Omesta
How it worksAd creationReviewsPricingCase studies
Log inGet started
How it worksAd creationReviewsPricingCase studiesLog inGet started

Integration data disclosureIntegration data disclosure

Know what connects.
Know what is shared.

How Omesta receives, uses and shares connected data—and which features can change your accounts. Review the permissions, controls and limits before connecting.

Explore the integrations

Storage & deletion

The connection reference

Read. Change.
Share.

Omesta Systems
Access should be understandable

More than
a read-only dashboard.

Omesta can analyze advertising, change supported campaign settings and send conversion data to connected platforms. Those are different activities, with different permissions and controls.

Review each connection ↓
Code reviewed · September 17, 2026

Before you connect

Know the boundaries.

Implementation reviewed September 17, 2026. This is a category-level description of the reviewed code, not an exhaustive inventory of every provider field or a certification of legal compliance. Live permissions and enabled features may vary.
01

Permissions are not all read-only

Several connections request write-capable access during authorization. Provider permissions describe what an integration may do; actual actions depend on supported features, account access and settings. Review both before connecting.

02

Automation can act without another click

Enabled automation can execute supported actions without approval for every change. Turning off campaign Autopilot is not the same as disconnecting an integration or stopping conversion delivery, webhook processing or installed website tracking.

03

Some integrations contain personal data

Lead, booking, event and payment sources can contain names, emails, phones and other provider-supplied fields. Event rosters can store readable contact details. Advertising hashing does not mean every record is anonymous or that Omesta never receives plaintext personal data.

04

Availability depends on your setup

This describes the reviewed implementation, not a guarantee that every tool is enabled in every account. Provider approval, granted scopes, selected accounts, plan, feature configuration and connection health can limit availability. Planned integrations are not represented as live connections.

Dashboard workflows

New screens. Defined permissions.

The new dashboard groups work into Home, Analytics, Plan, Apps, Campaigns, Creatives, Chat and Events. A renamed screen or preview feature does not expand a provider grant.
01

Analytics, Plan and Campaigns

Available reports, CRM stages, demographic breakdowns and action history use the source data and permissions described below. AI proposals and enabled campaign automation have different approval paths; the preview autonomy dial is not a universal stop switch for existing integrations or jobs.

02

Creatives and Chat

Enabled tools can process prompts, relevant campaign or website context, submitted assets, generated content, feedback and job records. Configured AI or creative providers may receive the inputs needed for that feature. The proposed new video/image pipeline is not a live provider list, and prototype vendor names are not verified production recipients.

03

Teams and human services

Workspace invitations and authorized access are separate from provider OAuth permissions. Omesta personnel providing support or expressly agreed human ad management may review relevant account context and perform agreed work. A review-only workspace switcher does not establish live multi-business access.

04

Credits are not media spend

The proposed production-credit wallet, top-ups and extra-workspace purchasing are not live purchase offers. They do not fund Meta or Google spend, alter an integration scope, establish an individual’s consent or activate a third-party workflow. Purchase and job records will need their own billing, retention and access controls before launch.

AI and creative privacy details ↗ · Planned credit purchases ↗

Per-integration reference

What comes in. What goes out.

Each connection lists data it can receive and changes or transfers it can make. Storage and deletion limits apply across these sources and are explained below. Tables scroll horizontally on small screens.
On this pageMeta AdsGoogle AdsTikTok AdsGoogle AnalyticsGoogle Search ConsoleGoHighLevel (LeadConnector)EventbriteCalendlyShopifyStripeSquareOmesta TrackingOmesta APIs, event check-in and webhooks

Meta Ads

Reporting, advertising diagnostics, supported campaign management, attribution and audiences.

Access: Facebook Login for Business uses the app’s configured permissions. The fallback OAuth request includes ads_management, ads_read, pages_show_list and pages_read_engagement; the partner flow requests ads_management and ads_read. Actual grants depend on the login configuration and account access.

Data categoryRead / receiveChange / send
Accounts and advertising assetsAccount, campaign, ad-set and ad IDs; names, status, budgets, targeting, schedules, creatives, destination URLs, performance metrics and available Page engagement.Supported tools can create advertising assets, pause/resume campaigns, ad sets and ads; change budgets, schedules, geographic targeting and exclusions; and add attribution URL tags. Actions depend on feature availability, permissions and automation settings.
Conversions and audiencesPixel/dataset identifiers, reported results and conversion-delivery responses.Configured Conversions API delivery sends event names, times, IDs, source URLs, values and available matching data, including hashed contact details and click/browser identifiers. Audience tools can upload hashed emails, create custom/lookalike or website audiences, and attach audiences to ad sets.

