Legal summary
Capell Subprocessors List
The provider categories Capell may use, the data-access limits that apply, and how material provider changes are communicated.
| Hosting | Covered in this document |
|---|---|
| Payments | Covered in this document |
| Support tools | Covered in this document |
Sections
Plain-language summary: Capell uses specialist providers to run parts of the service. Each provider should see only what its job requires, Capell keeps its own responsibilities, and material changes should be disclosed through this page or an agreed notice route.
Why providers may process data
Capell may use subprocessors and service providers for hosting, email, analytics, payments, support, error monitoring, authentication, repository access, marketplace operations, and security review.
Each provider should only receive the data needed for its role. Access may include account identifiers, email addresses, support messages, payment references, request metadata, logs, marketplace telemetry, and technical evidence needed to operate Capell services.
Capell does not treat subprocessors as a way to avoid its own responsibilities. Provider selection should support the product, marketplace, package access, security, and customer-support workflows described across the legal pages.
Current provider categories
- Hosting and infrastructure providers for application hosting, storage, networking, queues, cache, backups, and operational logs.
- Email and notification providers for verification, transactional messages, marketplace notices, security advisories, and support responses.
- Payment and billing providers for purchases, subscriptions, receipts, tax handling, refunds, disputes, and licence-related billing support.
- Authentication and repository providers where users connect GitHub or related developer accounts.
- Analytics, monitoring, and error reporting providers where optional analytics or operational diagnostics are enabled.
Limits on provider access
Provider access should be limited by role, environment, contract, and operational need. An email provider may need recipient details and message metadata; a payment provider may need billing references and transaction records.
Services this list does not cover
Customers remain responsible for the hosting providers, packages, logs, backups, analytics, and third-party integrations in their installed sites. This list covers Capell-operated services, not every provider selected by a site owner inside their own Laravel application.
How provider changes are handled
Capell may add, replace, or remove providers as the product changes. Material provider changes should appear here before customer workflows rely on them in production.
Customers with a written agreement that requires subprocessor notices should use the contact route in that agreement or the public legal contact route to request notice handling.
If a change materially affects account access, package delivery, payment handling, security reporting, or marketplace operations, Capell should update this page or the relevant customer notice path with enough context for customers to assess it.