siimple Back to siimple.ai
Draft

This document is under business and legal review. It is not yet in force and should not be relied on as the final agreement.

These Terms of Service (the "Terms") govern access to and use of the Siimple website, Shopify applications, software, support, early-access programs, and related services (collectively, the "Services").

In these Terms, "Siimple," "we," "us," and "our" mean Siimple INC, a Delaware corporation. "Merchant," "you," and "your" mean the business or organization accepting these Terms and any person acting on its behalf.

By accessing or using the Services, installing a Siimple application, accepting an order form, or enrolling in an early-access program, you agree to these Terms. These Terms include the Trust Network Addendum (Section 5), which applies if you elect to participate in Trust Network. By applying for or accepting Trust Network, you agree to the Trust Network Addendum in addition to these Terms. If you accept these Terms for a business, you represent that you have authority to bind that business. If you do not agree, do not use the Services.

1. The Services

Siimple provides tools intended to help Shopify merchants identify and respond to activity that may affect revenue, account integrity, store access, content protection, order risk, and related workflows.

The Services may include:

  • OTP+, which provides customer login, one-time-password, social-login, verification, access-control, and related functionality;
  • Securify, which provides traffic monitoring, country and IP controls, bot and VPN detection, content-protection controls, order-risk tools, and related functionality;
  • Trust Network, a limited-availability service that uses permitted signals from participating merchants to provide additional risk context; and
  • websites, dashboards, reports, onboarding, support, and related features made available by Siimple.

The features available to you depend on your plan, store configuration, Shopify eligibility, region, and any applicable order form or early-access acceptance.

2. Shopify and Third-Party Services

The Services are designed to work with Shopify and may rely on other third-party services. Shopify and those third parties are independent from Siimple and are governed by their own terms and privacy policies.

You must maintain an eligible Shopify account and comply with Shopify's applicable terms and policies. Siimple is not responsible for Shopify or another third party changing, suspending, or discontinuing its platform, APIs, billing system, or services.

You authorize Siimple to access your Shopify store and permitted data only through the permissions and integrations you approve. You are responsible for reviewing requested permissions and maintaining appropriate access controls for your staff and contractors.

3. Merchant Accounts and Responsibilities

You are responsible for:

  • providing accurate account, billing, and store information;
  • protecting credentials and promptly reporting suspected unauthorized access;
  • configuring the Services for your business and reviewing automated settings before enabling them;
  • deciding how to respond to risk signals, alerts, recommendations, or blocked activity;
  • maintaining lawful notices, consents, policies, and customer communications;
  • ensuring that your use of SMS, login, verification, customer, order, and device data complies with applicable law; and
  • ensuring that your staff, contractors, and users comply with these Terms.

Risk signals and automated actions may be incomplete or incorrect. You remain responsible for decisions affecting your customers, orders, fulfillment, refunds, account access, and store operations. You must provide a reasonable way for legitimate customers to seek support or correction when your configuration blocks or challenges them.

You may not use the Services to make unlawful discriminatory decisions or violate the rights of any person.

4. Acceptable Use

You may not, and may not allow another person to:

  • use the Services for unlawful, fraudulent, deceptive, or abusive activity;
  • access data or accounts without authorization;
  • interfere with, disrupt, probe, scan, or test the Services except through a Siimple-authorized security program;
  • reverse engineer, copy, resell, sublicense, or create a competing service from the Services except where applicable law prohibits this restriction;
  • bypass usage limits, access restrictions, security controls, or billing mechanisms;
  • upload malicious code or content that infringes another person's rights;
  • use Service outputs as the sole basis for a decision that produces a legal or similarly significant effect on an individual; or
  • represent that Siimple guarantees the identity, legitimacy, creditworthiness, or intent of any visitor or customer.
  • employ or authorize a Siimple competitor to use, view, audit, or evaluate the Services, Documentation, or risk-scoring methodologies, or to provide management, hosting, support, or similar services with respect thereto, without Siimple's prior written consent;
  • use the Services to develop, train, or improve a competing fraud detection, bot management, or risk-scoring product or service;
  • copy, store, or transmit any risk-scoring algorithms, model weights, or proprietary detection logic outside the Services;

5. Trust Network and Early Access

Trust Network is in limited release. Access is subject to eligibility, acceptance, applicable Securify plan requirements, technical readiness, and any additional onboarding terms. Submitting an early-access request does not guarantee acceptance, a launch date, continued access, or any specific feature.

