Current policy
Privacy and data handling.
This page describes how KSRO handles customer data today. It reflects the product as it exists, not a future template.
Effective July 7, 2026
At a glance
- Read-only by default; approved write tools require explicit admin enablement
- Secrets encrypted with AES-256-GCM before storage
- Claude OAuth codes and refresh tokens stored only as SHA-256 hashes
- KSRO never asks for your Odoo or Seller Central password
OAuth 2.0 + PKCE
Read-only by default
AES-256-GCM at rest
What KSRO collects
Only what is needed to operate the connection.
- Workspace contact details you register with
- Odoo URL, database name, Odoo user login, and encrypted Odoo API key
- Amazon seller identifiers, marketplace/region selections, and encrypted SP-API credentials when Amazon is connected
- OAuth client metadata and connector audit records for the hosted MCP service
What KSRO never asks for
The integration is intentionally narrow.
- Your Odoo password
- Your Seller Central password
- Unapproved write access to Odoo or Amazon
- Access beyond the validated connector scope
Storage and security
Secrets are encrypted before they touch the database.
- All submissions travel over HTTPS
- Odoo API keys and Amazon seller refresh tokens are encrypted with AES-256-GCM before storage
- Claude OAuth codes and refresh tokens are stored only as SHA-256 hashes
- Access is limited to KSRO personnel operating the service
Retention and deletion
Practical rules while the product is early.
- Intake links expire after 7 days
- Credentials are retained while the connection is active
- Deletion or revocation requests are honored on request
- You can revoke access in Odoo by deleting the API key, and in Seller Central by revoking app authorization