Current policy
Privacy and data handling.
This page describes how KSRO handles customer data today. It reflects the product as it exists, not a future template.
Effective July 7, 2026
What KSRO collects
Only what is needed to operate the connection.
- Workspace contact details you register with
- Odoo URL, database name, integration-user login, and encrypted Odoo API key
- Amazon seller identifiers, marketplace/region selections, and encrypted SP-API credentials when Amazon is connected
- OAuth client metadata and connector audit records for the hosted MCP service
What KSRO never asks for
The integration is intentionally narrow.
- Your Odoo password
- Your Seller Central password
- Write permissions to Odoo or Amazon
- Access beyond the read-only connector scope
Storage and security
Secrets are encrypted before they touch the database.
- All submissions travel over HTTPS
- Odoo API keys, LWA client secrets, and refresh tokens are encrypted with AES-256-GCM before storage
- OAuth codes and refresh tokens are stored only as SHA-256 hashes
- Access is limited to KSRO personnel operating the service
Retention and deletion
Practical rules while the product is early.
- Intake links expire after 7 days
- Credentials are retained while the connection is active
- Deletion or revocation requests are honored on request
- You can revoke access in Odoo by deleting the API key, and in Seller Central by revoking app authorization