Skip to main content

Legal

Cookie Notice

How ApexIQ WinCommand™ uses cookies and similar technologies.

Effective: 24 August 2026

Last reviewed: 24 August 2026

1. Who we are

Apex Edge Sales Engineering Limited operates ApexIQ WinCommand™.

Field Details
Legal name Apex Edge Sales Engineering Limited
Company number 15821626
Registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
ICO registration number ZB796431
Contact email privacy@apexedgesalesengineering.com

2. What this notice covers

This notice explains how ApexIQ WinCommand™ uses cookies and similar technologies.

Cookies and similar technologies may store information on, or access information from, a user's device. Similar technologies may include web storage, scripts, tags, tracking pixels, link decoration, navigational tracking, or device fingerprinting. The ICO's guidance covers cookies and other storage and access technologies, not just traditional browser cookies.

This notice covers ApexIQ WinCommand™ application cookies and similar technologies. It should be read alongside the Product Privacy Notice.

A separate website cookie notice may apply if the public Apex Edge Sales Engineering Limited website uses different cookies, analytics, pixels, embedded content, or marketing technologies.

3. Current cookie position

ApexIQ WinCommand™ uses essential cookies and similar technologies required for:

  • authentication;
  • sign-in;
  • session management;
  • secure access;
  • authorised administrative impersonation;
  • remembering that an in-product notice has been dismissed.

These technologies are the Supabase authentication token cookies, the Supabase PKCE code verifier cookie, an impersonation session cookie used only for authorised super-admin impersonation of a tenant account, and a notice dismissal cookie used to remember that a user has dismissed an in-product notice during the current sign-in session.

Every cookie we set is essential. We do not set any non-essential cookie, and we do not use web storage, device fingerprinting, or any other storage or access technology for a non-essential purpose.

We do run one third-party script for performance measurement, provided by our hosting supplier. It does not set or read a cookie, does not use web storage, and does not build an identifier for your device. Because it neither stores information on your device nor accesses information already stored there, it does not require consent. Section 5 explains it in full, including how to block it if you prefer.

No advertising, retargeting, social media, behavioural profiling, session replay, or cross-site tracking technologies are used.

4. Essential cookies and similar technologies

Essential cookies and similar technologies are needed to provide ApexIQ WinCommand™ and keep user sessions secure.

The following technologies are used:

Technology Purpose Essential? Consent required? Duration
sb-[project-ref]-auth-token Maintains the user's authenticated session. Without this technology, users cannot sign in to ApexIQ WinCommand™. Yes No Session
sb-[project-ref]-auth-token-code-verifier Used during the PKCE authentication flow to verify the authentication code exchange. Set briefly during sign-in and then deleted. Yes No Briefly during sign-in, then deleted
impersonation_session Set only for authorised super-admin users conducting authorised impersonation of a tenant account. Contains a signed, time-limited session token. Not set for regular users. Yes No Up to 30 minutes
notice_session_dismissed Set only when a user dismisses an in-product system notice. Remembers that dismissal so the notice is not shown again during the current sign-in session. Stores only a dismissal marker, scoped to the user's sign-in session. Not set for users who have not dismissed a notice. Yes No Up to 30 days, scoped to the current sign-in session

These technologies are treated as essential because they are required to provide authentication, session security, controlled administrative access, and core in-product functionality for the service requested by the user.

ApexIQ WinCommand™ also uses browser local storage for functional interface preferences, such as remembering whether the navigation sidebar is collapsed and the last deal a user viewed. These entries remain on the user's device, are not used for tracking or analytics, and are not shared with third parties.

5. Performance measurement and website analytics

5.1 Real user metrics (Netlify)

Our hosting supplier, Netlify, Inc., injects a real user metrics script into pages served from our platform, on both the public website and the signed-in application. We use it to see how quickly pages load for real users so we can find and fix slow pages.

