Home/Legal Hub/Privacy Policy
    Legal & Policies

    Privacy Policy

    Last Updated: 2026-09-03

    Welcome to  Simply Send , an email delivery service provided by Simply Invent Labs LLC ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

    Please read this Privacy Policy carefully. By accessing or using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.


    1. Definitions

    For the purposes of this Privacy Policy:

    • Service means the simplysend.email website and the  Simply Send  email delivery service.
    • Personal Data means data about a living individual who can be identified from those data.
    • Usage Data is data collected automatically, generated by the use of the Service or from the Service infrastructure itself.
    • Cookies are small files stored on your device (computer or mobile device).
    • Data Controller means the natural or legal person who determines the purposes for which and the manner in which any personal data are processed. For this Privacy Policy, we are a Data Controller of your data.
    • Data Processors (or Service Providers) means any natural or legal person who processes the data on behalf of the Data Controller.
    • Data Subject is any living individual who is using our Service and is the subject of Personal Data.
    • Sub-Processor means any third-party service provider engaged by us to process Personal Data on your behalf as part of delivering the Service.

    2. Information We Collect

    We collect several different types of information for various purposes to provide and improve our Service to you.

    2.1 Information You Provide

    When you use our Service, we may ask you to provide us with certain personally identifiable information, including but not limited to:

    • Account information (name, email address, password)
    • Contact information (email, phone number, address)
    • Billing and payment information
    • Email content, subject lines, and recipient addresses
    • Contact lists and subscriber data: email addresses and subscription status of recipients you manage through the Service
    • Campaign data: campaign names, schedules, targeting settings, and performance analytics you create within the Service
    • Email event data: delivery, open, click, bounce, complaint, and unsubscribe events associated with emails you send through the Service
    • Customer support communications

    2.2 Information We Collect Automatically

    We automatically collect certain information when you visit, use, or navigate our Service, including:

    • Usage Data: Information about how you interact with our Service, including API calls, email delivery metrics, and feature usage.
    • Log Data: Information that your browser sends whenever you visit our Service, including your IP address, browser type, and pages visited.
    • Device Information: Information about your device, including hardware model, operating system, and mobile network information.
    • Cookies and Tracking Technologies: We use cookies and similar tracking technologies to track activity on our Service.

    2.3 Third-Party Tools

    We use trusted third-party services to provide, improve, and support the Service:

    • Microsoft Clarity & Google Analytics: We use these tools to understand how you use our website (e.g., pages visited, time on site). These tools use cookies and tracking technology to collect Usage Data.
    • Zoho SalesIQ & Zoho Desk: We use Zoho SalesIQ for live chat and Zoho Desk for support ticketing. These services collect personal information such as name, email address, and IP address to facilitate customer support.
    • Amazon Web Services (AWS): Our core infrastructure runs on AWS, including email delivery via Amazon SES, data storage (DynamoDB, S3), and compute (Lambda). Email event data, contact lists, and campaign analytics are stored and processed within AWS.
    • Oracle Cloud Infrastructure (OCI): We use OCI as a secondary email delivery provider. When emails are routed through OCI, recipient email addresses and message content are processed by OCI in accordance with their privacy and security policies.
    • Stripe: We use Stripe for secure payment processing. We do not store your full credit card details on our servers.
    • Marketplace purchase channels: If you purchase a subscription through AWS Marketplace, Google Cloud Marketplace, or the Shopify App Store or another Shopify channel when those channels are available, the applicable channel processes the transaction under its own terms. We receive only the subscription, entitlement, account-linking, and related procurement information needed to provision and support your Simply Send subscription.
    • Cloudflare: We use Cloudflare for content delivery and security. Cloudflare may process technical data such as IP addresses and request metadata.

    2.4 Google Workspace Integration Data

    If you choose to connect Google Contacts, Google Sheets, or Google Forms, we access only the Google data needed for the integration you select, such as selected contact groups, selected files, mapped fields, and the imported contact information. We use that data to perform the one-way import into the subscription group you choose and to operate, secure, and support that integration. Google access is read-only; Simply Send does not use Gmail as its sending path.

