Last updated 11 August 2026
OdooConsole is operated by Cybergarden Software (“we”, “us”). This policy explains what we collect, why, who we share it with, and the choices you have. It covers the marketing site, the console, and the hosted Odoo instances and MCP endpoints we run for you (the “Service”).
For your account and billing data, we are the data controller. For the business records you put inside your Odoo instance, you are the controller and we are your processor — we host and safeguard that data and act on your instructions, but it is yours.
| Category | Examples | Why |
|---|---|---|
| Account | Email, name, a securely hashed password (or a Google sign-in identifier), your company name | To create and secure your account and name your instances |
| Billing | Plan, subscription status, and a Stripe customer reference. We never see or store full card numbers. | To take payment and enforce plan limits |
| Instance data | The ERP records, files, and users inside the Odoo instances you create | To provide the hosted instance you asked for |
| Connection grants | Which AI connectors you have authorised, and their scopes | So you can see and revoke access |
| Technical | Server and access logs, IP address, timestamps, minimal audit records of MCP tool calls | Security, abuse prevention, and debugging |
We do not run third-party advertising or analytics trackers on the console, and we do not sell your data to anyone.
Payments are processed by Stripe. When you subscribe, your card details are entered on Stripe’s secure checkout and are held by Stripe, not by us. We receive only a customer reference and your subscription status.
We use a small set of providers to run the Service. They act on our instructions and only receive what they need:
| Provider | Purpose | Where |
|---|---|---|
| Oracle Cloud Infrastructure | Hosting and storage of instances and databases | Sydney, Australia |
| Stripe | Payment processing and subscription management | Global |
| Optional “Sign in with Google” only, if you choose it | Global |
We may also disclose data if required by law, or to protect the rights, safety, and security of our users and the Service.
Your instances and databases are hosted in Oracle Cloud’s Sydney, Australia region. Some subprocessors (Stripe, Google) may process limited data in other countries; where they do, they provide their own safeguards for international transfers.
We keep your account and instance data for as long as your account is active. When you delete an instance, its database and files are removed. When you close your account, we delete your instances and personal data within 30 days, except records we must retain for legal, tax, or fraud-prevention reasons (for example, invoices).
Passwords are hashed with a strong, salted algorithm. Each instance runs in its own isolated network with a database role scoped to that instance alone. Traffic is encrypted in transit (TLS). AI connectors reach your data only through an authorised, scoped OAuth grant that you can revoke at any time. No system is perfectly secure, but we design for isolation and least privilege by default.
You can access, correct, export, or delete your data. Because instances are standard Odoo, you can ask us for a PostgreSQL dump and your filestore at any time — no export fee, no notice period. Depending on where you live, you may have additional rights under the Australian Privacy Act, the GDPR, or other laws, including the right to complain to your data protection authority. To exercise any of these, email us.
The Service is not directed to anyone under 16, and we do not knowingly collect their data.
We may update this policy. If we make a material change, we will update the date above and, where appropriate, notify you by email.
Questions or requests: almaz@cybergarden.au.