Lead Generation
RB2B
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by GetEmails, LLC · www.rb2b.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
RB2B, from GetEmails, LLC of Austin, Texas, identifies website visitors at person level for US traffic and company level worldwide through Demandbase. It scored strongest on data provenance and visitor identification and weakest on sovereignty, data coverage and prospecting compliance; CRM sync and export sat flat at 4 and pricing transparency at 3-4. Judges credited data-subject routes — opt-out and request-to-know forms, a toll-free line, a suppression file, 23,323 requests answered in 2025 — and a stated consent posture: person-level resolution is IP-ringfenced to US traffic, and consent capture is required for the global company-level ID. Weaknesses are structural: coverage claims (70-80% of traffic identified; 15-20% and 35-45% resolution) come without method, hosting is stated in the United States, the data protection addendum is stated to apply solely to data collected in the United States, and we found no public information on lawful-outreach support for EU markets. Visitor identification spread 4 to 6: the ABM marketer scored 6 for the mixed US/EU design; the 4s weighed the absence of a published cookieless option or TDDDG position.
Speaks for it
- Person-level identification of US website visitors returns names, LinkedIn profiles and email addresses, with IP ringfencing resolving only US traffic.
- Company-level identification is global through a named partner, Demandbase, with consent capture stated as required to enable it to comply with GDPR.
- Data-subject rights are published and exercised — an opt-out form, a request-to-know form, a toll-free line, a retained suppression file, and 23,323 requests in 2025 with none denied.
- One-way delivery spans 50+ apps including Salesforce, HubSpot, Slack, Clay and Zapier, plus webhook, CSV export and email enrichment.
- Entry pricing is public — Starter at $79/mo with 300 monthly resolutions and a forever-free plan of Company-Level ID at 150 resolutions per month — alongside a 7-day full-featured Pro trial with no credit card required.
Held against it
- Person-level coverage is US-only by design — profiles matched to US home addresses — so DACH and other EU visitors surface as companies only.
- Coverage figures of 70-80% of traffic identified and 15-20% basic / 35-45% premium resolution are published without method, verification or refresh cadence.
- Sovereignty scores sit at 1-2: a Texas LLC under Texas law with exclusive Austin jurisdiction, hosting stated in the United States, a data protection addendum stated to apply solely to data collected in the United States, and subprocessors disclosed only as categories.
- We found no public information on lawful-outreach support for EU markets, do-not-call screening or a buyer-side do-not-contact list, while the terms place usage restrictions on the buyer.
- We found no public information on the Pro tier's price, additional-seat costs, resolution rollover or VAT treatment, and the license to store output data runs only for the subscription term.
Best for
- You sell primarily into the United States and want named US website visitors pushed into Slack, Teams, Salesforce or HubSpot while the visit is fresh.
- You work a mixed US/EU list and can put consent capture on your site, which the vendor states is required to enable the global company-level ID.
- You want to evaluate before spending: the 7-day full-featured Pro trial requires no credit card and a forever-free plan follows at 150 company-level resolutions per month.
Avoid if
- You need person-level data on German, Austrian or Swiss visitors — the vendor states person-level profiles are matched to US home addresses and IP ringfencing resolves only US traffic.
- Your legal review requires EU-side processing — hosting is stated in the United States, the data protection addendum is stated to apply solely to data collected in the United States, and subprocessors appear only as categories.
- You must compute a team's annual invoice before signing — the Pro tier's price, seat costs and rollover terms are not public, and all payments are nonrefundable.
