We do not advise linking via serial number and will ask you to change it if detected when you publish your channel.
The problem we have with that is if the Roku is sold on eBay etc... It would still be associated with the previous owner's account information on your website.
If you store a device token in the registry, a factory reset will delete all registries and therefore device tokens when a new user gets the box. The Roku box would no longer be associated with the previous owner's account information.
It's OK to have the SN identified on your website for identification purposes to the user, but it should not be used for authentication.
--Kevin