Privacy
AgentHost privacy policy
Effective
GTMVP Inc. operates AgentHost. This policy covers agenthost.space, the Team Builder, accounts, purchases, and founder-led Growth Mode. AgentHost is a business-to-business service for marketing agencies.
The data we handle
- Application data: name, work email, agency, role, workflow answers, tool targets, review choices, campaign source, and consent record.
- Account and security data: account identifiers, login and session records, IP-based abuse controls, and security logs.
- Purchase data: Stripe customer and transaction identifiers, plan, payment status, and subscription details. AgentHost does not receive your full card number.
- Site data: pages viewed, referrer, campaign tags, browser and device type, approximate region, and similar limited analytics data.
- Communications: messages, support requests, calls, and feedback you choose to send.
Where it comes from and why we use it
We receive information from you, your browser, Stripe, and the service providers named below. We use it to review applications, verify work email addresses, prepare and deliver the service, follow up, run accounts and checkout, prevent abuse, measure site performance, keep business and consent records, enforce agreements, and meet legal duties. We collect only what we reasonably need for those purposes.
Who processes it
We use Vercel for hosting and privacy-focused web analytics, Neon for the application database, Close for sales CRM, Hunter for live work-email verification, Stripe for checkout and billing, and PostHog for limited product analytics when configured, and Meta for advertising measurement when Meta Pixel is allowed, when an accepted application is reported as a Lead through the Conversions API, or when completed purchase data is sent by Stripe through the official Meta app. They process information for those functions under their own contracts and policies. We may also disclose information when required by law, to protect people or systems, or as part of a merger, financing, or sale of the business.
We do not sell or rent personal information. If you allow Meta Pixel, Meta receives limited page, browser, device, referrer, and campaign information for advertising measurement. Declining prevents the browser Pixel from loading and prevents AgentHost from reporting an accepted application to Meta. When allowed, that Lead report uses a one-way hash of the independently checked work email and may include the first-party _fbp and _fbc identifiers. Stripe may separately send completed purchase and refund data to Meta through its server-side connection.
Cookies and browser storage
Essential cookies keep a signed-in account secure, protect an OAuth sign-in step, and link a submitted application to checkout; the account and checkout cookies expire within seven days unless cleared sooner. The Team Builder may keep workflow-only answers in first-party session storage so a refresh in the same tab does not erase the plan. That record is cleared when the tab closes and expires within seven days if the tab remains open. Identity fields are not kept in the Team Builder browser record.
AgentHost sets a first-party agenthost_first_touch session cookie to remember which first visit produced the application and purchase while you move through the site. It can contain utm_source, utm_medium, utm_campaign, utm_content, source_asset, landing_variant, and the referrer origin. Referrer paths, queries, and fragments are not kept. If you allow Meta measurement, the consent-approved fbclid may also be added; otherwise it is not written to this cookie. The cookie has no Expires or Max-Age attribute and is intended to end with the browser session. A browser configured to restore a prior session may preserve session cookies until they are cleared.
Meta Pixel can set the first-party _fbp and _fbc advertising identifiers only after you choose to allow it. Your choice is saved in first-party browser storage and a first-party cookie so the application flow can honor it server-side.
PostHog uses first-party session storage only to keep one anonymous visit connected across same-tab reloads. It does not put its identifier in cookies or local storage, and closing the tab clears that session record. Automatic click capture, session replay, surveys, and ad tracking remain off. Vercel Web Analytics does not use third-party cookies. You can change or withdraw that choice below. Withdrawing asks Meta Pixel to stop and removes its first-party identifiers from this site; it does not erase information already received by Meta or change Stripe's separate payment records and server-side Meta connection.
Browser marketing measurement is not chosen.
This choice controls AgentHost's browser Pixel and server-side Lead reporting, but it does not control Stripe's separate server connection. To request a server-side Meta opt-out for future purchase reporting, email steve@stevekaplan.ai.
Your model and tool connections
You authorize model providers, MCP servers, CRMs, ad platforms, and work tools in your own environment. AgentHost does not need the OAuth grant for your CRM or ad account. Tool data can move between your environment, the model provider, and the tools you choose without passing through an AgentHost integration service. If you invite GTMVP Inc. into your environment for setup or support, we use that access only for the work you asked us to perform, and you can revoke it.
Read how connections workHow long we keep data
- Account and prospect records are kept while the relationship is active and for a reasonable period afterward for support, disputes, security, and business records.
- Authentication sessions and checkout-link cookies expire within seven days.
- Workflow-only Team Builder session storage clears when the tab closes and is erased on a fixed seven-day deadline if the tab stays open.
- The first-touch attribution cookie has no fixed expiration and is intended to end with the browser session, subject to browser session-restore settings.
- Payment, tax, consent, and legal records are kept for the period required by law or reasonably needed to establish the transaction.
- Provider logs and analytics follow the configured retention period for that service.
We may delete, aggregate, or de-identify information sooner when it is no longer needed.
Security and international processing
We use encrypted connections, access controls, limited credentials, and provider safeguards appropriate to the information we handle. No online system can promise perfect security. GTMVP Inc. and its providers are based in or may process information in the United States and other countries where they operate.
Your choices and privacy rights
Depending on where you live, you may ask to access, correct, delete, or obtain a copy of personal information, or object to certain uses. We do not sell personal information. Depending on where you live, you may decline browser-based Meta Pixel measurement above and separately request a server-side Meta opt-out for future purchase reporting. Send a request from the email address tied to the record. We may verify your identity and may keep records required for legal, security, billing, or dispute purposes. We will not discriminate against you for making a privacy request.
Do Not Track
PostHog is set to honor a browser's Do Not Track signal where the browser sends one. Meta Pixel stays off unless you make the separate, explicit choice to allow it above. Because browsers and services do not apply Do Not Track in one standard way, that signal does not replace the choice shown on this site.
Children
AgentHost is a business service and is not directed to anyone under 18. We do not knowingly collect personal information from children.
Changes and contact
We may update this policy as the service changes. Material changes will be posted here and, for active account holders, sent by email or shown in the service before they take effect. To make a privacy request or ask a question, email steve@stevekaplan.ai. GTMVP Inc., 8 The Green, Ste A, Dover, DE 19901, USA.
Use of AgentHost is also governed by the Terms of Service.