TomaDash

All-in-one dispatching

TomaDash

Privacy Policy

Effective September 14, 2026. Questions: support@tomafreight.com

1. Who we are

TomaDash (https://tomadash.com) is a carrier-dispatching product operated by TomaFreight (“we,” “us,” or “our”). This Privacy Policy explains what we collect when you visit the site, start as a guest, create an account, subscribe, join Toma-Everywhere, or connect tools such as CloudTalk or your own Gmail.

Contact: support@tomafreight.com.

2. What this covers

This Policy covers https://tomadash.com and related pages we operate, including Log in, Create account, Forgot password, email verification, Subscribe (tomadash.com/landing), Teams (tomadash.com/teams), Marketplace (tomadash.com/marketplace), Community (tomadash.com/community), the preference center (tomadash.com/preferences), Toma-Everywhere (tomadash.com/everywhere), share links, and the in-app workspace (Import Leads, Prospecting, Opportunities & Trials, Customers, Sequence, Follow-ups, Automations, Dashboard, Settings, Team, Leaderboard, and Tomaboy). It also covers the internal operator console described in section 7.

It also covers people we contact about TomaDash who never signed up. If you got an email from us and want to know what we hold, read section 9.

It does not control third-party sites we link out to (Google, Microsoft, Stripe, CloudTalk, Hostinger, DAT One, FMCSA SAFER, DotLookup, OpenAI and the web-search provider behind Tomaboy, and similar). Their own policies apply when you use them.

3. Information we collect

Account. Email, display name (from the part of the email before @, or from Google), password hash (we do not store the raw password), Google account identifier if you use Sign in with Google, email-verified flag, plan (Free or Pro), Stripe customer and subscription ids if you subscribe, last seen time, active days, import counts, optional CloudTalk keys you paste in Settings, email-verification code hash and expiry if you signed up with email, Teams membership if you join or own a team, and — if you click Connect Gmail or Connect Outlook in Settings → Your inbox — that inbox address plus an encrypted refresh token so we can send mail you start in the app.

Profile photo. If you set an account photo we store the image itself on your account, compressed, so it can show in the account menu. Pick a JPEG, PNG, or WebP under 8 MB. It is visible to you and, on a team, to the owner in Team; replace or remove it in Settings.

Time in the app. While a workspace tab is open the browser sends a periodic heartbeat. We add it up into total time in the app and the list of days you were active. We use it to know whether an account is really being used (and, on a team, to fill the Leaderboard). It is a duration and a set of dates — not keystrokes, not screen contents, and not a recording of your session.

Product journey. After you are signed in, the workspace records which screen you opened (Prospecting, Settings, and so on), when you switch Cream/Black, when you open Tomaboy, when you expand or tap Start annual on Training’s 1:1 Coaching nudge, and product notes you send through Tomaboy. This is first-party product analytics so we can see where the app is slow or unused. It is not an advertising pixel, not a session recording, and not keystrokes. Marketing visits still use the separate toma_vid count in section 4.

Product feedback. If you tap Feedback in Tomaboy or type a product note there, we store the text, your account email, and the screen you were on so the operator can read it in the internal console.

Guest sessions. If you choose “Get started” without an account, we create a guest pipeline tied to a session cookie. Guest emails look like guest-…@guest.local and are not a real inbox. Guest work is lost if that cookie is cleared unless you create an account on the same session first.

Your pipeline. Carriers and related records you add or import: company name, USDOT, MC, phone, city, state, ZIP, equipment, cargo, authority dates, pipeline tag (Prospect / Opportunity / Trial / Customer), labels, notes, call outcomes, follow-up times, sequence order, DAT load-search boards, brokers and loads, activity history, call debriefs and coaching notes, workspace settings, and files you upload on a customer (MC authority letter, W-9, insurance, special permits — 10 MB max per file). Uploaded files are served only to your own signed-in session.

Bringing a book in. You can restore a book from a TomaDash JSON backup, paste or point us at a JSON feed of carrier rows on the Scraper page, or POST carrier and scraper rows to our ingest endpoints with your session or an ingest token. Whatever you send lands in your own book or review list. You are responsible for having the right to hold those contacts.

