What ERPipe processes for the hosted beta, why it is needed, retention, and how to exercise privacy choices.
Privacy notice — ERPipe
Scope and roles
This notice explains how ERPipe handles personal data for the hosted website, dashboard, authentication flow, and MCP gateway. For account and service administration, ERPipe acts as a controller. For Odoo data processed on a customer's instructions, the customer is the controller and ERPipe acts as its processor.
Data we process
- Account data: email address, workspace name, role, plan, and account status.
- Beta interest data: an email address submitted for priority beta onboarding.
- Connection data: Odoo hostname, database and username, encrypted credential material, transport, and policy settings.
- Service data: MCP tool inputs and Odoo responses needed to fulfill a request.
- Audit data: tool, model, outcome, timestamps, record identifiers, payload fingerprints, and redacted or truncated diagnostic detail.
- Security data: session identifiers, magic-link nonces, IP or bot-check signals, and operational logs provided by Cloudflare.
- Product feedback: the message you send from the signed-in dashboard, whether it is a bug, idea, or other note, the page path you were on, and your workspace and account email.
- Optional GA4 data: page path without query parameters, CTA location and label, and whether a completed authentication created a workspace or signed in an existing account. GA4 does not receive email, workspace IDs, Odoo URLs, credentials, or record data.
- Workspace origin: bounded labels describing where a workspace came from — campaign values from the sign-in link, the public landing path without query parameters, and the referring hostname. These are read from the sign-in request itself. No identifier is stored with them, nothing is written back to your browser, and no profile is built across other sites. The row is keyed to the workspace; the operator dashboard exposes only aggregate counts, not workspace-level origin.
- Optional first-touch cookie: with analytics permission, one bounded browser cookie keeps the original campaign or search source across pages so the workspace origin above can name an external source instead of an internal page.
ERPipe does not sell personal data and does not use it for cross-context behavioral advertising.
Why we process it
We process data to provide and secure the service, authenticate users, connect to the customer-selected Odoo system, execute requested tools, prevent abuse, troubleshoot failures, comply with law, communicate essential service messages, and contact people who request beta onboarding. Depending on the context, the legal bases are performance of a contract, legitimate interests in operating and securing the service, legal obligations, and consent where required.
Cookies and email
The dashboard uses a secure, HttpOnly, SameSite session cookie. Turnstile may process browser and network signals to distinguish people from bots. Magic-link emails are transactional and are sent only in response to a sign-in or signup request. Priority beta interest submissions receive a confirmation email and may trigger an internal operator alert so we can follow up on onboarding. When you send in-product feedback, operators may receive an email that a new item arrived; that notice includes who sent it and which page, not the message body.
Google Analytics 4 (GA4) and the first-touch cookie are optional and off until you choose Allow analytics. ERPipe does not load the Google analytics script, create authentication analytics state, or write a first-touch cookie before that choice. Your choice is remembered in a first-party preference cookie shared across ERPipe hosts. With permission, ERPipe keeps one bounded first-touch cookie for up to 30 days and consumes it at authentication so the workspace origin can name the external source. Google may set analytics cookies or use local storage to measure normalized page paths and allowlisted product actions. Advertising storage remains denied.
Workspace origin is recorded either way, and it is not analytics tracking. When you sign in, the request already carries any campaign values in the link and the referring hostname; ERPipe stores those bounded labels with the workspace so it can tell which channels lead to working integrations. Choosing Continue without analytics stops GA4 and the first-touch cookie, and any cookie-based source already captured is discarded — what remains is the label derived from the sign-in request, with no cookie and no cross-site profile. The legal basis is our legitimate interest in understanding how workspaces reach the service.
Retention and deletion
- Unused magic links expire after 15 minutes and are deleted by the next scheduled cleanup; used links are invalidated immediately.
- Sessions expire after seven days or are removed on logout or workspace disablement.
- Account, connection, and policy data remain while the workspace is active.
- Workspace origin labels remain while the workspace is active and are removed by final workspace deletion.
- Product feedback stays until the workspace is finally deleted after the recovery window, or earlier if you ask us to remove a specific message.
- Beta interest data is deleted after 12 months without activity, or earlier on request.
- A verified owner deletion request disables the workspace immediately and queues deletion after a 30-day recovery window.
- Security and audit records may be retained longer where reasonably needed for abuse prevention, service integrity, disputes, or legal obligations.
The deletion workflow is available under Settings. Contact hello@erpipe.com before the scheduled date to cancel a pending request.
Sharing and international transfers
We share data only with service providers needed to operate ERPipe, with the customer-selected Odoo endpoint, when the customer directs us, or when law requires it. Providers may process data in the United States and other locations where they operate. The beta does not promise a fixed processing region. See Subprocessors and the DPA.
Your choices and rights
You may change or revoke the analytics choice at any time through the Analytics choices control shown on the site. Revoking stops future GA4 collection and removes the browser first-touch cookie. The workspace origin row remains until final workspace deletion, because it records how the workspace reached the service rather than tracking you; contact hello@erpipe.com to object or to request earlier removal. You may request access, correction, export, restriction, objection, or deletion where applicable. We may verify your identity and apply lawful exceptions. You may also complain to the data-protection authority that covers your location.
Children and changes
ERPipe is a business service and is not intended for anyone under 18. We may update this notice as the service changes; the effective date above identifies the current version.
Last updated: 2026-08-26