- Your outbound operation needs vendor-side compliance support in the EU — ask the vendor: the public pages we read do not show it
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
Accuracy is asserted as percentages with nothing behind them — 70-80% of traffic identified, 15-20% basic and 35-45% premium resolution coverage — with no refresh cadence and no verification method beyond a mention of validated business emails. The vendor states person-level profiles are matched to US home addresses only, and we found no public information on European or DACH contact coverage, on phone or direct-dial data, or on any credit-back for inaccurate records; the terms state all payments are nonrefundable. 1 2 4
The RevOps Manager
The captured pages state identification rates — 15-20% of traffic on basic resolution, 35-45% on premium, and a 70-80% headline — with person-level profiles matched to US home addresses and IP ringfencing that resolves only US traffic; we found no public information on email verification method, refresh cadence, or per-country coverage, so these figures stand as assertions without method. The reporting view is US-shaped (profiles by state) and European reach is company-level only through the Demandbase partnership. 1 2
The Data Protection Officer
Coverage is asserted as bare percentages — 70-80% of traffic identified, 15-20% basic and 35-45% premium resolution coverage — with no method behind any of them, and person-level identification is United States-only by design, so there is no person-level coverage for DACH or the EU at all. We found no public information on verification, refresh cadence, or any credit-back for inaccurate records, and the terms state all payments are nonrefundable. 1 2 4
The ABM Marketer
Coverage is asserted as percentages with nothing behind them — identify 70-80% of website traffic, 15-20% basic and 35-45% premium contact-level resolution — and person-level coverage is US-only by design, so DACH visitors surface only as companies through the Demandbase layer. We found no public information on country or industry breakdowns, refresh cadence, or a verification method, and the terms disclaim all warranties on output data with every payment nonrefundable, so inaccurate data stays the buyer's cost. 1 2 4
The DACH Sales Director
Person-level data is US-only by design, and the global offer is company-level identification resold through a partnership with Demandbase; we found no public information on coverage for Germany, Austria or Switzerland, or on any verification or refresh cadence. The 70-80% identification claim and the 15-20% and 35-45% resolution figures are asserted without a method, and all payments are stated as nonrefundable, so inaccuracy remains the buyer's cost. 1 2 4
The Skeptic
The only accuracy numbers published are a claim to identify 70-80% of website traffic and resolution-coverage ranges of 15-20% and 35-45%, with no method, verification description or refresh cadence behind them, and person-level profiles are matched to US home addresses only, so we found no public information on DACH or EU contact coverage. The terms state all output data is provided "as is" and all payments are nonrefundable, so inaccuracy stays entirely the buyer's cost. 1 2 4
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
Sources are described in general terms — third-party data providers, integration parties, public APIs and the internet — alongside a disclosed contributor database, with consent and legitimate interest named as bases and no balancing test published. The people in the database get a self-service opt-out form, a request-to-know form, a toll-free line, a suppression file and published 2025 deletion statistics, but we found no public information on per-record source traceability or Art. 14 notification of the people added to the database. 3
The RevOps Manager
Sources are described in general terms — third-party data providers, integration parties, public APIs and the internet — alongside a disclosed contributor database, with consent or legitimate interest named as processing bases and a privacy-policy section addressed to the people in that database. Self-service opt-out, request-to-know and deletion routes exist and are backed by published 2025 statistics (23,323 requests, all complied with, one-day median response) with a suppression file retained; we found no public information on per-record source traceability, an Art. 14 notification practice, or a published balancing test. 3 1
The Data Protection Officer
Sources appear only in general terms — third-party data providers, integration parties, public APIs and the internet — and the named bases of consent and legitimate interest carry no published balancing, but a contributory database is disclosed and the people in it get a real removal route: an opt-out form, a request-to-know form, a toll-free line, 23,323 requests honored with none denied in 2025, and a retained suppression file. What I cannot find is an Art. 14 practice of actually notifying people when they are added, and the data protection addendum applies solely to data collected in the United States. 1 3 4
The ABM Marketer
Sources are described only in general terms — third-party data providers, integration parties, public APIs and the internet — alongside a disclosed contributor database, and the legal bases are named as consent or legitimate interest with no published balancing test. People in the database do get a self-service opt-out form, an access request form and a toll-free line, with 23,323 requests answered in 2025, but we found no public information on an Art. 14 notification practice, and the data protection addendum is scoped solely to data collected in the United States. 3 1 4
The DACH Sales Director
Sources are described in general terms — third-party data providers, integration parties, public APIs and the internet — with a contributor database disclosed as such, and consent or legitimate interest is named as the basis without any published balancing test. People in the database do get a self-service opt-out plus access and deletion forms with published response statistics, which is more than a bare form; we found no public information on an Art. 14 notification practice or per-record source traceability. 1 3
The Skeptic
The privacy notice admits only generic source categories — "data providers and integration parties" and "public APIs and the internet" — plus a disclosed contributor database, names consent and legitimate interest as bases without any published balancing, and we found no public information on a notification practice for the people added to the database. Real credit on the data-subject side: self-service opt-out and request-to-know forms, a toll-free line, permanent suppression from the contributor database, and published 2025 statistics showing 23,323 requests answered in about a day. 1 3 4
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
This is the core product and it is person-level for US visitors — names, LinkedIn profiles and business emails matched to US home addresses via IP ringfencing, using first- and third-party cookies, device IDs and Demandbase reverse-IP — with company-level ID global once consent capture is in place, plus ICP filters, hot-page intent tagging and visit history. That is a stated consent position, but we found no public information on a cookieless or consent-mode option, consent-management-platform integration, or any position on the German TDDDG consent requirement. 1 2 3
The RevOps Manager
Person-level identification is deliberately US-only, enforced by IP ringfencing, and the vendor states that consent capture is required to enable the global company-level ID under GDPR — a position a DPO can at least work with. Tracking runs on first- and third-party cookies plus device IDs and Demandbase reverse-IP, match rates of 70-80% are claimed without method, and we found no public information on cookieless operation, consent-management-platform integration, or a TDDDG-specific statement; intent exists as page-level tagging and ICP filters with Slack and Teams pushes. 1 2
The Data Protection Officer
The script is the exact model I fear — first and third-party cookies, device IDs, IP addresses and a Demandbase reverse-IP network resolving visitors into named people with LinkedIn profiles and email addresses — though the vendor does state a European position: person-level resolution is ringfenced to US traffic by IP, and consent capture is required before the global company-level identification. We found no public information on a cookieless or consent-mode variant, consent-platform integration, or any statement under the German Telekommunikation-Digitale-Dienste-Gesetz, and the 70-80% identification claim is made without method. 1 2 3
The ABM Marketer
This is the core of the product and the design is what I'd want to see for a mixed US/EU list: person-level resolution is ringfenced to US traffic only, company-level identification is global via a named source (Demandbase), and the vendor states that consent capture is required to enable the global company-level ID. Hot pages give high-intent tagging, ICP filtering and exclusions shape what reaches me, pageview history and session recaps give the visit story, and pushes to Slack and Teams hit the account owner while the signal is warm — though we found no public information on cookieless operation, consent-platform integration, or third-party intent topics beyond the vendor's own pixel. 1 2
The DACH Sales Director
The core promise is person-level identification of website visitors via first- and third-party cookies; EU traffic is not person-resolved because of IP ringfencing, and consent capture is stated as required for the global company-level identification. We found no public information on a cookieless mode, consent-management-platform integration or any TDDDG position, and the 70-80% identification rate is claimed without method. 1 2 3
The Skeptic
Person-level identification of visitors — names, LinkedIn profiles and emails — is IP-ringfenced to US traffic, with company-level identification global through a named partner, Demandbase, and a stated position that consent capture is required for the global company ID under GDPR, plus ICP filtering, high-intent page tagging and per-visitor history. But the script runs on first and third party cookies, device IDs and a cross-site network, and we found no public information on a cookieless or consent-mode option, consent-platform integration, or a German tracking-consent position; the 70-80% match claim comes without method. 1 2 3
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
There is no database search here to filter — the workflow is a pixel, an ICP filter on identified visitors, exclusions by domain and URL, and a push to Slack or the CRM — while the terms do restrict sender identities (no group inboxes, no fictional personas) and prohibit FCRA uses. We found no public information on country-aware flagging of German contacts, do-not-call screening, or any guidance on cold-outreach rules in the main EU markets, so the legal risk sits entirely with the buyer. 2 4
The RevOps Manager
The product offers ICP filtering (Hot Leads), high-intent page tagging, and exclusions by domain, URL and list, and the agreement restricts what buyers may do (internal business use only, no FCRA purposes, no scraping). We found no public information on a do-not-contact or suppression list for outreach, country-aware flagging of German or other EU contacts, or guidance on cold-outreach rules — the compliance risk after export sits with the customer. 2 4
The Data Protection Officer
The workflow runs from identification through ideal-customer-profile filtering, domain and list exclusions, and a push into cold-email tools like Instantly and HeyReach, with terms restricting FCRA uses and fake sender identities — but nothing on the captured pages addresses what a buyer may lawfully do with these person-level contacts in European markets. We found no public information on country-aware flagging, do-not-call checking, or outreach opt-outs synced back into the database. 1 2 4