If accepted, Merchant authorizes Siimple to process the data and signals described in the applicable onboarding materials, Privacy Policy, and any signed data-processing agreement for the purpose of operating and improving Trust Network. The Privacy Policy describes the applicable signal categories, purposes, retention approach, and merchant controls.

Trust Network may generate risk context from patterns associated with participating merchants. It does not guarantee that a person, device, visit, account, or order is legitimate or fraudulent. Merchant remains responsible for reviewing the context and configuring any resulting action.

Early-access features may be incomplete, contain errors, change materially, experience interruptions, or be discontinued. Unless an order form states otherwise, early-access features are provided without a service-level commitment. Siimple will use reasonable efforts to give notice of material changes when practical.

5.1 Trust Network Data Use and Restrictions

Siimple will:

  • Use your data solely for fraud prevention, abuse detection, and network risk intelligence;
  • Not sell, rent, or otherwise monetize your customer data;
  • Not identify you as the source of any data in network models provided to other merchants;
  • Apply data minimization and pseudonymization techniques where feasible;
  • Maintain the security measures described in Section 8.

Siimple will NOT:

  • Share your raw customer data (names, emails, full transaction histories) with other merchants;
  • Use network data for advertising or marketing purposes;
  • Contact your customers directly.

5.2 Your Obligations as a Trust Network Merchant

By participating, you represent and warrant that:

(a) Privacy Policy Update. You have updated your store's privacy policy to disclose:

  • Your participation in Trust Network;
  • The categories of data shared with Siimple;
  • The purpose (cross-merchant fraud prevention);
  • A link to Siimple's Privacy Policy;
  • How shoppers can exercise their privacy rights.

(b) Lawful Basis. You have a valid lawful basis under applicable data protection laws to share shopper data with Siimple for Trust Network purposes, and have obtained any necessary consents or provided any necessary notices.

(c) Data Accuracy. You are responsible for the accuracy of the data you provide to Trust Network.

(d) No Sensitive Data. You will not provide Sensitive Personal Information to Trust Network without prior written approval.

(e) No FCRA Use. You will not use Trust Network scores or data for credit, insurance, employment, or housing eligibility decisions governed by the Fair Credit Reporting Act (FCRA).

(f) No FCRA Use. You will not use Trust Network scores, data, or outputs for any purpose regulated by the Fair Credit Reporting Act (FCRA), including but not limited to: credit eligibility, employment eligibility, insurance underwriting, housing eligibility, or tenant screening. You acknowledge that Trust Network scores are not consumer reports and are not intended to replace individual credit checks or background investigations. You are solely responsible for ensuring your use of Trust Network complies with FCRA and all applicable fair lending laws.

5.3 Trust Network Scores and Merchant Actions

Siimple provides scores; you control actions. Siimple returns risk scores, reputation flags, and analytical insights. You decide whether and how to use them, including:

  • Setting thresholds for automated actions (blocks, challenges, reviews);
  • Configuring verification flows;
  • Determining final transaction decisions.

Siimple does not automatically block, cancel, or deny any transaction on your behalf.

5.4 Data Retention and Deletion

Network Data: Siimple retains active network risk records for approximately 30 days. Historical network reputation data linked to hashed identifiers may be retained for up to 12 months for model integrity. Aggregated, non-identifiable fraud patterns may be retained indefinitely.

Deletion Requests: If a shopper requests deletion, Siimple will delete identifiable personal data within 30 days. Where deletion would compromise model integrity, Siimple may retain hashed, non-reversible representations for the minimum period necessary, then delete them.

