Back to SIML

Your data, in plain language

Privacy Policy

SIML is an AI operating platform for ecommerce merchants. This policy explains what we process when you use SIML, connect a store or communication channel, or authorize SIML to work with Meta products.

1. Scope and who controls your data

This Privacy Policy describes how SIML Inc. ("SIML," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you use our websites and application (the "Services"). The merchant or organization that creates a SIML workspace controls the business data and third-party accounts connected to that workspace. If you use SIML on behalf of an organization, that organization may also control your workspace information.

2. Information we collect

2.1 Account and workspace information

We collect information you provide when you register or configure a workspace, such as your name, email address, authentication provider identifier, business name, workspace membership, role, preferences, and support requests.

2.2 Store and commerce information

When you connect a commerce service, SIML processes the data needed for the features you choose. Depending on the connector, this may include products, listings, catalogs, inventory, locations, orders, fulfillment, returns, customer records, reviews, support conversations, sales, payouts, and related operational metrics. We do not access a third-party account until an authorized user connects it or supplies valid credentials.

2.3 AI interactions and action history

We process prompts, chat messages, uploaded files, agent instructions, generated drafts, proposed actions, approvals or rejections, tool results, and audit events. This information lets SIML preserve context, show what an agent did, and enforce your approval settings.

2.4 Billing information

Shopify or Stripe may process payments, depending on how you subscribe. SIML receives billing status, plan, invoices, transaction identifiers, and limited billing contact information. We do not store full payment-card numbers.

2.5 Device, security, and usage information

We may collect IP address, browser and device information, timestamps, pages and features used, session and authentication events, error logs, and approximate location derived from IP address. We use this information to operate, secure, debug, and improve the Services.

3. Meta, Facebook, Instagram, Messenger, and WhatsApp data

Each Meta connection is optional and uses the permissions shown during its authorization flow.

3.1 Meta Ads and Facebook Pages

When you connect Meta Ads, we receive and store an access token, granted permissions, token expiry information, connection status, and available business assets. Asset data may include ad-account IDs and names, account status, currency, timezone, and Facebook Page IDs, names, and categories. You explicitly select the ad account and Page SIML may use.

When you ask SIML to create an ad, we process the creative or video location, ad copy, destination URL, budget, campaign settings, and the campaign, ad-set, creative, video, and ad IDs returned by Meta. Where a reporting feature is available and you request it, SIML may read delivery and performance data for authorized ad accounts. The initial SIML workflow creates Meta campaigns, ad sets, and ads in a paused state. Connecting Meta does not activate a campaign or begin spend.

The Meta Ads connection uses Page information to identify the Page attached to an ad creative. It does not publish organic Page or Instagram content, read friends, or read direct messages. Messaging requires a separate connector and separate permission.

3.2 Facebook Messenger and Instagram messaging

If you separately connect Messenger or Instagram messaging, we may process the authorized Page or Instagram professional-account ID and display name or username, access token and scopes, sender and recipient platform identifiers, conversation and message identifiers, message text, timestamps, delivery status, and webhook event data needed to route messages and prevent duplicates. SIML uses this data to display conversations and draft or send replies under the approval behavior you configure.

3.3 WhatsApp Business

If you connect WhatsApp Business, we may process your selected WhatsApp Business Account and phone-number identifiers, business and phone metadata, permissions, token and expiry information, message-template information when you use a template feature, and connection or webhook status. To operate a messaging agent, we may process inbound and outbound message text, WhatsApp user or phone identifiers, profile name when supplied by WhatsApp, message identifiers, timestamps, delivery status, and approval records.

You are responsible for having the authority and lawful basis to provide customer, supplier, or partner communications to SIML and for complying with WhatsApp consent, opt-out, template, and messaging requirements.

3.4 Credentials and isolation

SIML encrypts connector access and refresh tokens at the application layer using AES-256-GCM before database storage. Tokens are decrypted only on the server when an authorized SIML feature needs to call the connected service. Connector records and imported data are associated with the authorizing SIML user or workspace and protected by access controls. We do not expose connector tokens in the client interface or use one merchant's Meta data to operate another merchant's account.

