscribe mechanism in every commercial message
- Honour opt-out and unsubscribe requests promptly, and suppress those contacts from future outreach
- Provide any privacy notice required of you as a data controller, including notice at first contact where Article 14 GDPR requires it
- Not represent or imply that Tomba endorses, sponsors, sent, or is responsible for your communications
Some jurisdictions require prior consent for unsolicited commercial email to individuals. Verifying what applies in the jurisdictions you contact is your responsibility, not ours.
5. Data Protection, Opt-Outs and Suppression
You act as an independent data controller for the personal data you obtain through the Service, and you determine the purposes and means of your own processing.
You must:
- Process personal data only for the purposes permitted by your agreement and applicable law
- Keep personal data accurate and refresh or purge contact data at least every twelve (12) months
- Honour data subject requests you receive directly, within the period applicable law requires
- Delete any contact from your systems when we notify you that they have exercised a right of erasure, and suppress them from further outreach
- Maintain appropriate technical and organisational security measures for the data you hold
- Delete or return personal data obtained through the Service when your subscription ends, in line with the retention rules in the API Terms
Any individual whose personal data appears in the Service may request access, correction, or erasure by contacting privacy@tomba.io. Where the request is valid, we remove the data and add it to a suppression list to prevent re-collection. See the Privacy Policy and our GDPR commitments for detail.
6. API and Account Rules
- Keep API keys and secrets confidential; never commit them to source control, client-side code, or any publicly accessible location
- Rotate credentials immediately if exposed, and notify support@tomba.io
- Respect documented rate limits, honour
429 Too Many Requests, and retry with exponential backoff and jitter - Use bulk endpoints for bulk workloads rather than issuing high-volume single requests
- One seat is for one named individual. Seats must not be shared, pooled, or rotated between people
- Do not create multiple accounts to obtain additional free credits or evade a suspension
You are responsible for all activity carried out with your credentials, including usage and charges resulting from their exposure or misuse.
7. Security and Platform Integrity
You must not interfere with the integrity, security, or performance of the Service or the infrastructure it runs on. This includes denial-of-service activity, attempts to gain unauthorised access to any account or system, and any action that degrades the Service for other customers.
If you discover a security vulnerability, report it under our Security Policy rather than exploiting it. We do not pursue good-faith security research conducted in line with that policy.
8. Content Standards
Any content you upload, submit, or transmit through the Service — including bulk lists, file uploads, and enrichment inputs — must be lawful, must be data you have the right to process, and must not contain malicious code. You are responsible for having a lawful basis to upload any personal data you submit for verification or enrichment.
9. Monitoring and Enforcement
We may monitor use of the Service to enforce limits, investigate suspected abuse, meet legal obligations, and protect the Service and its users. This includes logging request metadata such as endpoint, timestamp, status, and volume, as described in the Privacy Policy.
Where we reasonably believe this Policy has been violated, we may take any of the following steps, proportionate to the circumstances:
- Throttle or rate-limit your usage
- Block IP addresses or specific request patterns
- Remove or disable access to offending content
- Suspend individual seats, API keys, or the entire account
- Terminate your agreement in accordance with the Terms of Service
- Report the activity to law enforcement or another competent authority where the law requires or permits it
Where practicable and not prohibited, we will give notice and an opportunity to cure a curable breach within ten (10) days. We may act immediately and without notice where there is a security risk, a risk of harm to a person, a threat to the stability of the Service, or a legal requirement to do so.
Enforcement is at our discretion. Not acting on a violation does not waive our right to act on it, or on any other violation, later.
10. Reporting a Violation
If you believe someone is using Tomba in breach of this Policy, tell us and we will investigate.
- Abuse, spam, and general reports: support@tomba.io
- Security vulnerabilities and incidents: security@tomba.io
- Privacy, data removal, and data subject requests: privacy@tomba.io
Please include the account, domain, or message concerned, plus any headers or evidence that will help us investigate. We do not disclose the outcome of investigations to third parties.
11. Changes to This Policy
We may update this Policy as the Service, the threat landscape, and the law evolve. Material changes will be announced in line with Section 22 of the Terms of Service, and the revision date at the top of this page will change. Continuing to use the Service after a change takes effect means you accept the updated Policy.
12. Contact
Abuse reports and general support: support@tomba.ioLegal notices: legal@tomba.ioPrivacy and data subject requests: privacy@tomba.ioSecurity: security@tomba.io
Mail: Tomba Technology Web Service LLC 2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States