Legal summary
Capell Privacy Policy
What personal and technical data Capell receives, why it is used, who receives it, how long it is kept, and which rights you can exercise.
| Account data | Covered in this document |
|---|---|
| Marketplace telemetry | Covered in this document |
| Support records | Covered in this document |
Sections
Plain-language summary: Capell collects the account, marketplace, installation, and security data needed to provide and protect its services. We do not sell personal profiles. You can ask about your data or exercise applicable rights through the legal contact.
Who controls this data
Ben Johnson, a sole trader trading as Capell, is the data controller for the Capell-operated services described here. The service address is Suite 2 The Gas Light, Lower Warrengate, Wakefield, West Yorkshire, WF1 1SA. Contact [email protected] for privacy questions or rights requests.
Data we receive
Capell collects information needed for accounts, marketplace submissions, package access, domain verification, install and upgrade checks, security notices, feedback, enquiries, and support.
- Account data: name, email address, password hash, GitHub account identifiers, login security information, email verification status, and terms-acceptance records.
- Marketplace data: author profile details, submitted package metadata, source repository URLs, manifests, review notes, package releases, download counts, saved extensions, ratings, and feedback.
- Capell account and site data: verified domains, domain-verification tokens, licence and package-matching data, install receipts, instance identifiers, app URLs, heartbeat timestamps, advisory-delivery data, webhook-delivery status, and marketplace-attestation results.
- Marketplace telemetry: installed extension lists, package names and versions, install-intent events, install or heartbeat source, local-development flags, payload-signature status, licence status, suspected unlicensed-use indicators, and related request evidence.
- Technical data: IP address, user agent, session cookies, security logs, request metadata, error records, and abuse-prevention signals.
What marketplace telemetry does
When a Capell install contacts the marketplace, web installer, command-line tooling, or attestation endpoint, Capell may receive a signed list of installed extensions and related technical evidence. We use it to keep download counts meaningful, avoid treating repeated or local installs as new downloads, recommend compatible extensions, deliver security or upgrade notices, and check paid-extension licence compliance.
Telemetry supports package and site integrity; it is not for selling personal profiles. We do not give extension authors raw IP addresses, user agents, or full install snapshots by default. Authors may receive non-sensitive aggregate signals, support context, and licence information needed to operate their packages.
Purposes and lawful bases
We use personal data to provide Capell services, secure accounts, verify domains, show package and licence information, process marketplace submissions, send transactional notices, prevent abuse, investigate security issues, and meet legal duties.
Where processing provides an account, marketplace, licence, paid extension, installer, or update service, our lawful basis is usually contract. For security, abuse prevention, product integrity, licence compliance, marketplace statistics, and package recommendations, we usually rely on legitimate interests. For optional marketing, non-essential cookies, or optional communications, we use consent where required.
Who receives data
We share data only where needed to run Capell, comply with the law, process payments or licences, connect GitHub login, send email, host infrastructure, investigate abuse, or support marketplace workflows.
An extension author may receive support messages, package feedback, and non-sensitive marketplace signals needed to support their package. Authors must handle personal data under their own legal duties and privacy terms.
How long we keep records
We keep account data while the account is active. Security, terms-acceptance, marketplace, package, licence, install, and advisory records remain for as long as needed to operate the service, prove consent or contract history, investigate security issues, preserve marketplace integrity, and meet legal obligations.
Raw marketplace telemetry and request evidence, including IP addresses, user agents, payload signatures, and install snapshots, is kept only for as long as needed for licence compliance, security, fraud prevention, support, audit, legal claims, or debugging. Aggregated download counts, compatibility patterns, and recommendation statistics may be retained longer to operate and improve the marketplace.
Some records may remain after account closure for security, audit, legal claims, fraud prevention, package continuity, or historic marketplace records. Where possible, we delete or anonymise data that is no longer needed.
Your data rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to, or receive a copy of your personal data. You may also withdraw consent where processing is based on consent.
Contact [email protected] to exercise a right. You may also complain to the Information Commissioner's Office in the UK.
How we protect data
Capell uses controls including hashed passwords, signed routes where appropriate, account verification, rate limiting, protected admin access, and careful logging. No system is risk-free, especially where optional packages can alter a site.
If you believe Capell or a marketplace package exposes personal data or creates a security issue, contact [email protected] with enough detail for us to investigate.