4. How we use information

  • Provide, personalize, and maintain the workspace, agents, connectors, and merchant-requested workflows.
  • Authenticate users, preserve workspace permissions, and secure connected accounts.
  • Sync authorized data, prepare drafts, execute approved actions, deliver messages, and create the records you request on third-party platforms.
  • Show action history, diagnose failures, prevent duplicate actions, and provide customer support.
  • Process billing, enforce plan limits, prevent fraud and abuse, and comply with law.
  • Analyze product reliability and usage using aggregated or de-identified information that is not used to target another merchant's customers.

We process data received from Meta only to provide and secure the user-facing functionality authorized by the merchant, consistent with applicable Meta terms and permissions.

5. No sale or cross-customer profiling

SIML does not sell or rent personal information or Meta Platform Data. We do not share it for third-party targeted advertising. We do not combine one merchant's Meta, store, customer, or conversation data with another merchant's data to create advertising audiences, customer profiles, or recommendations for that other merchant.

6. When we disclose information

We disclose information only as reasonably necessary:

  • Connected services. We send data and instructions to Shopify, Meta, and other services when you ask SIML to perform an authorized action.
  • Service providers. Hosting, database, security, AI-model, analytics, payment, email, and communication providers process the minimum information needed to perform services for SIML under contractual or other data-protection obligations.
  • Your workspace. Authorized workspace members may see information and action history according to their role.
  • Legal and safety reasons. We may disclose information when required by law or reasonably necessary to protect users, SIML, third parties, or the integrity of the Services.
  • Business transaction. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law.

7. AI processing

SIML may send prompts and the limited business context needed for a requested feature to third-party AI model providers. We use provider controls and agreements intended for business processing where available. AI output may be incomplete or incorrect. SIML records proposed and completed actions so you can review them, and higher-risk outbound actions may require approval according to the product workflow and your settings.

8. Retention, disconnecting, and deletion

  • We generally retain account, workspace, and operational data while your account is active and as needed to provide the Services.
  • We retain connector credentials while the relevant connection is active. Disconnecting a connector through SIML removes its stored connector credential and stops future access through that connection. A revoked or expired token is no longer used.
  • Disconnecting or revoking a connector does not automatically erase messages, campaign IDs, action history, or other information previously imported into SIML. You may separately request deletion of that information.
  • After a verified account or data-deletion request, we delete or anonymize the covered personal data within 30 days, except information we must retain for legal, tax, accounting, fraud-prevention, security, or dispute purposes.
  • Limited copies may remain in protected backups until those backups rotate out of use. We do not restore deleted data to ordinary production use.
  • Billing and transaction records may be retained for up to seven years where needed for tax, accounting, or legal compliance.

See our Data Deletion Instructions for steps to disconnect SIML, revoke the Meta business integration, and request deletion of previously stored data.

9. Security

We use technical and organizational safeguards designed to protect information, including encrypted transport, application-layer encryption for connector tokens, access controls, workspace isolation, database row-level security where applicable, audit logging, and restricted server-side credential access. No system is completely secure, and we cannot guarantee absolute security.

10. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal information, and to appeal or complain to a regulator. You may disconnect optional integrations at any time. To make a request, follow the deletion instructions or email founders@trysiml.com from the email associated with your SIML account. We may need to verify your identity and authority over the workspace before acting.

Removing SIML from Facebook's Business Integrations stops future authorized API access but does not itself instruct SIML to delete information previously received. Submit a separate deletion request if you want that information erased.

11. International processing

SIML and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws from your country. Where required, we use appropriate safeguards for international transfers.

12. Children

The Services are for businesses and are not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children through a SIML account.

13. Changes to this policy

We may update this policy to reflect changes to the Services, law, or our practices. We will post the updated version here and change the "Last updated" date. We will provide additional notice when required by law.

14. Contact us

For privacy questions or requests, contact: