Legal

Privacy Policy

Last updated: September 2026. This describes what HostOdooSH ("we", "us") collects when you use the platform, why, and what your options are.

What we collect

Account information. You sign in with GitHub — we receive your GitHub username, public profile, and email address from GitHub's own OAuth flow. We never see or store your GitHub password.

Team & project data. Any teammates you invite, the projects/branches you create, and the metadata around them (repository links, deploy keys, commit history references, custom domains).

Your server's connection details. HostOdooSH is bring-your-own-server: to manage deploys, backups, and upgrades on a server you connect, we store an SSH key we generate and use to reach it — encrypted at rest, never your own root/sudo password (that's only used once, live, to install our key, and is never stored). We never access or store the contents of your Odoo databases themselves — those stay on your own server the entire time.

Billing information. Your plan, subscription status, and payment/transaction history. Card and payment details themselves are handled directly by our payment processor (PayFast) — we never see or store your full card number.

Support & communications. The content of support tickets and any emails you send us, so we can actually help with what you're asking about.

Technical data. Standard request logs (IP address, timestamps, user agent) for security and abuse prevention, and a session cookie to keep you signed in.

How we use it

To operate the platform (provisioning, deploys, backups, billing), to communicate with you about your account and service (billing notices, security alerts, support replies), to secure the platform against abuse, and to improve the product. We do not use your data to train third-party AI models, and we do not sell it.

Who we share it with

Only what's needed to actually run the service: GitHub (authentication and your connected repositories), our payment processor (billing), and our email delivery provider (transactional emails — receipts, alerts, notifications). None of them receive more than what's needed for their specific job, and we don't sell or rent your data to anyone for marketing or any other purpose.

How it's secured

Secrets (your server's SSH key, GitHub access tokens) are encrypted at rest, never stored or logged in plain text. Staff access to customer data is permission-gated and audit-logged. Your Odoo instance's own data — your customers, your business records — lives entirely on your own server, under your own control, not on our infrastructure.

Data retention

We keep account and project data for as long as your account is active. Billing and transaction records are kept for as long as required by applicable financial regulation (typically several years), even after an account closes. You can request deletion of your account and associated data at any time, subject to that billing-record retention requirement.

Your rights

You can review and update your account details from your Account page at any time, and request a copy or deletion of your data by contacting us. Disconnecting your server (see the FAQ) destroys our stored access key to it immediately.

Cookies

We use one functional session cookie to keep you signed in. No third-party advertising or tracking cookies.

Changes to this policy

If this policy changes materially, we'll notify active customers by email before the change takes effect.

Questions? hello@hostodoo.com