Privacy Policy 

1. Our Commitment to Privacy
Tomba builds tools that find and verify business contact information. That work only holds up if the data behind it is handled lawfully. This policy explains what we collect, why we collect it, who we share it with, and how you control it.
It applies to everyone: customers who use our products, visitors to our website, and individuals whose business contact details appear in our database. If you are in the third group, Section 20 is the part you want.
2. Who We Are
Tomba Technology Web Service LLC is the controller of the personal data described in this policy.
2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States
| Purpose | Contact |
|---|---|
| Privacy questions and data subject requests | privacy@tomba.io |
| Removal from our database | Claim your profile or privacy@tomba.io |
| Legal notices | legal@tomba.io |
| General support | support@tomba.io |
3. Services Covered
This policy applies to every Tomba product and surface:
Finding contacts — Email Finder, Domain Search, Author Finder, LinkedIn Finder, Sales Navigator Finder, Phone Finder, Catch-All Email Finder, Reverse Email Lookup
Verifying contacts — Email Verifier, Catch-All Email Verifier, Phone Validator
Enrichment and company data — Email Enrichment, Person Enrichment, Company Enrichment, Company Search and Reveal, Technology Lookup, Social Links
Working at scale — Bulk Tasks, CSV enrichment, Database downloads, Lead and list management
Ways to reach us — REST API, MCP Server, CLI, official SDKs, Chrome, Firefox and Edge extensions, Google Sheets add-on, Microsoft Excel add-in, Airtable
Integrations — HubSpot, Pipedrive, Zapier, Make, n8n and other connected platforms
The public website — tomba.io, including free tools, directories and documentation
4. The Two Roles We Play
This distinction matters, because your rights differ depending on which one applies.
Tomba as controller. We independently compile business contact information from publicly available sources. We decide what to collect and why. For that database, we are the controller, and this policy governs it.
Tomba as processor. When a customer uploads a list to verify or enrich, we process that data on their instructions, not our own. For that data the customer is the controller and we are the processor. Our obligations there are set out in the Data Processing Addendum.
If a customer used our data to contact you, they became an independent controller of that copy. We can remove you from our database, but we cannot delete records already exported by a customer. You would need to contact them directly.
5. Information We Collect
When you visit our website
IP address, browser type and version, device and operating system, referring URL, pages viewed, time spent, and approximate location derived from IP.
When you create an account
Name, business email address, company name, job title, password hash, and billing details. Payment card data goes directly to Stripe and never reaches our servers.
When you use our services
Search queries, domains and names looked up, uploaded files, API request metadata, credits consumed, feature usage, and error logs.
When you contact support
Your message, contact details, and any attachments or account context you provide.
Publicly available web data
Business contact details gathered from company websites, public professional profiles, published articles, press releases, public directories, job postings and similar sources: name, business email address, business phone number, job title, employer, department, seniority, public profile URLs, and the source URL where each item was found.
We do not collect personal email addresses, home addresses, personal phone numbers, or any data behind a login or paywall.
Categories at a glance
| Category | Examples | Source | Why we hold it |
|---|---|---|---|
| Identifiers | Name, business email, account ID | You, public web | Deliver the service, discovery results |
| Professional information | Job title, employer, seniority | Public web | Enrichment and filtering |
| Commercial information | Plan, credits used, invoices | You, Stripe | Billing and support |
| Internet activity | Pages viewed, API calls, logs | Automatic | Security, debugging, product improvement |
| Approximate location | Country and region from IP | Automatic | Fraud prevention, localisation |
6. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on the following:
| Processing | Legal basis |
|---|---|
| Providing the service you signed up for | Contract (Art. 6(1)(b)) |
| Billing, invoicing and collections | Contract and legal obligation |
| Compiling business contact data | Legitimate interests (Art. 6(1)(f)) — enabling lawful B2B outreach |
| Security, fraud prevention, abuse handling | Legitimate interests |
| Product analytics and improvement | Legitimate interests |
| Marketing emails to prospects and customers | Consent, or legitimate interests where permitted |
| Non-essential cookies | Consent |
| Responding to legal process | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and limited collection to business contact data in a professional context. You can object at any time under Section 18, and we will stop unless we have compelling grounds that override your interests.
