siimple Back to siimple.ai
Draft

This policy is under operational and legal review. It is not yet in force and must be verified against production data practices before publication.

This Privacy Policy explains how Siimple INC ("Siimple," "we," "us," or "our") collects, uses, discloses, and retains information through siimple.ai, OTP+, Securify, Trust Network, support, and related services (the "Services").

It replaces references to our former name, Etterno.io Inc. This policy should be read with our Terms of Service and any merchant-specific order form or data-processing agreement.

1. Scope and Our Roles

This policy applies to merchants, merchant staff, store visitors, customers, applicants, and other people whose information is processed through the Services.

For merchant account, website, application, and support information, Siimple generally decides why and how the information is processed. For OTP+ and Securify, Siimple acts as a service provider or processor to each merchant, processing shopper and order data on the merchant's behalf and in accordance with the merchant's documented instructions. For Trust Network, Siimple acts as an independent controller for the cross-merchant risk intelligence processing, while remaining a service provider or processor for the core OTP+ and Securify functions. The parties' exact roles may depend on the product, jurisdiction, and applicable agreement.

Controller vs. Service Provider:

  • OTP+ and Securify (core services): Siimple is a service provider/processor. We process data solely to deliver the contracted service per merchant instructions. We do not use this data for our own independent purposes.
  • Trust Network: Siimple is an independent controller for the cross-merchant risk-modeling, commingling, and network-score generation. We independently determine the purposes and means of this processing, including which signals to combine, how to weight them, and what risk context to provide to participating merchants. Merchants authorize this processing but do not jointly determine its means.
  • Billing, security, product improvement: Siimple is an independent controller for its own account management, platform security, and product development using anonymized/aggregated data.

If you are a shopper or store visitor, contact the Shopify merchant first to exercise rights concerning that merchant's store. We support verified requests received from merchants and Shopify.

2. Information We Collect

CategoryExamplesWhy it is needed
Merchant and staff information Name, business email, phone number, address, Shopify store domain and ID, account role, plan, settings, billing status, and support messages. Install, authenticate, bill, administer, and support the Services.
Shopper and order information Name, email, phone number, physical address, customer and order IDs, cart or checkout context, order value, fulfillment status, Shopify risk recommendations, disputes, and merchant actions. Provide login, verification, order-risk, customer-risk, and merchant workflow features.
Device and activity information IP address, approximate geolocation, browser, operating system, client or device identifier, fingerprint, timestamps, page or store interactions, VPN, proxy, hosting-provider, bot, and browser-behavior signals. Operate visitor logs, enforce merchant rules, identify automation, and generate risk context.
Authentication information Phone number or email used for verification, OTP delivery and verification events, login method, Google or Apple login identifiers, and authentication status. Provide OTP+, social login, access control, and verification.
Risk and network information Email-validation results, device or fingerprint history, cross-merchant sightings, bot detections, order-risk assessments, dispute outcomes, signal sources, and risk reasons. Provide Securify and Trust Network risk context and improve detection quality.
Website and application information Work email, store URL, funnel concern, monthly-order range, consent record, page usage, and browser storage preferences. Review early-access requests, respond to inquiries, remember preferences, and measure website use when analytics consent is granted.

Sensitive Personal Information Prohibited: Merchants may not provide Sensitive Personal Information (as defined by CCPA/CPRA) or Special Category Data (as defined by GDPR Article 9) to Trust Network without Siimple's prior written approval. This includes: social security numbers, government IDs, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, biometric data, and genetic data.

Precedent basis: CHEQ DPA restricts processing of sensitive categories; Arkose Labs DPA restricts "Special Category Data" under GDPR Article 9.

Trust Network Signals

When you visit or make a purchase on a Merchant Store that participates in Trust Network, we may collect and process the following categories of risk signals:

CategoryExamplesHow used
Device signals Browser fingerprint, canvas fingerprint, operating system, screen resolution, installed fonts, timezone, language settings Detect device anomalies and spoofing
Traffic signals IP address (truncated/anonymized), referrer URL, session duration, click patterns, navigation path Identify bot behavior and session anomalies
Order-risk signals Order value, velocity, shipping/billing mismatch, payment method risk indicators Assess transaction fraud likelihood
Account signals Login attempt frequency, password reset patterns, account creation velocity Detect account takeover and synthetic identity
Outcome signals [HASHED] Chargeback flags, dispute outcomes, merchant-configured block/allow actions Train and validate network risk models

Important: Where technically feasible, we hash or tokenize direct identifiers (email addresses, customer IDs, order IDs) before including them in network comparisons. IP addresses are truncated or anonymized. We do not share your raw personal information with other merchants.

