← Back to Apex

Privacy Policy

Effective: August 16, 2026·Version 2026-08-16.1

1. Who this covers

Apex, Inc. (“Apex,” “we,” “us”) operates the Apex website and the Apex platform (the dashboard, APIs, snippet, SDKs, MCP server, Adaptive Journeys, communications, experimentation, attribution, and partner network).

This policy has two audiences:

  • Apex customers and site visitors. If you create an Apex account or visit apex.inc, Apex is the controller of your Account Data.
  • End Users of our customers. If you visit a merchant’s site or app that uses Apex, that merchant is the controller. Apex is their processor, except for Derived Data and, if the merchant has enabled it, the Data Co-op, where Apex is an independent controller of de-identified outputs.

Processing of Customer Data is also governed by the Data Processing Agreement and the Terms of Service.

2. Information we collect

2.1 Account Data (Apex as controller)

  • Name, email, company, role, and authentication identifiers (via our authentication service or OAuth).
  • Billing contacts, payment-method tokens (held by Stripe), and usage records.
  • Workspace settings, team membership, and support correspondence.
  • Product-usage telemetry: pages viewed, features used, and performance of the dashboard itself.

2.2 Customer Data (Apex as processor)

When a merchant installs the snippet or SDKs, or connects an integration, Apex collects on that merchant’s instructions:

  • Identifiers: first-party visitor ID (apex_vid), session ID (apex_sid), known-user ID when the merchant calls apex.identify() (apex_eid), IP address, user-agent, and (where the merchant’s mobile app and consent allow) IDFA, GAID, or IDFV.
  • Attribution: UTM parameters, click IDs, referrer, campaign information (apex_attr, apex_sattr).
  • Behavior: page URLs, events, conversions, experiment assignments, form-field values if the merchant enables form interception.
  • Identity and CRM: traits the merchant sends (email, name, commercial state, custom attributes), contacts, and segments.
  • Programs: experiment designs and outcomes, journey definitions, communication content and delivery receipts, partner-program records.
  • Connected platforms: campaign metadata and performance the merchant authorizes Apex to read from Meta, Google, LinkedIn, Stripe, HubSpot, Shopify, and similar integrations. When the merchant enables outbound conversions or audience sync, Apex sends the payloads the merchant configured.

2.3 Partner social connections

If you connect Instagram, YouTube, or TikTok to an Apex Partner profile, Apex reads the scopes listed in Section 10. Tokens are encrypted at rest and never shown to merchants.

2.4 MCP and agent tools

The MCP server sends experiment, journey, and workspace-configuration data required to run tools. It does not transmit source code, file contents, repository structure, or conversation history from your development environment.

3. How we use information

  • Provide the Service: run experiments, journeys, communications, attribution, partner programs, and the dashboard.
  • Improve the Service: train, calibrate, and fine-tune models, scoring, beliefs, and recommendations using Customer Data as instructed in the Terms. Raw Customer Data is not shown to another merchant.
  • Data Co-op (only if the merchant enables it): contribute the de-identified categories listed in that workspace’s settings (today: hashed advertising performance summaries) to a cross-merchant pool and return industry benchmarks. Default is off. No price penalty for staying out.
  • Secure the Service: fraud, abuse, debugging, and incident response.
  • Communicate: transactional and security messages. Marketing email only with a separate opt-in, and you can unsubscribe.
  • Bill and comply: usage metering, taxes, and legal process.

4. Legal bases (GDPR / UK GDPR)

  • Contract (Art. 6(1)(b)): Account Data and processing needed to deliver the Service you asked for.
  • Legitimate interests (Art. 6(1)(f)): security, fraud prevention, and Service Improvement that produces de-identified Derived Data. Those interests are balanced against End User rights; merchants remain responsible for their own End User notices.
  • Consent (Art. 6(1)(a)): Apex marketing to you; outbound ad-network sharing where the merchant’s CMP signal requires it.
  • Contract / documented instruction (Art. 6(1)(b) and Art. 28): a merchant’s workspace toggle to join the Data Co-op is that merchant’s instruction to Apex, not End User consent. The merchant must have its own lawful basis for any End User data that instruction covers.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and compulsory process.

Each workspace records a legal basis for End User processing (consent, legitimate_interest, or contract) in privacy settings. Apex does not invent a basis the merchant has not set.