Google Ads

Reporting, campaign optimization, conversion measurement and supported Customer Match features.

Access: OAuth requests https://www.googleapis.com/auth/adwords and https://www.googleapis.com/auth/datamanager. These are not read-only permissions.

Data categoryRead / receiveChange / send
Accounts and campaign performanceAccount IDs, campaigns, ad groups, ads, budgets, status, keywords, search terms, recommendations, spend and conversion metrics.Supported tools can create campaigns, ad groups and ads; pause/resume campaigns; change budgets, schedules, geographic criteria and keywords; add/remove negative keywords; dismiss recommendations and add attribution URL suffixes.
Conversion and audience uploadsConversion-action configuration, identifiers and upload results.Configured delivery can send click identifiers, hashed contact details, event time, value, currency and consent signals through Google conversion APIs or Data Manager. Consented Customer Match lists can be sent when uploaded or when the relevant audience automation is enabled.

TikTok Ads

Advertising reporting, supported campaign controls and server-side conversion delivery.

Access: TikTok Business API permissions are configured in the provider’s app and authorization settings, not an ads.read scope in Omesta’s authorization URL.

Data categoryRead / receiveChange / send
Advertisers and advertising assetsAdvertiser, campaign and ad-group identifiers, status, budgets, creatives and available performance reports.Supported tools can create campaigns, pause/resume campaigns or ad groups, and change daily budgets, subject to permissions and feature configuration.
Conversion eventsPixel and event identifiers and delivery results.Configured Events API delivery can send event details, values, URLs, click identifiers and available hashed contact and technical matching data.

Google Analytics

Website acquisition and conversion reporting alongside advertising performance.

Access: Separate GA4 OAuth connection: https://www.googleapis.com/auth/analytics.readonly.

Data categoryRead / receiveChange / send
Properties and reportsAccessible account/property identifiers and names; requested aggregate dimensions and metrics for traffic, sessions, events and conversions.The GA4 connector reads reports and property metadata; it does not change Analytics settings. Omesta Tracking is a separate feature described below.

Google Search Console

Organic search reporting and comparison with advertising queries.

Access: Separate OAuth connection: https://www.googleapis.com/auth/webmasters. This is a write-capable provider scope, even though the reviewed reporting flow reads data.

Data categoryRead / receiveChange / send
Sites and search analyticsAuthorized property URLs and organic queries, pages, clicks, impressions, click-through rates and positions available to the reporting feature.The reviewed connector lists sites and reads search analytics. The current authorization request does not include the Google Indexing API scope.

GoHighLevel (LeadConnector)

Match advertising leads with CRM activity, opportunity stages and first follow-up timing.

Access: OAuth requests contacts.readonly, conversations.readonly, conversations/message.readonly, opportunities.readonly and locations.readonly. Connected-location tokens and configured webhooks support ingestion.

Data categoryRead / receiveChange / send
Contacts and opportunitiesLocation/contact/opportunity IDs, contact details returned by the API, creation times, attribution fields, pipeline stages, status and monetary values. Identity events use hashed email and phone matching keys.The reviewed native connector does not create or edit GHL contacts, opportunities or workflows. A separate Zapier or other automation is not configured by this connection alone.
Conversations and follow-upConversation and message API responses, including message data returned by the provider. Follow-up analysis extracts outbound-message timing, direction, channel and identifiers.The native connector does not send emails, texts or calls through GHL. Reading follow-up activity does not prove a lead was reached or a message delivered.

Eventbrite

Event catalogs, registration attribution, attendee rosters and attendance reporting.

Access: OAuth or a supplied Eventbrite token; access depends on provider authorization and organization permissions. Omesta can register an order webhook.

Data categoryRead / receiveChange / send
Events, orders and attendeesOrganization/event/order/attendee IDs; event names, URLs, dates, times and timezones; amounts and currency; available attendee names, emails, phones, ticket status and Eventbrite check-in status.Omesta creates webhook subscriptions and records registrations. Check-ins entered in Omesta are stored in Omesta; the reviewed Eventbrite client does not write them back to Eventbrite.
Conversion sharingRegistration identifiers and outcome records for deduplication and attribution.With a connected Meta pixel and token, the Eventbrite bridge can automatically forward registration events and hashed contact details to Meta. Outcome sync can also send recorded attendance and append hashed attendee identities to a Meta customer-list audience. These paths do not independently verify each attendee’s marketing consent. Review the event’s notices and permitted data use before enabling them; website tracker consent settings do not cover these flows.