Technology Purpose Provider Sets a cookie or uses storage? Consent required? Data sent
Netlify real user metrics Measures page load performance and page views so we can monitor and improve the speed of the service. Netlify, Inc. No No Page address, page load timings, a broad browser, operating system, and mobile or desktop category, and your IP address

Why no consent is requested. The rules on cookies and similar technologies apply where a service stores information on your device, or gains access to information already stored there. This script does neither. It sets no cookie, reads no cookie, and uses no browser storage of any kind. The only device details it reports are broad categories, such as the browser family, the operating system, and whether the screen is a mobile or a desktop size. It builds no identifier, so it cannot recognise you on a later visit or across other websites, and it is not device fingerprinting.

The data is used for performance measurement only. It is not used for advertising, retargeting, profiling, cross-site tracking, or session replay, it does not identify individual users to us, and it is not shared with advertising networks. Netlify processes it as our supplier and is listed in the Sub-processor List, and it is retained for 30 days.

The script does send your IP address, as any request to a website does. For that we rely on our legitimate interest in monitoring and improving the performance of the service, and you can object to that use at any time by contacting privacy@apexedgesalesengineering.com. See the Product Privacy Notice.

If you would still rather not be included, you can block the script using your browser settings, a content blocker, or a browser privacy mode, as described in Section 7. Blocking it does not affect your access to any part of ApexIQ WinCommand™.

5.2 Website analytics (Netlify)

We also use Netlify Web Analytics. It is different in kind from the script in Section 5.1: it runs entirely on Netlify's servers and works from the request logs that are created whenever a page is served to you. Nothing is added to the page and nothing runs in your browser. There is no script, no cookie, no browser storage, and nothing is read from your device.

Technology Purpose Provider Sets a cookie or uses storage? Consent required? Data sent
Netlify Web Analytics Counts page views, visits, the most requested pages, referring sites, and not-found errors, so we can see what is used and what is broken. Netlify, Inc. No No Taken from the server request log rather than from your device: the page address, the referring page, your IP address, and your browser's user agent string

Why no consent is requested. The rules on cookies and similar technologies apply where a service stores information on your device, or gains access to information already stored there. This does neither, because it happens after your request has reached the server. It is ordinary server log analysis rather than a tracking technology placed in your browser.

What you cannot do, stated plainly. Because this runs on the server rather than in your browser, a content blocker, a browser setting, or a private browsing mode will not stop it, unlike the script described in Section 5.1. Your remedy is to object rather than to block, and you can do that at any time by contacting privacy@apexedgesalesengineering.com.

The data is used to understand which pages are used and to find broken links. It is not used for advertising, retargeting, profiling, cross-site tracking, or session replay, and it is not shared with advertising networks. We do not combine it with your account to build a profile of an individual user. Netlify processes it as our supplier and is listed in the Sub-processor List, and it is retained for 30 days.

It does process your IP address, because a server log records the address that made the request. For that we rely on our legitimate interest in understanding and maintaining the service. See the Product Privacy Notice.

5.3 Technologies not used

Apart from the performance measurement and website analytics described in Sections 5.1 and 5.2, the following are not used:

  • non-essential cookies of any kind;

  • advertising cookies;

  • retargeting pixels;

  • social media pixels;

  • behavioural tracking or profiling;

  • heatmap tools;

  • session replay tools;

  • cross-site tracking;

  • marketing attribution;

  • embedded third-party media trackers;

  • unnecessary tracking scripts or tags.

5.4 Introducing non-essential storage or access technologies

If a non-essential cookie or other storage or access technology is introduced, Apex Edge Sales Engineering Limited will:

  1. update this Cookie Notice;
  2. categorise each technology;
  3. explain what each technology does;
  4. confirm duration;
  5. identify the provider;
  6. state whether data is shared with third parties;
  7. obtain consent before setting or accessing the technology, unless a valid exemption applies;
  8. provide a way to withdraw or change consent.

6. Consent

Consent is not requested, for two distinct reasons.

The cookies listed in Section 4 are essential: they are needed to provide the service the user has asked for, which is a recognised exemption.

The performance measurement described in Section 5.1 and the website analytics described in Section 5.2 both fall outside the consent rules altogether, because neither stores information on the user's device nor accesses information already stored there. The analytics in Section 5.2 does not even reach the device: it is compiled on the server from request logs.

