01 · Active integrations
No advertising, analytics or social SDK is active.
The Next.js application and Go/MySQL service are first-party code. External museum and archive links open third-party websites but do not, by themselves, embed those parties' trackers. The game manifest may be fetched from a configured game origin; production must identify that operator if it is not the same Age of Seas operator.
- +Advertising networks: none
- +Analytics providers: none
- +Social login providers: none
- +Embedded support/chat providers: none
02 · Hosting and delivery
Production provider not yet disclosed.
Potential data: IP address, request headers, URL, timestamps, response and security logs, and hosted database content where the provider supplies infrastructure. Purpose: host, deliver, back up and protect the service. Role: entrusted processor/service provider unless it independently determines a purpose.
Launch requirement: publish legal entity, service, processing location, retention, safeguards and privacy-policy URL; sign appropriate data-protection terms.
- +Status: must be completed before production
- +No secondary advertising use
- +Access limited to service delivery and support
- +Cross-border transfer assessment where applicable
03 · Payment
Provider not selected; checkout remains disabled.
Potential data: order reference, amount, currency, account reference, checkout return URL, provider payment ID, payment/refund status, risk signals and the payment credentials the provider collects directly. Purpose: checkout, fraud prevention, settlement, refunds and disputes.
Launch requirement: name the payment entity and privacy link, separate provider-collected credentials from Age of Seas fields, document international transfer if any, and provide the Purchase and Refund Policy before payment.
- +Development payment adapter is forbidden in production
- +No live payment collection today
- +Age of Seas should not receive full card security codes
- +Provider notices apply to its independent processing
04 · Email and support
Provider not selected.
Potential data: recipient and sender address, message metadata/content, delivery events and support attachments. Purpose: verification, security, transaction notices and support requested by the user. Marketing, if introduced, requires a separate choice and a free unsubscribe method.
Launch requirement: name the provider, region, retention and privacy link, and configure access and deletion controls.
- +No marketing provider in current code
- +No purchased mailing lists
- +Transactional and marketing purposes remain separate
- +Sensitive attachments require a secure channel
05 · Legal disclosure and business change
A lawful disclosure is not a standing data feed.
We may provide the minimum relevant information to a competent authority, court, payment network or professional adviser when legally required or necessary to protect rights. We assess the authority and scope where permitted and preserve a record.
In a merger, acquisition, restructuring or asset transfer, affected users will receive notice of the recipient and choices required by law; the recipient must continue to honour this policy or obtain new consent.