Shopify determines and displays the permissions requested by each app. The exact fields available to Siimple depend on the app, plan, feature, configuration, and permissions approved by the merchant.

3. Sources of Information

We receive information:

  • directly from merchants, staff, applicants, and support contacts;
  • from Shopify through app permissions, webhooks, storefront pixels, APIs, and approved integrations;
  • automatically from browsers, devices, storefront interactions, and use of the Services;
  • from authentication, communications, hosting, analytics, geolocation, email-validation, IP-intelligence, and security providers; and
  • from participating merchants through Trust Network as described below.

4. How We Use Information

We use information to:

  • provide, configure, bill, maintain, and support the Services;
  • send OTPs, authenticate users, and maintain login or verification records;
  • show visitor activity and apply merchant-configured country, IP, VPN, bot, content, customer, and order controls;
  • evaluate email, device, visit, account, and order-risk signals;
  • operate Trust Network and identify patterns observed across participating merchants;
  • protect the Services, investigate abuse, troubleshoot errors, and maintain service reliability;
  • respond to support, privacy, legal, and security requests;
  • analyze and improve product performance and merchant workflows; and
  • send merchants product or service communications where permitted by law.

Trust Network — Cross-Merchant Fraud Prevention

We process Trust Network risk signals through our proprietary machine learning platform to:

  1. Generate a network risk reputation score for devices, sessions, and behavioral patterns;
  2. Identify connections between data attributes across our entire merchant network;
  3. Provide participating merchants with limited risk context (e.g., "this device has been associated with suspicious activity on other stores in the network");
  4. Improve our fraud detection models and algorithms.

What we do NOT do:

  • We do not tell Merchant B that you shopped at Merchant A;
  • We do not share your name, email address, or full transaction history with other merchants;
  • We do not use this information for advertising or marketing;
  • We do not sell your personal information.

Legal basis:

  • GDPR: Legitimate interest in preventing fraud and maintaining secure e-commerce ecosystems. We have conducted a Legitimate Interest Assessment documenting why this processing is necessary and proportionate.
  • CCPA/CPRA: We act as a service provider to each participating merchant, processing personal information for the business purpose of fraud prevention. We do not "sell" or "share" personal information as defined under CCPA/CPRA.

Marketing and Product Improvement

We may use anonymized and aggregated information derived from Trust Network operations for:

  • Product improvement and feature development;
  • Security research and fraud trend analysis;
  • Marketing communications about Siimple's services (e.g., case studies, performance statistics).

We do not use identifiable personal information from Trust Network for advertising or marketing purposes. Any marketing statistics we publish are based on aggregated, non-identifiable data.

Precedent basis: Arkose Labs Privacy Policy: "Showing you advertisements, including interest-based or online behavioral advertising" (with opt-out); Sift Privacy Notice: "We may use anonymized and aggregated information for product improvement and marketing".

Where applicable, our legal bases include performing a contract, the merchant's instructions, consent, compliance with law, and legitimate interests in providing, securing, and improving the Services. We do not use Shopify shopper data to market directly to those shoppers.

5. Trust Network

Trust Network is available to selected Securify Growth and early-access merchants. It compares permitted risk signals across participating stores so a pattern first observed at one store may provide additional context when it appears elsewhere.

Depending on the enabled features, signals may include email addresses and validation results, IP addresses, device or browser fingerprints, bot and VPN indicators, visit patterns, customer or order identifiers, Shopify risk recommendations, merchant risk actions, and dispute outcomes.

What another merchant receives: risk context relevant to activity at its own store, such as whether a permitted identifier or pattern has prior risk history. Trust Network is not designed to expose another participating merchant's identity, customer list, order records, or store-specific business data.

How Trust Network Works

Trust Network operates on a commingled model:

  • Your risk signals are combined with comparable signals from other merchants;
  • We analyze patterns across the combined dataset;
  • We provide analytical results only (risk scores, reputation flags, pattern alerts) to individual merchants;
  • No merchant receives another merchant's raw customer data.

Recipients: Participating Trust Network merchants (analytical results only); our hosting and infrastructure providers (subprocessors); data enrichment providers (limited, for fraud context only).

Network signals are indicators, not proof that a person or order is fraudulent. Merchants remain responsible for configuring actions, reviewing results, supporting legitimate customers, and complying with applicable law.

A merchant may leave Trust Network by changing its eligible plan or contacting Siimple. This stops new participation after the change is processed. Previously generated records remain subject to the retention and deletion rules below, legal obligations, and any applicable data-processing agreement.

