On this page本页目录
01
English
Overview and role boundaries
Apex’s legal role may differ by processing context. This candidate intentionally does not assign Apex one universal role. Final descriptions require purpose-by-purpose facts, contract review and qualified legal approval.
Use the website path for information submitted directly to Apex. Use the merchant-processing path when your question concerns a purchase or a merchant’s payment activity.
中文
概览与角色边界
Apex 的法律角色可能随具体处理场景而不同。本候选稿不会把 Apex 统一描述为某一种角色。最终说明必须基于逐项目的事实、合同审阅和合格律师批准。
如信息是你直接通过官网提交给 Apex,请查看官网路径;如问题涉及购买或商户的支付活动,请查看商户支付处理路径。
02
English
Website visitors and business contacts
When you request a demo, subscribe to the newsletter or request the whitepaper, the form asks for the details shown beside that form. Apex uses submitted details to respond to the request and operate that form. Newsletter or other marketing choices remain separate from this notice.
Website technologies
The production cookie, storage, analytics and network inventory has not yet been approved for public description. This review candidate therefore makes no statement about selling, sharing, advertising technology or browser preference signals.
中文
官网访客与商务联系人
当你申请演示、订阅邮件或申请白皮书时,表单会收集该表单旁展示的信息。Apex 使用你提交的信息回复请求并运行相应表单。邮件订阅或其他营销选择与本声明分开处理。
网站技术
生产环境中的 Cookie、存储、分析和网络清单尚未获准公开。本审阅候选稿因此不会就出售、共享、广告技术或浏览器偏好信号作出结论。
03
English
When a merchant uses Apex
For a question about a purchase, refund or transaction, contact the merchant identified on your receipt or statement first. Apex’s obligations and legal role for merchant-directed data depend on the relevant contract, purpose and applicable law; those conclusions are not finalized in this candidate.
This notice will not replace a merchant’s own privacy notice or the terms governing the merchant’s relationship with its customers.
中文
当商户使用 Apex 时
如问题涉及购买、退款或交易,请先联系收据或账单上标明的商户。对于由商户决定用途的数据,Apex 的义务和法律角色取决于相关合同、具体目的与适用法律;本候选稿尚未形成这些结论。
本声明不会替代商户自己的隐私声明,也不会替代商户与其客户之间的条款。
04
English
Payment and merchant data
The working inventory includes merchant account and onboarding information, merchant representative information, payment tokens, masked payment metadata, amounts, status events, operational logs and support communications. The final notice will include only categories and purposes verified against the production data flow.
| Data category | Source | Purpose | Apex role | Recipient | Retention |
|---|---|---|---|---|---|
| Website and business-contact details | Submitted by the visitor | Respond to the request and operate the form | Evidence and counsel review | Active register under review | Schedule not approved |
| Merchant account, onboarding and representative information | Merchant and its representatives | Account and onboarding purposes under review | Purpose-specific conclusion pending | Active register under review | Schedule not approved |
| Payment tokens, masked metadata, amounts and events | Merchant and configured PSPs | Orchestration, reporting and support in the working inventory | Contract and counsel review | Merchant and configured PSPs; current design under verification | Schedule not approved |
| Operational logs and support communications | Systems and users | Operational, security and support purposes under review | Purpose-specific conclusion pending | Active register under review | Schedule not approved |
| AI question text | User submission | Provide the AI-assisted feature | Evidence and counsel review | OpenRouter and routed upstream model providers | No period approved; no upstream promise |
- Buyer browserCard details are entered in PSP-hosted fields.
- Merchant / PSP → ApexToken, masked metadata and payment events.
- Apex → configured PSPsPayment instructions for the configured route.
- Apex → MerchantAnalytics, reconciliation and reporting outputs.
Text equivalent: the buyer enters card details in PSP-hosted fields; the Merchant or PSP sends Apex a token, masked metadata and events; Apex sends instructions to configured PSPs and returns analytics, reconciliation and reporting outputs to the Merchant. Every connector and recipient remains subject to production verification.
中文
支付与商户数据
当前工作清单包括商户账户与入驻信息、商户代表信息、支付 token、脱敏支付元数据、金额、状态事件、运营日志和支持沟通。最终声明只会纳入经生产数据流核实的数据类别与用途。
| 数据类别 | 来源 | 目的 | Apex 角色 | 接收方 | 保留 |
|---|---|---|---|---|---|
| 官网与商务联系信息 | 访客直接提交 | 回复请求并运行表单 | 证据与律师审阅中 | 启用清单审阅中 | 计划尚未获批 |
| 商户账户、入驻与代表信息 | 商户及其代表 | 账户与入驻目的审阅中 | 逐目的结论待定 | 启用清单审阅中 | 计划尚未获批 |
| 支付 token、脱敏元数据、金额与事件 | 商户与已配置 PSP | 工作清单中的编排、报告与支持 | 合同与律师审阅中 | 商户与已配置 PSP;当前设计待验证 | 计划尚未获批 |
| 运营日志与支持沟通 | 系统与用户 | 运营、安全与支持目的审阅中 | 逐目的结论待定 | 启用清单审阅中 | 计划尚未获批 |
| AI 提问文本 | 用户提交 | 提供 AI 辅助功能 | 证据与律师审阅中 | OpenRouter 及其路由的上游模型服务商 | 期限未获批;不承诺上游行为 |
- 买家浏览器在 PSP 托管字段中输入卡信息。
- 商户 / PSP → Apex传递 token、脱敏元数据与支付事件。
- Apex → 已配置 PSP向已配置路由发送支付指令。
- Apex → 商户返回分析、对账与报告输出。
文本等效说明:买家在 PSP 托管字段中输入卡信息;商户或 PSP 向 Apex 发送 token、脱敏元数据与事件;Apex 向已配置 PSP 发送指令,并向商户返回分析、对账与报告输出。每个 connector 与接收方仍须完成生产验证。
05
English
Sharing and service relationships
Apex may use other organizations to operate website, infrastructure, communications, payment and product functions. The active recipient register, exact entities, locations, data, purposes, legal roles and contracts are still being verified.