We keep this position under review, including whenever our hosting supplier changes that script or that product. If ApexIQ WinCommand™ introduces a non-essential cookie or any other storage or access technology, users will be asked for consent before it is set or accessed, unless a valid exemption applies, and this notice and the consent controls will be updated first.

Consent will be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • given through a clear positive action;
  • as easy to withdraw as it is to give.

The ICO states that consent must be actively and clearly given, and that the rules apply to similar technologies as well as cookies.

7. How users can control cookies

Users can control cookies through their browser settings.

Browser settings may allow users to:

  • block cookies;
  • delete cookies;
  • clear site data;
  • restrict third-party cookies;
  • manage permissions for a specific website.

Blocking essential cookies may prevent ApexIQ WinCommand™ from working properly or may prevent users from signing in.

If non-essential technologies are introduced, ApexIQ WinCommand™ will provide a consent control or preference mechanism that allows users to accept, reject, or change choices for those technologies.

8. Authentication and session management

ApexIQ WinCommand™ uses authentication and session technologies to:

  • verify that a user is signed in;
  • maintain the user's authenticated session;
  • protect against unauthorised access;
  • support password reset or sign-in flows;
  • support secure user access;
  • support authorised administrative access where required.

These technologies are necessary for the security and operation of the service.

9. Administrative impersonation

ApexIQ WinCommand™ includes an authorised administrative impersonation function for support, security, debugging, or service operation.

The impersonation_session technology is used only for authorised super-admin users conducting authorised impersonation of a tenant account.

It is:

  • signed;
  • time-limited;
  • restricted to authorised personnel;
  • logged where technically available;
  • used only where reasonably required;
  • unavailable to regular users.

10. Third-party suppliers

Cookies and similar technologies may be provided or influenced by suppliers used to operate ApexIQ WinCommand™.

The following suppliers are used to operate the service:

Supplier Role
Supabase Inc. Authentication, database, storage, and session-related infrastructure
Netlify, Inc. Application hosting, serverless functions, content delivery, real user metrics (Section 5.1), and website analytics (Section 5.2)
Stripe, Inc. Payment processing, subscription management, invoicing, and customer portal
Resend, Inc. Transactional email delivery

Some suppliers may set or rely on cookies or similar technologies when users interact with payment portals, authentication flows, hosted pages, customer portals, or embedded services.

11. Stripe and payment portal cookies

If subscribers use Stripe-hosted checkout, payment pages, invoicing links, or the Stripe Customer Portal, Stripe may use cookies or similar technologies for payment processing, fraud prevention, security, and compliance. Those pages are controlled by Stripe, and Stripe's own cookie and privacy notices apply to them.

12. Public website cookies

This Cookie Notice is for ApexIQ WinCommand™.

The public Apex Edge Sales Engineering Limited website may require a separate cookie notice if it uses analytics, marketing cookies, pixels, embedded forms, embedded media, social media plugins, scheduling tools, CRM forms, chat widgets, advertising tags, lead tracking, or consent management tools.

13. Changes to this notice

Apex Edge Sales Engineering Limited may update this Cookie Notice from time to time.

Updates may be needed where:

  • cookies or similar technologies change;
  • suppliers change;
  • authentication methods change;
  • payment flows change;
  • analytics or marketing tools are introduced;
  • consent mechanisms are introduced or changed;
  • legal or regulatory requirements change.

Where material changes are made, Apex Edge Sales Engineering Limited may notify users by website notice, in-product notice, email, cookie banner, or another reasonable method.

14. Contact

Questions about this Cookie Notice should be sent to:

Apex Edge Sales Engineering Limited, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

Email: privacy@apexedgesalesengineering.com

15. Contact points

Purpose Email
General enquiries contact@apexedgesalesengineering.com
Legal notices and contractual correspondence legal@apexedgesalesengineering.com
Billing, invoices, VAT, refunds, payment, and purchase orders billing@apexedgesalesengineering.com
Product support support@apexedgesalesengineering.com
Privacy, cookies, and data rights privacy@apexedgesalesengineering.com
Security reports and vulnerability concerns security@apexedgesalesengineering.com
Cookie Policy | ApexIQ WinCommand™