Charming Seal

Charming Seal·Sub-processors

Three vendors, and none of them near your shop.

Charming Seal is software you download and run on your own infrastructure, so the only vendors this project can list are the ones that serve these pages. The longer list, the one that matters to your buyers, is the set of vendors you choose yourself.

In effect 26 July 2026Version 1.0

1. Why the list is short

A sub-processor list is normally long because the company publishing it holds your data and hands parts of it to other companies. This project holds none of it. Nothing about a shop, a buyer, an order, a card or a Stripe key ever reaches it, so there is nothing to hand on.

2. No sub-processors for shop or buyer data

The project has no sub-processors at all for customer or buyer data. Your deployment runs on your infrastructure under credentials only you hold, and there is no telemetry, no phone-home and no console on this side. The DPA sets out who is controller of what, and why no processor relationship arises.

3. The sub-processors that run this website

These three vendors are involved in serving charmingseal.com and in running the project in the open. For this data Charming Seal is the controller, as the privacy notice explains.

VendorPurposeData involved
Vercel Inc. (United States)Website hosting and content deliveryRequest logs, which include IP address, user agent, requested URL and timestamp
GoogleWeb font delivery from fonts.googleapis.com and fonts.gstatic.comVisitor IP address, and the user agent the browser sends with the request
GitHubSource hosting, issues, discussions and pull requestsWhatever a person chooses to post, and the account they post it under

4. Email

Mail sent to hello@charmingseal.com passes through the provider that hosts the address, which necessarily receives the contents of the message and the sender's address, and stores them. The provider is not named on this page. If you need it for an assessment, ask and you will be told. As the privacy notice says, do not send card numbers, API keys or passwords to that address, or to anyone.

5. The vendors you will end up using

A working shop needs vendors, and you choose every one of them. Typically they are your host, a Postgres provider such as Supabase or Neon, Stripe, PayPal if you enable it, whatever sends your email, and your domain registrar.

Those are your sub-processors, not this project's. They receive your buyers' personal data because your deployment sends it to them, under your account, on your instructions. You need your own agreement with each, and each publishes a DPA for exactly that purpose. When a customer or an auditor asks who processes their data, that list is the honest answer, and this page is not a substitute for compiling it.

The one on that list nobody should skim past is your payment provider. Your PCI DSS obligations run through them, under your agreement with them, and the terms of use state why they cannot run through this project.

6. Changes to this list

If a vendor is added or removed, this page is updated and the date and version at the top move with it. A change will also be noted in the repository, so the record lives somewhere outside this website and can be checked against its history. No cookie is set here and no address list is held, so there is no way to notify anyone directly. Building one would mean collecting the data this site does without.

7. Questions

Write to hello@charmingseal.com, the single address for every enquiry. The companion documents are the DPA, the privacy notice, the terms of use and the acceptable use policy.