Trust, Data Privacy & Legal Scope
Privacy Policy
Last updated & effective: September 24, 2026
This entire application, platform, and operating environment (Apex Global Cart Online Shop / GCOS) is built and maintained solely as a comprehensive demonstration project and technology pilot. Its primary objective is to demonstrate, evaluate, and introduce a complete, operating headless e-commerce application architecture and multi-tier operational line-ups for the purpose of seeking business investor partnerships, strategic collaborators, and commercial evaluations.
Simulated Environment & Non-Financial Notice: Interacting with this platform involves no real financial transactions, binding commercial sales, or live monetary deals. All data processed during testing and demonstrations is strictly handled in accordance with privacy safeguards outlined below.
1. Data Controller Identification
The data controller responsible for personal information and demonstration records is:
Company / Organization: Apex Global Cart International Pte. Ltd.
Registration Reference (UEN): 202301984M
Corporate Office: 30 Cecil Street #21-05, Prudential Tower, Singapore 048716
Data Protection & Investor Desk: dpo@globalcart-onlineshop.com / legal@globalcart-onlineshop.com
2. Scope of Data Collection in Demo Environment
In this operational demonstration environment, information is collected solely to simulate and illustrate full headless marketplace lifecycle features:
- Contact & Profile Data: Name, test email address, phone number, and simulated delivery coordinates.
- Mock Order & Transaction Telemetry: Simulated cart checkouts, demo order states, tracking numbers, and fulfillment receipts.
- Technical Logs & Security Verification: IP address, device headers, browser user-agents, and timestamp diagnostics to demonstrate platform security capabilities.
- Reseller & Merchant Applications: Test partner onboarding inputs and mock verification files to showcase merchant onboarding pipelines.
3. Lawful Basis and Processing Intent
We process data under the following legitimate grounds:
- Demonstration & Architecture Evaluation: Demonstrating full-stack cart, checkout, merchant SLA, ARS, and automated operational features.
- Security & Abuse Prevention: Safeguarding the demonstration infrastructure against unauthorized intrusion, denial of service, or scraping.
- Investor & Partner Inquiries: Processing contact communications from potential investors, enterprise licensees, and retail partners.
4. Payment Security & Absence of Real Financial Charges
This application is configured with simulated and sandbox payment tokenization. No real financial transactions, live credit card billings, or actual bank debits are conducted. All payment workflows demonstrate PCI-DSS Level 1 compliant structures, tokenized handling, and 3D Secure 2.0 biometric flows in a risk-free demonstration environment.
5. Your Privacy Rights
Under international privacy frameworks (GDPR, CCPA, PDPA), visitors and demo participants retain complete rights over their data:
Information we collect
- Account details: name, email address, phone number and password (stored only in scrambled form) when you register as a shopper, reseller or staff member.
- Order and shop details: delivery address, items ordered, order history, reseller shop name, logo and banner.
- Support messages: chats and images you send to our support team or between resellers and staff.
- Device and security data: browser type, approximate location (city and country based on IP address) and sign-in times, used to protect accounts.
- Cookies and local storage: used to keep you signed in, remember your cart and language, and allow offline browsing.
Google sign-in and Google user data
If you choose "Continue with Google", Apex Global Onlineshop (Apex Global Cart) receives only your name, email address and profile picture from your Google account (the openid, email and profile scopes). We use this information only to create your account, sign you in and show your name and picture in your profile.
- We do not access your Gmail, contacts, Drive, calendar or any other Google data.
- We do not sell, rent or share Google user data with third parties, and we do not use it for advertising.
- We do not use Google user data to train artificial intelligence or machine learning models, and we never use it to create generated images of any person.
- Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
- You can remove our access at any time at myaccount.google.com/permissions, and ask us to delete your account and data using the contact details below.
How we use, store and share data
- Use: to run your account, process orders, operate reseller shops, provide customer support, send account emails (such as confirmations and password resets) and prevent fraud.
- Storage: data is stored on secure cloud servers with encrypted connections (HTTPS) and access limited to authorised staff.
- Sharing: only with service providers needed to run the platform (hosting, email delivery, payment processing) and when required by law. We never sell personal data.
- Retention: we keep data while your account is active and delete it within 30 days of a verified deletion request, unless the law requires us to keep it longer.
- Children: the service is not intended for people under 16.
6. Contact for Privacy & Investor Inquiries
To submit data requests or for questions regarding the commercial rollout and investment opportunities of this headless e-commerce architecture, contact:
legal@globalcart-onlineshop.com or investors@globalcart-onlineshop.com.