Google Ads
Reporting, campaign optimization, conversion measurement and supported Customer Match features.
Access: OAuth requests https://www.googleapis.com/auth/adwords and https://www.googleapis.com/auth/datamanager. These are not read-only permissions.
| Data category | Read / receive | Change / send |
|---|
| Accounts and campaign performance | Account IDs, campaigns, ad groups, ads, budgets, status, keywords, search terms, recommendations, spend and conversion metrics. | Supported tools can create campaigns, ad groups and ads; pause/resume campaigns; change budgets, schedules, geographic criteria and keywords; add/remove negative keywords; dismiss recommendations and add attribution URL suffixes. |
|---|
| Conversion and audience uploads | Conversion-action configuration, identifiers and upload results. | Configured delivery can send click identifiers, hashed contact details, event time, value, currency and consent signals through Google conversion APIs or Data Manager. Consented Customer Match lists can be sent when uploaded or when the relevant audience automation is enabled. |
|---|
TikTok Ads
Advertising reporting, supported campaign controls and server-side conversion delivery.
Access: TikTok Business API permissions are configured in the provider’s app and authorization settings, not an ads.read scope in Omesta’s authorization URL.
| Data category | Read / receive | Change / send |
|---|
| Advertisers and advertising assets | Advertiser, campaign and ad-group identifiers, status, budgets, creatives and available performance reports. | Supported tools can create campaigns, pause/resume campaigns or ad groups, and change daily budgets, subject to permissions and feature configuration. |
|---|
| Conversion events | Pixel and event identifiers and delivery results. | Configured Events API delivery can send event details, values, URLs, click identifiers and available hashed contact and technical matching data. |
|---|
Google Analytics
Website acquisition and conversion reporting alongside advertising performance.
Access: Separate GA4 OAuth connection: https://www.googleapis.com/auth/analytics.readonly.
| Data category | Read / receive | Change / send |
|---|
| Properties and reports | Accessible account/property identifiers and names; requested aggregate dimensions and metrics for traffic, sessions, events and conversions. | The GA4 connector reads reports and property metadata; it does not change Analytics settings. Omesta Tracking is a separate feature described below. |
|---|
Google Search Console
Organic search reporting and comparison with advertising queries.
Access: Separate OAuth connection: https://www.googleapis.com/auth/webmasters. This is a write-capable provider scope, even though the reviewed reporting flow reads data.
| Data category | Read / receive | Change / send |
|---|
| Sites and search analytics | Authorized property URLs and organic queries, pages, clicks, impressions, click-through rates and positions available to the reporting feature. | The reviewed connector lists sites and reads search analytics. The current authorization request does not include the Google Indexing API scope. |
|---|
GoHighLevel (LeadConnector)
Match advertising leads with CRM activity, opportunity stages and first follow-up timing.
Access: OAuth requests contacts.readonly, conversations.readonly, conversations/message.readonly, opportunities.readonly and locations.readonly. Connected-location tokens and configured webhooks support ingestion.
| Data category | Read / receive | Change / send |
|---|
| Contacts and opportunities | Location/contact/opportunity IDs, contact details returned by the API, creation times, attribution fields, pipeline stages, status and monetary values. Identity events use hashed email and phone matching keys. | The reviewed native connector does not create or edit GHL contacts, opportunities or workflows. A separate Zapier or other automation is not configured by this connection alone. |
|---|
| Conversations and follow-up | Conversation and message API responses, including message data returned by the provider. Follow-up analysis extracts outbound-message timing, direction, channel and identifiers. | The native connector does not send emails, texts or calls through GHL. Reading follow-up activity does not prove a lead was reached or a message delivered. |
|---|
Eventbrite
Event catalogs, registration attribution, attendee rosters and attendance reporting.
Access: OAuth or a supplied Eventbrite token; access depends on provider authorization and organization permissions. Omesta can register an order webhook.
| Data category | Read / receive | Change / send |
|---|
| Events, orders and attendees | Organization/event/order/attendee IDs; event names, URLs, dates, times and timezones; amounts and currency; available attendee names, emails, phones, ticket status and Eventbrite check-in status. | Omesta creates webhook subscriptions and records registrations. Check-ins entered in Omesta are stored in Omesta; the reviewed Eventbrite client does not write them back to Eventbrite. |
|---|
| Conversion sharing | Registration identifiers and outcome records for deduplication and attribution. | With a connected Meta pixel and token, the Eventbrite bridge can automatically forward registration events and hashed contact details to Meta. Outcome sync can also send recorded attendance and append hashed attendee identities to a Meta customer-list audience. These paths do not independently verify each attendee’s marketing consent. Review the event’s notices and permitted data use before enabling them; website tracker consent settings do not cover these flows. |
|---|
Calendly
Distinguish booking activity from completed appointments and connect bookings to advertising.
