This Privacy Policy explains how Siimple INC ("Siimple," "we," "us," or "our") collects, uses, discloses, and retains information through siimple.ai, OTP+, Securify, Trust Network, support, and related services (the "Services").
It replaces references to our former name, Etterno.io Inc. This policy should be read with our Terms of Service and any merchant-specific order form or data-processing agreement.
1. Scope and Our Roles
This policy applies to merchants, merchant staff, store visitors, customers, applicants, and other people whose information is processed through the Services.
For merchant account, website, application, and support information, Siimple generally decides why and how the information is processed. For OTP+ and Securify, Siimple acts as a service provider or processor to each merchant, processing shopper and order data on the merchant's behalf and in accordance with the merchant's documented instructions. For Trust Network, Siimple acts as an independent controller for the cross-merchant risk intelligence processing, while remaining a service provider or processor for the core OTP+ and Securify functions. The parties' exact roles may depend on the product, jurisdiction, and applicable agreement.
Controller vs. Service Provider:
- OTP+ and Securify (core services): Siimple is a service provider/processor. We process data solely to deliver the contracted service per merchant instructions. We do not use this data for our own independent purposes.
- Trust Network: Siimple is an independent controller for the cross-merchant risk-modeling, commingling, and network-score generation. We independently determine the purposes and means of this processing, including which signals to combine, how to weight them, and what risk context to provide to participating merchants. Merchants authorize this processing but do not jointly determine its means.
- Billing, security, product improvement: Siimple is an independent controller for its own account management, platform security, and product development using anonymized/aggregated data.
If you are a shopper or store visitor, contact the Shopify merchant first to exercise rights concerning that merchant's store. We support verified requests received from merchants and Shopify.
2. Information We Collect
| Category | Examples | Why it is needed |
|---|---|---|
| Merchant and staff information | Name, business email, phone number, address, Shopify store domain and ID, account role, plan, settings, billing status, and support messages. | Install, authenticate, bill, administer, and support the Services. |
| Shopper and order information | Name, email, phone number, physical address, customer and order IDs, cart or checkout context, order value, fulfillment status, Shopify risk recommendations, disputes, and merchant actions. | Provide login, verification, order-risk, customer-risk, and merchant workflow features. |
| Device and activity information | IP address, approximate geolocation, browser, operating system, client or device identifier, fingerprint, timestamps, page or store interactions, VPN, proxy, hosting-provider, bot, and browser-behavior signals. | Operate visitor logs, enforce merchant rules, identify automation, and generate risk context. |
| Authentication information | Phone number or email used for verification, OTP delivery and verification events, login method, Google or Apple login identifiers, and authentication status. | Provide OTP+, social login, access control, and verification. |
| Risk and network information | Email-validation results, device or fingerprint history, cross-merchant sightings, bot detections, order-risk assessments, dispute outcomes, signal sources, and risk reasons. | Provide Securify and Trust Network risk context and improve detection quality. |
| Website and application information | Work email, store URL, funnel concern, monthly-order range, consent record, page usage, and browser storage preferences. | Review early-access requests, respond to inquiries, remember preferences, and measure website use when analytics consent is granted. |
Sensitive Personal Information Prohibited: Merchants may not provide Sensitive Personal Information (as defined by CCPA/CPRA) or Special Category Data (as defined by GDPR Article 9) to Trust Network without Siimple's prior written approval. This includes: social security numbers, government IDs, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, biometric data, and genetic data.
Precedent basis: CHEQ DPA restricts processing of sensitive categories; Arkose Labs DPA restricts "Special Category Data" under GDPR Article 9.
