Apex FLO · Official notice
Privacy Policy
Version 2.1 · Effective 23 August 2026
Important: participation may involve financial loss. Income and withdrawal timing are not guaranteed. The operator's legal identity, registered address, jurisdiction, and grievance contact must be inserted before public financial launch.
This Privacy Policy describes how Apex FLO (“Apex FLO”, “we”, “us”, or “our”) collects, uses, discloses, stores, and otherwise processes personal information in connection with our websites, mobile and desktop dashboards, wallets, packages, team tools, support channels, and related services (together, the “Platform”). Please read it in full before you create an account. If you do not agree, do not register or use the Platform.
1. Who is responsible for your information
This notice applies to personal information processed when you visit, register for, or use Apex FLO. Until a public financial launch, the operating legal entity, registered office, privacy contact, and grievance officer will be published in this document and in the app. We do not invent those details here.
If you are using a test or staging environment, treat any data you submit as live operational data. Do not upload government identity documents, bank statements, or payment credentials unless a feature specifically requests them in an approved flow.
2. Scope
This policy covers members, visitors, sponsors, downline participants whose limited profile fields appear in team views, and people who contact Support. It does not cover independent websites, exchanges, blockchains, banks, or apps that we do not control, even if you reach them from the Platform.
3. Information we collect
We collect information that you provide, that is generated by your use of the Platform, and that we receive from service providers who help us operate it. Categories include:
- Identity and account: full name, email address, phone number with country code, member ID, sponsor / referral ID, password hash, and vault-key metadata (the vault key itself is not stored in recoverable form after signup).
- Profile and programme: packages, ranks, eligibility flags, capping status, income and passbook records, team structure, and feature usage.
- Security and device: IP address, browser and device type, session tokens, approximate location derived from IP, login timestamps, and failed-attempt or fraud signals.
- Support: messages, attachments, and ticket metadata you send to Support.
- Where a compliant payout or KYC feature is enabled: government identity documents, live/selfie checks, bank / UPI / wallet addresses, payment proofs, blockchain transaction hashes, and withdrawal history.
4. How we obtain it
Most information comes directly from you at registration, in Settings, or when you submit a wallet, package, or support request. We also generate logs as you use the dashboard. Your sponsor relationship is recorded when you register with a sponsor ID. Processors (hosting, email/SMS, identity, and payment partners) may return status, risk, or verification results that we store against your account.
5. How we use information
We process personal information only for purposes that are compatible with operating a network-earnings platform and meeting our legal duties. Those purposes include:
- Creating, authenticating, and recovering your account (including vault-key based password reset).
- Routing packages, income, ranks, pools, and wallet activity according to live programme rules.
- Showing limited team information to your sponsor and upline as required by the programme.
- Detecting duplicate accounts, credential stuffing, fraud, abuse, and prohibited automation.
- Providing customer support and keeping an audit trail of decisions that affect balances or eligibility.
- Complying with tax, accounting, record-keeping, identity-verification, and anti-money-laundering duties that apply to the operator.
- Sending service, security, and policy notices. We do not sell personal information, and we do not use it for third-party advertising.
6. Legal bases (where they apply)
Depending on your location, we may rely on one or more of the following: performance of a contract (providing the account you requested); legitimate interests (securing the Platform, preventing fraud, maintaining programme integrity) balanced against your rights; legal obligation (tax, KYC, or regulatory retention); and consent where a law specifically requires it (for example optional analytics or marketing, if introduced). You may withdraw consent without affecting processing that must continue on another lawful basis.
7. Wallets, payments, and blockchain
Deposit, withdrawal, transfer, and package-purchase records are stored so we can process requests, reconcile ledgers, and resolve disputes. Crypto addresses and transaction hashes you submit may appear on public ledgers that we do not control. Confirmed blockchain transfers cannot be reversed by us.
We may pause, review, or refuse a payout where identity, source-of-funds, sanctions, or fraud checks are incomplete or fail. Those reviews are logged. Payment partners may independently apply their own compliance rules.