The final notice will name or categorize only recipients that are active and evidenced. A connector that has been built but is not enabled will not be presented as a current recipient.
中文
共享与服务关系
Apex 可能使用其他组织来运行官网、基础设施、通信、支付与产品功能。当前接收方清单、准确实体、地点、数据、目的、法律角色与合同仍在核验中。
最终声明只会列出或分类实际启用且有证据支持的接收方。已经开发但尚未启用的 connector 不会被写成当前接收方。
06
English
International transfers
Hosting regions, onward transfers and any required transfer mechanisms remain under technical, contract and legal review. This candidate does not state that a particular safeguard or transfer framework applies.
中文
跨境传输
托管区域、后续传输以及任何可能需要的传输机制仍在技术、合同和法律审阅中。本候选稿不会声称某项特定保障措施或传输框架已经适用。
07
English
Retention and deletion
A category-by-category retention schedule and verified deletion behavior have not been approved. This candidate makes no fixed retention-period or automatic-deletion promise. Final wording will describe only implemented behavior, supported exceptions and verified backup handling.
中文
保留与删除
逐类保留计划和经验证的删除行为尚未获批。本候选稿不会承诺固定保留期限或自动删除。最终措辞只会描述已经实施的行为、有依据的例外与经验证的备份处理方式。
08
English
Rights and requests
Applicable rights, identity and authority checks, merchant forwarding, appeals, response timing and fulfillment procedures remain under legal and operational review. The final notice will describe only rights that apply and a request process that has passed an end-to-end operational test.
For merchant-controlled purchase or transaction questions, begin with the merchant. The approved Apex privacy route will appear in the Contact section only after it is monitored and tested.
中文
权利与请求
适用权利、身份与授权核验、商户转交、申诉、响应时限和履行流程仍在法律与运营审阅中。最终声明只会描述确实适用的权利,以及已经通过端到端运营测试的请求流程。
如问题涉及由商户决定用途的购买或交易信息,请先联系商户。经批准的 Apex 隐私入口只有在确认受监控并完成测试后,才会出现在“联系”章节。
09
English
AI-assisted features
Apex AI features may route the question text a user submits through OpenRouter to upstream model providers. Do not enter card numbers, account credentials or other sensitive or personal information in an AI question field.
Apex makes no promise in this candidate about upstream model-provider training or retention. Provider, model, routing, region, configuration and contractual facts must be reverified before publication and whenever they change.
中文
AI 辅助功能
Apex 的 AI 功能可能会通过 OpenRouter 将用户提交的问题文本路由给上游模型服务商。请勿在 AI 提问框中输入卡号、账户凭据或其他敏感信息或个人信息。
本候选稿不对上游模型服务商的训练或保留行为作出承诺。服务商、模型、路由、区域、配置和合同事实必须在发布前以及每次变更时重新核验。
10
English
Security statements
Security wording must identify the control, system boundary and supporting evidence. This candidate does not claim current PCI DSS certification or compliance, SOC 2, ISO certification, an independent audit or absolute security.
中文
安全说明
安全措辞必须明确具体控制、系统边界与支持证据。本候选稿不会声称 Apex 当前已获得 PCI DSS 认证或满足其合规要求,也不会声称已获得 SOC 2、ISO 认证、独立审计或绝对安全。
11
English
Privacy contact
The monitored privacy contact, accountable operator, backup, escalation process and public legal entity details have not been approved or operationally tested. The address in the shared site footer is not designated here as an approved privacy-contact or legal-entity address.
Do not use the general sales form to send card numbers, account credentials, identity documents or other sensitive information.
中文
隐私联系
受监控的隐私联系入口、负责人员、备份人员、升级流程与公开法律实体信息尚未获批,也未完成运营测试。共享网站 footer 中的地址不在此被指定为已批准的隐私联系地址或法律实体地址。
请勿通过一般销售表单发送卡号、账户凭据、身份证件或其他敏感信息。
12
English
Changes, approval and versioning
The effective date, review cadence, material-change process, controlling-language approach and archive process remain unapproved. The release version will show its effective date and last-updated date only after the exact English and Chinese text has been approved.
A new purpose, recipient, tracker, region, data category, AI provider, connector or card-data-boundary change triggers a fresh review before the public notice changes.
中文
变更、批准与版本
生效日期、审阅周期、重大变更流程、控制语言方案和归档流程尚未获批。只有在准确的中英文文本均获批准后,发布版本才会展示其生效日期与最后更新日期。
新增处理目的、接收方、追踪技术、区域、数据类别、AI 服务商、connector,或支付卡数据边界发生变化时,都必须先重新审阅,再修改公开声明。
