Integrations & data

How we connect.
How we handle the data.

Per-platform scope, data flow, and retention, written for the marketer evaluating us, the security team reviewing us, and the platform reviewers verifying us.

Integrations

Connected to the platforms that drive growth.

Finch Labs reads campaign performance, conversion outcomes, and product data from the systems where your customers and revenue actually live. Every connection is authorized by the customer via OAuth on a per-account basis, scoped to the minimum data needed for evolutionary fitness scoring and marketing-mix modeling. We do not aggregate, sell, or share customer data across tenants.

Google Ads

Read campaign performance and (optionally) sync optimized creative variants back to the customer's Google Ads account.

Scope
https://www.googleapis.com/auth/adwords
What we read
Ad-account metadata, customer IDs the user has access to, and campaign/ad-set/ad performance metrics (impressions, clicks, conversions, CTR, CPC, ROAS) over a configurable lookback window.
What we do with it
Per-ad fitness scoring inside the evolutionary loop; aggregate trends in the analytics dashboard; (optional, opt-in only) auto-promotion of winning creatives back into the same Google Ads account.
Write access
Off by default. Used only when the customer explicitly enables "auto-promote winning creatives" on their account. Every write action is logged to a tenant-visible audit log.
Retention
Performance metrics are stored per campaign, ad group and ad, by date, for as long as you use Finch. We do not store individual click or impression records. To have your data deleted, email privacy@finchlabs.ai and we delete it within 30 days (how to ask).
Google Analytics 4

Read GA4 conversion and revenue events to bridge ad spend to outcomes for fitness scoring. Optional: export Finch-generated audiences back to GA4 for retargeting.

Scopes
analytics.readonly · analytics.edit
What we read
Conversion events (purchase, signup, lead) attributed to ads we know about; revenue values when e-commerce tracking is enabled; audience-segment counts when audience-based fitness is enabled. We do not read demographics, user-level identifiers, or data outside the GA4 properties the user explicitly grants.
Write access (analytics.edit)
Used only when the customer requests audience export from the Finch dashboard. Creates new audiences in the customer's GA4 property; never deletes or modifies pre-existing audiences. Can be demoted to read-only on request.
Retention
Reported metrics are stored by date, by GA4 default channel group, and (for US traffic) by state, for as long as you use Finch. We read GA4 through its reporting API and never read or store user-level identifiers. To have your data deleted, email privacy@finchlabs.ai and we delete it within 30 days.
Meta Ads

Read campaign performance from Meta Ads Manager + (optionally) publish optimized creative variants back to the customer's Ad Account.

Permissions
ads_management · ads_read · pages_read_engagement · business_management
What we read
Ad account hierarchy (via business_management), per-ad insights (impressions, clicks, conversions, spend, CTR, CPC, ROAS), Facebook Page engagement metrics (likes, shares, video view-time) for ads attached to the customer's connected Pages.
Write access (ads_management)
Off by default. Used only with explicit opt-in to "auto-promote winning creatives." Writes are limited to the customer's connected Ad Account; never to others.
Retention
Same policy as the other ad platforms: performance metrics stored per campaign, ad set and ad, by date, for as long as you use Finch, plus the creative assets we archive. To have your data deleted, email privacy@finchlabs.ai and we delete it within 30 days.
Shopify

Read product catalog, orders, and customer data to bridge ad spend to actual revenue and feed product information into ad-creative generation.

Scopes
read_products · read_orders · read_customers · read_analytics · read_customer_events · read_inventory · read_all_orders
What we read
Product catalog (titles, images, descriptions), order history (totals, line items), aggregated customer counts, and storefront analytics events. Used for product-aware creative generation, customer-cohort retention analysis, and ROAS computation. read_all_orders lifts Shopify's 60-day cap on order history, which is what makes cohort and payback analysis possible on the years you have already traded. It is a gated scope: Shopify grants it per app on request, and it is granted for the app installed on your store.
Write access
None. Shopify integration is strictly read-only.
Retention
Orders and customer records are stored individually, including the payloads Shopify returns, but the shopper’s contact details are stripped on the way in rather than stored and deleted later: email, phone, name, IP address and street address never reach our database. Addresses are reduced to city, province and country, and the customer on an order is reduced to a Shopify ID plus a hashed email. What remains (order totals, line items, discounts, fulfillment status, attribution and that coarse geography) is kept for as long as you use Finch, because cohort and payback analysis reads the order history directly. To have your data deleted, email privacy@finchlabs.ai and we delete it within 30 days. A single shopper’s remaining identifiers can also be redacted on a verified deletion request for that person, without deleting the rest of your account.
How we use data

Read what's needed. Write only on request. Delete on demand.

Tenant isolation

Each customer is a separate tenant. Connections, ad accounts, and analytics data are scoped per tenant via row-level security in our Postgres database (Supabase, US region). One tenant's data is never accessible to another tenant's users or operators.

Token storage

Access tokens and other platform credentials are stored in Finch's own Postgres database, which our hosting provider encrypts at rest, or as references to credentials held in Google Secret Manager. They are read only by Finch's backend services and never reach the browser. Disconnecting a source stops syncing but does not yet erase the stored credential; erasing it on disconnect is a tracked engineering item, and the credential is erased when your data is deleted.

Retention

We keep your data for as long as you use Finch; there is no automatic time limit on it. To have it deleted, email privacy@finchlabs.ai from the address registered to your account (how to ask): we confirm receipt within 5 business days and delete your workspace and its data within 30 days, following a documented internal process. Amazon Information is the one exception with a fixed clock: rows older than 18 months are purged automatically, by each row's own date, per Amazon's Data Protection Policy.

What we don't do

We do not sell customer data, do not share it with third parties for advertising, and do not combine it across tenants. We do not read user-level identifiers from GA4. We do not modify Business Manager settings, billing, or user permissions on connected ad accounts. We do not act as a buyer of record. Customers spend on their own accounts.

Back to

The platform overview.

Return to the main page to see what Finch and Galton do for Shopify advertisers running paid acquisition.

finchlabs.ai →