Privacy Policy
Version: 1.1
Effective Date: April 27, 2026
Last Updated: April 27, 2026
Last Substantive Change: Added GDPR legal basis, DPA language, automated decision-making disclosure, and strengthened notice-at-collection (April 27, 2026).
Apex Auto Studios (“Apex,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, share, and protect information about you when you visit our website at https://apexautostudios.com (the “Site”), submit a quote or contact form, or otherwise interact with our business.
1. Scope of This Policy
This Privacy Policy applies to information collected through the Site and through our business operations. It does not apply to information collected by third parties we do not control, even if those third parties are linked from the Site.
2. Information We Collect
We collect the following categories of personal information:
Information you provide directly:
- Name (first and last)
- Email address
- Phone number
- Vehicle information (year, make, model, color)
- Service preferences and project details
- Messages and inquiries you send us
- Any other information you choose to provide
Information collected automatically:
- IP address and approximate geographic location
- Browser type and version
- Device type and operating system
- Pages visited, time spent on pages, click activity
- Referring website
- Cookie identifiers and similar tracking technologies
- Date and time of visit
Information from third parties:
- Information from social media platforms if you interact with our content there (Instagram, Facebook)
- Information from advertising platforms about ad performance and audience characteristics
- Information from review platforms (Google Business Profile, Yelp) if you leave us a review
We do not knowingly collect sensitive personal information as defined under California law (such as Social Security numbers, financial account details, precise geolocation, biometric data, or health information).
Notice at Collection. At or before the point at which we collect personal information from you (such as when you submit a quote request or contact form), we provide notice of the categories of personal information being collected and the purposes for which the information will be used. This Privacy Policy serves as our comprehensive notice; in addition, our online forms include a brief summary notice with links to this Policy.
3. How We Use Your Information
We use personal information for the following business and commercial purposes:
- To respond to your inquiries and provide quotes
- To schedule and deliver services
- To communicate with you about your project
- To send transactional emails (quote confirmations, appointment reminders, service updates)
- To send marketing communications (only with your consent or as permitted by law)
- To improve our website, services, and marketing
- To analyze website performance and customer behavior
- To prevent fraud, enforce our Terms, and protect our legal rights
- To comply with legal obligations
4. How We Share Your Information
We share personal information only as described below. We do not sell your personal information for money. However, our use of advertising and analytics technologies (such as Meta Pixel and Google Analytics) may constitute “sharing” or “selling” under California law due to cross-context behavioral advertising. See Section 11 for your rights regarding this.
We share information with the following categories of recipients:
Service providers acting on our behalf, including:
- Email delivery providers (Resend) for transactional emails and lead notifications
- Customer relationship management (CRM) tools used by Apex and our marketing partners
- Web hosting providers (Hostinger, Vercel)
- Analytics providers (Google Analytics)
- Advertising platforms (Meta/Facebook, Google Ads)
Marketing partners including our digital marketing agency, who assist us with advertising, lead management, and performance reporting.
Legal and safety recipients when required by law, court order, subpoena, or to protect our rights, property, or the safety of others.
Business transfers — if Apex is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
We do not share personal information with third parties for their own independent marketing purposes.
5. Service Providers and Data Processing
The third parties listed in Section 4 process personal information on our behalf as service providers or processors under contractual obligations. These contracts:
- Limit each provider’s use of personal information to the specific purposes for which we engaged them
- Prohibit each provider from selling personal information or using it for their own independent commercial purposes
- Require each provider to maintain appropriate security measures
- Require each provider to assist us in fulfilling consumer rights requests where applicable
For service providers that process personal information of European Union or United Kingdom residents, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms recognized under the EU General Data Protection Regulation (GDPR) and UK GDPR.
A current list of subprocessors and service providers is available upon request by contacting us at the email address in Section 17.
6. Cookies and Tracking Technologies
We use cookies and similar technologies on the Site, including:
- Strictly necessary cookies — required for the Site to function (form submission, security, basic navigation)
- Analytics cookies — Google Analytics 4 to understand how visitors use the Site
- Marketing cookies — Meta Pixel and similar tools for advertising attribution and retargeting
You can manage cookie preferences through your browser settings or through our cookie consent banner. Disabling certain cookies may affect Site functionality.
We honor Global Privacy Control (GPC) signals as a valid request to opt out of the sale or sharing of personal information.
7. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including:
- Lead and inquiry information: up to 3 years from last interaction
- Customer service records: up to 7 years (for warranty and legal purposes)
- Marketing communications opt-ins: until you unsubscribe
- Analytics data: typically 14–26 months per provider defaults
When information is no longer needed, we delete or anonymize it.
8. Data Security
We implement reasonable physical, technical, and administrative safeguards to protect personal information from unauthorized access, use, or disclosure. However, no system is completely secure. You acknowledge that you provide information at your own risk.
9. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you the following rights:
Right to Know. You may request that we disclose what personal information we have collected, used, disclosed, or shared about you in the prior 12 months.
Right to Delete. You may request that we delete personal information we have collected from you, subject to legal exceptions.
Right to Correct. You may request that we correct inaccurate personal information we maintain about you.
