Skip to Content

Odoo Service Policies


How do we protect your privacy?

On Odoo.com and when you use our services Markdebrand LLC and its affiliates offer several services to help you manage your business, one of them is a platform to host your own Odoo database. As part of the management of those services, we collect your data and your business data, these are not only essential for the operation of our services, but are also essential for the security of our services and all our users.


This policy explains what information we collect, why we collect it and how we use it.

Information we collect

Most of the personal information we collect is provided to us by our users when they register and use our services. Other information we collect through recordings of interactions with our services.

Account and contact details: when you register on our website to use, download or subscribe to one of our products or services (such as Odoo online, a free trial, Odoo apps, Odoo.sh, among others) you provide us with certain information on a voluntary basis, the same happens when you fill out one of our contact forms. Usually, when you share this information with us, you share your name, your company name, your email address and sometimes you also share with us your phone number, your address (when you request an invoice or we have to send you a product), the sector of your business and what you are interested in Odoo, as well as a personal password.

We never record or store our customers' banking information. Our PCI-DSS compliant payment processors handle both credit card and recurring payment processing.

Job application data: We generally collect your contact information (name, email, phone) and any other information you choose to share with us in your cover letter and resume when you apply for a job through our website or an employment agency. If we decide to send you a job offer, we will also ask you to provide other personal details if necessary to comply with our legal obligations and personnel management requirements.

We will not ask you to provide information that is not necessary for the recruitment process. In particular, we will never collect information about your racial or ethnic origin, political opinions, religious beliefs, trade union membership or sex life.

Browser data: when you visit our website and access our online services, we detect and store your browser language and geolocation in order to customize your experience based on your country and preferred language. Our servers also passively record a summary of the information your browser sends for statistical, security and legal purposes: your IP address, the date and time of your visit, the page or resource you access, your browser version and platform, and the web page that referred you to our website.

We may also use your browser to store and retrieve your current session data with the help of a session cookie (see the Cookie section for details).

Form protection: Some of our forms may be protected by Google reCAPTCHA. This technology uses heuristic procedures based on the technical characteristics of your browser and device. It may also use Google-specific cookies. Please see Google's privacy policy and terms of use in the Third-Party Service Providers section below.

Customer databases: when you subscribe to an Odoo cloud service and create your own Odoo database (e.g. when you start a free trial), any information or content you send or upload to your database belongs to you and you are in control of it.

Similarly, when you upload a local database to the Odoo update website, the data in it is yours.

Often, this data includes personal information such as your employee list, your contacts and customers, your messages, images, videos, among others. We only collect this information on your behalf and you will always retain full ownership and control over it.

Free trial session recording: when you start a free trial on our Odoo cloud service, we may provide you with the possibility to authorize us to record your free trial session to help us improve the user experience of our products.

If you give your consent we will collect information such as what is visible on the screen during the first two hours of your free trial, as well as your interactions with our applications (where you click, which menu you open, etc.). This data is aggregated into a video that our user experience experts can view for a limited time.

This is likely to include some personal data such as names, emails, phone numbers and photos, depending on the actual information you enter into your database during the recording period. We also automatically exclude password and other sensitive fields from recording, but we cannot completely exclude the possibility of recording some sensitive information, depending on where you enter it.

The other sections of this policy explain:

  • how we process this data.
  • how long we store it.
  • and how you can access or request that we delete this data.
  • and which external service providers are involved.

If you do not give your consent or if we do not offer you the option to record it, your test session will not be recorded and we will not collect any data for this purpose.

Github.com account details: When you subscribe to the Odoo.SH platform and create your project, the platform requires authorization to access your Github.com account, which includes an OAuth token that grants such access and allows you to access the content of your project repository.

In-app purchase transaction data: When you use Odoo in the Odoo Cloud or in your own self-hosted deployment, some optional "in-app purchase" services may be active by default. These typically include auto-complete functions to help you quickly enter customer and supplier information, as well as integration with third-party service providers to send and receive SMS messages, paper letters, etc.

When you use these services, with or without payment, some necessary transaction data is transmitted to Odoo Cloud services and must be communicated to third party services in order to run the service. You can find the detailed privacy policy for each service in the IAP Privacy Policy.

 IAP services are always optional, even when configured as default. The IAP privacy policy also explains how to disable these services.


How do we use this information?

