Who we are
Apex Insights ("Apex", "we", "us") runs this website at getapexinsights.com and the Apex platform, a business operating system for operator-run companies such as restaurants, bars, event spaces and professional practices. The platform is reached at app.getapexinsights.com and, for some clients, at an address on the client's own domain.
Questions about this policy go to solutions@getapexinsights.com.
Two roles
Apex handles personal information in two different ways, and the rules differ.
- As the business you deal with directly. When you visit this website, fill in a form here, or hold a user account on the platform, Apex decides what is collected and why. The sections below describe that.
- On behalf of a client. The platform holds information about a client's guests, customers, staff and contacts, such as a reservation inquiry, a contact list for a newsletter, or a timesheet. That information belongs to the client. The client decides what is collected and why, and the client's own privacy policy governs it. Apex processes it only to run the platform for that client and under the agreement with that client. If you are a guest or customer of a business that uses Apex, contact that business about your information; we will help them answer you.
What we collect
On this website
- What you send us. A contact or inquiry form asks for your name, email address, company and what you want to talk about. We use it to reply to you.
- How the site is used. Standard web server records (the page requested, the time, your browser type and IP address) and, if you accept them, analytics cookies that tell us which pages are read. See Cookies.
On the platform
- Your account. Your name, work email address, role, the businesses you may act for, and a record of what you did in the platform (what you edited, published, sent or scheduled, and when). That record is kept so a client can see who changed what.
- Accounts you connect. The platform works by reading from and writing to systems a client already uses. When an authorized person connects one, Apex receives an access credential for it and stores that credential encrypted. The systems a client may connect include Google (Business Profile, Ads, Analytics and Tag Manager), Meta (Facebook and Instagram advertising and posting), Microsoft 365, point-of-sale and accounting systems, scheduling and reservation systems, email and messaging providers, and file storage. What Apex reads from each is listed in the platform under Settings, Connections, and in the authorization screen each provider shows when a connection is made.
- Your own AI assistant. A person may connect their own Claude account to Apex. When they do, their requests reach Apex through that connection and are recorded in the same activity record as any other change. Apex does not receive their conversations; it receives the request each tool call makes.
Information from connected platforms
Information received from Google, Meta and other platforms through a connection is used only to provide the features the client turned on, such as showing an ad account's spend, publishing a post the client wrote, or answering a review. It is not used to build profiles of individuals, it is not combined across clients, and it is not sold or shared with anyone else. Apex's use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Apex's use of information from Meta follows the Meta Platform Terms.
How we use it
- To run the platform and this website, and to reply to you.
- To keep accounts secure, find faults and keep a record of changes.
- To send operational messages about a client's account, such as a scheduled report or a notice that a connection needs attention.
- To meet legal obligations and enforce our agreements.
Apex does not sell personal information and does not use it for advertising to you. Parts of the platform use AI models to draft text and read documents at a person's request; what is sent to a model is the material needed for that request, under terms that do not allow the provider to train on it.
Who we share it with
Apex shares personal information only with the providers it needs to run the service, each bound to use it only for that purpose:
| Provider | What for |
|---|---|
| Google Cloud | Hosting, databases and file storage, in the United States |
| Email and SMS delivery providers | Sending the messages a client schedules and the platform's own notices |
| AI model providers (Anthropic, OpenAI, Google) | Drafting and reading at a person's request |
| The platforms a client connects | Only what the client asked the platform to do there |
We may also disclose information when the law requires it, to protect the rights and safety of Apex, our clients or others, or as part of a sale or merger of the business, in which case this policy continues to apply.
Cookies
This website sets the cookies it needs to work and, only if you accept them in the cookie notice, analytics cookies that tell us which pages are read. You can change that choice at any time from the cookie notice or in your browser. The platform uses cookies and similar storage to keep you signed in and to remember your settings; those are needed for it to work.
How long we keep it
- Website inquiries: as long as we are in touch about them, and for two years after.
- Platform accounts and activity records: for as long as the client's agreement runs, and for a limited period after it ends so the client can retrieve their records, after which they are deleted.
- Credentials for connected accounts: until the connection is removed or the client's agreement ends, whichever is first.
Security
Credentials for connected accounts are stored encrypted. Access to client information is limited to the people who need it to run the service, and to people a client has authorized. The platform keeps a record of who changed what. No system is perfectly secure, and we will tell affected clients promptly if we learn of a breach involving their information.
Your choices and rights
You can ask us to tell you what personal information we hold about you, to correct it, to delete it, or to stop using it for a particular purpose. Depending on where you live, these may be legal rights. Email solutions@getapexinsights.com and we will answer within 30 days. If the information belongs to a client of ours, we will pass your request to that client and help them answer it.
Deleting your data and disconnecting accounts
To have Apex delete information it holds about you, or to remove a connected account, do any of these:
- Remove a connected account in the platform. In Apex, open Settings, then Connections, and remove the connection. Apex deletes the stored credential and stops reading from or writing to that account.
- Remove Apex from the provider's side. For Meta, open your Facebook settings, then Apps and websites, and remove Apex. For Google, open your Google account's Security settings, then Third-party apps, and remove Apex. When a provider tells Apex a connection was removed, Apex deletes the stored credential and the information received through it.
- Ask us. Email solutions@getapexinsights.com from the address on your account and say what you want deleted. We confirm the request, delete the information within 30 days, and tell you when it is done. Records we must keep by law, and a client's own business records that mention you, are explained in the reply.
Children
This website and the platform are for businesses and the adults who work for them. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. A change that affects how your information is used is also announced in the platform before it takes effect.
Contact
Apex Insights, Boston, Massachusetts. solutions@getapexinsights.com.