Scores we calculate. Some numbers on a record are computed, not typed. A carrier can carry a risk score that comes from DotLookup, a “heat” value we derive from public FMCSA attributes on hot-lead rows, and companies on our own prospect list (section 9) get a 0–100 fit score from whether a business email, phone, website, and social handle were published and what kind of business it is. These rank a list for a human to work. They are not credit, insurance, or employment decisions, and nothing is decided about a person automatically — a dispatcher still makes the call.

Lookups you run. When you search Import Leads we query DotLookup and, as a fallback, public FMCSA / SAFER records. Those queries include the filters or USDOT / MC / name you typed. Results are stored in your review list and, if you add them, in your pipeline.

Calls. If you connect CloudTalk, we receive call metadata (number, direction, duration, recording link, agent name, timestamps) via webhook or API sync and attach matching numbers to carrier files. TomaDash does not place the PSTN call itself. Recording audio stays with CloudTalk: we store the link and play it from there, so we never hold the audio file, and deleting a recording in CloudTalk removes what the link plays. Whether a call may be recorded at all, and who has to be told, is on you — see the Terms.

Connected mailboxes. You can connect a mailbox in Settings so TomaDash sends carrier email for you instead of opening webmail. For Hostinger we store the mailbox address, host, port, and the mailbox password, encrypted at rest; for Gmail and Outlook we store an encrypted OAuth refresh token. Those credentials are used only to send the messages you or your automations trigger, and are deleted when you disconnect. Sending runs through our server, so the recipient address, subject, body, time, and whether it succeeded are written to that carrier’s activity history on your pipeline. After a Hostinger send we may APPEND a copy to that mailbox’s IMAP Sent folder so it shows next to mail you sent from webmail. That is write-only: we do not list, search, or read the inbox or other folders. We do not send from your mailbox for our own purposes. If nothing is connected, Email can still copy a draft and open Hostinger webmail; that session is yours. We do not send carrier mail from a TomaDash mailbox.

Google sign-in and Gmail send. Sign in with Google is login only. It uses OpenID scopes openid, email, and profile. We receive your Google account identifier, verified email, and display name. That prompt does not request Gmail access. Connect Gmail is optional and separate: it starts only when you click Connect Gmail in Settings → Your inbox. That prompt asks for openid, email, and https://www.googleapis.com/auth/gmail.send so we can send outreach you start in the app (one Email or a Sequence / list send) through Gmail users.me.messages.send. The message is from your own Gmail address. Replies land in your Gmail inbox. We do not request or use Gmail scopes that read mail, labels, or contacts, and we do not read your inbox through the Gmail API. Connect Outlook is the same idea for send from a Microsoft inbox.

Payments. Card numbers are collected by Stripe, not by us. We store Stripe customer / subscription ids and plan status so we know whether you are on Pro.

Signup source. On a first visit we may store landing path, referrer host, UTM parameters, and click ids (such as gclid / fbclid), plus a Toma-Everywhere partner code if you arrived through a share link. That snapshot is attached to the account on signup so we know how people found TomaDash. We also email an internal notice to our ops inbox when someone creates an account (name, email, time, source).

Welcome email. An optional owner-controlled onboarding send can mail you one welcome message after you create an account. It is off unless the operator turns it on. The operator can attach an optional signature to that message. When it runs we keep a short record of that send — your address, name, whether it went out, and any failure reason — so you are never mailed twice. It is a one-time service message, not a newsletter. Reply or email support@tomafreight.com and we will stop.

Automations (Pro and Teams). If you build a carrier outreach automation, we store its rules (which carriers it targets, which template, an optional signature, how often, how long a carrier rests between messages), a per-carrier ledger of when it last mailed each one, and a log of each run with how many messages were sent, skipped, or failed. The messages go out from your connected mailbox, to carriers on your pipeline. You are the sender; see the Terms for what that makes you responsible for.

