Privacy Policy
1. Who we are
SimpliDeliver Email is operated by Niyam Vora, sole proprietor, trading as SimpliDeliver, in India. We are the party responsible for the personal data described in this policy, and you can reach us at support@simplideliver.com.
2. Two different roles
This distinction runs through the whole policy, so it comes first.
Your account data — we decide
For data about the people who hold accounts with us, we are the controller: we decide what to collect and why. Section 3 covers it.
The mail you send and the contacts you keep — you decide
For the messages our customers send, the contact lists they store with us, and the recipients they send to, the customer is the controller and we are a processor acting on their instructions. We transmit what we are told to transmit, to the addresses we are given. We do not decide who receives a customer's mail, we do not market to our customers' contacts, we do not use message content, contacts or recipient addresses for our own purposes, and we do not sell, rent or share them. Section 4 covers it.
If you received mail sent through us
The fastest way to stop marketing mail is the unsubscribe link in the message itself. It is added by us, it works in one click, and it takes effect immediately — you do not need to contact anyone.
For anything more — access to your data, correction, deletion — the sender is the party who holds it, so contact them. If you cannot identify or reach them, or the mail was abusive, write to abuse@simplideliver.com and we will act under our Acceptable Use Policy.
3. Account data we collect
- Identity and contact: name, email address, and the organisation name you give us.
- Authentication: a password hash, or the identifier issued by a third-party sign-in provider if you use one. We never store a password in a readable form.
- API credentials: API keys are stored only as a hash, along with a short non-secret prefix so we can show you which key is which. A key is displayed once, at creation, and cannot be recovered afterwards — not by you and not by us.
- Domains: the sending domains you add and the DNS records we generate and check for them, including any tracking subdomain you configure.
- Usage and security logs: API requests, timestamps, IP addresses, user agents, and the outcome of each request. We use these to run the service, to debug it, to enforce rate limits and quotas, and to investigate abuse and security incidents.
- Billing: if and when the service is paid for, the details required to bill you. We do not store card numbers.
We collect this because we need it to provide the service, to keep it secure, and to meet our legal obligations. We do not build advertising profiles and we do not sell personal data to anyone, ever.
4. Data we process for customers
Messages
- Message content: subject, body (HTML and text), headers, and any attachments — for as long as it takes to send the message, plus the retention period in section 5.
- Recipient data: the
To,Cc,Bcc,FromandReply-Toaddresses and any display names on them. - Delivery events: what happened to the message — sent, delivered, bounced, complained, delayed, rejected, or failed to render — with the timestamp, the recipient, the message ID, and any diagnostic code the receiving mail server returned.
Contact lists
Customers sending marketing mail store contact lists with us. A contact record holds the recipient's email address, whatever name and custom fields the customer chooses to attach, the subscription status, and the history of changes to it. Unlike message content, contact lists are held on an ongoing basis — that is what they are for — and they are controlled entirely by the customer, who can amend or delete them at any time.
Opt-outs and suppression
Addresses that hard-bounced, filed a spam complaint, or unsubscribed are kept on a suppression list so that we can refuse later sends to them. Keeping these is the point of them, so they are retained for the life of the account. When someone uses an unsubscribe link, we record the opt-out, the timestamp, and the IP address and user agent of the request — the last two only as evidence that the opt-out was genuine and to protect against abuse of the endpoint.
Open and click tracking — off unless the customer turns it on
Open and click tracking is disabled by default on every domain. No pixel is inserted and no link is rewritten unless a customer explicitly enables tracking for that domain, which also requires them to set up a tracking subdomain on their own DNS.
When a customer does enable it, for messages on that domain we record:
- Opens: a 1×1 transparent pixel is added to the message. When it loads, we record which message was opened, when, and the IP address and user agent that loaded it.
- Clicks: each link in the HTML is rewritten to route through the customer's tracking subdomain. When a recipient clicks, we record the message, the destination URL, the time, and the IP address and user agent, then redirect them onwards.
This data belongs to the customer and is processed on their instructions. We recommend enabling tracking only for marketing campaigns, and we recommend against it for transactional mail — a record of who opened a password reset and when is not something anyone should be creating by accident. If tracking is off, none of the data in this subsection exists.
