AES-256-GCM with a segregated keybcryptSHA-256 in memoryLinkedIn’s official Marketing API, authorized by the ad account administrator.
r_adsr_ads_reportingrw_adsrw_conversionsrw_dmp_segmentsr_ads_leadgen_automationr_marketing_leadgen_automationr_organization_adminrw_organization_adminr_organization_socialr_basicprofile| Data or resource | Access | When |
|---|---|---|
| Accounts, campaigns, ads and performance metrics | Read | Whenever the account is connected |
| Companies and job titles reached (aggregated LinkedIn data) | Read | Whenever the account is connected |
| Lead Gen Forms and their leads | Read | When you use lead management |
| Company page posts and engagement | Read | When you use organic signals |
| Conversion events (lead and qualified lead) | Write | Only when you turn on conversion sending |
| Target account, exclusion and CRM contact audiences | Write | Only when you create or sync an audience |
| Bids and per-company impression cap | Write | Only with the automation turned on for the campaign |
Google Ads API and Google Data Manager API, through Google’s official consent screen.
adwordsdatamanager| Data or resource | Access | When |
|---|---|---|
| Accounts, campaigns, ad groups and metrics | Read | Whenever the account is connected |
| Google lead form submissions | Read | When you use lead management |
| Conversion actions and events | Write | Only when you turn on conversion sending |
| Customer Match lists | Write | Only when you sync contacts |
Meta’s official Graph API, Marketing API and Conversions API.
ads_readads_managementbusiness_managementpages_show_listpages_read_engagementpages_manage_adspages_manage_metadataleads_retrieval| Data or resource | Access | When |
|---|---|---|
| Accounts, campaigns, ad sets and metrics | Read | Whenever the account is connected |
| Pages and Lead Ads leads | Read | When you use lead management |
| Lead and QualifiedLead events through the Conversions API | Write | Only when you turn on conversion sending |
| Custom audiences | Write | Only when you sync contacts |
HubSpot, Salesforce, Pipedrive, RD Station CRM and Clientify, through OAuth or an official token. Other CRMs can send data by webhook.
| Data or resource | Access | When |
|---|---|---|
| Deals, companies, pipelines, stages and owners | Read | Always: it is the basis of pipeline attribution |
| Contacts | Read | When you use CRM contacts in ad audiences |
| Create contacts, companies or deals from leads | Write | Only with the automation on and write permission granted in the CRM. Off by default |
| Temporary date filter (Pipedrive) | Write | Created and removed within the same query, to fetch only the requested period |
Apollo, Snov.io and Walead, through OAuth or the provider’s own API key.
| Data or resource | Access | When |
|---|---|---|
| Campaigns, lists and sequences | Read | When the tool is connected |
| Sending contacts to lists or sequences | Write | Only when you trigger the send |
| Vendor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, queues, file storage and logs | USA (us-east-1) |
| Stripe | Subscription billing with international cards | USA |
| Asaas | Subscription billing in Brazil (boleto, Pix and card) | Brazil |
| Brevo | Transactional emails, such as account activation and password reset | France (EU) |
On Amazon Web Services, in the us-east-1 region (Virginia, USA), with AES-256 encryption at rest for the database, files and queues.
No. Connections use OAuth or each provider’s official token. You approve the scopes on the LinkedIn, Google, Meta or CRM screen itself.
Because sending conversion events and syncing audiences requires writing to the platform. These actions only happen when you turn the feature on. Otherwise, access is read-only.
Not by default: the CRM is read for pipeline attribution. Contacts, companies or deals are only created if you turn on the automation and grant write permission in the CRM. It ships disabled.
Account users’ profiles, deal owners in the CRM and, when you use those features, leads and contacts. In those cases, your company is the controller and LinkedScope acts as the processor.
No. The data is used only to deliver LinkedScope to your company. We do not sell or rent it, and we do not use it to train general-purpose AI models.
Disconnect the integration in LinkedScope settings or revoke it directly with the provider. To erase what was already stored, send a deletion request through the contact form.
When you close the account, we delete or anonymize the data, except what the law requires us to keep, such as billing and audit records.
The warning is part of Google’s own app verification process. It does not mean passwords are collected or that access happens without consent: the connection is still official, revocable OAuth.