·

Privacy Policy

How Tomba collects, uses, shares, and protects personal data across our email finder, verification, enrichment, and API products, and the rights you have over it.

1. Our Commitment to Privacy

Tomba builds tools that find and verify business contact information. That work only holds up if the data behind it is handled lawfully. This policy explains what we collect, why we collect it, who we share it with, and how you control it.

It applies to everyone: customers who use our products, visitors to our website, and individuals whose business contact details appear in our database. If you are in the third group, Section 20 is the part you want.

2. Who We Are

Tomba Technology Web Service LLC is the controller of the personal data described in this policy.

2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States

PurposeContact
Privacy questions and data subject requestsprivacy@tomba.io
Removal from our databaseClaim your profile or privacy@tomba.io
Legal noticeslegal@tomba.io
General supportsupport@tomba.io

3. Services Covered

This policy applies to every Tomba product and surface:

Finding contacts — Email Finder, Domain Search, Author Finder, LinkedIn Finder, Sales Navigator Finder, Phone Finder, Catch-All Email Finder, Reverse Email Lookup

Verifying contacts — Email Verifier, Catch-All Email Verifier, Phone Validator

Enrichment and company data — Email Enrichment, Person Enrichment, Company Enrichment, Company Search and Reveal, Technology Lookup, Social Links

Working at scale — Bulk Tasks, CSV enrichment, Database downloads, Lead and list management

Ways to reach us — REST API, MCP Server, CLI, official SDKs, Chrome, Firefox and Edge extensions, Google Sheets add-on, Microsoft Excel add-in, Airtable

Integrations — HubSpot, Pipedrive, Zapier, Make, n8n and other connected platforms

The public website — tomba.io, including free tools, directories and documentation

4. The Two Roles We Play

This distinction matters, because your rights differ depending on which one applies.

Tomba as controller. We independently compile business contact information from publicly available sources. We decide what to collect and why. For that database, we are the controller, and this policy governs it.

Tomba as processor. When a customer uploads a list to verify or enrich, we process that data on their instructions, not our own. For that data the customer is the controller and we are the processor. Our obligations there are set out in the Data Processing Addendum.

If a customer used our data to contact you, they became an independent controller of that copy. We can remove you from our database, but we cannot delete records already exported by a customer. You would need to contact them directly.

5. Information We Collect

When you visit our website

IP address, browser type and version, device and operating system, referring URL, pages viewed, time spent, and approximate location derived from IP.

When you create an account

Name, business email address, company name, job title, password hash, and billing details. Payment card data goes directly to Stripe and never reaches our servers.

When you use our services

Search queries, domains and names looked up, uploaded files, API request metadata, credits consumed, feature usage, and error logs.

When you contact support

Your message, contact details, and any attachments or account context you provide.

Publicly available web data

Business contact details gathered from company websites, public professional profiles, published articles, press releases, public directories, job postings and similar sources: name, business email address, business phone number, job title, employer, department, seniority, public profile URLs, and the source URL where each item was found.

We do not collect personal email addresses, home addresses, personal phone numbers, or any data behind a login or paywall.

Categories at a glance

CategoryExamplesSourceWhy we hold it
IdentifiersName, business email, account IDYou, public webDeliver the service, discovery results
Professional informationJob title, employer, seniorityPublic webEnrichment and filtering
Commercial informationPlan, credits used, invoicesYou, StripeBilling and support
Internet activityPages viewed, API calls, logsAutomaticSecurity, debugging, product improvement
Approximate locationCountry and region from IPAutomaticFraud prevention, localisation

Where the GDPR or UK GDPR applies, we rely on the following:

ProcessingLegal basis
Providing the service you signed up forContract (Art. 6(1)(b))
Billing, invoicing and collectionsContract and legal obligation
Compiling business contact dataLegitimate interests (Art. 6(1)(f)) — enabling lawful B2B outreach
Security, fraud prevention, abuse handlingLegitimate interests
Product analytics and improvementLegitimate interests
Marketing emails to prospects and customersConsent, or legitimate interests where permitted
Non-essential cookiesConsent
Responding to legal processLegal obligation

Where we rely on legitimate interests, we have carried out a balancing assessment and limited collection to business contact data in a professional context. You can object at any time under Section 18, and we will stop unless we have compelling grounds that override your interests.

7. How We Use Your Data

  • Service delivery — running searches, verification, enrichment and bulk jobs
  • Account management — authentication, credits, plan limits, invoices
  • Business contact discovery — building and maintaining the contact database
  • Support — answering your questions and investigating issues
  • Security and fraud prevention — detecting credential abuse, scraping, payment fraud
  • Product improvement — aggregated, de-identified usage analysis
  • Communications — service notices always; marketing only where you have opted in or the law allows

We do not use your search queries or uploaded files to train models sold to third parties.

8. Sensitive Personal Information

We do not intentionally collect special category data under Article 9 GDPR or sensitive personal information under US state law. That includes racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation, precise geolocation, and government identifiers.

We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA. If you believe such data has reached our database, tell us at privacy@tomba.io and we will remove it.

9. Children's Privacy

Our services are for business use by adults. We do not knowingly collect data from anyone under 18, and our database is limited to professional contact details. If you believe a minor's data is present, contact privacy@tomba.io and we will delete it promptly.

10. Cookies and Tracking

We use strictly necessary cookies to run the site and keep you signed in. We also use analytics and performance cookies where you consent. Full detail, including each cookie's purpose and lifetime, is in our Cookie Policy.

Global Privacy Control. We honour the GPC browser signal as a valid opt-out of sale and sharing for jurisdictions that recognise it. We do not currently respond to Do Not Track headers, which have no agreed standard.

11. Do We Sell or Share Personal Information?

Under US state privacy laws, terms like "sell" and "share" are defined broadly. They can cover disclosures that involve no money at all.

