Exactly what we read. Exactly what we don’t.
Default posture
always
opt-in
< 60 min
18 months
Never collected
01 · Principle
Read-only by default.
Read scopes
always
We request only read-level OAuth scopes by default. Every scope is disclosed before you authorize.
Write scopes
opt-in
Write access is never enabled unless you explicitly opt in. Dunning emails on Growth; retries on Scale only.
Token purge
< 60 min
Revoke any integration in one click. Tokens are purged from our systems within 60 minutes.
Retention
18 months
Rolling 18-month window for transactional data. Customer metadata retained for account lifetime + 30 days.
02 · Per-integration tables
Every field, every scope.
7 live integrations
Stripe
Stripe Connect (Standard) or Restricted API Key
| Field | Read | Write | Retention |
|---|---|---|---|
| Customers | id, email, name, created | none | Account lifetime + 30 days after disconnect |
| Charges + Payment Intents | status, amount, currency, decline code | Optional retry (Scale plan) | 18 months rolling |
| Subscriptions | status, plan, renewal date | none | Account lifetime + 30 days |
| Refunds & Disputes | reason, amount, date | none | 18 months rolling |
Shopify
Admin API OAuth — read_orders, read_customers, read_products
| Field | Read | Write | Retention |
|---|---|---|---|
| Orders | id, total, line items, status | none | 18 months rolling |
| Customers | email, orders count, total spent | none | Account lifetime + 30 days |
| Products | title, price, inventory | none | Account lifetime + 30 days |
| Refunds | reason, amount, line items | none | 18 months rolling |
Meta Ads
Marketing API — ads_read, business_management
| Field | Read | Write | Retention |
|---|---|---|---|
| Campaigns & Ad Sets | spend, impressions, clicks | none | 18 months rolling |
| Conversions | event type, value, attribution | none | 18 months rolling |
| Creatives | id, status, preview URL | none | 18 months rolling |
Google Ads
Google Ads API — read-only scope
| Field | Read | Write | Retention |
|---|---|---|---|
| Campaigns & Ad Groups | budget, spend, status | none | 18 months rolling |
| Keywords | text, match type, performance | none | 18 months rolling |
| Conversions | action, value, time | none | 18 months rolling |
TikTok Ads
TikTok Marketing API OAuth — ads.read, reporting
| Field | Read | Write | Retention |
|---|---|---|---|
| Campaigns & Ad Groups | spend, impressions, status | none | 18 months rolling |
| Creatives | id, status, preview URL | none | 18 months rolling |
| Conversions | event type, value, attribution | none | 18 months rolling |
Google Analytics
GA4 Data API OAuth — analytics.readonly
| Field | Read | Write | Retention |
|---|---|---|---|
| Property metadata | property id, timezone, currency | none | Account lifetime + 30 days |
| Events & Conversions | event name, count, value | none | 18 months rolling |
| Acquisition reports | source, medium, campaign | none | 18 months rolling |
Square
Square OAuth — PAYMENTS_READ, ORDERS_READ, CUSTOMERS_READ
| Field | Read | Write | Retention |
|---|---|---|---|
| Payments | status, amount, currency, decline reason | none | 18 months rolling |
| Orders | id, total, line items, status | none | 18 months rolling |
| Customers | id, email, name | none | Account lifetime + 30 days |
| Refunds | reason, amount, date | none | 18 months rolling |
03 · In the queue
Disclosure tables we’ll publish at launch.
PayPal
01Transactions, Subscriptions
Plaid
02Account, Balance, Transactions (read-only)
Klaviyo
03Campaigns, Flows, Revenue attribution
04 · Things we never collect
Five categories of data Omesta never touches.
Full PANs
We never see your customers’ full card numbers. Only the last-4 and brand that Stripe tokenizes.
Bank or ACH details
Routing numbers, account numbers, micro-deposits — we don’t touch them.
Physical addresses
Unless the integration explicitly exposes them (Shopify orders do, Stripe customers generally don’t).
Off-platform data
We only read what you authorize. No screen scraping, no inferred cross-account joins.
Site-visitor tracking
Omesta doesn’t install pixels, cookies, or fingerprints on your storefront.