7. How We Use Your Data
- Service delivery — running searches, verification, enrichment and bulk jobs
- Account management — authentication, credits, plan limits, invoices
- Business contact discovery — building and maintaining the contact database
- Support — answering your questions and investigating issues
- Security and fraud prevention — detecting credential abuse, scraping, payment fraud
- Product improvement — aggregated, de-identified usage analysis
- Communications — service notices always; marketing only where you have opted in or the law allows
We do not use your search queries or uploaded files to train models sold to third parties.
8. Sensitive Personal Information
We do not intentionally collect special category data under Article 9 GDPR or sensitive personal information under US state law. That includes racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation, precise geolocation, and government identifiers.
We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA. If you believe such data has reached our database, tell us at privacy@tomba.io and we will remove it.
9. Children's Privacy
Our services are for business use by adults. We do not knowingly collect data from anyone under 18, and our database is limited to professional contact details. If you believe a minor's data is present, contact privacy@tomba.io and we will delete it promptly.
10. Cookies and Tracking
We use strictly necessary cookies to run the site and keep you signed in. We also use analytics and performance cookies where you consent. Full detail, including each cookie's purpose and lifetime, is in our Cookie Policy.
Global Privacy Control. We honour the GPC browser signal as a valid opt-out of sale and sharing for jurisdictions that recognise it. We do not currently respond to Do Not Track headers, which have no agreed standard.
11. Do We Sell or Share Personal Information?
Under US state privacy laws, terms like "sell" and "share" are defined broadly. They can cover disclosures that involve no money at all.
We sell personal information as those laws define it. Our business is providing business contact data to customers, and making that data available in exchange for payment falls within the statutory definition of a sale.
We do not:
- Sell or share sensitive personal information
- Sell data about anyone we know to be under 18
- Share personal information for cross-context behavioural advertising
You can opt out at any time, whether or not you are a Tomba customer, and we will not discriminate against you for doing so. Use the Claim tool, send a GPC signal, or email privacy@tomba.io. Opting out adds you to a suppression list so the data is not re-collected later.
12. Who We Disclose Data To
| Category | Providers | What they receive |
|---|---|---|
| Hosting and infrastructure | DigitalOcean, Cloudflare | Service data in transit and at rest |
| Security and CDN | Cloudflare WAF, Cloudflare Turnstile | IP address, request metadata |
| Payments | Stripe | Billing details, transaction data |
| Email delivery | SendGrid | Email address, message content |
| Analytics | Google Analytics, Microsoft Clarity | Usage and device data |
| Internal collaboration | Google Workspace, Slack, GitHub, Trello | Support and operational context |
Each provider is bound by contract to process data only on our instructions. A current sub-processor list is available on request from privacy@tomba.io.
We may also disclose data where required by law, to enforce our Terms of Service, to protect rights and safety, or in connection with a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy.
13. International Transfers
Where personal data originating in the EEA, United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and, for Switzerland, the equivalent recognised safeguards. We carry out transfer impact assessments where required. Details are in the Data Processing Addendum.
14. Data Retention
| Data | Retention |
|---|---|
| Active account data | While the account is active, plus 3 years of inactivity |
| Deleted accounts | Most data removed within days; remaining artefacts within 3 months |
| Billing records | As required by tax and accounting law, typically 7 years |
| Security and access logs | Up to 12 months |
| Support correspondence | 3 years from last contact |
| Public business contact data | While the public source remains live; re-verified regularly and removed when the source disappears |
| Suppression list | Indefinitely, so an opt-out stays honoured |
15. Data Security
We apply encryption in transit and at rest, role-based access control, network segmentation, regular vulnerability scanning and penetration testing. Full detail is in our Security Policy.
