Skip to main content
Menu
 

Privacy statement

Last updated: September 2026

ApexSafe ("we", "us") respects your privacy. Below you can read which personal data we process, why, who we share it with and what rights you have. We are the data controller within the meaning of the GDPR.

1. What data do we collect?

  • Question via the contact form: name, company name, email address, phone number and your message.
  • Order: name, email address, phone number, delivery address, what you ordered and the amount. For a business order also company name, company registration number and VAT number. Your payment runs through Mollie: we only learn whether it was paid and by which method, never your card or account number.
  • Withdrawal: name, email address, address, order number, date of receipt, product and any reason given.
  • Keep me posted: your email address, and if you fill them in also your company name, your trade and how many items you expect to need. Only if you sign up for a product that is not yet available.
  • Origin: with an order, a sign-up or a question via the contact form, we record which website or campaign link brought you to our site (for example Google or LinkedIn) and on which page you filled in the form. We keep only the name of that website, not the full address or your search terms. We place no cookies for this and store nothing in your browser.
  • Discount code: if you use a discount code with an order, we store the code and the discount amount with your order. If the code belongs to one of our partners, that partner receives a fee on the order; the partner does not see any of your details. Your browser remembers the code for up to 30 days so the discount is applied at checkout; how that works is explained further on.
  • Newsletter: your email address, only if you sign up for it.
  • Account: name, email address and password (stored encrypted, we cannot see it). For a business account also company name, company registration number and VAT number. Phone number and address only if you enter them yourself. If you log in with Google, we receive your name and email address from Google. If you add a profile photo yourself, we keep it in a shielded folder; only your own account can retrieve that photo.
  • Technical: IP address and browser information needed to run the website securely.

2. Purpose and legal basis

  • Answering your question: performance of, or steps prior to, a contract.
  • Processing, taking payment for and delivering an order: performance of the contract.
  • Handling a withdrawal: legal obligation.
  • Keeping invoices and records: legal obligation (tax retention requirement).
  • Emailing you once a product is available: your consent, which you can withdraw at any time by emailing us.
  • Keeping track of which channels customers use to find us: our legitimate interest in knowing which efforts work. This data is not shared and not used to build a profile of you.
  • Asking you for a review after an order, in our own email and via Trustpilot: our legitimate interest in showing how customers experience us. You can object to this at any time by emailing us.
  • Statistics via Google Analytics: your consent, which you can withdraw at any time via Cookie settings at the bottom of the page.
  • Sending the newsletter: your consent, which you can withdraw at any time.
  • Creating and maintaining your account: performance of the contract, because you ask for an account yourself.

3. Who do we share your data with?

We never sell your data. To run our website and administration we use the following processors:

  • Supabase: storage of quotes, orders, accounts and customer data. Logging in also runs through Supabase. Servers in the EU (Paris, France).
  • Cloudflare: hosting, security and visitor statistics for the website.
  • Google (Analytics): only if you give consent in the cookie banner: statistics on how the site is used, not for advertising.
  • Trustpilot: after an order we send your name, email address and order number to Trustpilot, so that Trustpilot can invite you to write a review. Trustpilot is based in Denmark. Whether you write a review is up to you.
  • Resend: sending our email notifications and order confirmations.
  • Mollie: handling your payment (iDEAL, Bancontact, card). Mollie is a Dutch payment provider and processes your payment data as an independent controller.
  • Google (Sheets): we copy messages from the contact form to a restricted spreadsheet for our own administration.
  • Google (login): only if you choose to log in with Google. Google then confirms who you are and gives us your name and email address.
  • Suppliers: for a dropship order we pass your name and delivery address to the supplier who ships the product directly to you. They receive no more data than is needed to deliver.

4. Transfers outside the European Economic Area

Some of the parties above are established in the United States or may process data outside the EEA. Appropriate safeguards apply to those transfers, such as the European Commission standard contractual clauses or the EU-US Data Privacy Framework. Our database is deliberately located in the EU.

5. Cookies and measurement

Cookies only with your consent. We only place cookies if you choose to by clicking Accept in the banner at the bottom of the site. If you click Decline, or choose nothing, the site places no cookies and nothing is sent to Google. You can change or withdraw your choice at any time via Cookie settings at the bottom of every page.