6. How We Disclose Information

We may disclose information:

  • to Shopify and platforms selected by the merchant to provide an integration;
  • to service providers that support hosting, storage, communications, authentication, analytics, support, geolocation, email validation, IP intelligence, security, and payment processing;
  • as limited Trust Network risk context to participating merchants, as described above;
  • when directed or authorized by the merchant;
  • to comply with law or protect rights, safety, and the integrity of the Services; and
  • in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

Depending on the product and configuration, providers may include Shopify, DigitalOcean, Google, Apple, Firebase, Google Analytics, Google Apps Script and Sheets, PostHog, Twilio, MSG91, MaxMind, IPData, IPQualityScore, and Reoon. A provider receives only the information needed for its function and processes it under its own terms and our applicable agreement.

We do not sell personal information. We do not sell Shopify customer personal information for money, and we do not use it for cross-context behavioral advertising. Under CCPA/CPRA, we act as a service provider to each merchant. We do not receive personal information as consideration for any service.

Do Not Sell or Share My Personal Information: Although we do not believe we are required to provide this option, we offer it as a defensive compliance measure. Submit an opt-out request.

Contractual certification: Under our agreements with each merchant, Siimple contractually certifies that we:

  • Do not sell personal information as defined by CCPA/CPRA;
  • Do not share personal information for cross-context behavioral advertising;
  • Do not retain, use, or disclose personal information outside the direct business relationship with each merchant;
  • Do not combine personal information received from one merchant with personal information received from another merchant or third party, except as necessary to provide the Services.

Precedent basis: CHEQ DPA: "not lease, sell (including as defined in the CCPA and CPRA) or otherwise distribute Personal Data"; Sift ToS: "Sift is a 'service provider' or 'processor' as defined under the applicable U.S. State Privacy Laws"; Arkose DPA: "Company agrees that it shall not: (a) sell the Personal Data".

7. Automated Decision-Making and Profiling

We use automated profiling to detect fraud patterns across our network. This includes analyzing device and behavioral signals, comparing them against known fraud patterns, and generating risk scores.

Automated decisions with legal or similarly significant effects:

Siimple does not automatically block transactions, cancel orders, or deny service. We provide risk scores to merchants, and the merchant decides what action to take. Merchants set their own thresholds for automated actions (e.g., requiring additional verification, flagging for review, or blocking).

Automated Challenges and Merchant-Configured Actions

Depending on merchant configuration, Trust Network scores may trigger:

  • Additional verification challenges (e.g., OTP, CAPTCHA, step-up authentication) — initiated by the merchant's system based on Siimple's risk score;
  • Transaction review flags — orders held for manual merchant review;
  • Access restrictions — in cases of high risk, merchants may configure temporary access limitations.

Siimple does not set these thresholds or configure these actions. The merchant independently decides what response to implement at each risk level. If you believe you were incorrectly challenged or restricted, please contact the merchant directly to request human review or explanation.

Your rights: Depending on your location, you may have the right to:

  • Obtain human intervention in automated decision-making;
  • Express your point of view;
  • Contest the decision.

8. Website Storage and Analytics

The website uses browser local storage to remember theme and analytics choices. Google Analytics loads only after a visitor grants analytics consent. A visitor may decline analytics without losing access to the website.

The early-access form sends the submitted fields to Google Apps Script and Google Sheets for review by the Siimple team. The form also includes a hidden anti-spam field.

You may change analytics consent through the website's Cookie choices control. Browser settings can also clear stored preferences.

9. Retention and Deletion

We retain information only for as long as reasonably needed for the purposes described in this policy, the merchant relationship, security, dispute resolution, legal compliance, and enforcement of agreements.

  • OTP codes: deleted after successful verification unless configured to expire, and otherwise retained only until expiration. Verification and authentication event records may be kept longer for account security, support, and abuse prevention.
  • Raw visitor and risk events: normally remain in active event partitions for approximately 30 days. Restricted archival copies may be retained longer for service continuity, security, debugging, legal obligations, and risk-history integrity.
  • Merchant, customer, and order records: retained while needed to provide the installed service and afterward as required for Shopify privacy requests, support, fraud or dispute investigation, financial records, and applicable law.
  • Early-access applications: retained for up to 12 months after the last meaningful contact unless the applicant joins the Services, requests deletion, or a longer period is required by law.
  • Aggregated or de-identified information: may be retained for product analysis and security while it can no longer reasonably identify a person or merchant.

Trust Network Retention Schedule

Data CategoryActive RetentionArchive/Model RetentionDeletion Protocol
Raw risk signals (device, traffic, order) ~30 days N/A — deleted or anonymized after active period Automated purge after 30 days
Network reputation scores (linked to hashed identifiers) Duration of merchant participation Up to 12 months for model training and validation Anonymized or deleted upon merchant exit or shopper request
Historical fraud patterns (aggregated, non-identifiable) Indefinite Indefinite Not personal data once properly anonymized
Application/audit records (merchant applicants) 12 months N/A Deleted after 12 months unless legal hold applies

Deletion requests: When you request deletion, we remove all identifiable personal data within 30 days. Where complete erasure would compromise the integrity of our fraud detection models, we retain hashed, non-reversible representations of risk signals for the minimum time necessary to maintain model accuracy, then delete them. Data in backup systems is securely isolated and deleted per our backup purge schedule.

