Last updated: 24 July 2026
This Privacy Policy explains how Simpled Tech Limited ("Simpled", "we", "us") collects, uses, discloses and protects personal information when you visit our US website, buy our products, create an account, use the Simpled mobile app, or use a Simpled smart lock or accessory, or contact us. It should be read alongside our Cookie Policy.
1. Who we are
Simpled Tech Limited is a UK-registered company (company number 13391034, office 2 Eastbourne Terrace, London, W2 6LG, United Kingdom) selling directly to US customers. There is no separate US entity. Contact us about privacy at support@simpled.tech (mark your message "Privacy") or by post to the office above.
2. Scope
This Policy covers our US website and online store, the Simpled app, Simpled smart locks, handles and accessories, and our customer-support channels. It does not cover third-party services you choose to connect (for example voice assistants or smart-home platforms) or sites we link to; they have their own privacy notices.
3. Personal information we collect
- Identifiers and contact data — name, email address, phone number, billing and shipping address.
- Order and transaction data — products purchased, order value, shipping, returns and refunds. Payments are processed by our payment providers; we do not receive or store your full card number.
- Account data — login credentials (passwords are designed to be stored in hashed form), settings and preferences.
- Product and app data — when you set up and use a Simpled lock with the app: device identifiers and model, firmware version, battery status, configuration settings, lock/unlock event logs and access history (including which registered user or credential operated the lock and when), diagnostic and error logs, and Bluetooth/Wi-Fi connection data (see §6).
- Location data — the app may request location permission for features such as auto-unlock or locating your devices. This is optional, controlled by your device permissions, and can be switched off at any time (the related features will then stop working).
- Support data — the content of your emails, calls, chats and reviews.
- Internet / device data — IP address, browser and device type, operating system, pages viewed, referral source and site interactions (see our Cookie Policy).
- Marketing preferences — your subscription choices and email interactions.
We collect this information directly from you, automatically from your devices and our products, and from third parties such as payment processors, shipping carriers and fraud-prevention services.
Biometric data (fingerprint, and where supported face or palm)
Where your lock has a biometric reader, biometric data such as your fingerprint and, where your device supports it, facial or palm recognition is converted into a biometric template — a mathematical representation, rather than an image of your fingerprint, face or palm. How that template is held and where it is stored depends on the specific model and its firmware, and we set out the position for a given model on its product page and here once verified for that model. We do not use biometric data for advertising, and we do not sell it. Our biometric handling is intended to be consistent with applicable US state biometric laws, including the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), Texas CUBI and Washington's biometric statute. Where, for a particular model, biometric templates remain on the device and are not received by us, we would not collect a biometric identifier from you. Where a model transmits biometric data off-device, or where it is otherwise received or processed by us or on our behalf, we will describe that here and provide any notice and consent handling required under those state laws.
4. How we use it
We use personal information to: fulfil and ship your order and process payments; provide warranty, returns and support; operate the app and your devices (syncing settings, access logs and firmware updates); provide security updates and notify you of safety or security issues; keep tax and business records; prevent fraud, secure our systems and enforce our terms; improve our products, website and app; and — where you have not opted out — send you marketing about our products and offers. You can unsubscribe from marketing emails at any time via the link in each message or by contacting us.
5. Biometric information
Where a lock has a biometric reader — fingerprint and, where your device supports it, facial or palm recognition — §3 governs. Where the biometric template is created and stays solely on the device and is never received by us, we would not collect, store, sell, lease, trade or otherwise profit from your biometric information, and we would not disclose it. If any model transmits biometric data off-device, we will provide notice, obtain any consent required, publish a retention/destruction schedule, and update this section — consistent with Illinois BIPA (740 ILCS 14), Texas CUBI, Washington's biometric statute and comparable laws. We never use biometric data for advertising.
6. Access logs and device data
Your lock and app can record access events (which user or credential operated the lock, and when), configuration and diagnostic data. Depending on your product and settings, some of this is held on the device and some may be synced to your account. We do not sell access-log data and do not use it for targeted advertising.
Shared homes, guests, tenants and workplaces. If you issue credentials to household members, guests, cleaners, tenants, short-term-rental visitors or employees, you are the person responsible for how those people's access is managed and for giving them any notice your circumstances or local law require.
Retention. We keep access-log and account data per your app settings and our retention schedule; order and transaction records are kept for approximately 7 years for tax and legal-claim purposes; support records up to around 6 years. You can ask us to delete your account and data — see §10.
7. How we disclose information
To service providers acting on our behalf under contract: payment processors, shipping carriers, cloud hosting and infrastructure, app and firmware infrastructure, email and customer-support platforms, analytics and fraud-prevention providers. We will make available the identity of the service providers we use. We also disclose to third-party platforms only when you choose to connect them; to professional advisers where reasonably necessary, and to authorities where the law requires or permits; and to a buyer or successor on a sale or restructuring of the business, under confidentiality.
