Politique de Confidentialité

Politique de Confidentialité

Last Updated: October 04, 2025 - Effective Date: October 04, 2025

Who we are

  • HyperMesh Network Pte. Ltd. (trading as “ApexVerify”)
  • Company number: 202528445W
  • Address: 68 Circular Road, #02-01, 049422, Singapore
  • Contact: contact@apexverify.com

What this policy covers

  • This privacy policy explains how we (as data controller) collect and use personal data about:
  • When you upload contact data (emails, phone numbers, postal addresses) to run verifications, we usually act as your data processor. Those activities are covered by our Data Processing Agreement (DPA).

Quick summary

  • We respect your privacy. Our website does not load any analytics or advertising cookies until you provide consent through our cookie banner (powered by Cookiebot).
  • If you opt in, we may use Google Analytics 4, Google Ads, Microsoft/Bing Ads, and LinkedIn Ads cookies.
  • We do not sell your personal data.
  • You can change or withdraw cookie consent at any time via “Cookie Settings” on our site.

Personal data we collect

  1. Data you give us
  • Account and profile: name, email, OAuth info (Google, Apple, Facebook, LinkedIn, GitHub), company details, VAT number, country.
  • Communications: emails or messages you send to support.
  • Billing references: purchase records from Stripe (we don’t store full card numbers).
  1. Data we collect automatically
  • Essential logs (no consent needed): IP address, device/browser info, pages visited in our app, timestamps, API usage, error and security logs. Used to run, secure, and troubleshoot the service.
  • Cookies and similar tech (consent-based):
    • Analytics: Google Analytics
    • Advertising/measurement (only if you opt in): Google Ads, Microsoft/Bing Ads, LinkedIn Ads.

How we use your data and legal bases

  • Provide and secure the service (create and manage your account, authenticate you, provide support, prevent fraud and abuse): contract and legitimate interests.
  • Payments and invoices (via Stripe): contract and legal obligation.
  • Service messages (e.g., account, security, product updates): contract/legitimate interests. You can opt out of non-essential marketing at any time.
  • Analytics (to understand usage and improve our website and app): consent (only after you opt in).
  • Advertising and measurement (to reach or measure audiences): consent (only after you opt in).
  • Legal, compliance, and security: legal obligation and legitimate interests.

Cookies and consent (Cookiebot)

  • We use Cookiebot to collect your consent before setting non‑essential cookies.
  • Categories:
    • Necessary (always on; required for the site to work).
    • Preferences (optional).
    • Statistics/Analytics (optional); Google Analytics.
    • Marketing/Advertising (optional); Google Ads, Microsoft/Bing Ads, LinkedIn Ads.
  • Change/withdraw consent anytime: use the “Cookie Settings” link shown in our footer or cookie banner.
  • Your consent choices are logged by Cookiebot for compliance.

Sharing your data (processors and partners) We share personal data only with trusted service providers and only for the purposes above:

  • Hosting and infrastructure: Google Cloud Platform (EU regions), OVHcloud (EU data centers).
  • Consent management: Cookiebot by Usercentrics A/S.
  • Payments: Stripe.
  • Analytics/ads (only if you consent): Google Analytics, Google Ads, Microsoft/Bing Ads, LinkedIn Ads.
  • Professional advisors and authorities: where required by law or to protect rights and safety.

We do not sell your personal data.

International transfers

  • Primary storage and processing are in the EEA (EU regions of Google Cloud/OVHcloud).
  • Some providers may process data outside your country. When required, we rely on approved transfer tools (for example, Standard Contractual Clauses) and apply data‑minimization measures.

How long we keep data

  • Account data: while your account is active. If you delete your account, we delete personal data; we keep billing records as required by law.
  • Support communications: typically up to 24 months after the last interaction.
  • Essential logs (security/operations): typically up to 12 months.
  • Cookie consent logs (Cookiebot): typically up to 12 months.
  • Analytics data (GA4): retained only if you consent; we aim for a 14‑month retention setting unless we state otherwise in our Cookie Declaration.

