siimple Back to siimple.ai

This Data Processing Addendum ("DPA") is between Siimple INC ("Siimple") and the merchant ("Merchant") using Siimple's Shopify applications and services (the "Services"). This DPA supplements the Terms of Service and Privacy Policy.

1. Roles

For OTP+ and Securify core services, Siimple acts as a Processor and Merchant is the Controller of personal data.

For Trust Network, Merchant authorizes Siimple to process risk signals as part of fraud prevention services. Siimple processes this data on Merchant's behalf and in accordance with Merchant's documented instructions.

Each party is responsible for its own compliance with applicable data protection law.

2. Data Categories

Siimple processes the following categories of personal data:

  • Merchant and staff information: Name, business email, phone, address, Shopify store domain and ID, account role, plan, settings, billing status;
  • Shopper and order information: Name, email, phone, address, customer and order IDs, cart/checkout context, order value, fulfillment status, Shopify risk recommendations, disputes, merchant actions;
  • Device and activity information: IP address (truncated), browser, operating system, device identifier, fingerprint (hashed), timestamps, page interactions, VPN/proxy/bot signals;
  • Authentication information: Phone/email for verification, OTP events, login method, authentication status;
  • Risk and network signals: Email validation results, device history, bot/VPN indicators, visit patterns, order-risk assessments, dispute outcomes.

Merchant will not provide Sensitive Personal Information (as defined by CCPA/CPRA) or Special Category Data (as defined by GDPR Article 9) without Siimple's prior written approval.

3. Subprocessors

Siimple uses the following subprocessors to provide the Services:

  • DigitalOcean — cloud infrastructure, US;
  • Google Cloud Platform — cloud infrastructure, US;
  • Twilio — SMS/OTP delivery, US;
  • MaxMind — IP geolocation and intelligence, US;
  • Google Analytics — website analytics (with consent), US;
  • PostHog — product analytics, US;
  • Google Apps Script / Sheets — early-access application management, US.

Siimple will email Merchant at least 14 days before adding a new infrastructure subprocessor. Merchant may object to a new subprocessor on reasonable data protection grounds by contacting [email protected].

4. Security

Siimple implements the following technical and organizational measures:

  • Encryption in transit using TLS 1.2 or higher;
  • Encryption at rest for databases and storage;
  • Role-based access controls and multi-factor authentication;
  • Security event logging and monitoring;
  • Regular vulnerability assessments;
  • Incident response procedures.

No system is completely secure. Siimple does not guarantee that unauthorized access, loss, or disruption will never occur.

5. Data Subject Rights

Siimple will assist Merchant in responding to data subject requests (access, correction, deletion, restriction) by:

  • Providing appropriate technical measures to fulfill requests;
  • Promptly forwarding requests received directly from data subjects;
  • Providing information necessary to respond to the request.

Siimple will process verified Shopify customer-data requests (customers/data_request, customers/redact, shop/redact) as required by Shopify's terms and applicable law.

Shoppers should contact the merchant first to exercise rights concerning that merchant's store.

6. International Transfers

Siimple is based in the United States and processes data in the US.

For personal data transferred from the European Economic Area (EEA), United Kingdom, or Switzerland, Siimple relies on:

  • EU Standard Contractual Clauses (2021/914, Module Two, Controller to Processor);
  • UK International Data Transfer Addendum (Version B1.0, where applicable);
  • Data Privacy Framework certification (if applicable).

EU Representative: Siimple is in the process of appointing an EU representative as required by GDPR Article 27. Until appointed, EU data subjects and supervisory authorities may contact Siimple directly.

UK Representative: Siimple is in the process of appointing a UK representative as required by UK GDPR Article 27. Until appointed, UK data subjects and the ICO may contact Siimple directly.

Merchants are responsible for providing any notices and obtaining any permissions required for their use of the Services in the countries where they operate.

7. Term and Termination

This DPA is effective as of the date Merchant first uses the Services and continues for the duration of the Services.

Upon termination, Siimple will delete or return Merchant's personal data within 90 days, except where retention is required by law or for security, fraud, or dispute investigation purposes.

Aggregated or de-identified information may be retained for product analysis and security while it can no longer reasonably identify a person or merchant.