Backups and archives are deleted or overwritten according to operational schedules. When immediate deletion from a backup is not practical, the information is isolated from ordinary use until deletion or overwrite.

10. Privacy Rights and Shopify Requests

Depending on location and our role, a person may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent. We will not discriminate against a person for exercising a privacy right.

Shopify sends required customer-data access and deletion requests to installed public apps. We process verified customers/data_request, customers/redact, and shop/redact requests as required by Shopify and applicable law.

Merchants and applicants may contact [email protected]. Shoppers should contact the merchant first. We may need information to verify identity, store authority, and the scope of a request.

California Privacy Rights: If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use it;
  • Delete your personal information (subject to exceptions);
  • Correct inaccurate personal information;
  • Opt out of "sale" and "sharing" of your personal information.

Do Not Sell or Share My Personal Information: Submit an opt-out request.

Even though we do not "sell" personal information for money and do not "share" it for cross-context behavioral advertising, we provide this opt-out mechanism as a defensive compliance measure.

Network-wide deletion: When a shopper requests deletion, we delete identifiable personal data across all Services, including Trust Network. Where deletion would compromise model integrity, we retain hashed, non-reversible representations for the minimum period necessary, then delete them. We do not retain identifiable data in the network after a valid deletion request.

11. Subprocessors

We use the following categories of subprocessors to provide the Services:

  • Cloud infrastructure: DigitalOcean, Google Cloud Platform
  • Analytics: Google Analytics (with consent), PostHog
  • Communications: Twilio, MSG91
  • Authentication: Google, Apple, Firebase
  • Geolocation and IP intelligence: MaxMind, IPData, IPQualityScore
  • Email validation: Reoon
  • Application management: Google Apps Script, Google Sheets

A current list of subprocessors is available in the Data Processing Addendum.

We provide at least 30 days' advance notice before adding or replacing infrastructure subprocessors. Merchants may object to new subprocessors on reasonable data protection grounds.

12. International Transfers

Siimple is based in the United States and uses providers that may process information in the United States and other countries. Where required, we use contractual or other recognized safeguards for transfers of personal information.

For data originating from the EEA, UK, or Switzerland, we rely on:

  • EU Standard Contractual Clauses (2021/914);
  • UK International Data Transfer Addendum (Version B1.0);
  • Data Privacy Framework certification (if applicable).

Merchants are responsible for providing any notices and obtaining any permissions required for their use of the Services in the countries where they operate.

13. Security

We use administrative, technical, and organizational measures designed to protect information, including access controls, authentication, encrypted connections, monitoring, backups, and restricted production access where appropriate.

No system is completely secure. Report suspected security issues involving the Services to [email protected]. Do not include sensitive customer information unless requested through a secure channel.

14. Children

The Services are business tools for Shopify merchants and are not directed to children. We do not knowingly collect personal information directly from a child through siimple.ai. A merchant using the Services remains responsible for its storefront audience and any legally required parental consent.

COPPA Compliance: The Children's Online Privacy Protection Act (COPPA) requires that online service providers obtain parental consent before knowingly collecting personally identifiable information from children under 13 years of age. We do not knowingly collect or solicit personal information from children under 13. If we learn we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe a child under 13 may have provided us personal information, please contact us at [email protected].

Precedent basis: Arkose Labs Terms of Use: "The Children's Online Privacy Protection Act (COPPA) requires that online service providers obtain parental consent...We do not knowingly collect or solicit personally identifiable information from a child under 16".

15. Changes to This Policy

We may update this policy as the Services, data practices, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when a material change requires it.

If we make material changes to how we process data in Trust Network, we will:

  • Post the updated policy at least 30 days before the changes take effect;
  • Notify participating merchants via email;
  • Require merchants to update their privacy policies if necessary.

16. Contact

Siimple INC
Attn: Privacy
6381 Almaden Road
San Jose, CA 95120
United States
[email protected]

EU/UK Data Protection: Siimple processes personal data in the United States. For data originating from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum for lawful international transfers. We are in the process of appointing an EU representative and a UK representative as required by GDPR Article 27 and UK GDPR Article 27. Until representatives are appointed, EU/UK data subjects and supervisory authorities may contact us directly at [email protected] or at the address above.

Contact us at the address above with questions, complaints, or privacy requests. You may also have the right to complain to a local data-protection authority.