Community and Marketplace. Posts and replies you publish on Community, and listings, messages, and reviews you publish on Marketplace, live on the shared product — not on your carrier book. Anyone can read Community threads and Marketplace ads. We email the team when someone posts in Support or Builders. Do not put another dispatcher’s book, passwords, or private rates in a public post.

Affiliate partners. If you join Toma-Everywhere, we store your partner name, login, and a dashboard of referred accounts (names, whether they signed in, whether they use TomaDash regularly, last used, Free vs Pro). That dashboard is for the partner, not a public listing.

Integration requests. Settings → “Want another integration?” stores the tool name and notes on your account and emails a notice to our ops inbox so we can follow up.

Tomaboy (Pro). If you are on Pro and you chat with Tomaboy, we use your question, recent chat turns in that session, a snapshot of your pipeline (counts, sequence, follow-ups, and carrier names that match your question), your dispatch country / time zone, the page you are on, and our product notes to answer. If this deploy has an OpenAI API key, that text is sent to OpenAI to write the reply. We do not use your chat to train our own models. Do not paste passwords, card numbers, or secrets you would not say to a dispatcher sitting next to you.

Tomaboy and the live web. Some questions only have a right answer today — diesel, spot rates, a road closure, a new rule. For those, Tomaboy sends a short search query to a web-search provider (Brave, Tavily, or Serper, depending on the deploy), may fetch the text of one or two result pages, and answers from what comes back, with the links shown under the reply. The query is built from your question, plus your approximate area when you asked something local like “near me”. US freight questions (diesel, DAT, FMCSA) are searched against the United States or the US state most of your pipeline sits in, even if you are signed in from another country. Tomaboy works the question the way a person would: it searches, reads a page or two, and if what it read does not actually contain the number, it goes back out to a primary source before answering. Your pipeline is never sent to the search provider. Chat history lives in your browser session only; we do not keep a transcript.

Tomaboy’s knowledge base. When Tomaboy reads a fact off a public page, it files that fact so the next question does not pay for another search. A filed note holds the published sentence, the site and link it came from, the date, and keywords from the search string. It does not hold your question, your chat, your name, or anything from your pipeline, and notes are shared across the product because a diesel price is not personal to anyone. Notes expire after about 45 days — freight facts go stale — and the store is capped, so the oldest fall off.

Approximate location. To answer local questions, Tomaboy reads the approximate city and region our host derives from your IP address, or falls back to your browser time zone and the states most of your carriers sit in. This is city-level at best, we never ask the browser for GPS, and we do not store it — it is used for that one reply and discarded.

Do-not-call / do-not-email. You can mark a carrier or broker file do-not-call or do-not-email. Those flags hide the phone or email in the app and CSV, block outbound calls or mail, and skip automations. Recipients can also change those choices at /preferences using a signed link from a message you sent, or by emailing support@tomafreight.com.

Email verification. If you create an account with email and password we email a short one-time code and store a hash of that code plus expiry and attempt count until you verify or the code expires. We do not keep the raw code after the send.

Marketplace. If you post a listing we store the title, pitch, description, category, the price you set, the account that owns it, and whatever you choose to publish with it: a contact email, a website or booking link, how you want to be paid, your seller name, experience, companies you have worked with, and up to six photos. All of that is public — a listing is an advertisement, so treat the contact email as one you are happy to publish. Signed-in users can message each other in the Marketplace inbox; we store those threads so both sides can read them. The inquiry form emails your name, email, and message to the seller. When a seller confirms you bought or attended, we store that record (your name and email, and the confirmation) because a review is only allowed from a confirmed buyer. Reviews, ratings, and seller-profile text are stored and shown publicly under your display name. You can pause or remove your ad from My ads. TomaDash is not the payment processor for a Marketplace deal — money moves directly between buyer and seller.

Teams. If you own or join a team we store the team name, the plan and Stripe ids, the seat count, each member’s email and role, an optional email domain that lets new signups on that domain join automatically, a hash of each pending invite token (invites expire after 7 days), and a log of seat changes for billing. Teammates cannot see each other’s carriers, notes, or documents.