Google Analytics, only after your consent. Google Analytics shows us which pages are visited, how visitors arrive at the site and what we can improve. For this Google places the cookies _ga and _ga_ followed by a code, which stay in your browser for up to 2 years unless you delete them earlier or withdraw your consent. Google Analytics 4 does not store IP addresses. We have set up Google Analytics so that the data is not used for advertising and is not linked to your Google account (Google signals are off). Google processes the data on our behalf as a processor; it may end up in the United States, under the EU-US Data Privacy Framework. We keep the data in Google Analytics for no longer than 14 months. If you withdraw your consent, we remove the Google cookies from your browser.

We also count visits without cookies. For that we use Cloudflare Web Analytics, for every visitor. It works without cookies and without storing or reading anything in your browser. We see how many visits a page received, which website someone arrived from, from which country, what kind of device they used and how quickly the page loaded, but not who you are. Because nothing is placed on or read from your device, no consent is required for this.

Apart from these measurement scripts, the pages load nothing from third parties. Fonts, images and styling come from our own server. Product photos come from our database in the European Union.

Two exceptions, both only on a form and both necessary:

  • When you fill in a form, we load a Cloudflare Turnstile check at that moment, which establishes that you are a person and not an automated program. Without it our forms would fill up with spam. The check only loads once you start typing in a field, so not while you are simply looking around.
  • That check passes your IP address to Cloudflare, because it cannot work otherwise. We do not store that IP address ourselves: it is not in our database and we cannot look anything up with it later.

If you log in to your account, your browser keeps a login key (in your browser's storage, not as a cookie), so that you stay logged in while you move around the site. This is strictly necessary for the account you asked for yourself, and no consent is required for it. The key is removed when you log out. If you turn off "Stay logged in", it is also removed as soon as you close the tab.

If you put something in your basket, your browser remembers which products those are (again in your browser's storage, not as a cookie). That too is strictly necessary for something you ask for yourself. The list stays in your own browser; only when you check out do we send it to our server to calculate the price.

If you use a discount code, or arrive through a link that contains one, your browser remembers that code for up to 30 days in the same way (not as a cookie). That way the discount is applied at checkout, even if you look around first. You will see a message with the code and can always remove it; after a paid order it is cleared automatically.

If an article contains a video, it only loads when you click play. Until then nothing from YouTube is loaded on the page: the preview image comes from our own server. When you click play, the video loads via youtube-nocookie.com, the more privacy-friendly version of YouTube. Google, the owner of YouTube, then receives your IP address and may store data in your browser, for example to play the video properly. Google's privacy policy applies to that. If you do not want this, do not click play; the rest of the article works as normal.

The radio on the login page works the same way. The music plays in the YouTube player, and only after you have clicked the radio and then Play. Until then nothing from YouTube is loaded on the page. After that your browser connects to YouTube (Google), as described above. If you do not want this, do not click Play; logging in works as normal.

6. Retention periods

  • Quotes and customer contact: no longer than 2 years after your last contact.
  • Orders, invoices and withdrawals: 7 years, because of the tax retention requirement.
  • Keep me posted: until we have emailed you that the product is available, and no longer than 12 months after you signed up.
  • Origin: for as long as the order, sign-up or question it belongs to is kept.
  • Google Analytics: no longer than 14 months in Google Analytics; the cookies in your browser for up to 2 years, unless you delete them earlier or withdraw your consent.
  • Newsletter: until you unsubscribe.
  • Account: for as long as your account exists. Email us if you want it deleted; we will do so within 30 days. Orders are kept for as long as the tax retention requirement demands.

7. Security

The website works exclusively over a secure connection (HTTPS). Our database is protected with row level access rules and the admin panel is only accessible to administrators. Account passwords are stored encrypted; we cannot see them either. When you choose a password, your browser checks with the Have I Been Pwned service whether it appears in known data breaches. Only the first five characters of an irreversibly encrypted version of your password are sent (and, as with any connection, your IP address), never the password itself.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, objection and data portability. If you have given consent, you can withdraw it at any time. Send your request to info@apexsafeofficial.com; we respond within 30 days.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens. If you live in Belgium or Luxembourg, you can contact the supervisory authority in your own country.

9. Contact

ApexSafe
Email: info@apexsafeofficial.com
Phone: +31 6 17 38 01 42
Chamber of Commerce number: 42162246
VAT identification number: NL005546121B20

May we measure how you use the site?

With your consent we use Google Analytics to see which pages are visited and what we can improve. Google places cookies for this. Without your consent we place no cookies. More in our privacy statement