Skip to content

Legal

Subprocessors

Last updated: June 26, 2026

AgentBuild uses the following subprocessors to provide the Service. Each is bound by a data-protection agreement that includes appropriate safeguards for international data transfers (Standard Contractual Clauses where applicable). We will give active customers at least 30 days’ notice before adding or replacing a subprocessor that processes personal data.

SubprocessorPurposeData processedRegion
Cloudflare, Inc.Hosting, edge compute, DNS, R2 object storage, D1 customer-site databases, Workers Browser Rendering, and Turnstile anti-spam verification on customer-site formsCustomer Content; site-visitor IPs and request metadata (a visitor's IP is sent to Cloudflare Turnstile at form submission to verify the submission is not automated, and is hashed for rate limiting — it is not stored in raw form by AgentBuild); domain DNS recordsGlobal edge; primary metadata in US
Supabase, Inc.AgentBuild platform database (accounts, API keys, site registry, billing)Account data, hashed API keys, billing records, platform eventsUS (us-east-2)
Vercel Inc.Hosting of the AgentBuild web application — marketing site, sign-in/sign-up, account dashboard, billing redirects, and OAuth consentAccount email and name, authentication/session cookies, account-form contents (waitlist, support), and request IP addresses — processed in transitUS (global edge)
Stripe, Inc.Payment processingCardholder data, billing address, transaction historyUS, EU
name.com, Inc. (a Donuts company)Registrar record lookups for legacy registered domainsDomain names looked up for registration records (a domain name can incidentally contain a personal identifier); no other personal dataUS
Domain registry operators (via the rdap.org bootstrap redirector)Public registry registration-status lookups (domain_check, RDAP protocol)Domain names looked up (a domain name can incidentally contain a personal identifier); no other personal dataGlobal (per-TLD registry, e.g. Verisign for .com)
AgentBuild Inbox (operated by AgentBuild on Cloudflare Workers)Transactional email — receipts, subscription renewal reminders, security notices, customer-site form notificationsRecipient email address, message contentsCloudflare global edge
PostHog Inc.Marketing-site analytics in cookieless modeAggregate page views and events tied to an in-memory identifier that resets on each page loadUS (us.i.posthog.com)
Sanity.ioMarketing-site blog content (no end-user personal data)None (editorial content only)EU
Dub, Inc.Referral and affiliate link tracking on the marketing siteClick events, referral codes, and the email address of a referred customer (received via the referral webhook)US

Subprocessors that process visitor data on customers’ behalf

For data submitted by visitors to customer-published sites (Section 1.3 of the Privacy Policy), AgentBuild engages only Cloudflare (stores form submissions in per-site D1 and uploaded assets in R2; verifies form submissions are not automated via Turnstile; serves the site) and AgentBuild Inbox (delivers form-notification emails containing the visitor’s submitted details to the inbox the customer configured). No other subprocessor receives customer-site visitor data — name.com receives domain names only, and Stripe, Supabase, Vercel, PostHog, Sanity, and Dub do not receive it.

Each subprocessor’s privacy policy and data-processing terms are available on its website. AgentBuild’s customer Standard Contractual Clauses for data transfers are incorporated by reference into the Customer Terms of Service Section 10.