Opt-out records. When someone uses the preference center we keep what they told us: the email addresses, phone numbers, USDOT or MC they identified, the do-not-call and do-not-email choices, the signed token from the message that brought them there, and when they saved it. That record is kept platform-wide on purpose — an opt-out has to outlive the pipeline that triggered it, or the same person gets mailed again by the next import.

AI drafts (optional). If this deploy has an OpenAI API key, Pro users can ask the model to draft an email template or a Marketplace listing from a short prompt, to sharpen call coaching from a debrief you wrote on a carrier file, or (on Load search) broker inquiries after a DAT paste. The prompt, a snapshot of that truck (equipment, lanes, MC, notes), pasted load rows, and any draft go to OpenAI for that request only. We do not use them to train our own models. Call coaching without a key (and for guests and Free) still uses this account’s notes and the file in front of you — it does not send itself as mail. Broker emails still send from the inbox you connected, and only after you tap Send.

Technical data. Standard request logs (IP, user agent, URL, time) on the host (Render). Health checks. We do not run a separate advertising pixel or Google Analytics tag in the product. Outreach email you send from the app may include a first-party open pixel and wrapped links so you can see opens and clicks on Automations → Templates. That signal stays on your workspace. It is not sold, and it is not an ad network pixel.

4. Cookies and similar

We use cookies that are needed to run the product:

  • tomadash_session — httpOnly session. Signs you (or a guest) in. Lasts up to 400 days and is refreshed while you keep using TomaDash.
  • toma_google_oauth — short-lived (about 10 minutes) OAuth state for Sign in with Google.
  • toma_mail_oauth — short-lived (about 10 minutes) OAuth state for Connect Gmail or Connect Outlook.
  • toma_signup_src — first-touch source (about 90 days).
  • toma_everywhere_ref — partner share code (about 90 days).
  • toma_everywhere_session — partner dashboard login.
  • toma_vid — anonymous visitor id (about 400 days) so we can count marketing visits and later bind that first visit to an account. It is not an advertising pixel.
  • toma_theme — light or dark chrome preference for the in-app workspace.

These are not ad-tracking cookies. Blocking session or OAuth cookies will break login, guest start, Google sign-in, Connect Gmail / Outlook, or partner attribution. Blocking toma_vid only drops visit counts. Blocking toma_theme only resets the theme.

A few things stay in your browser and never reach us: your workspace view preferences in local storage, a marker so a marketing page is only counted once per visit, and your open Tomaboy conversation in session storage. Clearing site data clears all three.

5. How we use information

  • Provide the workspace: import, files, sequence, follow-ups, documents, dashboard.
  • Authenticate you (email/password, Google, guest cookie) and keep you signed in.
  • Send outreach you start in the app from a Gmail or Outlook inbox you connected, so the mail is from your address and replies land there.
  • Send password-reset mail when you ask. Reset links expire in one hour.
  • Process Pro ($9.99/mo or $95.90/year) and Teams ($7.99/user/mo after a 14 day trial) through Stripe and show Plan in Settings or Team.
  • Count usage (active days, imports) so we know when to show the optional Pro banner. Free stays usable.
  • Attribute signups to a campaign or Toma-Everywhere partner.
  • Send a one-time welcome message only if the operator has that onboarding send turned on.
  • Notify our ops inbox of new accounts and of integration requests.
  • Verify an email address with a one-time code when you sign up with email.
  • Send the carrier email you write, or that your automations trigger, through the mailbox you connected.
  • Count opens and clicks on those outreach emails with a first-party pixel and wrapped links, so you can see how each template is doing. Prefetching inboxes can inflate opens.
  • Honour do-not-call / do-not-email flags and preference-center opt-outs.
  • Show public Marketplace listings you publish and deliver Marketplace inbox messages you send.
  • Keep a shared store of public facts Tomaboy looked up, so a question someone already asked is answered without another search.
  • Run the internal operator console described in section 7, and support you when you ask us to.
  • See which workspace screens you use and the product notes you send through Tomaboy, so we can make the app faster and clearer.
  • Draft email templates or Marketplace ads you ask for, when AI drafting is configured.
  • Debug outages, abuse, and failed lookups.
  • Improve TomaDash (including early Pro features).
  • Answer Tomaboy questions for Pro accounts, including searching the web and fetching a result page when the fact has to be current.
  • Find businesses that might want TomaDash and contact them about it (section 9).

