Charming Seal

Charming Seal·Acceptable use

Acceptable use. One half is a rule, the other is a request.

This policy binds your use of this website and of the project's own spaces, where the project can actually act. For the software it can only ask, because the MIT licence permits any use and deliberately does not let anyone take that permission back. Both halves are marked, so nobody mistakes one for the other.

In effect 26 July 2026Version 1.0

1. What this policy is

Charming Seal is software you download and run on your own infrastructure. The project operates this website and nothing else. It never receives your shop data, your buyers' data, card data or your Stripe keys, and it holds no switch that could suspend a deployment.

So this document does two different jobs. Sections 2 and 3 are rules for the places the project runs, and they are enforceable because the project decides who uses them. Sections 4 and 5 are a statement of what the project will not help with, and they are not licence conditions. The MIT licence cannot restrict use, and adding a restriction in a policy page would be theatre.

2. Where it binds

This policy applies to charmingseal.com and to the project's own spaces: the repository, its issues, discussions and pull requests, and any other venue the project runs. Those spaces also sit under the platform's own rules, which apply on top of these.

3. Not permitted here

  • Attacks and probing. Do not attack the site, scan it for vulnerabilities, attempt to gain access to anything not published, or interfere with anyone else's use of it. Genuine security research on the software belongs in the private reporting route, against your own copy, not against this host.
  • Scraping that degrades the site. Reading the pages is fine, and the source is public. Automated collection at a rate that slows the site for other people is not.
  • Impersonation. Do not present yourself as the project, as its maintainers, or as an authorised representative, reseller or support channel for it. The terms of use cover the name and the artwork.
  • Harassment. Abuse, threats, targeted pile-ons and personal attacks in the project's spaces. Disagreement about code is welcome and belongs in the open. Contempt for the person on the other side of it is not.

4. A request, not a condition

What follows is a request. It is not a term of the licence, it does not restrict your rights under the MIT licence, and breaching it does not put your grant at risk. Nobody can revoke your copy, and nobody here can see what you do with it. This section exists because a project that ships payment code should be willing to say what it thinks that code is for.

5. What we ask of the software

Please do not use Charming Seal to take payments for any of the following.

  • Fraud and laundering. Payments obtained by deception, and any arrangement whose purpose is to move criminal proceeds or to disguise where money came from.
  • Sanctioned parties. Business with people, entities or territories subject to applicable sanctions.
  • Goods and services that are illegal where the parties sit. Illegal at the seller's end or the buyer's end is enough. Selling across a border is your problem to work out, not a loophole.
  • Card testing. Running stolen or generated card numbers through a checkout to find the ones that work, with or without a real product behind it.
  • Deceptive checkouts. A page that misrepresents the price, the currency, whether a charge recurs and how often, or who the seller is. The theme customiser exists to make a checkout look like your shop, not like somebody else's.
  • Unread code in the card path. Do not put a buyer's card details through code you have not read. That includes forks, patches and dependencies you picked up from somewhere you cannot vouch for. Being able to read every line is the point of shipping the source.

6. Your payment providers' rules

Stripe and PayPal each publish their own acceptable use rules, and those apply to your business whatever this page says. They are enforced by them, not by this project, and they have the tools for it: a held payout, a reserve, a closed account. A prohibited-business list is worth reading before you build a shop around a product, rather than after the first payout stops.

7. Reporting abuse

Write to hello@charmingseal.com if someone is using the Charming Seal name, wordmark or artwork to imply that this project endorses, maintains or supports their service, or if you have found a deployment doing one of the things in section 5. Say what you saw and where, with a URL if you have one. Security vulnerabilities go through SECURITY.md instead, privately, never as a public issue.

8. What can actually be done

The honest inventory of enforcement. The project can remove someone from its own spaces and decline to serve them this website. It can act on misuse of its name and artwork, which are not covered by the licence. It can report a deployment to the host or the payment provider that does hold power over it.

What it cannot do is reach into a deployment, disable one, see what any of them are selling, or take back a licence grant. Anyone promising otherwise about self-hosted software is describing something else.

9. Questions

Write to hello@charmingseal.com, the single address for every enquiry, read by one person. The companion documents are the terms of use, the privacy notice, the DPA and the sub-processor list.