We sell personal information as those laws define it. Our business is providing business contact data to customers, and making that data available in exchange for payment falls within the statutory definition of a sale.

We do not:

  • Sell or share sensitive personal information
  • Sell data about anyone we know to be under 18
  • Share personal information for cross-context behavioural advertising

You can opt out at any time, whether or not you are a Tomba customer, and we will not discriminate against you for doing so. Use the Claim tool, send a GPC signal, or email privacy@tomba.io. Opting out adds you to a suppression list so the data is not re-collected later.

12. Who We Disclose Data To

CategoryProvidersWhat they receive
Hosting and infrastructureDigitalOcean, CloudflareService data in transit and at rest
Security and CDNCloudflare WAF, Cloudflare TurnstileIP address, request metadata
PaymentsStripeBilling details, transaction data
Email deliverySendGridEmail address, message content
AnalyticsGoogle Analytics, Microsoft ClarityUsage and device data
Internal collaborationGoogle Workspace, Slack, GitHub, TrelloSupport and operational context

Each provider is bound by contract to process data only on our instructions. A current sub-processor list is available on request from privacy@tomba.io.

We may also disclose data where required by law, to enforce our Terms of Service, to protect rights and safety, or in connection with a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy.

13. International Transfers

Where personal data originating in the EEA, United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and, for Switzerland, the equivalent recognised safeguards. We carry out transfer impact assessments where required. Details are in the Data Processing Addendum.

14. Data Retention

DataRetention
Active account dataWhile the account is active, plus 3 years of inactivity
Deleted accountsMost data removed within days; remaining artefacts within 3 months
Billing recordsAs required by tax and accounting law, typically 7 years
Security and access logsUp to 12 months
Support correspondence3 years from last contact
Public business contact dataWhile the public source remains live; re-verified regularly and removed when the source disappears
Suppression listIndefinitely, so an opt-out stays honoured

15. Data Security

We apply encryption in transit and at rest, role-based access control, network segmentation, regular vulnerability scanning and penetration testing. Full detail is in our Security Policy.

Primary data storage and processing take place within the European Union.

No system is perfectly secure. If a breach affects your personal data and creates a likely risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and in any case within the periods the law requires.

16. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

Our products do score and classify data — for example, an email verification confidence score or a predicted email pattern. These are informational outputs about a data point, not decisions about a person, and a human always chooses what to do with them.

17. Your Privacy Rights

RightWhat it means
AccessConfirm whether we process your data and obtain a copy
KnowLearn the categories, sources, purposes and recipients
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your personal data
RestrictionBlock processing in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests, or to direct marketing at any time
Opt out of sale or sharingDirect us to stop selling or sharing your data
Limit use of sensitive dataRestrict use of sensitive personal information
Withdraw consentWithdraw consent where processing relies on it
Non-discriminationExercise any right without being penalised or charged more
AppealAsk us to reconsider a refused request

18. Exercising Your Rights

If you have an account — sign in to view, update or permanently delete your data.

If your details are in our database — use the Claim tool for the fastest route, or email privacy@tomba.io.

Any request — email privacy@tomba.io. We will confirm receipt and respond within 45 days (US state laws) or one month (GDPR and UK GDPR). Where a request is complex we may extend once, and will tell you why before we do.

Verification. We ask for enough information to confirm the request is genuinely yours. For database records that usually means proving control of the email address concerned. We will not ask for more than necessary, and we use verification data only to process the request.

Authorised agents. An agent may act for you with written authorisation. We may still contact you directly to confirm.

Appeals. If we decline a request, we will explain why. You may appeal to privacy@tomba.io with "Appeal" in the subject line, and we will respond within 45 days.

Complaints. You may lodge a complaint with your local supervisory authority or, in California, the California Privacy Protection Agency. We would rather hear from you first.

19. Jurisdiction-Specific Notices

EEA, United Kingdom and Switzerland. Sections 6, 13 and 17 set out our legal bases, transfer safeguards and your rights. You may complain to your national data protection authority.

California. Additional CCPA and CPRA disclosures are in our Privacy Notice for California Residents. Sections 11, 17 and 18 cover the right to opt out of sale, the right to limit sensitive data use, and non-discrimination.

Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Residents of these states have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling. Exercise them under Section 18. Appeal rights apply where the state provides them.

Nevada. To request that we do not sell your covered information, email privacy@tomba.io.

Canada. You may access and correct your data and complain to the Office of the Privacy Commissioner of Canada.

20. Removing Your Data From Our Database

If your business contact details appear in Tomba and you want them gone, here is exactly what happens.

  1. Submit a request through Claim or email privacy@tomba.io
  2. We confirm the request relates to you
  3. We delete the record from our index
  4. We add it to a suppression list, so a later crawl of the same public source does not bring it back

There is no charge, no account required, and no obligation to explain why.

One limit worth stating plainly: we cannot recall data a customer already exported before your request. We will tell you the date we removed the record so you can approach any recipient directly.

21. Data Broker Registration

Some jurisdictions require businesses that sell data about individuals with whom they have no direct relationship to register as data brokers. Where that duty applies to us, we register and keep the entry current. Contact privacy@tomba.io for our registration details in a given jurisdiction.

22. Changes to This Policy

We may update this policy. Changes take effect when posted, with the date at the top revised. For material changes affecting how we use data you have already given us, we will give at least 30 days' notice by email or in-product notice before they take effect.

23. Contact Us

Tomba Technology Web Service LLC 2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States

Privacy and data subject requests: privacy@tomba.ioLegal notices: legal@tomba.ioGeneral support: support@tomba.io

Start free trial

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.

  • 25 free searches every month
  • Under 5% bounce rate
  • GDPR Compliant
4.7/5 from 150 reviews