App and lock-connectivity platform. Some app, connectivity and remote-management features of your Simpled lock may be provided through a third-party smart-lock software platform (currently including, where applicable, TTLock, operated by Sciener) and/or through Simpled's own software and cloud services. Where the TTLock platform is used, the information it may receive and process on its own servers includes your account information (name, email address, phone number) when you register or update a TTLock account; the credential identifiers you create (for example passcode values, eKey grants, and the name/label of a fingerprint, rather than the biometric template itself); unlock and access records (logs); and connection and log data, including your IP address and general location. This information may be processed outside the United States: TTLock's policy states data may be sent to the United States and possibly other countries, and that the policy is governed by the law of Singapore. TTLock's own policy is available at ttlock.app/data-privacy-and-security-policy.
Where TTLock supplies infrastructure that operates your lock on our behalf and under contract, we treat it as a service provider and this Policy applies. TTLock's own published policy governs the TTLock app under Singapore law and describes TTLock's own collection and use of account, location and log data — which indicates that, at least for its own app and account users, TTLock acts as an independent business in relation to that data. If you choose to install and use the TTLock app directly (rather than the Simpled app), you enter into and accept TTLock's own terms and privacy policy, and TTLock — not Simpled — is responsible for the personal information you provide to it in that capacity. We reserve the right to change, add or replace this platform.
We do not sell your personal information for money. Whether any of our current uses constitutes a "sale", "sharing" or "targeted advertising" as those terms are defined under certain state laws is addressed in §9. Our advertising/marketing tags are currently dormant — see our Cookie Policy.
8. State privacy rights
We do not assert here that any particular state privacy law does or does not apply to us. Applicability under laws such as the California CCPA/CPRA and the Virginia-model laws is gated on revenue and processing-volume thresholds; some laws (for example Texas) have no revenue threshold. Whether and which of these laws apply to Simpled is a factual determination reserved to Simpled.
Baseline rights we make available to US residents (offered as a matter of policy, and to the extent a state law grants them to you): depending on your state, you may have the right to (a) know / access the personal information we hold about you; (b) request deletion; (c) request correction; (d) obtain a portable copy; and (e) opt out of any "sale", "sharing", or "targeted advertising", and of certain profiling. Where a state law provides an appeal right after we decline a request, we will honour it.
Sensitive information. Some states treat biometric information and precise geolocation as sensitive. See §5 and §3 — we minimize our handling of both and, where a template stays on the device, we do not receive it.
How to exercise a right. Email support@simpled.tech (mark it "Privacy Request"). We may need to verify your identity before acting. We do not discriminate against you for exercising a privacy right. You may use an authorised agent where your state law allows. See also Your Privacy Choices.
Global Privacy Control (GPC). Where a state law requires us to treat an opt-out preference signal as a valid opt-out and we engage in "sale"/"sharing"/targeted advertising, we honour recognised browser opt-out signals such as GPC.
9. Advertising, "sale" and "sharing"
At present the US storefront's marketing/advertising tags are dormant (the tag container loads but is not firing advertising or cross-context tracking tags — see our Cookie Policy). On that basis we do not currently "sell" or "share" personal information or engage in cross-context behavioural ("targeted") advertising as those terms are defined under state law. If that changes, we will update this section, our Cookie Policy, and operate the opt-out and GPC handling accordingly. You can review the choices available to you on our Your Privacy Choices page. We do not knowingly sell or share the personal information of consumers under 16 without the required consent.
10. Account and data deletion; returned devices
You may ask us to delete your account and associated data by contacting support@simpled.tech. Before disposing of, returning or reselling a device, deregister it from your app account and factory-reset it so that credentials and any local data are cleared. We are not responsible for personal data left on a device you dispose of without wiping it.
11. Security
We apply administrative, technical and physical safeguards appropriate to a security product, designed to include: encryption in transit and at rest for sensitive data, access controls and least-privilege administration, hashed credentials, signed firmware updates, and a coordinated vulnerability-disclosure program. No system is perfectly secure, and we cannot guarantee absolute security. Where a security incident affecting your information occurs, we will notify you and any authority as required by applicable state law.
12. Children
Our website, store and app are not directed to children under 13, and we do not knowingly collect personal information from children under 13 (consistent with the Children's Online Privacy Protection Act). A lock owner may issue access credentials to household members, including minors, under the owner's own responsibility. If you believe a child under 13 has provided us personal information, contact support@simpled.tech and we will delete it.
13. Retention
We keep personal information only as long as needed for the purposes above or as required by law (see §6). We then delete or de-identify it.
14. Changes to this Policy
We may update this Policy from time to time; the version date shows the current version. Material changes may be notified (for example by email or in-app notice).
15. Contact
Simpled Tech Limited, 2 Eastbourne Terrace, London, W2 6LG, United Kingdom — support@simpled.tech — +44 (0)20 7096 0094. For privacy requests, mark your message "Privacy Request", or get in touch.