Compliance & Data Protection

Simple Chat is designed to support merchant compliance obligations while providing AI-assisted customer support features. This page summarizes our technical and operational controls at a high level.

For broader legal disclosures, see our Privacy Policy.

1 - Infrastructure and Data Processing Stack

Simple Chat uses a combination of platform and subprocessor services, including:

  • Shopify APIs and webhook infrastructure for app operations and required compliance workflows.
  • Amazon Web Services for hosting, storage, queueing, and email pipelines.
  • Google Cloud Vertex AI (Gemini) and Anthropic (Claude) for AI-assisted response generation.
  • Optional merchant-enabled integrations, such as Slack and image optimization services.

2 - Data Protection Measures

Encryption in Transit

Network traffic to and from Simple Chat services is transmitted over TLS-protected connections.

Encryption at Rest

Data stored in managed cloud infrastructure is protected using provider-managed encryption capabilities where available and applicable.

Access Controls

Access to production systems and sensitive operations is restricted to authorized personnel under role-based access controls and audit logging practices.

3 - Data Minimization and Purpose Limitation

We process data required to provide support workflows, app functionality, and security/compliance operations. We aim to minimize collection and access to what is needed for these purposes.

4 - GDPR and Platform Compliance Workflows

Simple Chat supports Shopify-required privacy and data workflows, including handling of shop and customer redaction/data request events routed through Shopify webhook mechanisms.

For customer privacy requests, merchants remain the primary point of contact for their end-customers and determine lawful processing of customer data in their store context.

5 - Incident Response

We maintain internal incident response procedures to detect, assess, and respond to potential security events, including escalation and remediation workflows appropriate to incident severity.

6 - Ongoing Updates

Our technical controls and subprocessor footprint may evolve as the product changes. We update legal and compliance disclosures to reflect material changes.

7 - Contact

For compliance or security questions, contact support@simple-chat.com. If needed, include your store domain and relevant request context so we can route the inquiry quickly.

Last updated: February 17, 2026