Agsemble
Docs/Trust & policies

Trust & policies

Privacy notice

Understand what Agsemble collects, why it is used, where providers are involved, and how to export or delete tenant data.

Scope and contact

This notice applies to the Agsemble website, self-service Sandbox, API, console, and Founder Pilot. Agsemble is the service operator. Privacy, access, correction, deletion, or complaint requests can be sent to hello@agsemble.com.

Last updated: 2 August 2026. The operator's legal name, business address, and designated data-protection contact must be added before paid checkout opens.

Data we process

  • Sandbox verification: the submitted email is used to deliver a one-time code. Agsemble stores a keyed email hash and masked hint, not the raw email address, in its application database
  • Tenant content: field names, farm references, crop metadata, GeoJSON boundaries, observation notes, timestamps, and optional observation coordinates that a developer submits
  • Security and operations: hashed API credentials, key identifiers, recovery state, request path, response status, duration, usage totals, coarse abuse-control counters, and a keyed network-address hash
  • No-signup preview: the submitted Polygon is validated in memory and sent to the configured data providers. Agsemble caches normalized response components under a geometry hash for up to six hours, but does not retain the Polygon itself in the preview cache or add it to a tenant history
  • Billing: Stripe customer, subscription, invoice, credit-note, and refund identifiers and status. Agsemble does not receive or store full card numbers
  • Optional website analytics: after a visitor allows analytics, Agsemble sends Google Analytics the page path without query strings, basic device/browser information, approximate region, and engagement events. Field data, email addresses, API credentials, and console form contents are excluded
  • Support: messages and attachments voluntarily sent to hello@agsemble.com

Why we use it

  • Provide, secure, meter, troubleshoot, and improve the service
  • Issue one free Sandbox per verified email and prevent automated or repeated abuse
  • Retrieve weather and earth-observation data for field coordinates requested by the tenant
  • Process subscriptions, reconcile payments and refunds, and keep required financial records
  • Understand how visitors find and navigate the public site and documentation, when they allow analytics
  • Respond to support, privacy, security, and legal requests

Providers and transfers

Agsemble uses service providers to operate the product. They process only the information needed for their role and may process it in countries outside the user's own country.

  • Cloudflare: API execution, database, domain delivery, and Turnstile abuse protection
  • Resend: one-time Sandbox verification-email delivery
  • OpenAI Sites: public website hosting
  • Open-Meteo and Copernicus Data Space Ecosystem: field-coordinate data requests and upstream agricultural data
  • Stripe: test-mode hosted checkout today; billing portal, payments, invoices, and refunds once live charging is enabled
  • Google Analytics and Search Console: consented website traffic, engagement, and organic-search performance. Google Analytics is disabled until a visitor allows it
  • Google Gmail: support email received through hello@agsemble.com

Retention and deletion

  • Tenant request activity is retained for seven days by default; aggregate usage totals are retained for 90 days
  • Privacy-preserving abuse counters are retained for 31 days; expired verification codes, provider tokens, caches, and incomplete checkout sessions are removed by scheduled maintenance
  • No-signup preview response caches expire after at most six hours (five minutes for partial failures); their geometry hashes and expired rows are removed by scheduled maintenance
  • Fields and observations remain until the tenant deletes them or asks Agsemble to do so
  • A keyed verified-email hash can remain after tenant deletion to enforce one free Sandbox per email; the raw verification email is not stored in the application database
  • Billing and transaction records can be retained where needed for accounting, disputes, fraud prevention, or legal obligations
  • Support correspondence is retained only as long as reasonably needed to resolve the request and meet operational or legal needs
  • The analytics choice is stored on the visitor's device until changed or browser storage is cleared; Google Analytics data follows the configured property retention settings

Access, correction, export, and deletion

GET /api/v1/tenant/export returns startup-owned fields and observations in a machine-readable format. DELETE /api/v1/tenant deletes an unbilled Sandbox after explicit key-ID confirmation. Tenants with billing history require a support-assisted deletion so transaction records are handled correctly.

Email hello@agsemble.com to request access, correction, deletion, or information about how personal data was used or disclosed. Agsemble will verify the requester's identity before acting.

Visitors can allow, decline, or revisit optional Google Analytics collection through the Privacy choices control shown on the site.

Security

Agsemble uses HTTPS, tenant-scoped authorization, hashed API credentials, one-time recovery material, signed billing webhooks, bounded request logs, and privacy-preserving abuse controls. No internet service is risk-free; suspected incidents should be reported to hello@agsemble.com without including an API key or recovery code.