    You may disconnect the integration in Simply Send. Disconnecting revokes Simply Send's connection to Google; contacts already imported into Simply Send remain subject to your workspace's retention and deletion controls.

    2.5 Marketplace Listings and Subscription Data

    Google Workspace Marketplace may be used to discover and install a Simply Send Google Workspace integration. It is separate from Google Cloud Marketplace, which may process a paid subscription if that purchase channel is offered. AWS Marketplace and the Shopify App Store or another Shopify channel may also make Simply Send available for discovery, installation, or purchase. The applicable channel may provide us with your organization or store identifier, purchaser or account contact information, order or charge identifier, selected plan, subscription or entitlement status, renewal, cancellation, and billing-period information.

    We use this information only to link the purchase to the correct Simply Send account or workspace, provision and administer the subscription, provide support, prevent fraud, meet tax, accounting, and legal obligations, and resolve purchase issues. We do not receive or store full payment-card numbers from Stripe or a marketplace. We do not sell marketplace subscription data or use it for advertising.

    2.6 Sensitive and Biometric Data Disclaimer

    We do not knowingly collect, request, or process any sensitive personal data or special categories of personal data (such as biometric data, genetic data, health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or sexual orientation). If you believe such information has been mistakenly uploaded or transmitted through the Service, please contact us immediately so we can remove it.

    3. How We Use Your Information

    We use the collected data for various purposes, including:

    • To provide and maintain our Service
    • To notify you about changes to our Service
    • To allow you to participate in interactive features of our Service
    • To provide customer support via email, Zoho Desk ticketing, or Zoho SalesIQ chat
    • To gather analysis or valuable information so that we can improve our Service (via Clarity and GA)
    • To monitor the usage of our Service
    • To detect, prevent and address technical issues, fraud, and abuse
    • To provision, administer, and support subscriptions purchased directly or through an available marketplace channel
    • To perform the Google Workspace integrations you explicitly connect and configure
    • To conduct compliance and abuse inspections: We may access and review the content of emails sent through the Service on a random or targeted basis to verify compliance with our Acceptable Use Policy, applicable laws, and third-party provider requirements. Such access is limited to authorised personnel and is used solely for enforcement purposes.
    • To enforce our Terms of Service and Acceptable Use Policy
    • To provide you with news, special offers, and general information about other goods, services, and events which we offer (where you have consented or where we have a legitimate interest)
    • To comply with our legal obligations

    4. Purpose Limitation

    We are committed to using your data only for the purposes described in this policy. Below is a clear summary of what we do and do not do with your data:

    ✅ What We DO

    • Deliver your emails as instructed
    • Provide delivery analytics and reporting
    • Improve service reliability and performance
    • Prevent abuse, spam, and fraud
    • Comply with our legal obligations
    • Use aggregated, anonymised data for infrastructure improvements
    • Conduct random compliance and abuse inspections of email content (limited to authorised personnel, solely for enforcement)

    🚫 What We DON'T Do

    • Sell your data to third parties
    • Use your email content for advertising
    • Train AI or ML models on your message content
    • Share data beyond what is necessary to provide the Service
    • Access your message content for any purpose other than compliance enforcement, abuse detection, or legal obligations

    5. Data Security

    We take the security of your data seriously and implement appropriate technical and organizational measures to protect it, including:

    • All data is encrypted in transit using TLS 1.2+
    • Data stored in our databases and storage services is encrypted at rest using AES-256 encryption with AWS-managed keys (SSE-S3 / SSE-DynamoDB)
    • Role-based access controls limiting data access to authorised personnel only
    • Access logging for sensitive operations via AWS CloudWatch
    • Infrastructure security provided by AWS and Cloudflare, including DDoS protection, TLS enforcement, and network-level controls
    • Dead-letter queues and data retention controls to limit exposure of message data
    Note: While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but we take reasonable steps to protect your information from unauthorized access, use, or disclosure.