Account and contact information: We need your contact information to provide you with our services, fulfill your requests, bill you, and manage your account. We may also use this information for communication and marketing purposes, but all marketing messages you receive will come with an option that allows you to opt-out of receiving these messages. We also use this data in aggregate and anonymous form to analyze trends in our services.

If you have registered for one of the events we publish on our website, we may transfer your name, email address, phone number and company name to the event organizer and sponsors, both for marketing and event preparations.

If you showed interest in Odoo, or if you asked one of Odoo's service providers to contact you, then we will also transfer your name, email address, phone number and company name to one of our Partners in your country or region, for the purpose of contacting you to offer you their local support services.

Job application data: We will only process this information for our recruitment process, in order to evaluate and follow up on your application, and in the course of preparing your contract, if we decide to send you a job offer. You may contact us at any time to request deletion of your information.

Browser data: this automatically recorded data is analyzed anonymously to maintain and improve our services. Google reCAPTCHA may also be used for security purposes, to prevent abuse of our services. In that case, we only process the anonymous score that reCAPTCHA determines based on your browser and device.

We only link this data to your personal data when required by law or for security purposes, if you have violated our terms and conditions. Acceptable use policy.

Customer database: We only collect and process this data on your behalf, to perform the services you have subscribed to, and based on the instructions you explicitly gave when registering or setting up your service and your Odoo database.

Our technical support staff and engineers may access this information on a limited and reasonable basis to resolve any problems with our services, or upon explicit request for support reasons, or as required by law, or to ensure the security of our services in case of violation of our Acceptable Use Policy to keep our services secure.

Free trial session recording: the purpose of these recordings is to improve our products, as they will only be viewed and analyzed by our R&D Usability team, who will treat your data as strictly confidential information. By reviewing the recordings you will be able to observe a tangible representation of a user's first steps in Odoo and therefore improve the user experience.

These recordings are processed and stored with tools provided by FullStory (see our list of service providers), which follow strict confidentiality terms to the letter.

The other sections of this policy explain:

  • what is recorded.
  • how long we store them
  • and how you can access or request that we delete this data

Github.com account data: During the setup phase of your Odoo.SH project, the platform uses your OAuth token to configure the Github.com project you will use for Odoo.SH, including the webhooks and the deployment key to allow Odoo.SH to detect every commit you make in your project repository. The OAuth token is not stored and is deleted as soon as you log out of Odoo.SH, or after 2 days.

The content of your project repository is stored as long as your Odoo.SH subscription is active to provide the service itself.

Our support staff and engineers may access this information on a limited and reasonable basis to resolve any problems with our services, or at your explicit request for support purposes, or as required by law, or to ensure the security of our services in case of violation of our terms and conditions. Acceptable use policy to keep our services secure.

In-app purchase transaction data: you can find the detailed privacy policy for each service in the IAP Privacy Policy.

Access, update or delete your personal information.


Account and contact details: you have the right to access and update the personal data you have previously provided to us, just log in to your personal Odoo.com account. If you want to delete your account or your information permanently, please contact our Helpdesk to request it. We will take all reasonable steps to permanently delete your personal information, except where we are required to keep it for legal reasons (typically for administration, billing or tax reporting reasons).

Application Data: You may contact us at any time to request access to, update or delete your application information. The easiest way to do this is to reply to the last message you exchanged with our Human Resources staff.

Customer database: you can manage any of the data collected in your databases hosted on Odoo.com at any time, while using your administrator credentials, including modifying or deleting any stored personal data.

At any time, you can export a full backup of your database through our control panel, in order to transfer it or manage your own backups/archives. You are responsible for the processing of this data in compliance with all privacy regulations.

You can also request the complete deletion of your database through your control panel, at any time.

When you use Odoo's database update service, your data is automatically deleted after the update has been successfully completed, and can also be deleted at your request.

Free trial session recording: you can contact us at any time to request access to or deletion of your trial session recording (see contact information below). Don't forget to include the name or URL of your database (e.g. mydatabase.odoo.com) so that we can retrieve your record. Records are automatically deleted after 2 months, so if your trial has passed that period, then that data no longer exists.

The other sections of this policy explain:

  • what is recorded.
  • how we process this data.
  • how long we store it.
  • and which external service providers are involved.

Github.com account data: You can view and manage the project repository data collected from your Github.com account directly in Odoo.SH.

