Privacy Policy
Last updated: September 2026
1. Controller
Red Clover, operator of Koru Suite, controls your data in accordance with Argentina's Personal Data Protection Law 25,326.
2. Data we collect
We collect your Auth0 identity (including its immutable identifier), normalized email, name, organization, websites, verification status, installations, authorizations, and operational events needed to provide the service. We do not collect Auth0 passwords, VTEX credentials, prompts, VTEX payloads, or unnecessary sensitive data.
3. Account
We use account data to authenticate you, recover incomplete onboarding, prevent takeovers, and preserve continuity when your email changes. The Auth0 identifier is primary; a matching email never replaces a linked identity.
4. Organization and websites
Organization data, registered websites, and control evidence are used to isolate tenants, authorize installations, and prevent cross-account access. Conflicts do not disclose the organization that owns a domain.
5. Verification
We retain the verification method, status, timestamps, and minimal evidence. A confirmed absence blocks operational access without automatically deleting the entitlement.
6. Apps and privacy
Each installation may have a privacy profile and version. Protected is the initial profile; changing it may require assistants to re-authorize. License price, visible cost, and Pricing markup are recorded per website where applicable.
7. How we use it
We use data to provide App Manager, create and protect accounts, verify websites, deliver entitlements, issue OAuth authorizations, show the dashboard, prevent abuse, provide support, and meet legal obligations. We do not share it with third parties for advertising.
8. Providers and assistants
We use Auth0 for identity, infrastructure and email providers, and Koru VTEX MCP for the operational connection you authorize. External assistants receive only OAuth grants for the consented website, app, and scopes; App Manager does not provide VTEX credentials.
9. Security and audit
We record sensitive mutations, authorizations, and outcomes with pseudonymous identifiers and tenant controls. Audit events contain no tokens, prompts, VTEX payloads, or unnecessary personal data.
10. Retention and closure
Audit events are retained for 12 months. Minimal metadata for onboarding, OAuth, and pairing is retained for up to 30 days after consumption or expiry, then deleted. Account or website closure has a 30-day recovery period; afterward data is deleted or anonymized except for legal retention and acceptance evidence.
11. Your rights
You may access, correct, or request deletion of your data by writing to appmanager@redclover.com.ar. Closure respects audit and legal retention obligations. We respond within five business days.
12. Contact
For privacy, verification, conflict, or recovery help, use Contact Koru. Privacy questions: appmanager@redclover.com.ar