← Back to home

Privacy Policy

Last updated: September 2026

1. Controller

Red Clover, operator of Koru Suite, controls your data in accordance with Argentina's Personal Data Protection Law 25,326.

2. Data we collect

We collect your Auth0 identity (including its immutable identifier), normalized email, name, organization, websites, verification status, installations, authorizations, and operational events needed to provide the service. We do not collect Auth0 passwords, VTEX credentials, prompts, VTEX payloads, or unnecessary sensitive data.

3. Account

We use account data to authenticate you, recover incomplete onboarding, prevent takeovers, and preserve continuity when your email changes. The Auth0 identifier is primary; a matching email never replaces a linked identity.

4. Organization and websites

Organization data, registered websites, and control evidence are used to isolate tenants, authorize installations, and prevent cross-account access. Conflicts do not disclose the organization that owns a domain.

5. Verification

We retain the verification method, status, timestamps, and minimal evidence. A confirmed absence blocks operational access without automatically deleting the entitlement.

6. Apps and privacy

Each installation may have a privacy profile and version. Protected is the initial profile; changing it may require assistants to re-authorize. License price, visible cost, and Pricing markup are recorded per website where applicable.

7. How we use it

We use data to provide App Manager, create and protect accounts, verify websites, deliver entitlements, issue OAuth authorizations, show the dashboard, prevent abuse, provide support, and meet legal obligations. We do not share it with third parties for advertising.

8. Providers and assistants

We use Auth0 for identity, infrastructure and email providers, and Koru VTEX MCP for the operational connection you authorize. External assistants receive only OAuth grants for the consented website, app, and scopes; App Manager does not provide VTEX credentials.

9. Security and audit

We record sensitive mutations, authorizations, and outcomes with pseudonymous identifiers and tenant controls. Audit events contain no tokens, prompts, VTEX payloads, or unnecessary personal data.

10. Retention and closure

Audit events are retained for 12 months. Minimal metadata for onboarding, OAuth, and pairing is retained for up to 30 days after consumption or expiry, then deleted. Account or website closure has a 30-day recovery period; afterward data is deleted or anonymized except for legal retention and acceptance evidence.

11. Your rights

You may access, correct, or request deletion of your data by writing to appmanager@redclover.com.ar. Closure respects audit and legal retention obligations. We respond within five business days.

12. Contact

For privacy, verification, conflict, or recovery help, use Contact Koru. Privacy questions: appmanager@redclover.com.ar