We do not sell your personal information, your pipeline, or carrier lists. We do not use your pipeline, your carrier notes, or your Tomaboy chats to train any model, ours or a vendor’s.

6. Who we share with

We share information only as needed to run TomaDash:

  • Render — hosting.
  • MongoDB (when configured) — account and pipeline storage. Local file storage is used only on some development deploys.
  • Google — Sign in with Google (OpenID openid email profile) for login only. If you click Connect Gmail, we also use Gmail send (https://www.googleapis.com/auth/gmail.send) to send mail from your address. We do not read your Gmail inbox, labels, or contacts.
  • Microsoft — only if you click Connect Outlook, to send mail from that inbox.
  • Stripe — checkout, subscriptions, customer portal.
  • Hostinger, Resend, and/or SMTP — password reset, welcome mail, internal notices, and the carrier email you or your automations send. TomaDash tries Hostinger first and falls back to the others, so one dead provider does not drop a message.
  • DotLookup — carrier list search.
  • FMCSA / SAFER — public US authority data.
  • CloudTalk — only if you connect it.
  • Hostinger webmail — only when you click Email without a connected inbox (or choose that fallback); that session is yours.
  • OpenAI — if this deploy has an API key: Tomaboy chat (the payload described above), and optional email-template or Marketplace-ad drafts you start.
  • Brave, Tavily, or Serper — the web-search provider behind Tomaboy’s live answers and our own prospect research. They receive a search query, never your pipeline.

We may disclose information if required by law, to protect TomaDash or others from fraud or abuse, or as part of a sale or reorganization of the business (the buyer must honor this Policy).

Accounts are private. TomaDash is not a shared company CRM. Each login owns its own pipeline. Teams lets an owner invite seats; teammates do not see each other’s carriers, notes, or documents. The owner can see Leaderboard activity counts (dials, imports, emails, pipeline), not another member’s files. Marketplace listings, reviews, and seller profiles you publish are visible to other visitors. Marketplace inbox messages are visible only to the people in that thread.

7. What the operator can see

Someone runs this product, and you should know what that seat can see. TomaDash has one internal console, reachable only by the operator’s own login and excluded from search engines. It shows an account-level view of the business: how many people signed up, who is on Free, Pro, Teams, or a trial, whether an email was verified, how each account arrived (landing page, referrer, campaign, partner code), time in the app and active days, which in-app screens they open, theme changes, Tomaboy opens, product feedback sent through Tomaboy, how many carriers and imports an account has, Marketplace listings and inquiries, partner referral counts, the welcome-mail log, and our own prospect list (section 9). It can also trigger the welcome message and export that account list.

What that console does not do is open your book. It shows counts about an account, not the carriers, notes, call recordings, documents, or Marketplace messages inside it. Support may need to look at a specific record to fix something you reported, and we do that only when you ask us to or when we have to for security, fraud, or law.

8. Public records and your lists

Carrier data from DotLookup and FMCSA is public or licensed business data. Once it is in your pipeline, it is treated as your workspace data. You are responsible for how you use phones and emails you store (calling, TCPA, and similar rules). We do not sell those lists.

9. If we contacted you about TomaDash

This section is for people who have not signed up. To find businesses that might want TomaDash — dispatch services, carriers, and companies who could sell on our Marketplace — we search the public web and read the pages we find. From a company’s own website or public listing we may record the business name, a business website, a business email or phone published on it, a city and region, public social handles, and the page we found it on. We also add rows by hand and from CSV files.

This is ordinary business contact information, published by the business. We do not buy lists, we do not scrape logged-in or paywalled pages, we do not collect special-category data, and we do not build profiles of individuals beyond the work contact details a company chose to publish. In the EEA/UK we rely on legitimate interests (business-to-business marketing of a relevant product), balanced against the limited and public nature of the data. Where an email is a named individual rather than a role address, you have the right to object and we will act on it.

