For customers

Account

Your account and security

Email, password, sessions, and what data we store.

Sessions

Cookies are scoped per-host. Signing out of one storefront does not sign you out of others — explicit by design. Use the apex /logout to clear the apex marketplace session.

Password

Bcrypt-hashed at rest. Reset via the "Forgot password" link on /login (uses the platform email provider). On a roadmap: SSO with Google + Apple; passkeys; 2FA.

What we store

  • Profile: email, display name.
  • Bookings: items, status history, total paid, payment method last4.
  • Reviews + your wallet balance per tenant.
  • No card numbers — Stripe / Razorpay holds those.