AOS / D02 · Third-party processing list

Third-Party Processing and Sharing List

No production third-party vendor is named in the repository configuration reviewed on the update date. A category marked 'not selected' must not be enabled until its legal name, data fields, purpose, role, location and privacy link are published here.

Status
Public version
Last updated
20 August 2026
Sections
05

01 · Active integrations

No advertising, analytics or social SDK is active.

The Next.js application and Go/MySQL service are first-party code. External museum and archive links open third-party websites but do not, by themselves, embed those parties' trackers. The game manifest may be fetched from a configured game origin; production must identify that operator if it is not the same Age of Seas operator.

  • +Advertising networks: none
  • +Analytics providers: none
  • +Social login providers: none
  • +Embedded support/chat providers: none

02 · Hosting and delivery

Production provider not yet disclosed.

Potential data: IP address, request headers, URL, timestamps, response and security logs, and hosted database content where the provider supplies infrastructure. Purpose: host, deliver, back up and protect the service. Role: entrusted processor/service provider unless it independently determines a purpose.

Launch requirement: publish legal entity, service, processing location, retention, safeguards and privacy-policy URL; sign appropriate data-protection terms.

  • +Status: must be completed before production
  • +No secondary advertising use
  • +Access limited to service delivery and support
  • +Cross-border transfer assessment where applicable

03 · Payment

Provider not selected; checkout remains disabled.

Potential data: order reference, amount, currency, account reference, checkout return URL, provider payment ID, payment/refund status, risk signals and the payment credentials the provider collects directly. Purpose: checkout, fraud prevention, settlement, refunds and disputes.

Launch requirement: name the payment entity and privacy link, separate provider-collected credentials from Age of Seas fields, document international transfer if any, and provide the Purchase and Refund Policy before payment.

  • +Development payment adapter is forbidden in production
  • +No live payment collection today
  • +Age of Seas should not receive full card security codes
  • +Provider notices apply to its independent processing

04 · Email and support

Provider not selected.

Potential data: recipient and sender address, message metadata/content, delivery events and support attachments. Purpose: verification, security, transaction notices and support requested by the user. Marketing, if introduced, requires a separate choice and a free unsubscribe method.

Launch requirement: name the provider, region, retention and privacy link, and configure access and deletion controls.

  • +No marketing provider in current code
  • +No purchased mailing lists
  • +Transactional and marketing purposes remain separate
  • +Sensitive attachments require a secure channel

05 · Legal disclosure and business change

A lawful disclosure is not a standing data feed.

We may provide the minimum relevant information to a competent authority, court, payment network or professional adviser when legally required or necessary to protect rights. We assess the authority and scope where permitted and preserve a record.

In a merger, acquisition, restructuring or asset transfer, affected users will receive notice of the recipient and choices required by law; the recipient must continue to honour this policy or obtain new consent.

Next route

Optional tracking remains off unless it is disclosed and chosen.

Read the Cookie Policy