Skip to main content
Capell home
Live demo

Legal summary

Capell Privacy Policy

What personal and technical data Capell receives, why it is used, who receives it, how long it is kept, and which rights you can exercise.

Clear Capell operating agreements arranged with consent controls, revision layers, support correspondence, and stewardship evidence.
Key areas covered
Account dataCovered in this document
Marketplace telemetryCovered in this document
Support recordsCovered in this document

Plain-language summary: Capell collects the account, marketplace, installation, and security data needed to provide and protect its services. We do not sell personal profiles. You can ask about your data or exercise applicable rights through the legal contact.

Ben Johnson, a sole trader trading as Capell, is the data controller for the Capell-operated services described here. The service address is Suite 2 The Gas Light, Lower Warrengate, Wakefield, West Yorkshire, WF1 1SA. Contact [email protected] for privacy questions or rights requests.

Capell collects information needed for accounts, marketplace submissions, package access, domain verification, install and upgrade checks, security notices, feedback, enquiries, and support.

  • Account data: name, email address, password hash, GitHub account identifiers, login security information, email verification status, and terms-acceptance records.
  • Marketplace data: author profile details, submitted package metadata, source repository URLs, manifests, review notes, package releases, download counts, saved extensions, ratings, and feedback.
  • Capell account and site data: verified domains, domain-verification tokens, licence and package-matching data, install receipts, instance identifiers, app URLs, heartbeat timestamps, advisory-delivery data, webhook-delivery status, and marketplace-attestation results.
  • Marketplace telemetry: installed extension lists, package names and versions, install-intent events, install or heartbeat source, local-development flags, payload-signature status, licence status, suspected unlicensed-use indicators, and related request evidence.
  • Technical data: IP address, user agent, session cookies, security logs, request metadata, error records, and abuse-prevention signals.

When a Capell install contacts the marketplace, web installer, command-line tooling, or attestation endpoint, Capell may receive a signed list of installed extensions and related technical evidence. We use it to keep download counts meaningful, avoid treating repeated or local installs as new downloads, recommend compatible extensions, deliver security or upgrade notices, and check paid-extension licence compliance.

Telemetry supports package and site integrity; it is not for selling personal profiles. We do not give extension authors raw IP addresses, user agents, or full install snapshots by default. Authors may receive non-sensitive aggregate signals, support context, and licence information needed to operate their packages.

We use personal data to provide Capell services, secure accounts, verify domains, show package and licence information, process marketplace submissions, send transactional notices, prevent abuse, investigate security issues, preserve marketplace integrity, and meet legal duties.

Where processing provides an account, marketplace, licence, paid extension, installer, or update service, our lawful basis is usually contract. For security, abuse prevention, product integrity, licence compliance, marketplace statistics, and package recommendations, we usually rely on legitimate interests. For optional marketing, non-essential cookies, or optional communications, we use consent where required.

After you consent to optional analytics, public Capell pages may use PostHog on its EU-hosted service and a small first-party attribution request. PostHog autocapture and session recording are disabled. Requests to PostHog necessarily make your IP address and user agent available at the network layer; those values are not added to Capell's purchase-attribution records.

Capell's first-party attribution records contain the page path, UTM campaign fields, the referring site's hostname, and an opaque attribution identifier carried to Lemon Squeezy in checkout custom data so a confirmed purchase can be matched to its journey. They do not store a raw IP address, user agent, or full referring URL. Unattached attribution records are deleted after 7 days; records linked to a purchase are deleted after 400 days.

We share data only where needed to run Capell, comply with the law, process payments or licences, connect GitHub login, send email, host infrastructure, investigate abuse, or support marketplace workflows.

An extension author may receive support messages, package feedback, and non-sensitive marketplace signals needed to support their package. Authors must handle personal data under their own legal duties and privacy terms.

Personal data is kept only for as long as needed for the purpose it was collected for, and is then deleted or anonymised. The periods below set out how that principle applies to each type of record.

We keep account and profile data while the account is active. Closing an account removes access immediately and the profile is anonymised within 30 days.

Minimised order, invoice, tax, refund, payment, licence, and contract records are kept for six years after the end of the relevant accounting period. Support correspondence is deleted or anonymised 24 months after a request closes, and support attachments are deleted 90 days after closure. Authentication events and account activity logs are kept for 12 months. Anonymous aggregate metrics that cannot identify a person may be kept indefinitely.

Capell's current Stripe and Lemon Squeezy integrations do not persist raw provider request bodies. They store cryptographic digests and the minimum normalised facts needed for payment, entitlement, audit, and fraud controls. If a raw provider payload is temporarily retained for an authorised investigation, it must be deleted within 30 days.

A legal hold, open dispute, chargeback, fraud investigation, or statutory enquiry pauses deletion only for the affected records and only while that exclusion remains active. It does not extend unrelated retention periods.

Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to, or receive a copy of your personal data. You may also withdraw consent where processing is based on consent.

Active account holders can download a structured copy of their account data from profile settings. Contact [email protected] for a rights request, including if the account is no longer active or a different export format is needed. You may also complain to the Information Commissioner's Office in the UK.

Capell uses controls including hashed passwords, signed routes where appropriate, account verification, rate limiting, protected admin access, and careful logging. No system is risk-free, especially where optional packages can alter a site.

If you believe Capell or a marketplace package exposes personal data or creates a security issue, contact [email protected] with enough detail for us to investigate.

Loading footer