Tapper
Search docs...
⌘K
SupportDashboard

Connect Salesforce

Link your Salesforce org to Tapper so real deal outcomes - qualified, won, and their value - feed back into your Google Ads bidding.


Google Ads optimises for whatever you tell it a conversion is. If that is a form submission, it will buy you form submissions - including the ones that never become customers. Connecting Salesforce lets Tapper send back what actually happened to each lead, so bidding chases revenue instead of volume.

The connection is read-only. Tapper never writes to your Salesforce org.

Before You Start

Check your Salesforce edition first. Enterprise, Unlimited, Performance and Developer editions include API access and work out of the box. Professional edition requires the paid Web Services API add-on - note that the Additional API Calls product is a different thing and does not enable it. Group and Essentials editions have no API access and cannot be connected.

Grant Read-Only Access

Salesforce has no read-only OAuth scope, so read-only is enforced by the permission set you assign - not by the login itself. Set this up before connecting.

1
Create a Permission Set

In Salesforce, go to Setup → Permission Sets → New. Name it something like Tapper Integration (Read Only).

2
Enable API Access

Under System Permissions, enable API Enabled. Leave every write permission off.

3
Grant Read on Four Objects

Under Object Settings, grant Read - and only Read - on Lead, Opportunity, Contact and Account. Do not grant Create, Edit or Delete on any of them.

4
Assign It

Assign the permission set to the user who will authorise the connection.

A free Salesforce Integration User licence works well here if your edition includes one, since it keeps the integration separate from a person's login.

Connect from Tapper

1
Open Your Protection Script

In your Tapper dashboard, open the Protected Website whose leads you want to measure and select the CRM tab.

2
Click Connect Salesforce

You will be sent to Salesforce to sign in and approve access. Sign in as the user you assigned the permission set to.

3
Approve

Review the requested access and approve. You are returned to Tapper and the connection appears on the CRM tab.

4
Review, Then Enable

A new connection starts paused on purpose. Check the detected click ID field, then switch Syncing on.

Enabling begins a one-time import of the last 12 months, which uses your Salesforce API quota. Starting it deliberately means it never runs at a surprising moment.

If the CRM tab shows no click ID field detected, follow Add the Click ID Field next. Without it, Tapper cannot tell which ad click produced a lead, and no values will reach Google.

What Tapper Reads

A deliberately small set - enough to answer which ad click produced this deal and what was it worth, and nothing more.

ObjectFields
LeadRecord ID, email, phone, status, lead source, created/modified dates, conversion details, click ID.
OpportunityRecord ID, stage, amount, close date, created/modified dates, won/closed flags, click ID.
ContactRecord ID, email, phone, created/modified dates.
Opportunity Contact RoleOpportunity ID, contact ID, primary flag.

Email and phone are hashed the moment they arrive and the original values are never stored - not in our database, not in logs, not in our warehouse.

Tapper does not read names, company, job titles, addresses, notes, descriptions, activities, tasks, attachments, or any custom object. It does not read orders, invoices, payments, refunds, or any payment method or gateway data. Ask your account manager for the full data disclosure document if your security team needs the complete list.

Keeping It in Sync

After the first import, Tapper checks for changes every 15 minutes and reads only records modified since the last successful sync. You can force a check at any time with Sync now on the CRM tab.

Pausing or Disconnecting

Pause stops syncing but keeps the connection and everything collected so far.

Disconnect revokes Tapper's access with Salesforce and deletes the stored credentials. Outcomes already collected are kept unless you ask us to remove them.

If a connection stops working - usually because the Salesforce grant was revoked or a password changed - the CRM tab shows the error and a Reconnect button that restores it without losing your history.