Primary data storage and processing take place within the European Union.
No system is perfectly secure. If a breach affects your personal data and creates a likely risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and in any case within the periods the law requires.
16. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Our products do score and classify data — for example, an email verification confidence score or a predicted email pattern. These are informational outputs about a data point, not decisions about a person, and a human always chooses what to do with them.
17. Your Privacy Rights
| Right | What it means |
|---|---|
| Access | Confirm whether we process your data and obtain a copy |
| Know | Learn the categories, sources, purposes and recipients |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your personal data |
| Restriction | Block processing in certain circumstances |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests, or to direct marketing at any time |
| Opt out of sale or sharing | Direct us to stop selling or sharing your data |
| Limit use of sensitive data | Restrict use of sensitive personal information |
| Withdraw consent | Withdraw consent where processing relies on it |
| Non-discrimination | Exercise any right without being penalised or charged more |
| Appeal | Ask us to reconsider a refused request |
18. Exercising Your Rights
If you have an account — sign in to view, update or permanently delete your data.
If your details are in our database — use the Claim tool for the fastest route, or email privacy@tomba.io.
Any request — email privacy@tomba.io. We will confirm receipt and respond within 45 days (US state laws) or one month (GDPR and UK GDPR). Where a request is complex we may extend once, and will tell you why before we do.
Verification. We ask for enough information to confirm the request is genuinely yours. For database records that usually means proving control of the email address concerned. We will not ask for more than necessary, and we use verification data only to process the request.
Authorised agents. An agent may act for you with written authorisation. We may still contact you directly to confirm.
Appeals. If we decline a request, we will explain why. You may appeal to privacy@tomba.io with "Appeal" in the subject line, and we will respond within 45 days.
Complaints. You may lodge a complaint with your local supervisory authority or, in California, the California Privacy Protection Agency. We would rather hear from you first.
19. Jurisdiction-Specific Notices
EEA, United Kingdom and Switzerland. Sections 6, 13 and 17 set out our legal bases, transfer safeguards and your rights. You may complain to your national data protection authority.
California. Additional CCPA and CPRA disclosures are in our Privacy Notice for California Residents. Sections 11, 17 and 18 cover the right to opt out of sale, the right to limit sensitive data use, and non-discrimination.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Residents of these states have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling. Exercise them under Section 18. Appeal rights apply where the state provides them.
Nevada. To request that we do not sell your covered information, email privacy@tomba.io.
Canada. You may access and correct your data and complain to the Office of the Privacy Commissioner of Canada.
20. Removing Your Data From Our Database
If your business contact details appear in Tomba and you want them gone, here is exactly what happens.
- Submit a request through Claim or email privacy@tomba.io
- We confirm the request relates to you
- We delete the record from our index
- We add it to a suppression list, so a later crawl of the same public source does not bring it back
There is no charge, no account required, and no obligation to explain why.
One limit worth stating plainly: we cannot recall data a customer already exported before your request. We will tell you the date we removed the record so you can approach any recipient directly.
21. Data Broker Registration
Some jurisdictions require businesses that sell data about individuals with whom they have no direct relationship to register as data brokers. Where that duty applies to us, we register and keep the entry current. Contact privacy@tomba.io for our registration details in a given jurisdiction.
22. Changes to This Policy
We may update this policy. Changes take effect when posted, with the date at the top revised. For material changes affecting how we use data you have already given us, we will give at least 30 days' notice by email or in-product notice before they take effect.
23. Contact Us
Tomba Technology Web Service LLC 2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States
Privacy and data subject requests: privacy@tomba.ioLegal notices: legal@tomba.ioGeneral support: support@tomba.io
Privacy Notice for California Residents
This California Privacy Notice supplements Tomba's Privacy Policy for California residents, covering CCPA rights and disclosures.
Quality Policy
Tomba's quality policy outlines our commitment to delivering high-quality email finder services and continuous improvement.