Trust Network Signals
When you visit or make a purchase on a Merchant Store that participates in Trust Network, we may collect and process the following categories of risk signals:
| Category | Examples | How used |
|---|---|---|
| Device signals | Browser fingerprint, canvas fingerprint, operating system, screen resolution, installed fonts, timezone, language settings | Detect device anomalies and spoofing |
| Traffic signals | IP address (truncated/anonymized), referrer URL, session duration, click patterns, navigation path | Identify bot behavior and session anomalies |
| Order-risk signals | Order value, velocity, shipping/billing mismatch, payment method risk indicators | Assess transaction fraud likelihood |
| Account signals | Login attempt frequency, password reset patterns, account creation velocity | Detect account takeover and synthetic identity |
| Outcome signals | [HASHED] Chargeback flags, dispute outcomes, merchant-configured block/allow actions | Train and validate network risk models |
Important: Where technically feasible, we hash or tokenize direct identifiers (email addresses, customer IDs, order IDs) before including them in network comparisons. IP addresses are truncated or anonymized. We do not share your raw personal information with other merchants.
Shopify determines and displays the permissions requested by each app. The exact fields available to Siimple depend on the app, plan, feature, configuration, and permissions approved by the merchant.
3. Sources of Information
We receive information:
- directly from merchants, staff, applicants, and support contacts;
- from Shopify through app permissions, webhooks, storefront pixels, APIs, and approved integrations;
- automatically from browsers, devices, storefront interactions, and use of the Services;
- from authentication, communications, hosting, analytics, geolocation, email-validation, IP-intelligence, and security providers; and
- from participating merchants through Trust Network as described below.
4. How We Use Information
We use information to:
- provide, configure, bill, maintain, and support the Services;
- send OTPs, authenticate users, and maintain login or verification records;
- show visitor activity and apply merchant-configured country, IP, VPN, bot, content, customer, and order controls;
- evaluate email, device, visit, account, and order-risk signals;
- operate Trust Network and identify patterns observed across participating merchants;
- protect the Services, investigate abuse, troubleshoot errors, and maintain service reliability;
- respond to support, privacy, legal, and security requests;
- analyze and improve product performance and merchant workflows; and
- send merchants product or service communications where permitted by law.
Trust Network — Cross-Merchant Fraud Prevention
We process Trust Network risk signals through our proprietary machine learning platform to:
- Generate a network risk reputation score for devices, sessions, and behavioral patterns;
- Identify connections between data attributes across our entire merchant network;
- Provide participating merchants with limited risk context (e.g., "this device has been associated with suspicious activity on other stores in the network");
- Improve our fraud detection models and algorithms.
What we do NOT do:
- We do not tell Merchant B that you shopped at Merchant A;
- We do not share your name, email address, or full transaction history with other merchants;
- We do not use this information for advertising or marketing;
- We do not sell your personal information.
Legal basis:
- GDPR: Legitimate interest in preventing fraud and maintaining secure e-commerce ecosystems. We have conducted a Legitimate Interest Assessment documenting why this processing is necessary and proportionate.
- CCPA/CPRA: We act as a service provider to each participating merchant, processing personal information for the business purpose of fraud prevention. We do not "sell" or "share" personal information as defined under CCPA/CPRA.
Marketing and Product Improvement
We may use anonymized and aggregated information derived from Trust Network operations for:
- Product improvement and feature development;
- Security research and fraud trend analysis;
- Marketing communications about Siimple's services (e.g., case studies, performance statistics).
We do not use identifiable personal information from Trust Network for advertising or marketing purposes. Any marketing statistics we publish are based on aggregated, non-identifiable data.
Precedent basis: Arkose Labs Privacy Policy: "Showing you advertisements, including interest-based or online behavioral advertising" (with opt-out); Sift Privacy Notice: "We may use anonymized and aggregated information for product improvement and marketing".
Where applicable, our legal bases include performing a contract, the merchant's instructions, consent, compliance with law, and legitimate interests in providing, securing, and improving the Services. We do not use Shopify shopper data to market directly to those shoppers.
5. Trust Network
Trust Network is available to selected Securify Growth and early-access merchants. It compares permitted risk signals across participating stores so a pattern first observed at one store may provide additional context when it appears elsewhere.
Depending on the enabled features, signals may include email addresses and validation results, IP addresses, device or browser fingerprints, bot and VPN indicators, visit patterns, customer or order identifiers, Shopify risk recommendations, merchant risk actions, and dispute outcomes.
