Last updated: June 24, 2026
This Privacy Policy explains how Apex Ecommerce Group LLC ("Apex", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Apex learning platform and mentorship program (the "Service"). It uses the same defined terms as our Terms of Service.
If you do not agree with this Policy, do not use the Service. For privacy questions or to exercise your rights, contact us at admin@apexecommerce.co.
The data controller responsible for your personal information is Apex Ecommerce Group LLC, located at 30 N Gould St Ste R, Sheridan, WY 82801, United States. Contact: admin@apexecommerce.co.
We collect the categories of personal information below to provide the Service, secure your account and protect our content, communicate with you, and comply with law. We do not sell your personal information and do not "share" it for cross-context behavioral advertising. We retain information as described in Section 7. Details follow.
A. Discord account data (via OAuth login). When you log in with Discord, we request only the access needed to identify you and confirm your membership: we receive your Discord ID, username/handle, avatar, and email address, and we verify that you hold the paid "Member" role in the Apex Discord server. We do not request access to your Discord messages, friends, or other servers beyond what is needed to confirm your membership and the "Member" role.
B. Identity and recovery data (optional). We may collect and verify an email address and a phone number (via an SMS one-time code) for account recovery, security, and accountability.
C. Learning and submission data. Watch/progress data (which lessons you've watched and your completion progress), homework files you upload, product-test journal entries and any files you upload to them, and mentor notes and messages exchanged about your submissions.
D. Security and anti-piracy telemetry. IP address, device and browser information, and session information. Your IP address can indicate an approximate, city or country level location; we do not collect precise GPS location and do not track your physical movements. These are personal data. We use them to secure your account, enforce the one-active-session rule, detect abuse, maintain a security and activity log of events such as logins and content access, and power the per-user content watermark.
E. Watermark/identity embedded in content. To protect content and make it traceable, your Discord handle/identifier and a timestamp are embedded as a visible watermark into videos while you watch, and identifying information may be stamped onto downloadable resources/images. You acknowledge this when you sign up (see Terms, Section 6). The legal basis for this is in Section 4.
F. Communications. Messages you send us (for example, support requests) and our transactional emails to you.
We do not knowingly collect special-category/sensitive personal data, and you should not submit it in homework or journal entries. Certain data we collect (account log-in credentials) may be treated as "sensitive personal information" under some U.S. state laws; we use it only to provide and secure the Service, not to infer characteristics about you (see Section 9).
We use your information for the purposes below. Where the GDPR or UK GDPR applies, the legal basis is shown.
| Purpose | Examples | Legal basis (where GDPR/UK GDPR applies) |
|---|---|---|
| Provide the Service | Authenticate you via Discord, gate access by "Member" role, deliver lessons, store and review homework/journal entries, enable mentor feedback | Performance of a contract; legitimate interests |
| Content protection & traceability (watermark) | Embed your Discord handle/identifier and a timestamp into video playback and stamp downloadable resources so content is licensed to and traceable to you; investigate and act on leaks | Performance of a contract and our legitimate interest in protecting high-value intellectual property and our members; this is a condition of access, not optional consent |
| Account security & anti-piracy | Enforce one active session, detect/prevent fraud, abuse, sharing, and content theft, investigate violations | Legitimate interests (protecting our content, members, and business); legal obligation where applicable |
| Identity verification & recovery | Verified email and SMS one-time codes (transactional only, not marketing) | Performance of a contract; legitimate interests; consent where required |
| Communications | Send transactional emails (e.g., notifications, approvals, security alerts) and respond to support | Performance of a contract; legitimate interests |
| Improve the Service | Understand usage and fix problems | Legitimate interests |
| Legal & compliance | Enforce our Terms, comply with law, and establish/exercise/defend legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing test: our interest is protecting high-value intellectual property, our members, and our business from content theft and account sharing; we considered your reasonable expectations (you are told before sign-up that your identity is embedded in playback) and your privacy, and we use the minimum data needed (your Discord handle or identifier and a timestamp for the watermark, and IP, device, and session data for security). We concluded these interests are not overridden by your rights, given the targeted, security-only use and the prominent up-front disclosure. The per-user watermark and identity embedding are a condition of access, not optional consent: they cannot be switched off while you use the Service, because they are how the content is protected. You may object to legitimate-interests processing (Section 9), but where processing is strictly necessary for security, anti-piracy, or providing access, an objection may mean we can no longer provide the Service to you. You can request a summary of our balancing assessment at admin@apexecommerce.co. Where we rely on consent (for example, where SMS verification requires it), you may withdraw it as described in Section 9.
Our anti-piracy and abuse controls (watermark traceability, the one-active-session rule, and security telemetry) help us detect possible violations and can lead to account suspension or termination. We do not make decisions producing legal or similarly significant effects about you solely by automated means: a human reviews and decides any enforcement action that has a significant effect on you, so the safeguards in Article 22(3) of the GDPR apply. You have the right to obtain human intervention, to express your point of view, and to contest the decision, and you may request human review as described in the Terms (Section 13). Account access may be revoked automatically when your Discord "Member" role is removed (a human action in Discord); any account termination or suspension decision is made or reviewed by a person.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are used under U.S. state privacy laws. The Service has no advertising network and no public, social, leaderboard, or member-to-member marketplace features. Because we do not sell or share, there is no sale/share to opt out of; we have no obligation to act on opt-out preference signals (such as Global Privacy Control) for that purpose, though we honor applicable rights as described in Section 9.
We share personal information only as needed to run the Service, with the following recipients:
| Provider | Role | Data involved |
|---|---|---|
| Discord | Login/identity and community | Discord ID, username, avatar, email, role/membership |
| Supabase | Database, file storage, and authentication | Account data, progress, homework and journal files, messages, security telemetry |
| Bunny | DRM-protected video hosting and per-user watermarking | Your Discord handle/identifier and a timestamp (transmitted so they can be burned into the video you watch), plus playback/session data |
| Vercel | Web/application hosting | Technical and request data needed to serve the app |
| Sentry | Error tracking and performance monitoring | Diagnostic error and performance data, configured to exclude IP addresses and personal data |
| Twilio | Phone-number verification via SMS | Phone number and one-time verification messages |
These providers act as our processors and process data only on our documented instructions under data-processing agreements (DPAs) that include the confidentiality, security, sub-processing, and (for international transfers) Standard Contractual Clauses terms required by Article 28 of the GDPR. We have executed, or will execute before relying on them, a DPA with each provider listed above. We may also disclose information (a) to comply with law, legal process, or government requests; (b) to enforce our Terms and protect our rights, content, members, and safety (including investigating and acting on content theft or account sharing, and supporting takedown notices using the watermark identifier); and (c) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We maintain the list of providers above and will update this Policy and provide reasonable notice before adding a new processor or materially changing how an existing one handles your data.
We and our providers (including Supabase, Discord, Bunny, Vercel, Sentry, and Twilio) may process and store your information in countries other than where you live, including the United States. These countries may have data-protection laws different from yours. For transfers out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum or Swiss equivalent where applicable) and supplementary measures. Contact us for a copy of the relevant safeguards.
Depending on where you live, you may have rights to:
For California residents (CCPA/CPRA) and residents of other U.S. states with similar laws: you have rights to know, access, correct, and delete your personal information, to limit the use of sensitive personal information, and to not receive discriminatory treatment for exercising these rights. For transparency:
As noted in Section 6, we do not sell or "share" personal information for cross-context behavioral advertising.
To exercise any right, contact us at admin@apexecommerce.co (you may also reach us through the designated Discord support channel). We will verify your request (typically using your Discord identity and/or verified email or phone). Where the GDPR or UK GDPR applies, we respond within one month of receiving a verifiable request (extendable by up to two further months for complex requests, with notice). Where U.S. state privacy laws apply, we confirm receipt within 10 business days and respond within 45 days (extendable once by a further 45 days with notice). We do not charge a fee for exercising your rights except where a request is manifestly unfounded, excessive, or repetitive, as permitted by law. You may use an authorized agent where the law allows. If we decline a request, we will tell you why and how to appeal or complain.
We keep personal information for as long as your account is active and as needed to provide the Service, and afterward as needed to comply with legal, tax, and accounting obligations, enforce our Terms and resolve disputes, and maintain security records and investigate content theft or abuse. We use the following categories and criteria:
| Data category | Retention approach |
|---|---|
| Account & Discord profile data | Kept for the life of the account, then deleted or anonymized within 90 days of a deletion request |
| Homework/journal files & messages | Deleted with your account, then purged from backups on the cycle below |
| Security & anti-piracy telemetry (IP, device, session) and leak-investigation records | 12 months, retained as needed to investigate and act on abuse, then removed by a scheduled purge |
| Soft-deleted/deactivated records held in a hidden/locked state | No longer than 90 days, after which they are anonymized or hard-deleted |
| Backups | Purged on our normal 30-day backup cycle |
The Service supports data export and deletion: when an account is deleted or deactivated, we first place certain records in a hidden/locked state (for example, to preserve homework and journal history, prevent account "resurrection," and meet legal and security needs), and we then anonymize or permanently delete your personal information within the maximums above (no longer than 90 days for soft-deleted records) by an automated process. The only exceptions, kept after that window and to the extent permitted by law, are your consent and acceptance records and our security and anti-piracy activity logs (for example, login and content-access events with IP address and device), which we retain only for as long as reasonably needed to establish, exercise, or defend legal claims, prevent fraud, and protect our content. You can ask us to erase your data sooner by contacting admin@apexecommerce.co, subject to those same legal-claims and security exceptions.
We use technical and organizational measures designed to protect your information, including private (non-public) file storage with short-lived signed access links, access controls, DRM and per-user watermarking for video content, the one-active-session rule, and server-side permission checks. Staff with access to member data use additional protections such as two-factor authentication. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law (for example, where the GDPR applies, notifying the supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay).
The Service uses only essential cookies and similar local/session storage that are strictly necessary to run it, including:
These are set when you log in and expire on logout or after 7 days. We use no advertising or cross-site tracking cookies. Our error-monitoring provider (Sentry) is configured not to capture your IP address or other personal data and is used for diagnostics, not advertising. If we use hosting-level performance measurement from Vercel, it is configured to be privacy-friendly and cookieless and is not used to build a profile of you or for advertising. You can control cookies through your browser settings, but disabling essential storage may prevent the Service from working.
The Service is not directed to children under 13, and Discord itself requires users to be at least 13. If you are under 18 (or the age of majority where you live), you may use the Service only with a parent or legal guardian's consent, as described in our Terms. We do not knowingly collect personal information from children under 13. If we learn we have collected data from a child under 13 (or under any minimum age required by law), we will hard-delete it (not place it in soft-deletion/retention) and terminate the account. If you believe a child has provided us information, contact us at admin@apexecommerce.co.
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date and provide reasonable notice through the Service or the Discord server. Your continued use of the Service after changes take effect means you accept the updated Policy.
We are established in the United States and have no establishment in the EU or UK. To the extent Article 27 of the GDPR or UK GDPR requires a U.S. controller that offers services to people in the EEA or UK to appoint an in-territory representative, we will appoint one and update this Policy with their name and contact details (or state the applicable exemption under Article 27(2)). We have not appointed a Data Protection Officer because we are not required to under Article 37; our privacy contact for all questions and requests is admin@apexecommerce.co. You also have the right to lodge a complaint with your local data-protection or privacy authority (for EEA residents, your national supervisory authority; for UK residents, the Information Commissioner's Office; for California residents, the California Privacy Protection Agency or the Attorney General).
Apex Ecommerce Group LLC 30 N Gould St Ste R, Sheridan, WY 82801, United States Email: admin@apexecommerce.co Or reach us through the designated Discord support channel.