Post-Termination: Upon your exit from Trust Network, Siimple will cease using your store's data for new network insights within 30 days and will delete or anonymize your store's identifiable data within 90 days, subject to legal retention requirements.

5.5 Subprocessors

Siimple uses third-party subprocessors to provide Trust Network. A current list is available in the Data Processing Addendum. Siimple will provide at least 30 days' advance notice before adding infrastructure subprocessors. You may object to new subprocessors on reasonable data protection grounds. If we cannot resolve your objection, you may terminate Trust Network without penalty.

5.6 No Guarantee Disclaimer for Trust Network

TRUST NETWORK SCORES ARE PROVIDED "AS IS" AND "AS AVAILABLE." WHILE WE STRIVE FOR ACCURACY, SIIMPLE DOES NOT GUARANTEE THAT ANY SCORE WILL CORRECTLY IDENTIFY FRAUDULENT OR LEGITIMATE ACTIVITY. YOU ARE SOLELY RESPONSIBLE FOR DECISIONS MADE BASED ON TRUST NETWORK OUTPUTS.

5.7 Limitation of Liability for Trust Network

TO THE MAXIMUM EXTENT PERMITTED BY LAW, SIIMPLE'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO TRUST NETWORK SHALL NOT EXCEED THE FEES PAID BY YOU FOR TRUST NETWORK IN THE TWELVE (12) MONTHS PRIOR TO THE CLAIM.

5.8 Indemnification for Trust Network

You agree to indemnify and hold harmless Siimple from any claims arising from:

  • Your failure to disclose Trust Network participation in your privacy policy;
  • Your misuse of Trust Network scores (e.g., FCRA violations, discriminatory actions);
  • Your failure to obtain necessary consents or provide necessary notices.

5.9 Early Access Terms

Trust Network is currently in early access. By applying, you acknowledge that:

  • Features may change or be discontinued;
  • No service level agreement (SLA) applies;
  • These Terms govern your participation if accepted;
  • The Privacy Policy governs data collection from the moment you submit your application.

TRUST NETWORK IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. SIIMPLE HEREBY DISCLAIMS ALL LIABILITY FOR ANY HARM OR DAMAGE ARISING OUT OF OR IN CONNECTION WITH TRUST NETWORK, INCLUDING BUT NOT LIMITED TO INCORRECT RISK SCORES, FALSE POSITIVES, FALSE NEGATIVES, MERCHANT MISCONFIGURATION, OR SERVICE INTERRUPTIONS. THIS DISCLAIMER IS IN ADDITION TO, AND NOT IN LIMITATION OF, THE GENERAL DISCLAIMERS IN SECTION 13.

Precedent basis: Sift ToS: "Beta Services will be clearly designated as beta...SIFT HEREBY DISCLAIMS ALL LIABILITY FOR ANY HARM OR DAMAGE ARISING OUT OF OR IN CONNECTION WITH ANY BETA SERVICE".

6. Fees, Billing, Trials, and Taxes

Pricing and plan features are displayed in the applicable Shopify App Store listing, in-product checkout, order form, or written offer. You agree to pay the fees you approve, plus applicable taxes.

When charges are processed through Shopify, Shopify's billing system and applicable billing terms govern payment processing. Recurring subscriptions continue until canceled through the applicable Shopify or Siimple cancellation process.

If a trial automatically converts to a paid plan, the price and conversion date must be disclosed before you approve the trial. Except where required by law, required by Shopify, or stated in an applicable written offer, fees already paid are non-refundable.

Any separate Trust Network fee, renewal period, and cancellation process will be disclosed in writing before Merchant accepts the charge.

7. Merchant Data and Privacy

"Merchant Data" means data, content, configurations, and other information submitted by or processed for Merchant through the Services. As between the parties, Merchant retains its rights in Merchant Data.

Merchant grants Siimple a limited right to host, process, transmit, and otherwise use Merchant Data only as needed to provide, secure, support, and improve the Services; comply with law; and carry out other purposes disclosed in the applicable Privacy Policy, onboarding materials, or written agreement.