Calendly

Distinguish booking activity from completed appointments and connect bookings to advertising.

Access: OAuth requests users:read, scheduled_events:read, webhooks:read and webhooks:write. Configured booking-event ingestion can also receive supported website or server events.

Data categoryRead / receiveChange / send
Users, events and inviteesUser/organization, event and invitee IDs, booking times/status, available names, emails, phones, cancellation/reschedule information, tracking parameters and supplied metadata.Omesta can create and remove webhook subscriptions. The reviewed connector does not create appointments or modify availability in Calendly.
Booking conversionsEvent identifiers, attribution data, supplied consent signals and delivery results.Eligible booking events can be matched to advertising and forwarded to configured destinations, subject to the booking integration’s consent and delivery controls. A booking click is not itself a scheduled appointment.

Shopify

Relate store activity to advertising and support available product/content tools.

Access: OAuth requests read_analytics, read_customers, read_inventory, read_orders, read_products, write_products, read_content and write_content. A grant does not make every feature available to every shop.

Data categoryRead / receiveChange / send
Store, orders and catalogShop metadata; orders, amounts, currency, line items, refunds, abandoned checkouts, customer IDs/contact fields, products and inventory-related fields. API responses may contain personal data beyond fields displayed in a report.Reporting reads store data. The connection is not read-only: the same authorization also requests product/content write permissions.
Content and SEO toolsProduct, page and article IDs, URLs, titles, descriptions and related content.Where available and invoked, these tools can create draft pages/articles and update SEO title/description metafields on products, pages and articles.

Stripe

Compare connected payment outcomes with advertising; process Omesta billing separately.

Access: The connected-account OAuth flow requests read_write. Separately, Stripe processes your own Omesta subscription.

Data categoryRead / receiveChange / send
Connected payment recordsCharge/PaymentIntent, customer and invoice IDs; available contact fields, amounts, currency, status, failure details, refunds and subscription/webhook data. Responses may contain billing metadata.The reviewed advertising audit reads payment outcomes. The OAuth grant is broader than those reads; connecting an account does not establish that payment retries are enabled. No payment-retry service is promised here.
Your Omesta subscriptionBilling customer/subscription IDs, plan, payment and invoice status, and checkout/webhook information.Checkout, billing-portal and subscription-management requests handle your Omesta plan, separately from your connected customers’ payments. Omesta’s checkout does not ask you to submit full card details to Omesta’s own application server.

Square

Connected payment/refund reporting and configured payment-event processing.

Access: OAuth requests MERCHANT_PROFILE_READ, PAYMENTS_READ, PAYMENTS_WRITE, ORDERS_READ, CUSTOMERS_READ, ITEMS_READ and INVENTORY_READ.

Data categoryRead / receiveChange / send
Payments and related recordsMerchant, payment, refund, order and customer IDs, amounts, currency, statuses, timestamps and available invoice/customer/card-on-file metadata.PAYMENTS_WRITE permits payment creation, and the code includes a saved-card payment method. That method’s presence does not establish that automatic charging is enabled for your account. Confirm any payment-write workflow separately; reporting does not imply automatic retries.

Omesta Tracking

Measure events, match journeys to ads, detect suspected bot activity and deliver eligible conversions.

Access: An installed website script, configured event endpoint or server-side conversion source; not a provider OAuth connection.

Data categoryRead / receiveChange / send
Website and event dataPage/referrer URLs, events/times/values, UTM parameters, ad/click IDs, visitor/session IDs, user-agent information and device/interaction signals. Form detection can read email and phone fields. Hashing happens on the server where implemented, so raw values may be received before hashing. Requests also expose network information such as IP addresses.The script uses first-party cookies and session storage. Configured events and matching data can be sent to Meta, Google and TikTok. Hashing is not anonymization. Matching can join website, CRM, booking and event records within an account.
Consent and configurationConsent preferences, Global Privacy Control signals and the merchant’s tracking configuration.The customer script reads a saved marketing choice before Global Privacy Control. Without a saved choice it honors that signal, but can otherwise run by default unless requireConsent is enabled. Configure and verify required opt-in and opt-out controls before use; Omesta website Cookie settings are separate. Server/webhook integrations have their own behavior; OAuth approval is not a visitor’s marketing consent.

Omesta APIs, event check-in and webhooks

Allow authorized external applications to work with connected accounts and event operations.

Access: Configured partner/workspace credentials, hosted connection sessions or event API keys. Event API scopes include events:read, registrants:read and checkins:write.

