Current policy

Privacy and data handling.

This page describes how KSRO handles customer data today. It reflects the product as it exists, not a future template.

Effective July 7, 2026

What KSRO collects

Only what is needed to operate the connection.

  • Workspace contact details you register with
  • Odoo URL, database name, integration-user login, and encrypted Odoo API key
  • Amazon seller identifiers, marketplace/region selections, and encrypted SP-API credentials when Amazon is connected
  • OAuth client metadata and connector audit records for the hosted MCP service

What KSRO never asks for

The integration is intentionally narrow.

  • Your Odoo password
  • Your Seller Central password
  • Write permissions to Odoo or Amazon
  • Access beyond the read-only connector scope

Storage and security

Secrets are encrypted before they touch the database.

  • All submissions travel over HTTPS
  • Odoo API keys, LWA client secrets, and refresh tokens are encrypted with AES-256-GCM before storage
  • OAuth codes and refresh tokens are stored only as SHA-256 hashes
  • Access is limited to KSRO personnel operating the service

Retention and deletion

Practical rules while the product is early.

  • Intake links expire after 7 days
  • Credentials are retained while the connection is active
  • Deletion or revocation requests are honored on request
  • You can revoke access in Odoo by deleting the API key, and in Seller Central by revoking app authorization