EcomSolveBD
Legal & compliance

Last updated: 19 May 2026

OAuth Permissions Explained

Transparency about Google, Meta (Ads + Inbox / Facebook Page), and TikTok permissions requested by EcomSolveBD during account connection.

Google OAuth

Used to sign in (optional) and to connect Google Ads and Google Analytics 4. We request read/manage access only for Google Ads customers and GA4 properties you select. We use tokens to list accessible accounts, sync reporting metrics, manage conversion actions you authorize, and upload conversions with gclid/gbraid/wbraid and hashed customer data per your settings.

  • We do not access Gmail, Drive, or unrelated Google services.
  • You can revoke access in Google Account → Security → Third-party access.

Meta Ads — Facebook Login for Business

Used from Advertisement / Integrations to connect ad accounts, pixels, and Conversions API. Permissions typically include ads_read, ads_management (where needed for conversion setup), and business_management for assets in your Business Manager. We send server events only for pixels and accounts you configure.

  • We do not post to your personal timeline on your behalf.
  • Revoke in Business Settings → Integrations or disconnect Meta ads in our dashboard.

Meta Inbox — Connect Facebook Page

Used from Dashboard → Inbox when a merchant clicks Connect Facebook Page. This is a separate OAuth flow from Meta Ads. It authorizes a Facebook Page and (when linked) the Instagram professional account so EcomSolveBD can operate Inbox channels: Facebook comments, Messenger, Instagram comments, and Instagram Direct messages.

  • Page scopes typically include: pages_show_list, pages_messaging, pages_manage_metadata, pages_read_engagement, pages_read_user_content, pages_manage_engagement, business_management.
  • Instagram scopes typically include: instagram_basic, instagram_manage_comments, instagram_manage_messages.
  • Purpose: sync and display conversations in the merchant Inbox; allow merchant replies; power optional comment/DM automations the merchant enables.
  • We do not use Inbox content to advertise for EcomSolveBD or sell message data.
  • Revoke in Meta Business Settings → Integrations, or disconnect the Page from Inbox in our dashboard.

TikTok OAuth

Used to connect TikTok For Business advertisers and Events API. Permissions allow reading campaign performance and sending events to your TikTok Pixel / Events Manager configuration.

  • Revoke in TikTok Ads Manager → Authorized apps.

Token storage

Refresh tokens are encrypted at rest. Access tokens are short-lived and refreshed automatically. Disconnecting deletes stored tokens for that integration.

Frequently asked questions

Why does Google ask for sensitive scopes?
Google Ads API and offline conversion uploads require approved developer token and OAuth scopes tied to conversion management and reporting. We request the minimum scopes needed for features you enable.