8. Team, genealogy, and referral data
Network products require limited visibility up and down the tree. Your member ID, join date, package or rank status, and selected public profile fields may be visible to your sponsor and upline. Downline members see only what programme rules expose. You must not export, scrape, or share other members’ personal data outside the Platform. Doing so is a breach of the Terms of Use.
9. Who we share information with
We share the minimum information necessary with:
- Infrastructure processors: hosting, databases, file storage, email/SMS, error monitoring, and security vendors, under contracts that limit use to providing their service to us.
- Identity and payment processors, only when those features are enabled.
- Your sponsor / upline, limited to programme fields described above.
- Professional advisers and the operating entity’s officers, under confidentiality.
- Authorities, courts, or regulators when the law requires a disclosure, or to protect members, the Platform, or the public from crime or serious harm.
10. International processing
Servers, backups, and processors may be located in a country other than yours. Where we transfer personal information internationally, we use contractual and organisational measures that are reasonable and available to keep it protected to a comparable standard. Some processors (for example global cloud or blockchain infrastructure) operate under their own terms.
11. How long we keep information
We keep account, ledger, and security records for as long as the account is active and for a further period after closure that is reasonable for disputes, audits, tax, and legal holds. Typical working periods (subject to a longer legal requirement) are:
- Active account profile and programme data: life of the account.
- Authentication logs and fraud signals: generally up to 24 months, longer if an investigation is open.
- Support tickets: generally up to 36 months after closure.
- KYC files: only while verification and applicable AML / record-keeping rules require them.
- Ledger and wallet movements: retained as financial records even after account closure where the law does not allow erasure.
12. Security
We use HTTPS in transit, access controls, hashed credentials, and environment isolation between projects. Vault keys and passwords are not stored in recoverable plaintext after signup. No online service is perfectly secure. You are responsible for keeping your password, vault key, devices, recovery codes, and wallet credentials secret, and for notifying Support immediately if you suspect unauthorised access.
On-screen privacy: when enabled, the app can hide balances while you are away from the tab, and mask amounts until you tap to show them. These steps reduce accidental leaks, for example in the app switcher. They do not stop someone from photographing or recording your screen. For your security, please avoid sharing screenshots of balances, keys, or personal details.
13. Your rights and choices
Subject to applicable law, you may request access to the personal information we hold, correction of inaccurate data, deletion, restriction of processing, a portable copy, or information about how we process your data. You may update profile fields in the app at any time.
We will need to verify that the request comes from you (for example by signed-in session, vault key, or KYC). We may refuse or limit a request where the law requires us to keep records, where it would adversely affect others, or where it is manifestly unfounded or excessive. We will explain the reason if we cannot fully comply.
15. Children
Apex FLO is for adults. You must be at least 18 years old (or the age of majority in your country, if higher) to register. We do not knowingly collect personal information from children. If we learn that an account belongs to a minor, we will close it and delete associated data where the law allows.
16. Automated decisions
Income, rank, capping, and pool results are calculated by configured programme rules. Fraud and duplicate-account checks may automatically flag or restrict an account. Those flags can be reviewed by Support. They are not credit-scoring or employment decisions. You can ask Support to explain a restriction that affects you.
17. Third-party services and links
The Platform may link to payment gateways, block explorers, or operator announcements hosted elsewhere. Their privacy practices are their own. Once you leave Apex FLO, this policy no longer applies.
18. Security incidents
If we become aware of a personal-data incident that is likely to result in a high risk to you, we will take steps required by applicable law, which may include notifying you and the competent authority. Do not treat Support messages that ask for your password or vault key as legitimate — we will never request those in full.
19. Changes to this policy
We may update this policy as the product, law, or operator changes. The version and effective date at the top of this notice will be revised. Material changes will be highlighted in the app or sent to the email on your account where we have a working address. Continued use after the new date means you accept the updated policy. If you do not agree, you must stop using the Platform and request account closure through Support.
20. How to contact us
Questions about this policy, data access, correction, or deletion can be sent through in-app Support. The operating entity name, registered address, privacy email, and grievance officer will be published in this section before any public financial launch that requires them. Until then, Support is the designated channel for privacy requests.
