siimple.ai Privacy Policy
Welcome to siimple.ai's Privacy Policy!
This Privacy Policy is about how we collect, use, and share your personal information when you install or use an App provided by siimple.ai.
When you install an App, we will be able to access certain types of information from the host platform you installed it on — most commonly your Shopify Store or your Klaviyo account. The specific data access for each integration is described in its own section below.
We may update this Privacy Policy from time to time to reflect, for example, changes to the permissions and data access rights required by the app's policy and functionality.
If we have essential material changes to this Privacy Policy, we will notify you of those changes by posting the revised policy on this Website and in other ways. By continuing to use our applications or our website or any of our services after these changes are posted, you agree to the revised policy.
Personal information that the app collects
When you install the App, we will be able to access your information from your Shopify account, the reason for this is to provide you with our service, to confirm your identity, to contact and to provide customer support and assistance when you contact us.
How do we use your personal information?
We use the personal information collected from you to provide the Service and to operate our app. Additionally, we use personal information to: communicate with you, optimize or improve the Service, notify you about our product's updates, and handle software bugs or support requests.
Legal bases for processing (GDPR / UK GDPR)
We do process personal data of individuals in the EU/EEA and the UK. Where the GDPR or UK GDPR applies, we rely on the following Article 6(1) legal bases for each processing purpose:
- Providing and operating the App (authentication, dashboard, customer support) — account metadata, OAuth tokens, store domain, and your contact email — Art. 6(1)(b), performance of a contract.
- Validating subscriber email addresses that you submit for validation — processed on your documented instruction, with siimple.ai acting as a processor on your behalf; as controller, you (the merchant) typically rely on Art. 6(1)(f), legitimate interests in list hygiene and email deliverability.
- Maintaining a de-duplicated validation-result cache — Art. 6(1)(f), legitimate interest in avoiding repeated validation probes and improving accuracy and performance.
- Service notifications (e.g., scan-complete emails) — Art. 6(1)(b) and Art. 6(1)(f).
- Security, logging, and abuse prevention — Art. 6(1)(f), legitimate interest in securing the Service.
- Compliance with legal obligations — Art. 6(1)(c).
- Marketing and advertising on our website (analytics and ad pixels) — Art. 6(1)(a), consent, where required.
If you or your data subjects wish to object to processing based on legitimate interests, contact us at the address below.
Data retention
We retain personal data only as long as needed for the purposes above, and in any case no longer than the periods below:
- OAuth access and refresh tokens — revoked at the platform immediately upon uninstall or disconnect; encrypted token records are permanently deleted no later than 90 days after uninstall.
- Validation-result cache — cached results are reused for at most 30 days; cached result records are retained for up to 12 months from the most recent validation and then purged on a scheduled basis.
- Validation summaries and sample records shown in your dashboard — retained for the life of your integration; deleted within 30 days of a verified deletion request.
- Store contact email (used for scan-complete notifications) — retained for the life of your integration; deleted within 30 days of a verified deletion request.
- OAuth login state (anti-forgery keys) — 10 minutes, auto-expiring.
- Per-batch validation working data — 7 days, auto-expiring.
- Server-side analytics events — pseudonymous identifiers only (account ID or store domain); subscriber email addresses are never sent to analytics.
Securify for Klaviyo
When you install Securify for Klaviyo from the Klaviyo App Marketplace, we authenticate via OAuth 2.0 with PKCE (Proof Key for Code Exchange). We never receive or handle your Klaviyo account password.
Scopes we request. accounts:read (to identify your Klaviyo account), profiles:read and profiles:write (to read email addresses from lists you select for validation and to write our securify_* profile properties back), events:write (to emit our branded securify.email_validated and securify.list_validated metric events), and lists:read + segments:read (to show the list/segment picker in the dashboard). We do not request campaign, flow, metric-read, delete, or any broader scope.
What we read. Only the email addresses on the list or segment you explicitly click "Validate" on — no historical campaign data, no message content, no flow definitions, no SMS numbers.
What we write. Four profile properties per validated contact — securify_deliverability (deliverable / undeliverable / risky / unknown), securify_is_disposable, securify_email_score, and securify_validated_at — plus two branded events. Nothing else.
How we store OAuth tokens. Your access and refresh tokens are encrypted with AES-256-GCM at the application layer before being written to our database. The encryption key lives only in the Cloudflare Workers secret store and is never shared with our upstream validation pipeline.
Email validation pipeline. Email addresses you submit for validation flow through our own validation service (Securify), which runs an in-house RFC 5322 + disposable-domain check and, where needed, a third-party SMTP deliverability probe (currently provided by Reoon). Validation results are retained so we can serve repeated validation requests quickly (de-duplicated cache) and surface reputation over time. We do not sell or otherwise share email addresses with third parties outside of the validation pipeline.
Uninstall. When you uninstall the app from Klaviyo, we receive a signed uninstall webhook, immediately mark your integration inactive, and revoke the OAuth grant so the app disappears from your Klaviyo Integrations page. Encrypted OAuth token records are permanently deleted no later than 90 days after uninstall and are never used to call the Klaviyo API again. To have all associated records deleted sooner, contact us at the address below.
How do we share information?
We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful requests for information we receive, or to otherwise protect our rights.
We may use your Personal Information to provide you with targeted advertisements or marketing communications we believe could be of interest to you.
You can opt out of Facebook and Google targeted advertising at facebook.com/settings/?tab=ads and google.com/settings/ads/anonymous.
Use of siimple.ai Apps by Children
siimple.ai apps are not intended for children and are directed at businesses and their operators.
Your Rights
You have rights over your personal information: if you want to access, correct, amend, delete, port, or limit the usage of your personal information, please contact us through the contact information below. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your supervisory authority.
International transfers
Our infrastructure is hosted in the United States. If you are outside the United States, your personal information will be transferred to the United States. Where we transfer personal data of EU/EEA or UK individuals, we rely on our infrastructure providers' data processing agreements, which incorporate the European Commission's Standard Contractual Clauses where applicable.
Contact information
If you have any questions about this Privacy Policy, or if you would like to list a complaint about how we process your personal data, please contact us by email [email protected]