How Trust Network Works
Trust Network operates on a commingled model:
- Your risk signals are combined with comparable signals from other merchants;
- We analyze patterns across the combined dataset;
- We provide analytical results only (risk scores, reputation flags, pattern alerts) to individual merchants;
- No merchant receives another merchant's raw customer data.
Recipients: Participating Trust Network merchants (analytical results only); our hosting and infrastructure providers (subprocessors); data enrichment providers (limited, for fraud context only).
Network signals are indicators, not proof that a person or order is fraudulent. Merchants remain responsible for configuring actions, reviewing results, supporting legitimate customers, and complying with applicable law.
A merchant may leave Trust Network by changing its eligible plan or contacting Siimple. This stops new participation after the change is processed. Previously generated records remain subject to the retention and deletion rules below, legal obligations, and any applicable data-processing agreement.
7. Automated Decision-Making and Profiling
We use automated profiling to detect fraud patterns across our network. This includes analyzing device and behavioral signals, comparing them against known fraud patterns, and generating risk scores.
Automated decisions with legal or similarly significant effects:
Siimple does not automatically block transactions, cancel orders, or deny service. We provide risk scores to merchants, and the merchant decides what action to take. Merchants set their own thresholds for automated actions (e.g., requiring additional verification, flagging for review, or blocking).
Automated Challenges and Merchant-Configured Actions
Depending on merchant configuration, Trust Network scores may trigger:
- Additional verification challenges (e.g., OTP, CAPTCHA, step-up authentication) — initiated by the merchant's system based on Siimple's risk score;
- Transaction review flags — orders held for manual merchant review;
- Access restrictions — in cases of high risk, merchants may configure temporary access limitations.
Siimple does not set these thresholds or configure these actions. The merchant independently decides what response to implement at each risk level. If you believe you were incorrectly challenged or restricted, please contact the merchant directly to request human review or explanation.
Your rights: Depending on your location, you may have the right to:
- Obtain human intervention in automated decision-making;
- Express your point of view;
- Contest the decision.
9. Retention and Deletion
We retain information only for as long as reasonably needed for the purposes described in this policy, the merchant relationship, security, dispute resolution, legal compliance, and enforcement of agreements.
- OTP codes: deleted after successful verification unless configured to expire, and otherwise retained only until expiration. Verification and authentication event records may be kept longer for account security, support, and abuse prevention.
- Raw visitor and risk events: normally remain in active event partitions for approximately 30 days. Restricted archival copies may be retained longer for service continuity, security, debugging, legal obligations, and risk-history integrity.
- Merchant, customer, and order records: retained while needed to provide the installed service and afterward as required for Shopify privacy requests, support, fraud or dispute investigation, financial records, and applicable law.
- Early-access applications: retained for up to 12 months after the last meaningful contact unless the applicant joins the Services, requests deletion, or a longer period is required by law.
- Aggregated or de-identified information: may be retained for product analysis and security while it can no longer reasonably identify a person or merchant.
Trust Network Retention Schedule
| Data Category | Active Retention | Archive/Model Retention | Deletion Protocol |
|---|---|---|---|
| Raw risk signals (device, traffic, order) | ~30 days | N/A — deleted or anonymized after active period | Automated purge after 30 days |
| Network reputation scores (linked to hashed identifiers) | Duration of merchant participation | Up to 12 months for model training and validation | Anonymized or deleted upon merchant exit or shopper request |
| Historical fraud patterns (aggregated, non-identifiable) | Indefinite | Indefinite | Not personal data once properly anonymized |
| Application/audit records (merchant applicants) | 12 months | N/A | Deleted after 12 months unless legal hold applies |
Deletion requests: When you request deletion, we remove all identifiable personal data within 30 days. Where complete erasure would compromise the integrity of our fraud detection models, we retain hashed, non-reversible representations of risk signals for the minimum time necessary to maintain model accuracy, then delete them. Data in backup systems is securely isolated and deleted per our backup purge schedule.
Backups and archives are deleted or overwritten according to operational schedules. When immediate deletion from a backup is not practical, the information is isolated from ordinary use until deletion or overwrite.