Each party will comply with applicable data-protection law. If the parties sign a data-processing agreement, that agreement controls for its subject matter if it conflicts with these Terms.

Merchant represents that it has the rights, notices, and lawful basis needed for Siimple to process Merchant Data as instructed. Merchant must not provide data that the Services do not request or that Merchant is not authorized to provide.

Siimple may create aggregated or de-identified information from use of the Services, provided that the information cannot reasonably identify Merchant or an individual. Siimple may use that information to operate, secure, analyze, and improve the Services.

Data Processing Agreement. The parties acknowledge that for OTP+ and Securify core services, Siimple acts as a service provider/processor. For Trust Network, Siimple acts as an independent controller for the cross-merchant risk intelligence processing. The parties' obligations under applicable data protection law are governed by the Master Data Processing Agreement and the Trust Network Addendum (Section 5).

8. Security

Siimple will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Services and Merchant Data. No system is completely secure, and Siimple does not guarantee that unauthorized access, loss, or disruption will never occur.

Merchant must use reasonable security practices, keep credentials confidential, limit administrative access, and notify Siimple promptly at [email protected] if it suspects unauthorized access involving the Services.

Any specific security commitments, incident-notification periods, audit rights, or security exhibits must be stated in a signed order form or data-processing agreement.

9. Intellectual Property and Feedback

Siimple and its licensors own the Services, software, documentation, designs, trademarks, and related intellectual property. Subject to these Terms and payment of applicable fees, Siimple grants Merchant a limited, non-exclusive, non-transferable, non-sublicensable right to use the Services for Merchant's internal business operations during the subscription or authorized access period.

If Merchant provides suggestions or feedback, Siimple may use it without restriction or payment, provided that Siimple does not publicly identify Merchant as the source without permission.

Merchant grants Siimple the rights necessary to display Merchant-provided names, logos, and content only when Merchant expressly approves that use or when needed to provide the Services.

10. Confidentiality

Each party may receive non-public information that a reasonable person would understand to be confidential. The receiving party will use confidential information only to perform or receive the Services and will protect it using reasonable care.

Confidential information does not include information that the receiving party can show was lawfully known without restriction, becomes public without breach, is received lawfully from another source, or is independently developed without using the disclosing party's confidential information.

A party may disclose confidential information when required by law after giving notice when legally permitted.

11. Service Changes, Suspension, and Termination

Siimple may update the Services to improve functionality, security, compliance, or compatibility. Siimple may suspend access when reasonably necessary to prevent harm, address a security issue, comply with law, respond to nonpayment, or investigate a material violation of these Terms.

Either party may terminate a paid subscription according to the applicable plan, Shopify billing flow, or order form. Merchant may stop using a free Service at any time. Siimple may discontinue a free or early-access Service with reasonable notice when practical.

Upon termination, Merchant's right to use the affected Services ends. Sections that by their nature should survive will survive, including payment obligations, confidentiality, intellectual property, disclaimers, liability limits, indemnification, and dispute terms.

Data return and deletion will follow the Privacy Policy, applicable law, Shopify requirements, and any signed data-processing agreement. Merchant should export needed information before termination when an export feature is available.

12. No Guarantee of Results

Siimple does not guarantee recovered revenue, conversion improvements, fraud reduction, successful delivery, lower chargebacks, reduced return abuse, complete detection, or any other business outcome. Historical results, merchant reviews, simulations, risk scores, and network signals do not guarantee future performance.

The Services support Merchant's decisions; they do not replace Merchant's judgment, customer-service processes, fraud review, legal obligations, or other controls.

13. Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." SIIMPLE DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

SIIMPLE DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, COMPLETELY SECURE, OR COMPATIBLE WITH EVERY THEME, APPLICATION, CONFIGURATION, OR THIRD-PARTY SERVICE. NOTHING IN THESE TERMS EXCLUDES A WARRANTY THAT CANNOT LAWFULLY BE EXCLUDED.

14. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR DATA, ARISING FROM OR RELATED TO THE SERVICES, EVEN IF ADVISED THAT SUCH DAMAGES ARE POSSIBLE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL LIABILITY ARISING FROM OR RELATED TO THE SERVICES WILL NOT EXCEED THE FEES MERCHANT PAID TO SIIMPLE FOR THE AFFECTED SERVICE DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. IF MERCHANT PAID NO FEES, THE CAP WILL BE US$100.

These limits do not apply to liability that cannot lawfully be limited.

15. Indemnification

Merchant will defend and indemnify Siimple and its personnel from third-party claims arising from Merchant Data, Merchant's unlawful or unauthorized use of the Services, Merchant's breach of Section 3 or 4, or Merchant's violation of another person's rights.

Additional Trust Network indemnification obligations are set forth in Section 5.8.

Third-Party Beneficiaries. Siimple's officers, directors, employees, and independent contractors are third-party beneficiaries of the indemnification, limitation of liability, and dispute resolution provisions of these Terms and may enforce those provisions directly against Merchant.

Precedent basis: Arkose Labs Terms: "Arkose Labs' officers, directors, employees and independent contractors ('Personnel') are third-party beneficiaries of these Terms and that upon your acceptance of these Terms, Personnel will have the right...to enforce these Terms against you".

The indemnified party must promptly notify the indemnifying party of a claim, provide reasonable cooperation, and allow the indemnifying party to control the defense and settlement. A settlement may not admit fault or impose a non-monetary obligation on the indemnified party without its consent.

16. Governing Law and Disputes

These Terms are governed by the laws of the State of California, excluding conflict-of-law rules. The state and federal courts located in Santa Clara County, California will have exclusive jurisdiction. Each party consents to those courts.

Governing Law for EU/UK Merchants. For merchants headquartered in the European Economic Area, Switzerland, or the United Kingdom, the parties acknowledge that EU/UK data protection law may require that disputes related to GDPR compliance be brought in the merchant's home jurisdiction. Nothing in this Section 16 prevents either party from bringing GDPR-related claims in the courts of the merchant's country of establishment, as permitted by GDPR Article 79.

Precedent basis: CHEQ.ai Terms: "For Customers located in North America, this Agreement is governed by the laws of the State of New York...For Customers located outside North America, this Agreement is governed by the laws of the State of Israel".

Before filing a claim, each party will give written notice describing the dispute and allow 30 days for authorized representatives to attempt an informal resolution. This requirement does not prevent either party from seeking urgent injunctive relief.

17. Changes to These Terms

Siimple may update these Terms. If a change materially reduces Merchant's rights or increases Merchant's obligations, Siimple will provide reasonable notice through the Services, by email, or by posting the updated Terms with a new effective date.

Continued use after the effective date of an update constitutes acceptance to the extent permitted by law. If Merchant does not agree to a material update, Merchant must stop using the affected Services and may cancel according to the applicable plan or order form.

18. General Terms

Neither party is liable for delay or failure caused by events beyond its reasonable control, except for payment obligations. Merchant may not assign these Terms without Siimple's written consent. Siimple may assign these Terms as part of a merger, reorganization, financing, or sale of all or substantially all of its relevant business or assets.

The parties are independent contractors. These Terms do not create a partnership, agency, fiduciary, employment, or franchise relationship. No third party is a beneficiary of these Terms.

If a provision is unenforceable, it will be modified only as much as necessary, and the remaining provisions will continue. A waiver must be in writing and applies only to the specific instance. Section headings are for convenience.

These Terms, the Privacy Policy, any applicable order form, and any signed data-processing agreement form the complete agreement for the Services. If they conflict, the order form controls, then the data-processing agreement for its subject matter, then these Terms, then the Privacy Policy.

19. Contact and Legal Notices

Questions and support requests may be sent to:

Siimple INC
6381 Almaden Road
San Jose, CA 95120
United States
[email protected]

Legal notices to Siimple must be sent by email and postal mail to the addresses above. Siimple may send notices to the email address associated with Merchant's Shopify account, application, or order form.