Access: OAuth requests users:read, scheduled_events:read, webhooks:read and webhooks:write. Configured booking-event ingestion can also receive supported website or server events.
| Data category | Read / receive | Change / send |
|---|
| Users, events and invitees | User/organization, event and invitee IDs, booking times/status, available names, emails, phones, cancellation/reschedule information, tracking parameters and supplied metadata. | Omesta can create and remove webhook subscriptions. The reviewed connector does not create appointments or modify availability in Calendly. |
|---|
| Booking conversions | Event identifiers, attribution data, supplied consent signals and delivery results. | Eligible booking events can be matched to advertising and forwarded to configured destinations, subject to the booking integration’s consent and delivery controls. A booking click is not itself a scheduled appointment. |
|---|
Shopify
Relate store activity to advertising and support available product/content tools.
Access: OAuth requests read_analytics, read_customers, read_inventory, read_orders, read_products, write_products, read_content and write_content. A grant does not make every feature available to every shop.
| Data category | Read / receive | Change / send |
|---|
| Store, orders and catalog | Shop metadata; orders, amounts, currency, line items, refunds, abandoned checkouts, customer IDs/contact fields, products and inventory-related fields. API responses may contain personal data beyond fields displayed in a report. | Reporting reads store data. The connection is not read-only: the same authorization also requests product/content write permissions. |
|---|
| Content and SEO tools | Product, page and article IDs, URLs, titles, descriptions and related content. | Where available and invoked, these tools can create draft pages/articles and update SEO title/description metafields on products, pages and articles. |
|---|
Stripe
Compare connected payment outcomes with advertising; process Omesta billing separately.
Access: The connected-account OAuth flow requests read_write. Separately, Stripe processes your own Omesta subscription.
| Data category | Read / receive | Change / send |
|---|
| Connected payment records | Charge/PaymentIntent, customer and invoice IDs; available contact fields, amounts, currency, status, failure details, refunds and subscription/webhook data. Responses may contain billing metadata. | The reviewed advertising audit reads payment outcomes. The OAuth grant is broader than those reads; connecting an account does not establish that payment retries are enabled. No payment-retry service is promised here. |
|---|
| Your Omesta subscription | Billing customer/subscription IDs, plan, payment and invoice status, and checkout/webhook information. | Checkout, billing-portal and subscription-management requests handle your Omesta plan, separately from your connected customers’ payments. Omesta’s checkout does not ask you to submit full card details to Omesta’s own application server. |
|---|
Square
Connected payment/refund reporting and configured payment-event processing.
Access: OAuth requests MERCHANT_PROFILE_READ, PAYMENTS_READ, PAYMENTS_WRITE, ORDERS_READ, CUSTOMERS_READ, ITEMS_READ and INVENTORY_READ.
| Data category | Read / receive | Change / send |
|---|
| Payments and related records | Merchant, payment, refund, order and customer IDs, amounts, currency, statuses, timestamps and available invoice/customer/card-on-file metadata. | PAYMENTS_WRITE permits payment creation, and the code includes a saved-card payment method. That method’s presence does not establish that automatic charging is enabled for your account. Confirm any payment-write workflow separately; reporting does not imply automatic retries. |
|---|
Omesta Tracking
Measure events, match journeys to ads, detect suspected bot activity and deliver eligible conversions.
Access: An installed website script, configured event endpoint or server-side conversion source; not a provider OAuth connection.
| Data category | Read / receive | Change / send |
|---|
| Website and event data | Page/referrer URLs, events/times/values, UTM parameters, ad/click IDs, visitor/session IDs, user-agent information and device/interaction signals. Form detection can read email and phone fields. Hashing happens on the server where implemented, so raw values may be received before hashing. Requests also expose network information such as IP addresses. | The script uses first-party cookies and session storage. Configured events and matching data can be sent to Meta, Google and TikTok. Hashing is not anonymization. Matching can join website, CRM, booking and event records within an account. |
|---|
| Consent and configuration | Consent preferences, Global Privacy Control signals and the merchant’s tracking configuration. | The customer script reads a saved marketing choice before Global Privacy Control. Without a saved choice it honors that signal, but can otherwise run by default unless requireConsent is enabled. Configure and verify required opt-in and opt-out controls before use; Omesta website Cookie settings are separate. Server/webhook integrations have their own behavior; OAuth approval is not a visitor’s marketing consent. |
|---|
Omesta APIs, event check-in and webhooks
Allow authorized external applications to work with connected accounts and event operations.
Access: Configured partner/workspace credentials, hosted connection sessions or event API keys. Event API scopes include events:read, registrants:read and checkins:write.
| Data category | Read / receive | Change / send |
|---|
| Workspace and event operations | Authorized workspace/account identifiers; event/registrant records, contact details exposed by the endpoint, check-in status, timestamps, API actions and delivery logs. | Authorized clients can read permitted data and write supported check-ins. Omesta can send check-in/reversal/reconciliation notifications to configured webhook destinations. Partner access depends on the key’s scope; connecting through a partner may expose authorized workspace information to that partner. |
|---|