You can request the deletion of this information through your Odoo.SH dashboard at any time.

You can also request the removal of your OAuth token from Github.com by simply logging out of Odoo.SH.

In-app purchase transaction data: you can find the detailed privacy policy for each service in the IAP Privacy Policy.

 Security retention period: we store a copy of your data in our backups for security purposes, even after it is removed from our active systems. See our Data Retention information for more details.


Security

We know how important and sensitive your personal information can be, and we take a variety of steps to ensure that it is processed, stored and kept safe from loss or unauthorized access. Our technical, administrative and organizational security measures are described in our Security Policy.

Service providers / external subprocessors

To strengthen our operations, we rely on several service providers. They help us with various services such as payment processing, web audience analysis, cloud hosting, marketing and communication, etc.

Whenever we share information with these Service Providers, we ensure that they comply with Data Protection legislation, and that the processing they do for us is limited to our specific purpose and covered by a specific data processing contract.

A continuación encontrarás una lista con los proveedores de servicios que usamos en este momento, por qué los utilizamos y qué tipo de datos les compartimos.

A. Subprocessors

These external service providers are processing data for which Odoo is the controller or processor on behalf of Odoo.

Important: due to the great variability in resources and services that these subprocessors provide, Odoo customers cannot select the subprocessor that will be used to process their data. However, they can choose their main hosting region (see Data Location).


SubprocessorsPurpose Shared data

OVH S.A.S.

Privacy and security

Infrastructure and hosting of Odoo.com (production + backups), Odoo SaaS (production + backups), Odoo.SH (backups), protection against DDoS attacks.

 Currently hosted by OVHCloud: Production data from Odoo.com and its affiliated services, which includes Odoo Online (SaaS) customer databases and Odoo database update services, including customer databases being updated; backup data for all Odoo cloud services.
Data center certifications: ISO 27001, SOC 1 TYPE II, SOC 2 TYPE II, PCI-DSS, CISPE, SecNumCloud, CSA STAR.

Google Cloud EMEA Ltd

Privacy and Security

Odoo.com infrastructure and hosting (production + backups), Odoo SaaS (production + backups), Odoo.SH (production + backups), Protection against DDOS attacks.

Currently hosted by Google: Production data from Odoo.com and its affiliated services, which includes Odoo Online (SaaS) customer databases and Odoo.SH (PaaS) customer databases, as well as Odoo database update services, including customer databases that are being updated; backup data for all Odoo cloud services.

Data center certifications: ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC3, PCI-DSS, HIPAA, CISPE, CSA STAR.

Amazon Web Services, Inc.

Privacy and Security

Infrastructure and lodging (inherited)

Currently hosted by AWS: Odoo database upgrade services for customer databases that are loaded on the pre-existing upgrade web platform, that were previously started on that legacy platform with custom scripts or that were started since the end of life of OpenERP v6.1. AWS does not process newer upgrades that start with a command line script or the new web form.

Datacenter certifications: ISO 9001, ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC3, PCI-DSS, HIPAA, CISPE, CSA STAR

FullStory

Security and privacy

Information about GDPR

Cookie Policy

Free temporary trial registrations for users who have consented to the UX improvement program.

Shared with FullStory: recording of your screen for the first 2 hours of your free trial session + FullStory cookies.

B. External processors and controllers

These third party service providers are processing data for which Odoo is both controller and processor on their behalf or receive data as controllers for the specific purpose of providing the services for which they were contracted.

Service ProviderPurpose Shared data

PayPal

PCI - Privacy and Security

Payment processing on Odoo.com.

 Shared with Paypal: Order details (quantity, description, reference), customer name and email.
Stored only by Paypal: credit card information.

Ingenico Payment Services

PCI - Privacy

Payment processing on Odoo.com.

Shared with Ingenico: Order details (quantity, description, reference), customer name and email.

Stored only by Ingenico: credit card information.

Stripe

PCI - Privacy and Security

Payment processing on Odoo.com.

Stored with Stripe: Order details (quantity, description, reference), customer name and email.

Stored only by Stripe: credit card information.

Adyen

PCI - Privacy - T&C

Payment processing on Odoo.com.

Shared with Adyen: Order details (quantity, description, reference), customer name and email.

Stored only by Adyen: credit card information.

