BuildCaster public test · No real charges · Support · Legal notices
BuildCaster.

LEGAL · September 16, 2026

Service providers and subprocessors

The providers involved in the current test and the information they handle.

Version 2026-09-16-test.3 · Invitation-only test

Operated by Hiltos LLC · Michigan, United States

1. Scope of this disclosure

This list describes the public test deployment reviewed on September 16, 2026. Some providers process workspace content on BuildCaster’s behalf; others can act independently for their own account, security, support or legal purposes. Inclusion in this list is not a claim that every provider has the same legal role.

No customer-owned managed domain is active yet. The current application uses a dedicated BuildCaster Postmark server, credentials and message stream, and a shared Stripe sandbox with separate BuildCaster test resources. Separate server or product resources do not by themselves establish separate provider accounts.

2. DigitalOcean — hosting and database

Purpose: application hosting, PostgreSQL, logical/managed backups, temporary portal DNS and external uptime checks. Data involved: application and workspace records, authentication and operational records, backups and network traffic; monitoring also uses the operator’s alert address.

The application and database are deployed in the New York, US region (nyc3). Provider support and infrastructure operations may involve other locations. Uptime checks probe a public health response, not private workspace content.

3. Cloudflare — network, security and email routing

Purpose: DNS and the public network/security edge for buildcaster.app. Data involved: requests routed through Cloudflare, IP addresses, request headers and relevant traffic/security information. Cloudflare operates a global network. The temporary test portal hosts currently use DigitalOcean DNS and a separate direct HTTPS route.

BuildCaster’s domain is configured to use Cloudflare for inbound email routing. Messages to its public contact addresses can pass through Cloudflare and the receiving mailbox provider. Data involved includes sender and recipient addresses, message content and attachments, and delivery/security information.

Cloudflare for SaaS custom-hostname management is not active in this deployment. Any future addition must be reflected in the provider disclosure and applicable customer arrangements.

4. Postmark / ActiveCampaign — application email

Purpose: sign-in links, invitations, selected product notifications, delivery events and suppression. Data involved: recipient addresses, subjects and message bodies, verification or invitation URLs when applicable, unsubscribe URLs, delivery identifiers and operational metadata.

Application messages use the verified sender BuildCaster <hello@buildcaster.app>, with replies to support@buildcaster.app. Open and link tracking are disabled. Provider retention depends on its settings and agreement; BuildCaster’s own dispatch records and backups have separate retention. Do not assume deleting an application record recalls a sent email.

5. Stripe — test checkout and subscriptions

Purpose: hosted test checkout, customer subscription management and signed billing events. Data involved: the owner email, workspace/customer identifiers, selected plan, subscription state and information entered directly on Stripe’s pages. Stripe may also process device, security and fraud-prevention information.

Only test resources are active. Do not enter a real payment card. BuildCaster stores provider references and confirmed subscription dates/state, not full card numbers or security codes. Stripe’s role varies with the activity, including its independent processing under its own privacy policy.

6. Google / Gmail — operational correspondence

Purpose: the operator uses an existing Gmail mailbox for operational correspondence. Data involved: sender addresses, email content and attachments, and delivery/security information handled by the mailbox provider. Public support and privacy contacts use BuildCaster’s domain addresses; their routing service and receiving mailbox provider also handle messages addressed to them.

This is currently a Gmail mailbox, not a representation that a Google Workspace enterprise agreement is in place. Avoid sending sensitive content or account secrets. Your own email provider also handles messages you send or receive.

7. Google — optional account sign-in

Purpose: authenticating people who choose Continue with Google. Data involved: your Google account identifier, name, email and verification status, plus sign-in requests and browser/network information handled by Google. BuildCaster requests only basic identity scopes. Google access tokens are used transiently to retrieve identity information and are not kept in BuildCaster account records.

Google operates this optional identity service under its own terms and privacy policy. Listing the service here does not represent that Google processes all of this information solely on BuildCaster’s instructions or that a Google Workspace agreement is in place. Email-link sign-in remains available.

8. Questions and provider changes

Contact privacy@buildcaster.app for questions about providers, processing locations or a required data processing agreement. Any contractually required advance notice or objection process must be established in the applicable agreement before customer processing begins. This informational list does not itself execute a DPA or an international-transfer mechanism.