    6. Data Retention

    We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy:

    • Account Information: After an account-deletion request, you have seven days to cancel. At the end of that period, we begin deleting or anonymizing account information and Service data. We may retain limited records where required for legal, billing, security, fraud-prevention, or audit purposes.
    • Email Records & Event Data: Email delivery records (including recipient address, subject, status, and email events such as opens, clicks, bounces, and complaints) are retained for up to 120 days, after which they are automatically deleted. Contact list subscription data is retained for as long as your account is active.
    • Campaign Data: Campaign configuration and aggregate statistics are retained for as long as your account is active.
    • Logs and Analytics: Retained for up to 12 months for security and analytics purposes. Usage data in Clarity/GA is retained according to their standard retention periods.
    • Billing Information: Retained as required by tax and accounting laws (typically 7 years).
    • Support Data (Zoho Desk/SalesIQ): Retained in accordance with Zoho's data retention policies, typically for the duration of the support relationship plus a reasonable period thereafter.

    To help prevent fraud and unauthorized re-registration, we retain a deletion tombstone that includes a cryptographic hash of the deleted account's email address. That hash is used to enforce a six-month re-registration cooldown and is not used to restore access to the deleted account.

    You can request deletion of your personal data by contacting us at support@simplyinventlabs.com, subject to our legal obligations.

    7. Data Sharing and Disclosure

    We may share your information in the following circumstances:

    • Service Providers and Purchase Channels: We use providers such as AWS, OCI, Stripe, Google, Shopify, OpenAI, Zoho, Microsoft, and Cloudflare to provide the Service. We disclose only the data reasonably necessary for the applicable service, subject to the provider's contractual terms and, where applicable, data-processing terms. This includes exchanging subscription, entitlement, account-linking, and purchase-status information with Stripe or an available marketplace only as needed to process, provision, administer, support, secure, or reconcile your subscription.
    • Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or a prominent notice on our website at least 30 days prior to any such transfer and the change in ownership.
    • Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency), and only to the extent required by applicable law.
    • Protection of Rights: We may disclose your information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

    We do not sell, rent, or trade your Personal Data to third parties for their own marketing or commercial purposes.

    8. Your Data Protection Rights

    Depending on your location, you may have certain rights regarding your personal information, including:

    • Access: You can request a copy of your personal data.
    • Correction: You can request correction of any inaccurate or incomplete data.
    • Deletion: You can request deletion of your personal data (including data stored in our support and analytics tools), subject to our legal retention obligations.
    • Objection: You can object to our processing of your personal data where we rely on legitimate interests as the legal basis.
    • Portability: You can request a copy of your data in a structured, commonly-used, machine-readable format.
    • Restriction: You can request that we restrict the processing of your personal data in certain circumstances — for example, while we verify the accuracy of your data or while you contest our grounds for processing.
    • Withdraw Consent: Where we rely on your consent as the legal basis for processing, you can withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.

    To exercise any of these rights, please contact us at support@simplyinventlabs.com. We may need to verify your identity before processing your request. We will respond to your request within 30 days (or within the timeframe required by applicable law).

    If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority (e.g., the relevant EU supervisory authority, or the UK Information Commissioner's Office).

    9. California Privacy Rights (CCPA & CalOPPA)

    If you are a California resident, you have the right to:

    • Request access to the categories and specific pieces of personal information we have collected about you
    • Request deletion of your personal information
    • Opt-out of the sale of your personal information (we do not sell personal information)
    • Not be discriminated against for exercising any of these rights

    To make a request, please contact us at support@simplyinventlabs.com. We will respond to your request within 45 days.

    10. International Data Transfers

    Simply Invent Labs LLC is headquartered in the United States. Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those of your jurisdiction.

    Where we transfer Personal Data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not received an adequacy decision from the relevant authority, we rely on the following safeguards:

    • Transfer Mechanisms: Where required by applicable law, we use appropriate transfer mechanisms, which may include the European Commission-approved Standard Contractual Clauses and other safeguards recognized by applicable law.
    • Data Processing Terms: We use the applicable contractual and data-processing terms offered by our service providers, and apply additional safeguards where required by applicable law.
    • Transfer Assessments: Where required, we assess the circumstances of an international transfer and apply appropriate supplementary safeguards.

    If you have questions about the safeguards we use for international data transfers, please contact us at support@simplyinventlabs.com.