Your privacy choices and rights

  • Cookies: change or withdraw consent via “Cookie Settings” at any time.
  • Email preferences: you can opt out of marketing emails from any marketing message we send.
  • Access, correction, deletion, portability, and restriction/objection (GDPR/UK GDPR/Swiss FADP): email contact@apexverify.com and we will respond without undue delay.
  • Singapore PDPA: you can request access and correction of your personal data; contact us at contact@apexverify.com.
  • California (CPRA): we do not sell personal information. If you consent to Marketing cookies, we may “share” data for cross‑context behavioral advertising via ad tags. You can opt out anytime by turning off Marketing cookies in “Cookie Settings.” Where supported, we honor browser signals like Global Privacy Control (GPC) as an opt‑out of sale/sharing.
  • If we act as your processor (verification data you upload), please use your account tools or contact us per the DPA; we will act on your instructions.

Authentification with Secure Providers (Oauth)

Authentication via Google OAuth

We provide the option to sign in or register for our Service using your Google account. When you choose to authenticate with Google OAuth, we receive limited information from your Google profile, such as your full name, email address, and profile picture.

This data is used exclusively for the following purposes:

  • To authenticate your identity and create or link your user account
  • To facilitate secure login without requiring a separate password
  • To personalize your account experience (e.g., displaying your profile name or image)

We do not access any additional data from your Google account beyond what is necessary for authentication.
We do not store your Google password or have access to your Google credentials.

Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you wish to revoke our access to your Google account, you may do so at any time from your Google Account permissions settings.

Authentication via Apple OAuth

We offer the option to sign in or register using your Apple ID. When you authenticate with Apple OAuth (“Sign in with Apple”), we receive limited information from your Apple account, such as your name and email address.

This data is used solely to:

  • Authenticate your identity and create or link your user account
  • Facilitate secure, password-free login
  • Personalize your user experience

Apple may also provide a private relay email address (ending with “@privaterelay.appleid.com”), which forwards messages to your real email address. We use this only for account-related communications.

We do not access or store your Apple ID password or any other Apple account data.
You may revoke our access at any time through your Apple ID settings.

Authentication via LinkedIn OAuth

You may choose to sign in or register using your LinkedIn account. When you authenticate with LinkedIn OAuth, we receive basic profile information such as your full name, email address, profile picture, and professional title (if available).

This information is used to:

  • Authenticate your identity and provide access to your account
  • Pre-fill your user profile
  • Improve your onboarding experience

We do not request or access any other LinkedIn data, such as your connections or activity.
You may revoke access at any time from your LinkedIn account settings.

Authentication via Facebook OAuth

We provide the option to sign in using your Facebook account. When you authenticate through Facebook OAuth, we may receive information from your public Facebook profile, including your name, email address, and profile picture.

This data is used exclusively for:

  • User authentication and account creation
  • Displaying your profile name or image within your account

We do not post content to Facebook on your behalf or access your friends list or activity data.
You may withdraw our access at any time via your Facebook settings.

Authentication via GitHub OAuth

You may sign in or register using your GitHub account. When you authenticate with GitHub OAuth, we receive basic account details such as your username, name, email address, and profile picture.

We use this information to:

  • Authenticate your identity and provide access to your account
  • Streamline registration for users from the developer community
  • Personalize your account experience

We do not request or access your repositories, code, or any other GitHub data unless explicitly required and consented to by you.
You can revoke our access at any time in your GitHub account settings.

Security

  • We use encryption in transit, access controls, secure hosting, logging and monitoring, backups, and other safeguards. No system is 100% secure, but we work to protect your data and review our controls regularly.

Children’s data

  • Our services are not directed to children. Do not use our sites or submit personal data if you are under 13 (or under 16 in the EEA) without proper consent.

Links to other sites

  • Our website may link to other sites. Their privacy practices are their own. Please review their policies.

Changes to this notice

  • We may update this notice. We will post the new date above and, for material changes, we will also notify you in‑app or by email.

Contact us

  • Email: contact@apexverify.com
  • Post: HyperMesh Network Pte. Ltd., 68 Circular Road, #02‑01, 049422, Singapore