Trust

Subprocessors

The third-party services we use to run AgencyPitch. We pick vendors that meet our security bar so you don't have to vet each one.

Last updated: May 2026

Per our Privacy Policy, AgencyPitch shares limited data with the following subprocessors. We notify customers at least 30 days before adding any new subprocessor that processes personal data.

Core infrastructure

SubprocessorPurposeLocationCompliance
Google Cloud / FirebaseAuthentication, Firestore database, file storage, analytics events.USA (us-central1)SOC 2 II, ISO 27001, GDPR, HIPAA
VercelWeb application hosting + edge CDN.GlobalSOC 2 II, GDPR, CCPA
RailwayPDF rendering microservice (Puppeteer + Chromium).USASOC 2 II

AI providers

SubprocessorPurposeLocationData retention
Anthropic (Claude)AI proposal generation (fallback model).USA30 days for abuse monitoring; not used for training.
Google AI (Gemini)AI proposal generation (primary model).USAPer Google AI policy; not used for training paid tier.

Payments + email

SubprocessorPurposeLocationCompliance
RazorpaySubscription billing and one-time payments.India + globalPCI DSS Level 1, ISO 27001
ResendTransactional email (proposal-view notifications, billing receipts).USASOC 2 II, GDPR

Analytics + monitoring

SubprocessorPurposeLocation
PostHogProduct analytics (page views, feature usage). Self-host option available for Enterprise.USA / EU (configurable)
SentryError monitoring + performance traces.USA

Cross-border data transfers

Where AgencyPitch transfers personal data of EU/UK residents to the US or India, transfers happen under Standard Contractual Clauses (SCCs) plus supplementary technical measures (encryption in transit and at rest).

How to be notified of new subprocessors

Email privacy@agencypitch.io with the subject line “subprocessor-updates” and we’ll add you to the notification list. We notify at least 30 days before any new subprocessor that processes personal data is added to the stack.