OneSignal

Privacy and security

Push notifications in the browser for Odoo.com visitors.

Shared with OneSignal: Non-personal browser data, geolocation information, language (non-identifiable information).

Stored only by OneSignal: Browser/Mobile Device ID.

Google Tag Manager

Privacy and terms - Types of cookies

Website audience analysis.

Cancellation

Shared with Google: Advertising campaign data, browser information, pages visited.

Google reCAPTCHA

Privacy and security

Protection of forms.

Used by Google reCAPTCHA: Browser and device features, Google cookies.

Acuity Scheduling

Privacy and security

Schedule a demo or meeting on Odoo.com

Shared with Acuity: Any personal information entered by the user in the planning form: name and contact information, reason for request, etc.

Clearbit

Privacy and security

Retrieval of business information for prospecting purposes.

Retrieved from Clearbit for visitors of companies that are from EU: name, industry, estimated size, estimated revenue, website, social networks and general contact information.

Retrieved from Clearbit for non-EU company visitors: same as for EU companies plus company executive information, if known.

CloudFlare

Security and Privacy - Cookie Policy

Distributed cache of static resources and images from Odoo.com.

Used by CloudFlare: Browser and device characteristics, CloudFare cookies.

Data retention

Account and Contact Data: We will only retain such data for as long as it is necessary for the purpose for which we collect it, as explained in this policy, including any legal retention period or as long as it is necessary to enable us to promote our products and services in a legitimate and acceptable manner.

Job Application Data: If we do not hire you, we may keep the information you provide for up to 3 years to contact you again if a new job becomes available, unless you ask us not to. If we do hire you, personal information will be stored for the duration of your employment contract with us and thereafter for the applicable legal retention period in the country where you were hired.

Browser data: We may retain this data for a maximum of 12 months, unless we need to retain it due to a legitimate concern related to the security or performance of our services or as required by law. Any server session information is discarded no later than 7 days after it is no longer actively used.

Security and server logs: We may retain this data for up to 12 months, unless we need to retain it due to a legitimate security or performance issue with our services or as required by law.

Customer database: we only keep this data as long as necessary to be able to provide you with the services you have subscribed to. For databases hosted in the Odoo cloud, if you cancel the service, your database is kept deactivated for 3 weeks (the grace period during which you can change your mind) and then destroyed. For databases uploaded on the Odoo database update website, your database is kept for a maximum of 4 months after the last successful update, and can be deleted earlier at your request.

Free trial session recording: recordings are automatically deleted after two months. They may be deleted earlier, after they have been processed, if they are deemed irrelevant or if you request it.

Github.com account data: we keep this data as long as your Odoo.SH subscription is active, except for the OAuth token which is deleted after 2 days, or as soon as you log out of Odoo.SH.

In-app purchase transaction data: you can find the detailed privacy policy for each service in the IAP Privacy Policy.

Security Retention Period: as part of our Security Policy against accidental or malicious deletion, as stated in our Security Policy. To keep your information secure, whenever you ask us to delete personal information from your database (Accounting and Contact Information), after you delete personal information from your database (Customer Database), or if you delete your entire database, that information will not be immediately deleted from our backup systems. These systems are secure and unalterable, and they keep a backup of your data for up to 12 months. After this time, they are automatically destroyed.

We promise to only use these backup copies to maintain the integrity of our backups, unless you or the law requires us to do otherwise.

Physical data location / data transfer

Accommodation services

Hosting locations: customer databases are hosted in the Odoo Cloud region closest to their location, and they can request a change of region (subject to availability):

  • America Canada , United States
  • Europe: France, Belgium
  • Asia and Pacific: Singapore, Taiwan
  • Middle East and South Asia India , Saudi Arabia
  • Oceania: Australia

Backup locations: Backups are replicated across multiple continents in order to meet our disaster recovery objectives, and are located in the following countries regardless of the original hosting region:

  • Canada
  • France
  • Belgium
  • Netherlands

Note: It is not possible to choose or restrict the backup locations, they are replicated in at least 3 of them. It is not possible to host backup data only within the EU.

For more details about our hosting services, please visit Cloud Hosting SLAs.


Updating of local Odoo databases: customers' databases are updated at their current hosting locations (see above) or on an update server located in France or Belgium.

