Your data, in plain language
Privacy Policy
Siml is an AI operating platform for ecommerce merchants. This policy explains what we process when you use Siml, connect a store or communication channel, or authorize Siml to work with Meta products.
1. Scope and who controls your data
This Privacy Policy describes how Siml Inc. ("Siml," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you use our websites and application (the "Services"). The merchant or organization that creates a Siml workspace controls the business data and third-party accounts connected to that workspace. If you use Siml on behalf of an organization, that organization may also control your workspace information.
2. Information we collect
2.1 Account and workspace information
We collect information you provide when you register or configure a workspace, such as your name, email address, authentication provider identifier, business name, workspace membership, role, preferences, and support requests.
2.2 Store and commerce information
When you connect a commerce service, Siml processes the data needed for the features you choose. Depending on the connector, this may include products, listings, catalogs, inventory, locations, orders, fulfillment, returns, customer records, reviews, support conversations, sales, payouts, and related operational metrics. We do not access a third-party account until an authorized user connects it or supplies valid credentials.
2.3 AI interactions and action history
We process prompts, chat messages, uploaded files, agent instructions, generated drafts, proposed actions, approvals or rejections, tool results, and audit events. This information lets Siml preserve context, show what an agent did, and enforce your approval settings.
2.4 Billing information
Shopify or Stripe may process payments, depending on how you subscribe. Siml receives billing status, plan, invoices, transaction identifiers, and limited billing contact information. We do not store full payment-card numbers.
2.5 Device, security, and usage information
We may collect IP address, browser and device information, timestamps, pages and features used, session and authentication events, error logs, and approximate location derived from IP address. We use this information to operate, secure, debug, and improve the Services.
3. Meta, Facebook, Instagram, Messenger, and WhatsApp data
Each Meta connection is optional and uses the permissions shown during its authorization flow.
3.1 Meta Ads and Facebook Pages
When you connect Meta Ads, we receive and store an access token, granted permissions, token expiry information, connection status, and available business assets. Asset data may include ad-account IDs and names, account status, currency, timezone, and Facebook Page IDs, names, and categories. You explicitly select the ad account and Page Siml may use.
When you ask Siml to create an ad, we process the creative or video location, ad copy, destination URL, budget, campaign settings, and the campaign, ad-set, creative, video, and ad IDs returned by Meta. Where a reporting feature is available and you request it, Siml may read delivery and performance data for authorized ad accounts. The initial Siml workflow creates Meta campaigns, ad sets, and ads in a paused state. Connecting Meta does not activate a campaign or begin spend.
The Meta Ads connection uses Page information to identify the Page attached to an ad creative. It does not publish organic Page or Instagram content, read friends, or read direct messages. Messaging requires a separate connector and separate permission.
3.2 Facebook Messenger and Instagram messaging
If you separately connect Messenger or Instagram messaging, we may process the authorized Page or Instagram professional-account ID and display name or username, access token and scopes, sender and recipient platform identifiers, conversation and message identifiers, message text, timestamps, delivery status, and webhook event data needed to route messages and prevent duplicates. Siml uses this data to display conversations and draft or send replies under the approval behavior you configure.
3.3 WhatsApp Business
If you connect WhatsApp Business, we may process your selected WhatsApp Business Account and phone-number identifiers, business and phone metadata, permissions, token and expiry information, message-template information when you use a template feature, and connection or webhook status. To operate a messaging agent, we may process inbound and outbound message text, WhatsApp user or phone identifiers, profile name when supplied by WhatsApp, message identifiers, timestamps, delivery status, and approval records.
You are responsible for having the authority and lawful basis to provide customer, supplier, or partner communications to Siml and for complying with WhatsApp consent, opt-out, template, and messaging requirements.
3.4 Credentials and isolation
Siml encrypts connector access and refresh tokens at the application layer using AES-256-GCM before database storage. Tokens are decrypted only on the server when an authorized Siml feature needs to call the connected service. Connector records and imported data are associated with the authorizing Siml user or workspace and protected by access controls. We do not expose connector tokens in the client interface or use one merchant's Meta data to operate another merchant's account.
4. Google user data
Connecting Gmail and signing in with Google are both optional.
4.1 What we access
If you sign in with Google, we receive your name, email address, and profile picture to create and secure your Siml account.
If you connect Gmail, you grant Siml permission to read your email and to send email as you, and we receive your Gmail address to label the connection. Siml reads recent messages in your inbox (sender, recipients, subject, date, and body text) to find customer emails and store contact-form submissions, and checks new messages for replies in the supplier conversations Siml tracks for you. Siml sends email from your account only for features you use: replies to customers and suppliers that you write or approve (or that an auto-reply rule you turned on allows), one-off emails you approve, and review requests if you turn them on. Siml does not delete, archive, label, or mark your email as read.