The ABM Marketer
There are ICP filters, exclusions by domain, URL and list, and terms clauses barring fictional sender identities and group-distribution senders, but the outreach legal risk sits with me: we found no public information on a buyer-side suppression or do-not-contact list, phone numbers checked against national do-not-call registers, or any guidance on cold outreach rules in Germany or other EU markets. 2 4
The DACH Sales Director
What is published is exclusion lists for domains and URLs plus ICP filtering; we found no public information on cold-outreach guidance for any EU market, checking against national do-not-call registers, or a do-not-contact list shared across a team's exports. The terms restrict fictional sender identities and group distribution addresses, but say nothing about the lawful basis a buyer should rely on when contacting the identified people — nothing here tells a rep that a cold call under UWG §7 is not a growth hack. 2 4
The Skeptic
The buyer gets ICP filtering and domain exclusions but no help with lawful outreach: we found no public information on cold-outreach guidance for EU markets, a buyer-side do-not-contact suppression list, or checks against do-not-call registers. The terms impose rules on the customer — no FCRA purposes, no fictional sender identities, internal business use only — rather than support for staying within UWG §7 or the GDPR once contacts are exported. 2 4
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Native connections to Salesforce, HubSpot and fifty-plus apps plus webhooks, CSV export and email enrichment are public, which is a real pipeline for my SDRs. But we found no public information on field mapping, deduplication, bidirectional sync, or documented API limits and credit costs per call; the license to store exported data runs only throughout the subscription term, and we found no public information on what a cancelled customer may keep or for how long. 1 2 4
The RevOps Manager
One-way pushes to Salesforce, HubSpot, Clay, Slack and Teams, a webhook, CSV export and an email-enrichment feature are evidenced across 50+ integrations, but we found no public information on field mapping, deduplication, scheduled re-enrichment, or documented API limits — as the person who cleans the CRM, that absence decides the score. The license to store output data runs "throughout the term of Customer's subscription" and is revocable, and we found no public information on what data a customer may keep after cancellation; integrations may also be discontinued without refund or credit. 1 2 4
The Data Protection Officer
Native connections to Salesforce and HubSpot among 50-plus apps, plus CSV export, a webhook and email enrichment, do get data into the systems where sales works. We found no public information on field mapping, deduplication, bidirectional sync, API limits or per-call credit costs, and the license to store exported data is granted only for the duration of the subscription, so what a buyer may keep after cancellation is left without a stated right. 1 2 4
The ABM Marketer
One-way pushes to Salesforce and HubSpot plus Slack, Teams, Clay, Zapier, webhooks and CSV export cover the destinations my reps live in, with email enrichment and an identity-graph waterfall in the feature list. We found no public information on field mapping, deduplication, a documented API with stated limits, or data retention after cancellation — the license to store output data runs only for the subscription term. 1 2 4
The DACH Sales Director
Pushes to Salesforce, HubSpot, Slack, Clay and Zapier, a webhook and CSV export are documented, with fifty-plus apps claimed overall. We found no public information on field mapping or deduplication on sync, a documented API with stated limits, or post-cancellation retention — and the license to store output data is granted only throughout the term of the subscription. 1 2 4
The Skeptic
Pushes to Salesforce, HubSpot, Slack, Teams and Clay plus CSV export, a webhook and email enrichment are listed, but we found no public information on field mapping, deduplication, scheduled re-enrichment, or a documented API with stated limits and per-call costs — the terms only say output data is obtained solely through the vendor's APIs. The licence to store output data is revocable and granted for the subscription term, and we found no plain statement of what a customer may keep after cancellation. 1 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
A US vendor end to end: GetEmails, LLC of Austin, Texas, hosting stated as United States, Texas governing law and Austin courts, and a DPA that applies solely to data collected in the United States. Subprocessors appear only as categories — advertising and data platforms, data enhancement platforms, business partners — and we found no public information on an EU representative, EU hosting, or any transfer basis for European traffic; the vendor's own ringfence is that person-level profiles are US residents only. 1 3 4
The RevOps Manager
This is a US vendor end to end: GetEmails, LLC in Austin, hosting stated as the United States, Texas governing law with an Austin forum, and subprocessors disclosed only as categories (advertising and data platforms, data enhancement platforms, business partners). The DPA by its own note applies solely as to data collected in the United States, EU visitors are tracked at company level through cookies and Demandbase reverse-IP from US infrastructure, and we found no public information on an EU representative, an EU hosting option, or a transfer basis for EU visitors' data. 3 4 1
The Data Protection Officer
The contracting entity is a Texas LLC under Texas law with exclusive jurisdiction in Austin, hosting is in the United States, subprocessors appear only as categories, and the data protection addendum expressly applies solely to data collected in the United States — leaving the cookies, IP addresses and company-level data of EU visitors processed in the US with no stated transfer basis and no Art. 27 representative. The single mitigating design decision is the IP ringfencing that resolves person-level traffic only within the US. 1 3 4