    11. AI/ML Data Usage

    Simply Send does not use Customer Content or Google Workspace data to create, train, or improve generalized AI or machine-learning models.

    We use the following AI-assisted features only to provide visible Service functionality:

    • AI template creation: When you choose an AI template feature, the prompt and template content you submit may be sent to OpenAI's API to generate or refine that template.
    • Email-content review: We may use Google's Gemini API to help identify abusive, fraudulent, phishing, or otherwise unsafe email content. Before this review, Simply Send locally removes direct identifiers, known Google-imported contact values, recipient-specific URLs and tokens, and embedded data. If that de-identification cannot be completed, we withhold the content from Gemini and route the review for internal handling.
    • Operational security: We use automated systems to detect abuse, fraud, and delivery-risk signals and to protect the Service.

    Our third-party AI providers are OpenAI (paid API service) and Google Gemini (paid Gemini Developer API tier). We integrate directly with those providers and do not use an AI aggregator, model hub, or gateway. Their paid configurations are not used to train generalized models on our inputs or outputs; provider retention and processing remain subject to the applicable provider terms and service configuration.

    Google Workspace Limited Use

    The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We use Google Workspace data only to provide and improve the Google integration that you choose, do not sell it or use it for advertising, and do not transfer Google Workspace data to create, train, or improve generalized AI or machine-learning models.

    Simply Send does not programmatically provide Google Workspace integration data to OpenAI. For Gemini email-content review, Simply Send removes direct identifiers and known Google-imported contact values locally before any external request. We do not transfer raw, aggregated, anonymized, or derived Google Workspace user data to a third-party AI service for model training.

    You may contact us at support@simplyinventlabs.com if you have any questions about how we use automated systems in connection with your data.

    12. Automated Decision-Making

    We use automated systems to help operate, secure, and enforce our Service. The following automated processes may directly affect your account:

    • Spam detection: Automated scanning of sending patterns (not message content) to identify and block spam or abusive traffic. This may result in automatic throttling or temporary suspension of sending.
    • Bounce and complaint rate monitoring: Automated thresholds for bounce rates (>1.25%) and complaint rates (>0.07%) may trigger automatic account restrictions to protect our sending infrastructure.
    • Fraud detection: Automated analysis of account activity may flag suspicious behaviour and result in account holds pending manual review.
    • Rate limiting: Automated throttling of sending volume to protect infrastructure and prevent abuse.

    Where an automated decision significantly affects your account (such as a suspension or restriction), you have the right to request human review of that decision. To do so, please contact support@simplyinventlabs.com. We will review your case and respond within 5 business days.

    Manual Compliance Inspections

    In addition to automated systems, authorised Simply Send personnel may conduct manual, random, or targeted inspections of email content sent through the Service. These inspections are performed solely to:

    • Verify compliance with our Acceptable Use Policy
    • Investigate suspected violations of applicable law (including CAN-SPAM, CASL, GDPR)
    • Respond to third-party provider compliance requirements or complaints
    • Investigate reports of abuse, spam, or harmful content submitted by recipients or providers

    Access is restricted to a limited number of authorised personnel, is logged for audit purposes, and the content accessed is not used for any commercial purpose. By using the Service, you acknowledge and consent to this access as a condition of using a shared email delivery infrastructure.

    13. Children's Privacy

    Our Service is not intended for use by children. We do not knowingly collect personally identifiable information from:

    • Children under the age of 16 if they are located in the European Economic Area or United Kingdom (as required by GDPR Article 8 and the UK GDPR).
    • Children under the age of 13 in all other jurisdictions (including the United States, in compliance with COPPA).

    If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us immediately at support@simplyinventlabs.com. If we become aware that we have collected Personal Data from a child without verification of parental consent (where required), we will take steps to remove that information from our servers promptly.

    14. Changes to This Privacy Policy

    We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.

    For material changes that affect your rights or how we process your data, we will provide at least 30 days' advance notice via email to the address associated with your account.

    You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

    15. Contact Us

    If you have any questions about this Privacy Policy, our privacy practices, or to exercise your data rights, please contact us at: support@simplyinventlabs.com

    Simply Invent Labs LLC
    Email: support@simplyinventlabs.com