4.2 How we use it
We use Gmail data only to provide the features you use: your support inbox, your supplier inbox, drafting replies for your review, and sending the email described above. To sort messages and draft replies, Siml sends the relevant message and business context to AI model providers acting on our behalf, which process it to produce results for you only. Your own approve, edit, and reject decisions on those drafts may tailor the drafts your agents write for you; they are not shared with other merchants.
4.3 What we never do with it
- We do not sell Google user data.
- We do not use it for advertising, including to target ads or build advertising audiences.
- We do not use it to develop, improve, or train generalized AI or machine-learning models. It is never used in Siml's cross-merchant learning data or in the research datasets described in your data-licensing setting, even if you opt in to that setting.
- We do not transfer it to others except as needed to provide the features above, to comply with law, for security, or as part of a merger, acquisition, or sale of assets.
- People do not read it, except with your consent for specific messages, when needed for security purposes such as investigating abuse, to comply with applicable law, or when it is aggregated and anonymized for internal operations.
Siml's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Gmail in Siml at any time, or revoke access from your Google Account. Section 9 explains how to delete email previously stored in Siml.
5. How we use information
- Provide, personalize, and maintain the workspace, agents, connectors, and merchant-requested workflows.
- Authenticate users, preserve workspace permissions, and secure connected accounts.
- Sync authorized data, prepare drafts, execute approved actions, deliver messages, and create the records you request on third-party platforms.
- Show action history, diagnose failures, prevent duplicate actions, and provide customer support.
- Process billing, enforce plan limits, prevent fraud and abuse, and comply with law.
- Analyze product reliability and usage using aggregated or de-identified information that is not used to target another merchant's customers.
We process data received from Meta only to provide and secure the user-facing functionality authorized by the merchant, consistent with applicable Meta terms and permissions.
6. No sale or cross-customer profiling
Siml does not sell or rent personal information or Meta Platform Data. We do not share it for third-party targeted advertising. We do not combine one merchant's Meta, store, customer, or conversation data with another merchant's data to create advertising audiences, customer profiles, or recommendations for that other merchant.
7. When we disclose information
We disclose information only as reasonably necessary:
- Connected services. We send data and instructions to Shopify, Meta, and other services when you ask Siml to perform an authorized action.
- Service providers. Hosting, database, security, AI-model, analytics, payment, email, and communication providers process the minimum information needed to perform services for Siml under contractual or other data-protection obligations.
- Your workspace. Authorized workspace members may see information and action history according to their role.
- Legal and safety reasons. We may disclose information when required by law or reasonably necessary to protect users, Siml, third parties, or the integrity of the Services.
- Business transaction. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law.
8. AI processing
Siml may send prompts and the limited business context needed for a requested feature to third-party AI model providers. We use provider controls and agreements intended for business processing where available. AI output may be incomplete or incorrect. Siml records proposed and completed actions so you can review them, and higher-risk outbound actions may require approval according to the product workflow and your settings.
9. Retention, disconnecting, and deletion
- We generally retain account, workspace, and operational data while your account is active and as needed to provide the Services.
- We retain connector credentials while the relevant connection is active. Disconnecting a connector through Siml removes its stored connector credential and stops future access through that connection. A revoked or expired token is no longer used.
- Disconnecting or revoking a connector does not automatically erase messages, campaign IDs, action history, or other information previously imported into Siml. You may separately request deletion of that information.
- After a verified account or data-deletion request, we delete or anonymize the covered personal data within 30 days, except information we must retain for legal, tax, accounting, fraud-prevention, security, or dispute purposes.
- Limited copies may remain in protected backups until those backups rotate out of use. We do not restore deleted data to ordinary production use.
- Billing and transaction records may be retained for up to seven years where needed for tax, accounting, or legal compliance.
See our Data Deletion Instructions for steps to disconnect Siml, revoke the Meta business integration, and request deletion of previously stored data.
10. Security
We use technical and organizational safeguards designed to protect information, including encrypted transport, application-layer encryption for connector tokens, access controls, workspace isolation, database row-level security where applicable, audit logging, and restricted server-side credential access. No system is completely secure, and we cannot guarantee absolute security.
11. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal information, and to appeal or complain to a regulator. You may disconnect optional integrations at any time. To make a request, follow the deletion instructions or email founders@trysiml.com from the email associated with your Siml account. We may need to verify your identity and authority over the workspace before acting.
Removing Siml from Facebook's Business Integrations stops future authorized API access but does not itself instruct Siml to delete information previously received. Submit a separate deletion request if you want that information erased.
12. International processing
Siml and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws from your country. Where required, we use appropriate safeguards for international transfers.
13. Children
The Services are for businesses and are not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children through a Siml account.
14. Changes to this policy
We may update this policy to reflect changes to the Services, law, or our practices. We will post the updated version here and change the "Last updated" date. We will provide additional notice when required by law.
15. Contact us
For privacy questions or requests, contact: