Privacy Policy
The short version: your Odoo databases live on your own servers, not ours. We process the minimum we need to run the platform, and we do not sell data. The details are below.
Last updated: July 21, 2026
1. Who we are
CICDoo ("we", "us") provides a platform for deploying and managing Odoo on your own servers, plus managed services. This policy explains what personal data we process when you use cicdoo.com, app.cicdoo.com and the services, and what your choices are. Contact us any time at [email protected].
2. What we collect
We collect what is needed to run your account and operate the service:
- Account data: name, email address, password (stored hashed), optional two-factor settings and recovery codes, and sign-in metadata such as last login. If you sign in with Google or GitHub, we receive your basic profile from them.
- Billing data: plan, subscription status and, when you purchase as a business, company name, VAT number and address. Card details go directly to Stripe; we never see or store your full card number.
- Connection credentials: the SSH credentials, Git access tokens and API keys you provide so the platform can operate your servers and repositories. These are stored for the sole purpose of running the service on your behalf.
- Operational data: server and instance metrics, deployment and job logs, uptime checks and audit trails of actions taken in the platform.
- Support data: tickets, chat messages and attachments you send us.
- Alert contacts: email addresses, phone numbers or Telegram details you configure for notifications.
3. What we deliberately do not hold
Your Odoo databases, filestore and backups live on servers you own and control. They are your data on your infrastructure. Our engineers access instances and their contents only to operate the service or when you ask for help, and access happens over the credentials you granted.
4. Why we process it
We process data to provide the service you signed up for (deployments, monitoring, backups, alerts, support), to bill you, to secure accounts (for example login rate limiting and audit logs), to communicate service messages, and to meet legal obligations. We do not sell personal data and we do not use your data to train AI models.
5. Service providers
We share data only with processors needed to run the service:
- Stripe for payments and subscription management.
- Amazon Web Services for sending transactional email.
- Cloudflare for DNS and traffic proxying, including the free subdomains we create for your instances.
- Uptime monitoring providers that check your instance URLs from outside.
- Messaging channels you configure, such as your email provider, Telegram or SMS carrier, to deliver the alerts you asked for.
If you use the optional AI log analysis, log excerpts are sent to the AI provider you configured with your own API key, under that provider's terms. That feature is off unless you set it up.
6. Cookies and analytics
We use a session cookie to keep you signed in. The marketing site may use Google Analytics to understand aggregate traffic; you can block it with standard browser tools without affecting the service.
7. Security
Passwords are stored hashed, connections run over TLS, server access uses SSH, and the platform offers two-factor authentication, IP rules and rate limiting. No system is perfectly secure, but if we learn of a breach affecting your personal data we will inform you without undue delay.
8. Retention
We keep account and operational data while your account is active. When you delete your account, we remove the credentials you granted us and delete or anonymize personal data within a reasonable period, except what we must keep for legal or accounting reasons. Data on your own servers is under your control and is not affected by our retention.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. Write to [email protected] and we will handle your request. You can also raise a complaint with your local data protection authority.
10. Changes
We will update this policy as the service evolves and announce material changes on the site or by email. See also our Terms of Service.