Legal

Privacy Policy

How Apex Digital Media collects, uses, and shares information submitted through the partner application at apexdm.co.

Last updated: August 19, 2026. This page describes the current, live version of the apexdm.co business site only — see “Who this policy covers” below.

Who this policy covers

This policy applies to apexdm.co and the partner-application flow found at /apply, /program, and /annuity-appointments. It covers business professionals — annuity producers, agency owners, and agency staff — who visit this site or submit an application to be evaluated for the Apex Digital Media appointment program. This is a business-to-business (B2B) service.

Apex Digital Media has also designed a separate, consumer-facing retirement-planning product for individual retirement-age consumers. That product is not live. It collects no data today, this policy does not describe it, and this policy will be updated before it launches.

Information we collect

When you submit the application at /apply, we collect:

Business contact information

  • First and last name
  • Business email address
  • Mobile or direct business phone number
  • Company or agency name
  • Company website or professional LinkedIn URL

Business and qualification answers

Your role and decision-making authority; your organization’s licensing and production status; the annuity and related products you sell; producer headcount and approximate annual premium band; acquisition channels and constraints you select; the state you want evaluated and whether you are licensed there; your target consumer profile; monthly appointment capacity; whether you agree to our meeting-verification protocol and outcome-reporting process; the investment level you could approve; your desired start timeline; and any free-text context you choose to add.

Your consent

The exact checkbox text you agreed to, and when you agreed to it.

Advertising and attribution data

If you arrive from an ad or link carrying tracking parameters, we capture UTM parameters (source, medium, campaign, and similar), Meta’s fbclid click identifier, the landing page URL, and the referring page. If our advertising pixel is active on your visit, we also read the pixel’s own _fbp/_fbc browser cookies. This is stored with your application record so we can measure which ad or channel it came from.

We also record the IP address and browser user agent your device sends when you submit an application, for fraud prevention and to improve ad-measurement accuracy with Meta (see Meta Conversions API below).

Information we derive internally

From your answers, we compute an internal qualification score and tier, and internal reasons for that outcome. This derived material is used to route your application; it is stored on your application record but is not shown back to you, and is not shared with Meta or any other third party.

Scheduling information

If your application qualifies, we generate a single-use Calendly booking link tied to your application. When you use it, Calendly collects the booking details you provide to it directly (such as your name, email, and the time you select) and sends us a webhook confirming the booking, cancellation, or reschedule so we can update your application record. We do not receive your Calendly account credentials, and we do not control what Calendly itself collects — see Calendly’s own privacy policy for that.

How we use information

  • To evaluate whether your organization fits the appointment program and route your application accordingly.
  • To detect and link repeat or duplicate applications from the same person or organization.
  • To generate and manage your program-fit call booking.
  • To communicate with you about your application, in line with the consent you gave.
  • To measure and improve the performance of our advertising, using the hashed and pseudonymous data described below.
  • To operate, secure, and improve the site and application process itself.

Who we share information with

We do not sell your information. We share it only with the service providers (“processors”) that operate the application on our behalf, each acting under our instructions and only for the purpose described:

  • Supabase — hosts the database that stores your application, including your answers, contact details, and derived qualification data.
  • Vercel — hosts this website and processes your application submission and Calendly webhook events on our servers.
  • Calendly — powers the single-use scheduling link presented to qualified applicants, and notifies us when a call is booked, rescheduled, or canceled.
  • Meta Platforms, Inc. — receives limited, hashed contact data and ad-attribution identifiers for advertising measurement, described in the next section.

We do not send Meta, or any other third party, your qualification tier, your raw score, the internal reasons behind either, or your free-text answers.

We may also disclose information where required by law, to protect the rights, property, or safety of Apex Digital Media or others, or in connection with a merger, acquisition, or sale of business assets, subject to the confidentiality of your information being maintained.

Meta Conversions API and hashed data

When you submit an application, and again when you book a call, our server sends an event to Meta’s Conversions API — a server-to-server channel Meta provides for measuring how well an ad performed — so we can tell whether our advertising is working. This is separate from, and in addition to, any browser-based Meta pixel that may be active on the page.

Before your email address or phone number is ever sent to Meta, it is run through a one-way cryptographic hash (SHA-256): your email is lowercased and trimmed, your phone number is stripped to digits only, and each is transformed into a fixed-length string that cannot practically be reversed back into your original email or phone number. We never send your email or phone number to Meta in plain, readable form.

Alongside the hashed contact data, we send:

  • A general value and category signal derived from your qualification tier — never the tier, score, or reasons themselves.
  • The Meta click identifiers and browser cookies described above, when present, to help Meta match the event to the correct ad.
  • Your IP address and browser user agent, which Meta uses for the same matching purpose.

This transmission only happens while our advertising pixel is configured and active. If you would like Meta to stop using this data for advertising, you can manage your ad preferences directly with Meta, or contact us using the details below.

Cookies and tracking technologies

This site stores the UTM and click-identifier data described above in your browser’s local storage, so it survives your visit long enough to be attached to an application you submit later in the same session. When our advertising pixel is active, it also sets Meta’s own _fbp and _fbc browser cookies. We do not use these technologies for any purpose beyond ad measurement and attribution, and we do not run third-party advertising cookies of our own beyond Meta’s.

How long we keep information

We keep application records for as long as needed to operate the program, evaluate repeat applications, and maintain an audit trail of qualification decisions. When you submit a new application within 30 days of a prior one from the same email, phone, or company domain, the earlier application is marked superseded rather than deleted, so both remain part of the record.

[Placeholder — retention period]: a specific retention period and deletion schedule for application records has not yet been set by the business owner and should be defined with counsel before this policy is treated as final.

Your choices and rights

  • Text messages: reply STOP to any text message from us to opt out.
  • Calls and email: contact us using the details below to ask us to stop contacting you.
  • Access or deletion: you may ask what information we hold about you, or ask us to delete it, by contacting us below. We will honor deletion requests except where we need to keep limited records for legal, audit, or fraud-prevention reasons.

Security

Application data is stored with row-level security enabled and is not readable by unauthenticated or client-side requests — only our server-side application code can read or write it. We do not ask for or store highly sensitive identifiers such as a Social Security number, account number, or password anywhere in this application. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.

Children’s privacy

This site is a business tool for licensed insurance and financial professionals and their organizations. It is not directed at, and we do not knowingly collect information from, children.

Changes to this policy

We may update this policy as the site and program change. We will update the “Last updated” date above when we do, and we will describe any new consumer-facing product separately, and before it collects any data, rather than folding it silently into this policy.

Contact

Questions about this policy, or requests to access, correct, or delete your information, can be sent to privacy@apexdm.co.

[Placeholder — operating entity]: this policy is issued by the Apex Digital Media operating entity. Its exact registered legal name and business address have not been confirmed in this repository and must be added here before this policy is treated as final.