5. How long we keep things
- Message content — 30 days. Subject, body and attachments are retained for 30 days from the send, and then purged. This is so you can inspect what was actually sent when you are debugging a delivery problem. After 30 days the content is gone and we cannot produce it, for you or for anyone else.
- Contact lists — until you delete them, or until the account closes, at which point they are deleted within 90 days. Contacts are not on a 30-day clock; they persist because a mailing list that emptied itself every month would be useless.
- Delivery and tracking event metadata — life of the account. Events and their metadata — addresses, timestamps, statuses, diagnostic codes, message IDs, and open/click records where tracking is on — outlive the content, because they are what your reporting and your suppression list are built from. Deleted within 90 days of the account being closed.
- Suppression entries — life of the account, then deleted with it. We do not remove an entry just because a customer asks.
- Account data — life of the account, then deleted within 90 days of closure.
- Security and abuse logs — up to 12 months, and longer for a specific incident where we need the record to investigate it, defend a claim, or comply with a legal obligation.
- Billing records are kept for as long as tax and accounting law requires.
6. Sub-processors
The complete list of third parties who process data on our behalf:
Amazon Web Services — mail delivery
Outbound mail is sent through Amazon Simple Email Service (Amazon SES) in
AWS region ap-southeast-1 (Singapore), which also handles the
resulting delivery events. Message content and recipient addresses pass
through and are processed in that region. AWS acts as our processor under
its own data processing terms.
Cloudflare — this website and DNS
This website is served by Cloudflare Pages, and DNS for our domains is hosted by Cloudflare. Cloudflare processes the request logs inherent in serving a web page. It has no access to message content or contact lists.
Zoho — our own business mailboxes
Mail you send to us at support@ or abuse@
is received in mailboxes hosted by Zoho. This is our correspondence with
you, not customer message data.
That is the whole list. We will update this page before adding a sub-processor, and we will notify account administrators by email before a new one begins processing customer message or contact data.
7. International transfer
We operate from India and send mail from Singapore, so your data will be transferred to and processed in both. If you or your recipients are elsewhere, including in the European Economic Area or the United Kingdom, using the service involves a transfer of personal data outside your own country. We rely on our processors' standard contractual clauses and equivalent safeguards for those transfers.
8. This website
This website sets no cookies and carries no analytics, no advertising, no third-party fonts and no third-party scripts of any kind. Nothing on these pages loads from another host or reports your visit anywhere. The only record of your visit is the ordinary server request log described under Cloudflare above.
9. Security
- All data is encrypted in transit with TLS, and encrypted at rest by our infrastructure provider.
- Passwords and API keys are stored only as hashes, and API keys are shown once and never again.
- Access to production systems is limited to those who need it, and is logged.
- If a breach affects your personal data, we will notify you and the relevant authority as the law requires, and we will tell you what we know rather than the minimum we can get away with.
No system is perfectly secure, and we would rather say that plainly than imply otherwise.
10. Your rights
Depending on where you live — including under India's Digital Personal Data Protection Act, 2023, and under the GDPR if you are in the EEA or the UK — you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy of it in a portable form, to object to or restrict certain processing, and to withdraw consent where our processing rests on it.
Write to support@simplideliver.com and we will respond within 30 days. We may need to verify your identity first. If your request concerns mail a customer of ours sent to you, or a contact record they hold about you, we will refer you to that customer, or pass the request to them, because it is their data and not ours to give. If you are not satisfied with how we handled a request, you may complain to your data protection authority — in India, the Data Protection Board of India.
11. Children
The service is for developers and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to us and we will delete it.
12. Changes to this policy
We may update this policy. The date at the top reflects the current version, and material changes will be notified to account administrators by email before they take effect.
13. Governing law
This policy is governed by the laws of India, and the courts at Mumbai, Maharashtra have exclusive jurisdiction over any dispute arising out of it.
14. Contact
- Privacy questions and rights requests
- support@simplideliver.com
- Abuse reports
- abuse@simplideliver.com
- Operator
- Niyam Vora, sole proprietor, trading as SimpliDeliver. India.