Legal summary
Capell Subprocessors List
Providers used for hosted services, commerce, repository access and consent-based analytics.

| Laravel Cloud | Covered in this document |
|---|---|
| Lemon Squeezy | Covered in this document |
| Consent-based PostHog | Covered in this document |
Sections
Plain-language summary: These providers support the live Capell services identified below. Each should receive only the data needed for its job.
Current named providers
- Laravel Cloud: managed application and database hosting, networking, storage, logs and backups in the region selected for a customer instance.
- Lemon Squeezy: merchant and seller of record for paid Capell package checkout, payment, tax, receipts, refunds, disputes and related buyer support.
- GitHub: optional sign-in connection and private-repository access for eligible package purchases.
- PostHog: EU-hosted product analytics, loaded only after analytics consent.
Other operational providers
Capell may use the infrastructure and transactional-email provider configured for the Capell-operated account service. A production provider must be added to this list before it processes customer personal data. Customer-selected packages and integrations inside a customer instance are not Capell subprocessors merely because the customer installs them.
Access, contracts and changes
Provider access is limited by role and operational need. Capell requires subprocessors handling hosted customer data to protect confidentiality and security and to support deletion, incident and rights obligations. Material additions or replacements will be published here or notified through an agreed route before reliance in production, allowing a customer to raise a reasoned data-protection objection.