·

API Terms

These API Terms govern your use of the Tomba API, keys, rate limits, and acceptable developer practices.

1. Scope

These API Terms govern your access to and use of the Tomba API, SDKs, official client libraries, webhooks, MCP server, and related developer tools (the "API"). They supplement the Terms of Service, which continue to apply in full. Capitalised terms not defined here have the meaning given there.

If you do not agree to these API Terms, do not use the API.

2. Licence

Subject to these API Terms and your subscription, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence to:

  • Access the API to build and operate applications that integrate with the Service
  • Use data returned by the API for your own internal business purposes, or to deliver functionality to your own end users where your plan permits

This licence does not permit you to make the API, or data obtained through it, available as a standalone data product, lookup service, or competing dataset.

3. API Keys and Credentials

Your API key and secret identify your account and are confidential. You must:

  • Store credentials securely and never commit them to source control, client-side code, mobile binaries, or any publicly accessible location
  • Never expose credentials in a browser, front-end application, or anything a third party can inspect
  • Rotate credentials immediately if they are exposed, and notify us at support@tomba.io
  • Not share, sell, sublicense, or transfer credentials

You are responsible for all activity carried out with your credentials, including usage and charges resulting from exposure or misuse. We may rotate or revoke credentials that we reasonably believe are compromised.

4. Rate Limits and Fair Use

API requests are subject to rate limits and credit allowances determined by your plan and published in our developer documentation. We may adjust limits to protect the stability, security, and availability of the Service.

You must:

  • Respect documented rate limits and honour 429 Too Many Requests responses
  • Implement exponential backoff with jitter on retry, and never retry in a tight loop
  • Cache responses where reasonable to avoid redundant calls
  • Use bulk endpoints for bulk workloads rather than issuing high-volume single requests
  • Not distribute requests across multiple accounts, keys, or IP addresses to circumvent limits

We may throttle, suspend, or terminate access that degrades the Service for others, regardless of whether a documented limit was exceeded.

5. Prohibited Developer Practices

In addition to the prohibitions in Section 5 of the Terms of Service, you must not:

  • Mirror, republish, resell, or redistribute API data, or expose it through a public endpoint, free tool, or open dataset
  • Build or contribute to a product that competes with Tomba, or use the API to benchmark for a competing service without our prior written consent
  • Store API data longer than necessary for your permitted use, or build a persistent shadow copy of our database
  • Use the API to enrich or resolve data about individuals in their personal capacity
  • Circumvent authentication, credit metering, or usage accounting
  • Present API data in a way that suggests Tomba endorses your product, or misrepresent the source or accuracy of the data
  • Use the API for any FCRA-regulated purpose described in Section 2 of the Terms of Service

6. Data Caching and Retention

You may cache API responses to improve performance and reduce redundant calls. You must:

  • Refresh or purge cached contact data at least every twelve (12) months, since contact data decays and stale data raises accuracy and legal risk
  • Delete cached data for any contact when we notify you that the contact has exercised a right of erasure, or when you receive such a request directly
  • Delete all cached and stored API data within ninety (90) days of terminating your subscription

7. Attribution

Where you display data obtained through the API to end users, you must attribute Tomba as the source unless your written agreement with us says otherwise. Use of our name and logo must follow our brand guidelines and must not imply partnership, endorsement, or certification.

8. Changes to the API

We version the API and aim to avoid breaking changes within a major version. Where we must make a breaking change or deprecate an endpoint, we will:

  • Give at least ninety (90) days' notice by email to the account owner and in our developer changelog
  • Maintain the deprecated version during that period, except where a shorter timeline is required for security, legal, or third-party reasons

Non-breaking additions — new endpoints, new optional fields, new enum values — may ship without notice. Your integration must tolerate unrecognised fields and values.

9. Monitoring

We may monitor API usage to enforce limits, investigate abuse, meet legal obligations, and improve the Service. This includes logging request metadata such as endpoint, timestamp, status, and volume. Handling of this data is described in the Privacy Policy.

10. Availability and Support

Unless a separate service level agreement applies, the API is provided without any uptime commitment and as is, subject to the disclaimers in Section 13 of the Terms of Service. We may perform maintenance that temporarily interrupts availability and will give advance notice of planned maintenance where practicable.

Support is provided at the level included in your plan, through support@tomba.io.

11. Suspension

We may suspend or revoke API access immediately, with or without notice, where we reasonably believe there is: a security risk or compromised credential; a violation of these API Terms or the Terms of Service; usage that threatens the stability of the Service; non-payment; or a legal requirement to do so.

Where practicable and not prohibited, we will notify you and give an opportunity to cure a curable breach.

12. Contact

Developer support: support@tomba.ioLegal notices: legal@tomba.ioPrivacy and data subject requests: privacy@tomba.io

Documentation is available at docs.tomba.io.

Start free trial

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.

  • 25 free searches every month
  • Under 5% bounce rate
  • GDPR Compliant
4.7/5 from 150 reviews