Some data can’t leave your network as it is — customer records, for example. The on-prem sync connector lets you analyse it anyway. You run a small container (a packaged program) inside your network. It reads your database with a read-only user, applies your rules to every field before anything leaves, and pushes the result out over outbound HTTPS. You don’t open any inbound port, and you decide, column by column, exactly what Crunch ever sees.
It syncs MongoDB today.
What you’ll need
- A Team plan (see pricing).
- A machine in your network that can run Docker and reach your database.
- A read-only user for the database.
Set it up
- In the hub, open Connectors, click + Create connector and choose On-prem database. Give it a name.
- Install the container. Click Get an enrollment token — it is shown once and is valid for
24 hours, so copy it now. Then run the
docker runcommand on the card, with your database’s address and name. - Approve the machine. When the container starts, it appears on the card with a fingerprint (a short code that identifies that machine). Click Approve only if the fingerprint matches the one in the container’s log — that’s how you know it’s your container and not someone else’s.
- Decide what leaves. For each table, set the collection, how it syncs (merge updates, append new, or full refresh), its key and its changed-at field — and a rule for every column.
- Accept the rules on your side. Rules that send more data wait until someone runs this on the container:
bb-connector accept-rules
That last step means a change that sends more data out always needs someone inside your network to agree to it.
Rules
| Rule | What leaves |
|---|---|
| Drop | nothing |
| Hash with your key | a hash only your key can make |
| Hash as email / Hash as phone | a hash that matches the website tag’s hashed user IDs |
| Round time | to the hour, day or month |
| Keep first 3 / last 4 characters | part of the value |
| Keep email domain only | example.com |
| Send as is | the value |
A hash turns a value into a scrambled code: the same value always gives the same code, so records can still be matched, but the original can’t be read back from it.
Heads up: A column without a rule is dropped.
Join with your website data
To match these records with your website’s visitors, use Hash as email/phone on both sides, or Send as is for an internal ID.
Heads up: A value hashed with your key never matches your website’s events, so don’t use Hash with your key on a column you want to join on.
How to tell it worked
What landed shows each run — table, mode, status and rows. From there you can Pause, Resume and Resync. It syncs every hour by default.
Related
- Hash user IDs — how the website tag hashes emails and phones.
- Your own data lake — read Postgres or Iceberg tables where they live.