For customers interested in data protection in the EU, the countries marked with a sign in the above lists belong to the EU or are currently subject to an adequacy decision by the European Union authorities.


In-app purchase transaction data: you can find the detailed privacy policy for each service in the IAP Privacy Policy.

Free trial session recording: FullStory is responsible for processing the recorded data (see our Service Providers) in Google Cloud data centers in the United States. Please note that this data is only recorded if you participate and is only stored for a very limited time.

International Staff

In some cases, the personal data mentioned in this Privacy Policy may be accessed by staff members of Odoo SA subsidiaries in other countries. Such access will always be for the same purposes and with the same privacy and security precautions as if done by our own local staff, so all the safeguards we provide remain applicable.

We use EU standard contractual clauses to bind our subsidiaries so that we can offer sufficient data protection security for the limited and temporary data transfers that occur for such an access.

Third party disclosure clause

Except as explicitly mentioned above, we do not sell, exchange or otherwise transfer your personal data to third parties. SMS and text messaging is excluded from any transfer of data mentioned above. We may share or disclose aggregated or anonymous information only for research purposes or to review trends and statistics with third parties.

Cookies

Cookies are small pieces of text that our servers send to your computer or device when you access our services. They are stored in your browser and then sent to our servers so that we can provide contextual content. Without cookies, using the site would be a much more frustrating experience. We use them to support your activities on our website, for example: your session (so you don't have to log in again) or your shopping cart.

Cookies are also used to help us understand your preferences based on your previous or current activity on our website (the pages you have visited), your language and country, which enables us to provide you with better services. We also use cookies to help us gather aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future.

We also use external services such as Google Analytics that set and use their own cookies to identify visitors and provide their own contextual services. For more information about third-party vendors and their Cookie Policies, please review the relevant references in Third-Party Service Providers.

Cookie CategoryPurpose Cookies

Session security

Authenticate users, protect user data and enable the website to provide the services users expect, such as retaining the contents of their shopping cart or allowing file uploads.


The website will not function properly if you reject or discard these cookies.

 session_id (Odoo) 
td_id (Odoo) 
fileToken (Odoo) 
__cfduid (CloudFlare)

Preferences

Remember information about your visual preferences or website behavior such as language, region or time zone. Your experience may change if you do not select these cookies, but the website will still work.

frontend_lang (Odoo)

cids (Odoo)

odoo_no_push (Odoo)

tz (Odoo)

Interaction history

It is used to collect information about your interactions with the website, the pages you have viewed and any specific marketing campaigns that brought you to the website. We may not be able to provide you with the best service if you reject these cookies, but the website will work.

im_livechat_history (Odoo)

im_livechat_previous_operator_pid (Odoo)

utm_campaign (Odoo)

utm_source (Odoo)

utm_medium (Odoo)

fs_uid (FullStory)

Advertising and marketing

We use this cookie to make ads more appealing to users and to help advertisers and advertisers get more value from them. To achieve this, we deliver more relevant ads on ad-enabled websites and improve reporting of ad campaign performance.


Please note that third-party services may place additional cookies on your browser to identify you.


If you do not wish to allow third parties to use cookies on you, please go to the Network Advertising Initiative opt-out page. The website will continue to function even if you reject or opt-out of those cookies.

__gads (Google)

__gac (Google)

_fbp (Facebook)

Analysis

Learn how our visitors interact with our website through Google Analytics. Learn more about analytics cookies and privacy information.


The website will still work if you reject or opt-out of these cookies.

_ga (Google)

_gat (Google)

_gid (Google)

_gac_* (Google)

This is a general description of the cookies that may be stored on your device when you visit our website:

You can choose whether you want your computer to warn you each time a cookie is being sent or whether you prefer to turn off all cookies. Each browser is a little different, so check your browser's help menu to learn the correct way to modify your cookies, or click on the link below.

Currently, we do not support any Do Not Track (DNT) signals as there is no industry compliance standard.

Policy updates

This Privacy Policy may be updated from time to time to make it clearer, to reflect any changes to our website or to comply with legal obligations. The "Last Updated" legend at the top of the policy indicates the latest revision, which is also the effective date of those changes. We give you access to archived versions of this policy so that you can review the changes.

Contact us at

In case you have any questions about this privacy policy, or about your personal data, do not hesitate to contact us at Odoo Helpdesk or contact us by email at info@markdebrand.com.