5. How we share information

We do not sell personal information for money. We share as follows:

  • Sub-processors that host or help operate the Service, listed at /legal/sub-processors.
  • Integrations you connect: Meta, Google, LinkedIn, Stripe, and others receive only what you enable. Those platforms process under their own terms.
  • Data Co-op outputs: only de-identified aggregates, and only if you enabled the program. Other merchants see industry ranges, not your workspace.
  • Legal process and to protect rights, safety, and the Service.
  • Business transfers: merger, acquisition, or sale of assets, with notice where required.

Under the California CPRA, some sharing with ad networks that you enable can be “sharing” for cross-context behavioral advertising. That sharing is your instruction. Apex injects Meta Limited Data Use for California End Users on CAPI and audience rows. End Users should use the merchant’s privacy controls and, where applicable, a Global Privacy Control signal the merchant honors.

6. Cookies and similar technology

The snippet uses first-party cookies on the merchant’s domain. Apex does not set third-party advertising cookies.

CookiePurposeDuration
apex_vidPseudonymous visitor identifier1 year
apex_sidSession identifier (idle timeout 30 minutes)1 year
apex_attrAttribution (UTM, click IDs)1 year
apex_sattrAttribution for the current visit1 year
apex_eidKnown-user identifier, set only after apex.identify()1 year
apex_consent_v2Consent signal on Apex-owned sites (not a substitute for the merchant’s CMP)1 year

Merchants must run their own CMP for End Users. Apex accepts consent via apex.setConsent, event properties, the Apex-Consent header, or an IAB TCF v2 string.

Apex-owned sites (app.apex.inc, partners.apex.inc, apex.inc) also set authentication and session cookies required to sign you in. Those are strictly necessary. Apex does not run third-party advertising pixels on those sites.

7. Retention

  • Account Data: life of the account, then up to 90 days after closure.
  • Customer Data: life of the workspace, then export for 30 days and deletion within 90 days.
  • Tracking events: typically 13 months unless an Order Form says otherwise.
  • Install attribution: typically 24 months.
  • Communication bodies: typically 90 days; delivery metadata may be kept longer.
  • Partner payout and tax records: as required by law, often 7 years.
  • Derived Data and Co-op aggregates: retained as de-identified datasets.
  • Backups: rolling deletion, typically within 35 days.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing, and to appeal a denial. End Users should contact the merchant first. Apex will assist the merchant. Apex-account holders can email privacy@apex.inc. We respond within the time the applicable law requires (typically 30 days, extendable as permitted).

California notice at collection (Account Data): we collect identifiers, commercial information, and internet activity as described in Section 2.1 to provide and secure the Service, bill you, and communicate with you. Retention is in Section 7. We do not sell personal information for money. You may opt out of “sharing” by disabling outbound ad integrations in the merchant’s Apex workspace, or by using the merchant’s End User controls. You may limit use of sensitive personal information by not sending it to Apex.

9. International transfers

Apex processes in the United States unless an Order Form specifies another region. Transfers from the EEA, UK, or Switzerland rely on the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, plus encryption in transit and at rest. Request the SCC package at privacy@apex.inc.

10. Social platform integrations (Partner Network)

Connecting Instagram, YouTube, or TikTok is optional. You can revoke access in the Partner portal or on the platform.

10.1 Instagram (Meta Graph API)

Scopes: instagram_business_basic, instagram_business_manage_insights. Apex reads username, profile, account type, follower and media counts, and aggregated audience demographics (shares, never individual accounts).

10.2 YouTube (YouTube Data API v3)

Scope: youtube.readonly. Apex reads channel id, handle, title, thumbnail, subscriber / view / video counts, and public-video statistics used to compute engagement rate. Apex does not request YouTube Analytics demographic scopes.

10.3 TikTok (Login Kit)

Scopes: user.info.basic, user.info.profile, user.info.stats, video.list. Apex reads open id, username, display name, avatar, and public counts. TikTok does not provide viewer demographics to third-party developers.

Tokens are encrypted (AES-256-GCM), never returned to the browser, never logged, and never shared with merchants. Stats refresh about weekly. Disconnecting marks the record inactive; hard-delete on request or after 12 months. Merchants see public profile fields only.

11. Security

Apex uses TLS in transit, encryption at rest, IAM least-privilege, workspace isolation at the data layer, and access logging. No system is perfectly secure. Details: /security.

12. Children

The Service is not directed to children under 18. We do not knowingly collect their data. If we learn we have, we will delete it.

13. Changes

We will post updates with a new effective date. Material changes are announced by email or in-product notice where required. Continued use after the effective date is acceptance.

14. Contact

Apex, Inc. privacy@apex.inc.