Guides
Privacy and security
What is sent to Tomba
- Only the values you pass to a procedure: the columns you name (domains, names, emails, URLs, phone numbers) or the filters of a company search. The rest of your table never leaves Snowflake.
- Only to
api.tomba.io, over HTTPS. The app's network rule allows no other destination, and it works only after you approve the Tomba API connection. - Usage counts for billing: run id, tool, number of rows and hits, credits and amount charged. Never your data.
What stays in your account
- Result tables, in the app's
resultsschema, readable by the roles you grantapp_public. - Run history, settings, the cache and schedules, inside the app.
- The app's Tomba credentials, in a private schema that no role can read. They can only call Tomba's lookup endpoints.
Tomba doesn't keep a copy of your tables.
Access control
- The app reads only the tables you
GRANTit, and you can revoke a grant at any time. - People use the app through its roles,
app_publicandapp_admin(see Installation). - Background runs and schedules run as the app, on serverless tasks, using the same grants.
Legal
- Terms of Service
- Privacy Policy
- Data Processing Addendum
- GDPR
- Security Policy
- Acceptable Use Policy
- Privacy Notice for California Residents
Last modified on