The ABM Marketer
GetEmails, LLC of Austin, Texas is the contracting entity, the service is hosted in the United States, Texas law and Austin courts govern, and the data protection addendum applies solely to data collected in the United States. We found no public information on an EU representative, on named subprocessors beyond categories such as data-enhancement platforms and business partners, or on any transfer basis for the consent-captured EU company-level visitor data. 3 4
The DACH Sales Director
The contracting entity is a Texas LLC under Texas law with exclusive jurisdiction in Austin, hosting is stated to be in the United States, and the data protection addendum is stated to apply solely to data collected in the United States; we found no public information on an EU entity or an Art. 27 representative. Subprocessors appear only as broad categories, and there is no published safeguard for the CRM data a European customer would submit. 1 3 4
The Skeptic
Everything sits in the United States by the vendor's own words: a Texas LLC, hosting in the United States, Texas governing law and Austin courts, and a data protection addendum that the terms state applies solely to data collected in the United States. Recipients are disclosed only as categories — advertising and data platforms, data enhancement platforms, business partners — with no named list, and we found no public information on an EU representative, EU hosting or any EU-side processing arrangement. 1 3 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Public numbers exist — Starter at $79/mo with 300 monthly resolutions, a forever-free plan at 150 company-level resolutions per month, and a 7-day full-featured trial with no credit card required — but we found no public information on the price of the higher tiers, per-seat add-on costs, what a resolution costs by data type, or credit expiry and rollover. The terms state all payments are nonrefundable, so the annual invoice is not computable from public pages alone. 1 2 4
The RevOps Manager
Starter at $79/mo with 300 monthly resolutions, a forever-free tier (Company-Level ID, 150 resolutions/month) and a 7-day full-featured Pro trial with no credit card are public, and the money terms are stated plainly — auto-renewal with 30-day notice on annual terms, all payments nonrefundable, a 1.5% per month finance charge, a 30-day dispute window. But the captured pages show no price for the email-bearing Pro tier, and we found no public information on additional-seat costs, credit expiry or API pricing — the annual invoice for a team that needs email addresses is not computable from public pages. 1 2 4
The Data Protection Officer
The Starter tier is publicly priced at $79/mo with 300 monthly resolutions and a forever-free plan of 150 company-level resolutions per month, and billing mechanics such as auto-renewal, the thirty-day dispute window and nonrefundable payments are stated plainly. We found no public information on the Pro plan's price, the cost of an additional seat, rollover of unused resolutions, or VAT treatment, so the full-year invoice is not computable from the captured pages. 1 2 4
The ABM Marketer
Starter at $79/mo with 300 monthly resolutions and the forever-free plan of 150 company-level resolutions per month are public, but the captured pages give different visibility by tier and we found no public information on the price of the Pro tier that actually includes validated email addresses, extra-seat costs, VAT treatment or overage rates. With every payment nonrefundable and a 30-day dispute window, I can't compute the real annual invoice for a working ABM stack from these pages alone. 2 1 4
The DACH Sales Director
The Starter plan at $79/mo with 300 monthly resolutions and the free plan's 150 monthly company-level resolutions are public, but we found no public prices for the higher tiers, no per-seat cost, and no expiry, rollover or overage terms for resolutions. With all payments stated as nonrefundable and no credit-back for inaccurate data, the real annual invoice is not computable from the public pages. 1 2 4
The Skeptic
The Starter plan at $79/mo with 300 monthly resolutions and a forever-free tier with 150 company-level resolutions per month are public, but we found no public information on the Pro plan's price — the tier that carries the validated business emails — nor on additional seats, API costs, rollover of unused resolutions or VAT treatment. The refund rule is at least unambiguous: all payments are nonrefundable, disputes must be raised within 30 days, and unpaid balances carry a 1.5% monthly finance charge. 1 2 4
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | US by default ⚠ unverified | 0/3 pts | 3 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. No EU or other hosting region is offered anywhere in the excerpts, so US hosting is presented as the sole, unconditional default with no configurability discussed.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 11 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.rb2b.com Checked 22 Sep 2026 Details →
- 2 Pricing page www.rb2b.com Checked 22 Sep 2026 Details →
- 3 Privacy policy www.rb2b.com Checked 22 Sep 2026 Details →
- 4 Terms of service www.rb2b.com Checked 22 Sep 2026 Details →
- 5 Security / trust page www.rb2b.com Checked 30 Sep 2026 Details →
- 6 Visitor identification & intent signals — found from sitemap support.rb2b.com Checked 1 Oct 2026 Details →
- 7 Visitor identification & intent signals — found from sitemap support.rb2b.com Checked 1 Oct 2026 Details →
- 8 Prospecting workflow & outreach rules — found from sitemap www.rb2b.com Checked 1 Oct 2026 Details →
- 9 Prospecting workflow & outreach rules — found from sitemap support.rb2b.com Checked 1 Oct 2026 Details →
- 10 CRM sync, enrichment & export — found from sitemap support.rb2b.com Checked 1 Oct 2026 Details →
- 11 CRM sync, enrichment & export — found from sitemap www.rb2b.com Checked 1 Oct 2026 Details →