10. Privacy Rights and Shopify Requests
Depending on location and our role, a person may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent. We will not discriminate against a person for exercising a privacy right.
Shopify sends required customer-data access and deletion requests to installed public apps. We process verified customers/data_request, customers/redact, and shop/redact requests as required by Shopify and applicable law.
Merchants and applicants may contact [email protected]. Shoppers should contact the merchant first. We may need information to verify identity, store authority, and the scope of a request.
California Privacy Rights: If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it;
- Delete your personal information (subject to exceptions);
- Correct inaccurate personal information;
- Opt out of "sale" and "sharing" of your personal information.
Do Not Sell or Share My Personal Information: Submit an opt-out request.
Even though we do not "sell" personal information for money and do not "share" it for cross-context behavioral advertising, we provide this opt-out mechanism as a defensive compliance measure.
Network-wide deletion: When a shopper requests deletion, we delete identifiable personal data across all Services, including Trust Network. Where deletion would compromise model integrity, we retain hashed, non-reversible representations for the minimum period necessary, then delete them. We do not retain identifiable data in the network after a valid deletion request.
11. Subprocessors
We use the following categories of subprocessors to provide the Services:
- Cloud infrastructure: DigitalOcean, Google Cloud Platform
- Analytics: Google Analytics (with consent), PostHog
- Communications: Twilio, MSG91
- Authentication: Google, Apple, Firebase
- Geolocation and IP intelligence: MaxMind, IPData, IPQualityScore
- Email validation: Reoon
- Application management: Google Apps Script, Google Sheets
A current list of subprocessors is available in the Data Processing Addendum.
We provide at least 30 days' advance notice before adding or replacing infrastructure subprocessors. Merchants may object to new subprocessors on reasonable data protection grounds.
12. International Transfers
Siimple is based in the United States and uses providers that may process information in the United States and other countries. Where required, we use contractual or other recognized safeguards for transfers of personal information.
For data originating from the EEA, UK, or Switzerland, we rely on:
- EU Standard Contractual Clauses (2021/914);
- UK International Data Transfer Addendum (Version B1.0);
- Data Privacy Framework certification (if applicable).
Merchants are responsible for providing any notices and obtaining any permissions required for their use of the Services in the countries where they operate.
13. Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, authentication, encrypted connections, monitoring, backups, and restricted production access where appropriate.
No system is completely secure. Report suspected security issues involving the Services to [email protected]. Do not include sensitive customer information unless requested through a secure channel.
14. Children
The Services are business tools for Shopify merchants and are not directed to children. We do not knowingly collect personal information directly from a child through siimple.ai. A merchant using the Services remains responsible for its storefront audience and any legally required parental consent.
COPPA Compliance: The Children's Online Privacy Protection Act (COPPA) requires that online service providers obtain parental consent before knowingly collecting personally identifiable information from children under 13 years of age. We do not knowingly collect or solicit personal information from children under 13. If we learn we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe a child under 13 may have provided us personal information, please contact us at [email protected].
Precedent basis: Arkose Labs Terms of Use: "The Children's Online Privacy Protection Act (COPPA) requires that online service providers obtain parental consent...We do not knowingly collect or solicit personally identifiable information from a child under 16".
15. Changes to This Policy
We may update this policy as the Services, data practices, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when a material change requires it.
If we make material changes to how we process data in Trust Network, we will:
- Post the updated policy at least 30 days before the changes take effect;
- Notify participating merchants via email;
- Require merchants to update their privacy policies if necessary.
16. Contact
Siimple INCAttn: Privacy
6381 Almaden Road
San Jose, CA 95120
United States
[email protected]
EU/UK Data Protection: Siimple processes personal data in the United States. For data originating from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum for lawful international transfers. We are in the process of appointing an EU representative and a UK representative as required by GDPR Article 27 and UK GDPR Article 27. Until representatives are appointed, EU/UK data subjects and supervisory authorities may contact us directly at [email protected] or at the address above.
Contact us at the address above with questions, complaints, or privacy requests. You may also have the right to complain to a local data-protection authority.