Right to Opt Out of Sale or Sharing. You may opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising. We do not sell information for money, but our use of advertising pixels may qualify as “sharing.” See the Your Privacy Choices page.
Right to Limit Use of Sensitive Personal Information. We do not knowingly collect or use sensitive personal information as defined by California law.
Right to Non-Discrimination. We will not discriminate against you for exercising your privacy rights. We will not deny services, charge different prices, or provide different quality of service based on your exercise of these rights.
How to Exercise Your Rights
To submit a request, contact us at:
- Email: vj12111@gmail.com (subject line: “California Privacy Request”)
- Phone: (619) 251-1282
- Mail: Apex Auto Studios, 9240 Dowdy Dr, Suite D, San Diego, CA 92126
We will verify your identity before processing your request, typically by confirming information you have previously provided to us. We will respond within 45 days. If we need additional time, we may extend by 45 days with notice to you.
You may use an authorized agent to submit a request on your behalf, but we will require written authorization from you and may verify your identity directly.
Shine the Light Law
California Civil Code § 1798.83 allows California residents to request information about disclosures of personal information to third parties for direct marketing purposes. To request this information, email us at vj12111@gmail.com.
10. International Visitors and GDPR Legal Basis
The Site is operated from California, United States. If you visit from outside the United States, including from the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, your personal information will be transferred to and processed in the United States. By using the Site, you consent to this transfer.
Legal Basis for Processing (GDPR Article 6)
For visitors subject to the EU General Data Protection Regulation or UK GDPR, we process personal information on the following legal bases:
- Consent — Where you have given explicit consent (such as submitting a form, opting in to marketing communications, or accepting non-essential cookies). You have the right to withdraw consent at any time.
- Legitimate Interests — Where processing is necessary for our legitimate business interests, including responding to inquiries, providing requested services, securing the Site, preventing fraud, and improving our services. These interests are balanced against your rights and freedoms.
- Contract Performance — Where processing is necessary to provide services you have requested or to take steps at your request before entering into a contract.
- Legal Obligation — Where processing is necessary to comply with a legal obligation we are subject to (such as tax, accounting, or regulatory requirements).
EEA / UK Resident Rights
In addition to the rights described in Section 9, EEA and UK residents have rights to: access, rectification, erasure, restriction of processing, data portability, and objection to processing. To exercise these rights, contact us using the methods in Section 17. You also have the right to lodge a complaint with a supervisory authority in your jurisdiction.
International Data Transfers
Where personal information is transferred outside the EEA or UK, we rely on appropriate safeguards including Standard Contractual Clauses approved by the European Commission, or other transfer mechanisms recognized under applicable law.
11. Do Not Sell or Share My Personal Information
We do not sell personal information for money. However, our use of Meta Pixel, Google Analytics, and similar advertising technologies constitutes “sharing” of personal information under the CPRA for cross-context behavioral advertising purposes.
To opt out:
- Visit our Your Privacy Choices page
- Email vj12111@gmail.com with the subject line “Do Not Sell or Share”
- Enable Global Privacy Control (GPC) in your browser — we honor GPC signals automatically
Opt-out requests apply to the browser and device used to submit the request. You may need to opt out separately on each device or browser.
12. Do Not Track Signals
Some browsers offer a “Do Not Track” (DNT) signal. There is no industry-standard interpretation of DNT signals. We do not currently respond to DNT signals, but we do honor Global Privacy Control (GPC) signals as described in Section 11.
13. Children’s Privacy
The Site is intended for adults and is not directed to children.
Children Under 13 (COPPA). In compliance with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us using the methods in Section 17, and we will delete it promptly.
California Residents Aged 13–15 (CPRA). Under the California Privacy Rights Act, we will not sell or share the personal information of California residents under 16 without affirmative authorization. For residents aged 13–15, this requires opt-in consent from the resident. For residents under 13, this requires opt-in consent from a parent or guardian. Because we do not knowingly collect information from individuals under 16 in any form that constitutes a sale or sharing under California law, this provision serves as our policy commitment.
Parents and Guardians. If you are a parent or guardian and believe your child has provided personal information to us, please contact us so we can delete the information.
14. Automated Decision-Making and Profiling
We do not use personal information to make automated decisions that produce legal effects or similarly significant effects concerning you. We do not engage in profiling for the purpose of evaluating personal aspects, predicting performance, behavior, or making decisions without human involvement.
We may use analytics and advertising tools that perform statistical analysis or audience segmentation, but final decisions regarding our services, pricing, and customer interactions are made by human staff at Apex Auto Studios.
If we ever begin using automated decision-making in a manner that produces legal or similarly significant effects, we will update this Policy and provide notice to affected individuals, along with the right to obtain human review of any such decision.
15. Third-Party Links
The Site may contain links to third-party websites (such as social media platforms). We are not responsible for the privacy practices of those sites. Please review their privacy policies.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. Material changes will be communicated through a notice on the Site. Your continued use of the Site after changes take effect constitutes acceptance.
17. Contact Us
For questions, requests, or concerns about this Privacy Policy or our privacy practices:
Apex Auto Studios
9240 Dowdy Dr, Suite D, San Diego, CA 92126
Email: vj12111@gmail.com
Phone: (619) 251-1282