Data categoryRead / receiveChange / send
Workspace and event operationsAuthorized workspace/account identifiers; event/registrant records, contact details exposed by the endpoint, check-in status, timestamps, API actions and delivery logs.Authorized clients can read permitted data and write supported check-ins. Omesta can send check-in/reversal/reconciliation notifications to configured webhook destinations. Partner access depends on the key’s scope; connecting through a partner may expose authorized workspace information to that partner.

Storage & deletion

Disconnect is not delete.

Connection credentials, imported records and copies sent to other platforms have different lifecycles. Do not treat a disconnect button as a promise of complete erasure.
01

What is stored

Depending on the integration, Omesta stores connection credentials/metadata, reporting snapshots, event/CRM and attribution records, rosters, actions, consent records and delivery/error logs. Reading an API response and storing selected fields are different operations; supplied metadata and payloads can contain additional fields.

02

Disconnecting is not historical erasure

The disconnect flow clears active stored connection credentials and marks the connection disconnected. It does not automatically erase historical reports, attribution, rosters or logs, or undo earlier changes. Calendly disconnect attempts webhook removal; other providers may require removing the app or webhook in their own settings. Remove installed scripts and disable separate event sources where applicable.

03

Retention commitments and implementation

The reviewed implementation does not establish a single automatic deletion process for every integration record. Historical records can remain after disconnect until deleted through an applicable process. A reporting lookback window is not a retention limit. Applicable retention and deletion commitments in earlier notices and accepted agreements remain obligations; this disclosure does not extend them or confirm that every automated purge has been verified. See the Privacy Policy and Data Deletion instructions for requests and the scope of existing commitments.

04

Deletion requests and external copies

Account deletion and targeted tracking-deletion tools cover particular records; they are not a verified purge of every log, backup, linked identity record or provider copy. For access or deletion requests, contact support@omestasystems.com with the account and data concerned, without passwords or payment credentials. Data already delivered to another provider is subject to that provider’s controls and policies.

Beyond the source connection

Other services can process data.

Advertising platforms are not the only recipients. Infrastructure, AI features, email delivery and configured external destinations can also process data needed for their functions.
01

Hosting, storage and processing

Omesta uses infrastructure including Vercel and Supabase to run the application and store operational data. Configured background-job and storage services can process job payloads or uploaded assets. This page is not a complete, contractually verified subprocessor register; contact us for your deployment’s details.

02

AI-assisted features

When configured, OpenAI or Anthropic can receive prompts and feature-specific context such as campaign names, performance figures, findings, website content and material you submit. Do not assume all analysis stays inside Omesta. Creative generation can use Creatify when that separately configured feature is enabled; code support does not mean it is available to every account.

03

Dashboard inputs and history

Enabled workflows can retain conversations, briefs, submitted assets, generated outputs, reviews, proposals and job or usage records. The new dashboard preview and proposed provider pipeline do not establish that new vendors are receiving customer data. See the Privacy Policy for feature-specific purposes, access, retention and requests.

04

Emails and external automations

Configured email providers, such as Resend or an SMTP service, receive recipient addresses and content for messages Omesta sends. External automations you configure, including Zapier flows, have their own permissions and recipients; connecting a source to Omesta does not automatically configure those flows.

Notices & permissions

A connection is not customer consent.

Before enabling tracking, audience uploads or conversion forwarding, review what you collect, where it goes and the notices and permissions that apply. Do not send sensitive health, financial or other restricted information through advertising events or free-text metadata.
01

Review your specific setup

Website tracking, Eventbrite registrations, CRM ingestion and booking webhooks do not all use the same consent mechanism. Review each source separately. A hashed identifier is still usable for matching; it is not a substitute for appropriate permission.

02

Read alongside the Privacy Policy

This technical disclosure does not replace the Privacy Policy, your contract or a provider’s terms. If a statement appears inconsistent with your configuration or another Omesta page, contact us for clarification. A page update alone does not resolve a missing technical control.

Privacy Policy ↗ · Google Ads authorization ↗ · Meta Customer List Custom Audiences terms ↗

A specific field or scope?
Ask us.

Contact the team

Product

  • How it works
  • Ad creation
  • Pricing
  • Reviews
  • Integrations

Solutions

  • Local businesses
  • E-commerce
  • Marketing agencies
  • Growth teams
  • Multi-brand

Resources

  • Blog
  • Case studies
  • Compare
  • Glossary
  • Help center
  • Changelog

Company

  • About
  • Careers
  • Partners
  • Press
  • Security
  • Contact
  • Privacy
  • Terms
  • Refund policy
  • Data disclosure
  • System status

© 2026 Omesta Systems.