Last updated: October 7, 2026
Integrations & Developer Information
This page describes how the Adviuz platform connects to outside services: exactly what data moves in each direction, how each connection is secured, and how to connect or disconnect. It is written for our clients, their technical teams, and the platform partners who review us. How we handle personal information is covered in our Privacy Policy; deletion requests are covered on our Data Deletion page.
The Adviuz platform at a glance
Adviuz, operated by Instad Web Services Ltd. (Saskatoon, SK, Canada), is a lead-generation and lead-conversion platform for businesses:
- adviuz.com — this website: product information, checkout (processed by Stripe), and demo booking.
- hub.adviuz.ca — the client dashboard, where each business signs in to see its own leads, conversations, call recordings, appointments, and campaign settings.
- Digital Flyers — advertising campaigns that bring a business new leads.
- AI Conversion Engine — AI assistants that answer and follow up a business's own leads by phone, text, and email, and book appointments into the business's calendar.
Our application services run on Supabase; the endpoints referenced on this page live under https://crhvvfomwkrgwlnfruad.supabase.co/functions/v1/. Every endpoint is HTTPS-only.
Facebook & Instagram Lead Ads
What it does. When a business runs lead ads on Facebook or Instagram, the answers a person submits on the lead form are delivered into that business's Adviuz campaign, so follow-up can start within about a minute instead of days later.
Data we receive. Only what the person typed or selected on the form — typically name, phone number, email, and the form's custom questions — plus Meta's form ID and lead ID.
How it is used. Solely so that the business the person contacted can follow up its own lead. Lead data is never sold, never used for Adviuz's own marketing, and never shared with other businesses.
Protections built in.
- Test leads are never contacted. Meta's form-testing tool sends dummy submissions; our intake recognizes them, uses them only to learn the form's field names, and never creates a lead or sends any message.
- Duplicates are blocked using Meta's unique lead ID, so nobody is contacted twice for one submission.
- Unknown forms are quarantined. A submission from a form that has not been mapped to a client campaign is held for review instead of being guessed at.
Connecting and disconnecting. Our team sets up lead delivery during onboarding — either directly or through a bridge the client already uses (Google Sheets, Zapier, or Make). To stop delivery, a client simply asks us or removes the bridge; deletion of already-received leads follows our Data Deletion process.
Google Calendar sync (Google user data)
What it does. A client can connect a Google Calendar to their campaign so that appointments booked through Adviuz — including appointments booked by their AI assistant — appear on their real calendar, and busy slots are not double-booked.
OAuth scopes we request, and why — nothing more:
openid email— to show the client which Google account they connected.…/auth/calendar.readonly— to list the client's calendars so they can pick one, and to read busy times on that calendar so we never book over an existing appointment.…/auth/calendar.events— to create and update the appointment events we book. We never delete or modify events we did not create.
Storage and security. The Google token is stored server-side in our database and used only for the purposes above. Humans do not read Google user data except with the client's permission, for security, or to comply with law.
Disconnecting. The client can disconnect at any time from campaign settings in the dashboard — we then revoke the token with Google immediately — or from their Google Account permissions page.
Adviuz's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Lead intake webhook (Zapier, Make, Google Sheets, custom forms)
Clients can send leads into their Adviuz campaign from almost any tool that can make a web request — Zapier ("Webhooks by Zapier"), Make (HTTP module), Google Sheets automations, or a form on their own website.
- Endpoint:
POST https://crhvvfomwkrgwlnfruad.supabase.co/functions/v1/fb-leadform-intake - Authentication: a per-account secret sent in the
x-adviuz-secretheader. Secrets are issued by our team during onboarding, are never published, and requests without a valid secret are rejected. - Body: JSON including the integration ID (
form_id) we issue for the source, plus the lead's details, for example:
{ "form_id": "your-integration-id", "full_name": "…", "phone_number": "…", "email": "…", "your custom question": "…" }
- Field names are flexible — common variants (name / full_name, phone / phone_number, email) are recognized automatically, and extra fields are kept with the lead so no answer is lost.
- Honest responses: a lead for an unrecognized integration ID is refused with an error rather than silently accepted, so the sending tool shows a failure and nobody's lead disappears behind a green tick.
- Test submissions are detected and never contacted, and duplicates are blocked.
To get an integration ID and secret for a campaign, contact [email protected].
Text messages and calls (Twilio)
- Each client gets a dedicated business phone number, provisioned through Twilio into the client's own isolated sub-account.
- Messaging is consent-based: the platform contacts people who submitted their details to that business, or whose documented consent the business has confirmed. Purchased, rented, or scraped lists are prohibited by our Terms of Service.
- Where US A2P 10DLC registration applies, traffic is sent under registered campaigns with the opt-in language shown on the collecting form.
- STOP ends messaging immediately and is honored across channels; HELP returns help. Calls respect waking hours in the lead's own time zone, and daily contact limits apply.
- Call recordings and transcripts are available to the client in their dashboard, with recording notices given where the law requires.
Payments (Stripe)
All checkout and card payments are processed by Stripe. Card details go directly to Stripe; Adviuz never sees or stores full card numbers. Payment confirmations reach our platform through Stripe's signed webhooks, and every payment produces an instant receipt and tax invoice.
Email (Resend)
Transactional and campaign email is sent through Resend. Clients can send from their own domain once it is verified (we provide the DNS records). Every commercial email identifies the sender and carries a working unsubscribe link, as CASL and CAN-SPAM require.
Security practices
- HTTPS everywhere; no API keys or secrets ever appear in website code.
- Integration endpoints are protected by per-account shared secrets or signed webhooks; unauthenticated requests are rejected.
- Each client's data is scoped to their own account in the dashboard; telephony runs in per-client Twilio sub-accounts.
- Webhooks are idempotent — a payment or lead delivered twice is processed once.
- To report a security concern, email [email protected] with the subject "Security".
Developer contact
Integration setup, API questions, and partnership requests: [email protected] · +1 647 250 1152 · Instad Web Services Ltd., Scotiabank Building, 111 2nd Ave S, Unit 400, Saskatoon, SK, Canada.