You can ask us at any time to show you what we hold, correct it, or delete it, and to stop contacting you. Email support@tomafreight.com or reply to the message. We mark the record do-not-contact rather than deleting the fact you asked, so the same address is not picked up again on a later search. That suppression record is the minimum needed to honour your request.

This list is ours, for our own outreach. It is not shown to customers, not part of anyone’s pipeline, and not sold or shared with anyone except the hosting and email providers in section 6.

10. Retention

Account and pipeline data stay until you ask us to delete them or we close the account. Guest pipelines stay while the session cookie and stored guest record exist. Password-reset tokens expire after one hour. OAuth state cookies expire in minutes. Signup-source cookies last about 90 days. Connected Gmail or Outlook tokens stay until you disconnect that inbox in Settings or we delete the account. Stripe keeps payment records under its own rules.

Operational logs are capped and roll over on their own: the welcome-mail log keeps the most recent sends, each automation keeps a bounded run history, and our prospect list keeps a bounded note history per company. Tomaboy chats are not stored on our side at all — they live in your browser tab until you close it. The public facts Tomaboy files in its knowledge base expire after about 45 days and are capped in number. Preference-center opt-out records are kept indefinitely on purpose, so a later import cannot undo an opt-out.

The in-app product refuses a one-click “wipe everything” so a bad save cannot empty a live pipeline. Email support@tomafreight.com if you want an account and pipeline deleted; we will delete or anonymize what we reasonably can, except records we must keep for billing, security, or law.

11. Security

Passwords are stored as salted hashes. Session cookies are httpOnly. Production is served over HTTPS. No method is perfect. Do not reuse a weak password. Log out on shared devices. Guest mode is not a backup — create an account if the work matters.

12. Your choices and rights

  • See and edit most pipeline fields in the app (click-to-edit on a carrier file).
  • Change password via Forgot password, or use Google only.
  • Log out; clear cookies to end a guest session.
  • Disconnect Gmail or Outlook in Settings → Your inbox. That removes the stored send token from TomaDash. You can also revoke TomaDash in your Google Account permissions (myaccount.google.com/permissions).
  • Disconnect CloudTalk by removing keys in Settings (and in CloudTalk).
  • Disconnect a mailbox in Settings. That deletes the stored password or token and stops any automation that was sending through it.
  • Turn an automation off, or delete it, on the Automations page.
  • Mark a file do-not-call or do-not-email, or open /preferences to change those choices.
  • Pause or remove a Marketplace listing from My ads. Leave a Marketplace thread from the inbox.
  • Replace or remove your account photo in Settings.
  • Use the preference center linked above to opt out of contact for good — no account and no sign-in needed.
  • Manage or cancel Pro (monthly or annual) in Settings → Manage billing (Stripe portal) when billing is on.
  • Email support@tomafreight.com to access, correct, or delete personal data, to object to our processing, or to be removed from our prospect list (section 9).

If you are in the EEA/UK, we process data to perform the contract (providing TomaDash), with your consent (Google sign-in, optional Connect Gmail or Outlook, other optional integrations), and for legitimate interests (security, attribution, improving the product). You may have rights to access, rectify, erase, restrict, port, or object, and to complain to a supervisory authority.

If you are a California resident, we do not sell or share personal information as those terms are used in the CCPA/CPRA. You may request know/delete/correct by emailing support@tomafreight.com. We will not discriminate for exercising those rights.

13. Children

TomaDash is for business dispatching, not for children. We do not knowingly collect data from anyone under 18. If you think a child created an account, email us and we will delete it.

14. International

We host on US-oriented infrastructure (including Render and MongoDB). If you use TomaDash from another country, you understand your data may be processed in the United States.

15. Changes

We may update this Policy. The effective date at the top will change. Continued use after a change means you accept the new Policy. Material changes may also be noted in the product or by email if we have one for you.

16. Contact