Privacy Policy
1. Who we are
SimpliDeliver Email is operated by Niyam Vora, sole proprietor, trading as SimpliDeliver, in India. We are the party responsible for the personal data described in this policy, and you can reach us at support@simplideliver.com.
2. Two different roles
This distinction runs through the whole policy, so it comes first.
Your account data — we decide
For data about the people who hold accounts with us, we are the controller: we decide what to collect and why. Section 3 covers it.
The mail you send — you decide
For the messages our customers send and the recipients they send to, the customer is the controller and we are a processor acting on their instructions. We transmit what we are told to transmit, to the addresses we are given. We do not decide who receives a customer's mail, we do not use message content or recipient addresses for our own purposes, and we do not sell, rent or share them. Section 4 covers it.
If you received mail sent through us and want it stopped or your data removed, the sender is the party who holds it — contact them. If you cannot identify or reach them, or you believe the mail was abusive, write to abuse@simplideliver.com and we will act under our Acceptable Use Policy.
3. Account data we collect
- Identity and contact: name, email address, and the organisation name you give us.
- Authentication: a password hash, or the identifier issued by a third-party sign-in provider if you use one. We never store a password in a readable form.
- API credentials: API keys are stored only as a hash, along with a short non-secret prefix so we can show you which key is which. A key is displayed once, at creation, and cannot be recovered afterwards — not by you and not by us.
- Domains: the sending domains you add and the DNS records we generate and check for them.
- Usage and security logs: API requests, timestamps, IP addresses, user agents, and the outcome of each request. We use these to run the service, to debug it, to enforce rate limits, and to investigate abuse and security incidents.
- Billing: if and when the service is paid for, the details required to bill you. We do not store card numbers.
We collect this because we need it to provide the service, to keep it secure, and to meet our legal obligations. We do not build advertising profiles and we do not sell personal data to anyone, ever.
4. Message data we process for customers
- Message content: subject, body (HTML and text), headers, and any attachments — for as long as it takes to send the message, plus the retention period in section 5.
- Recipient data: the
To,Cc,Bcc,FromandReply-Toaddresses and any display names on them. - Delivery events: what happened to the message — sent, delivered, bounced, complained, delayed, rejected, or failed to render — with the timestamp, the recipient, the message ID, and any diagnostic code the receiving mail server returned.
- Suppression entries: addresses that hard-bounced or filed a spam complaint, kept so that we can refuse later sends to them. Keeping these is the point of them, so they are retained for the life of the account.
We do not track opens or clicks. We do not insert tracking pixels into messages and we do not rewrite links in them, so we hold no record of whether a recipient opened a message or what they clicked.
5. How long we keep things
- Message content — 30 days. Subject, body and attachments are retained for 30 days from the send, and then purged. This is so you can inspect what was actually sent when you are debugging a delivery problem. After 30 days the content is gone and we cannot produce it, for you or for anyone else.
- Delivery event metadata — life of the account. The events and their metadata — addresses, timestamps, statuses, diagnostic codes, message IDs — outlive the content, because they are what your delivery reporting and your suppression list are built from. They are deleted within 90 days of the account being closed.
- Suppression entries — life of the account, then deleted with it.
- Account data — life of the account, then deleted within 90 days of closure.
- Security and abuse logs — up to 12 months, and longer for a specific incident where we need the record to investigate it, defend a claim, or comply with a legal obligation.
- Billing records are kept for as long as tax and accounting law requires.
6. Sub-processors
The complete list of third parties who process data on our behalf:
Amazon Web Services — mail delivery
Outbound mail is sent through Amazon Simple Email Service (Amazon SES) in
AWS region ap-southeast-1 (Singapore), which also handles the
resulting delivery events. Message content and recipient addresses pass
through and are processed in that region. AWS acts as our processor under
its own data processing terms.
Cloudflare — this website and DNS
This website is served by Cloudflare Pages, and DNS for our domains is hosted by Cloudflare. Cloudflare processes the request logs inherent in serving a web page. It has no access to message content.
Zoho — our own business mailboxes
Mail you send to us at support@ or abuse@
is received in mailboxes hosted by Zoho. This is our correspondence with
you, not customer message data.
That is the whole list. We will update this page before adding a sub-processor, and we will notify account administrators by email before a new one begins processing customer message data.
7. International transfer
We operate from India and send mail from Singapore, so your data will be transferred to and processed in both. If you or your recipients are elsewhere, including in the European Economic Area or the United Kingdom, using the service involves a transfer of personal data outside your own country. We rely on our processors' standard contractual clauses and equivalent safeguards for those transfers.
8. This website
This website sets no cookies and carries no analytics, no advertising, no third-party fonts and no third-party scripts of any kind. Nothing on these pages loads from another host or reports your visit anywhere. The only record of your visit is the ordinary server request log described under Cloudflare above.
9. Security
- All data is encrypted in transit with TLS, and encrypted at rest by our infrastructure provider.
- Passwords and API keys are stored only as hashes, and API keys are shown once and never again.
- Access to production systems is limited to those who need it, and is logged.
- If a breach affects your personal data, we will notify you and the relevant authority as the law requires, and we will tell you what we know rather than the minimum we can get away with.
No system is perfectly secure, and we would rather say that plainly than imply otherwise.
10. Your rights
Depending on where you live — including under India's Digital Personal Data Protection Act, 2023, and under the GDPR if you are in the EEA or the UK — you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy of it in a portable form, to object to or restrict certain processing, and to withdraw consent where our processing rests on it.
Write to support@simplideliver.com and we will respond within 30 days. We may need to verify your identity first. If your request concerns mail a customer of ours sent to you, we will refer you to that customer, or pass the request to them, because it is their data and not ours to give. If you are not satisfied with how we handled a request, you may complain to your data protection authority — in India, the Data Protection Board of India.
11. Children
The service is for developers and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to us and we will delete it.
12. Changes to this policy
We may update this policy. The date at the top reflects the current version, and material changes will be notified to account administrators by email before they take effect.
13. Governing law
This policy is governed by the laws of India, and the courts at Mumbai, Maharashtra have exclusive jurisdiction over any dispute arising out of it.
14. Contact
- Privacy questions and rights requests
- support@simplideliver.com
- Abuse reports
- abuse@simplideliver.com
- Operator
- Niyam Vora, sole proprietor, trading as SimpliDeliver. India.