CRM connectors

Open CRM → Integrations to see providers and workspace connections. You need Manage CRM connectors permission to connect, map, pause, repair, or disconnect a source.

Select a connection to review its status, push health, mapping version, latest successful import, import and event job history, and open conflicts. Catalog entries marked unavailable need deployment configuration before they can be connected.

The overview also shows aggregate imported records, received events, stale sources, failures, and connector-triggered automations. Administrators can copy a redacted support report containing versions, scopes, health, timestamps, counts, opaque correlation IDs, and recent redacted errors. The report excludes credentials, provider payloads, mapped customer values, account names, and external object IDs.

Each provider shows whether an object supports initial import, continuous push, event-only use, or manual refresh. Bnder does not poll providers for changes. If push delivery becomes unhealthy, existing data stays available but is marked stale and an administrator can repair the connection.

Members with Manage CRM connectors receive a browser notification when a connection needs action: authorization expired, required scopes disappeared, push registration failed, webhooks repeatedly failed, an import retained errors, a mapping became invalid, or a provider API version changed. Bnder does not notify for a temporary failure that is still retrying, and repeated workers do not send duplicate alerts for the same unresolved condition.

Credentials are encrypted before storage and are never shown again after saving. Multiple accounts from one provider keep separate mappings, health, source links, and job history.

Provider webhooks are notifications, not trusted record snapshots. Bnder reads the changed object once after a verified event so partial webhook payloads do not erase mapped fields. Shopify privacy callbacks are always subscribed even when customer imports are not selected.

OAuth authorization opens the provider's own consent page and returns through a short-lived, one-time Bnder callback. Self-hosted commerce connections require an HTTPS store URL. After authorization, use Test connection, select the account or locations, review scopes, and confirm mappings before Import now. The import does not start merely because authorization succeeded.

Use Repair webhook when push health is unavailable or degraded. Bnder renews the provider subscription where the provider exposes a per-connection API. A temporary provider outage does not delete the connection or its mappings.

Use Pause to park queued imports and retries without losing their progress. Resume continues them from the saved checkpoint. In job history, Cancel stops queued work immediately; a running import finishes its current bounded page and then stops. Records already completed before cancellation remain in the CRM and are not rolled back.

Bnder automatically limits concurrent work per connection and provider. Jobs delayed by provider capacity or rate limits remain in history and retry from their checkpoint; no import needs to be restarted manually.

During a provider outage, Bnder temporarily pauses new calls to that provider after repeated failures and retries them later. Incoming push notifications remain queued, and a successful provider response restores normal processing.

Before an initial import, choose objects and locations, configure identity and field mappings, and review the preview. Events use the mapping version active when Bnder received them. Organizations match only by an exact domain or an exact normalized legal name and address. Name-only matches are held for review. For a domain mapping, the generic email-domain override prevents consumer email domains from becoming Organization identity. Ambiguous matches are never merged automatically.

Discovery suggests common customer and organization mappings, but does not save or run them automatically. Select Edit mapping to choose the CRM destination and configure every discovered standard or custom source field. A field can map to a system field or existing CRM custom field, remain connected data only, or be ignored. Transformations are selected from a safe fixed list, and ownership controls whether provider data fills an empty value, wins, stops updating after import, follows the newest timestamp, or waits for review. Saving creates a new mapping version. The preview shows a bounded sample and expected creates, exact matches, updates, conflicts, and skips. It never changes CRM data. Review held conflicts to link the source object to the correct Person, Organization, or Record, or ignore that source object.

After reviewing a new mapping version, choose Remap source data to apply it to the provider's current objects. Remapping is a resumable background job, keeps existing source links, and still follows every field's ownership policy.

Objects such as orders and fulfillments can stay as connected source data or be mapped to an Interaction or Signal. Activity mappings must identify an existing Bnder participant or entity so the result appears on the correct timeline. Connected-data suggestions retain the displayed safe source fields without creating CRM schema fields. For Square, selected locations also apply to payments and refunds received through push events; out-of-scope objects are skipped.

HubSpot imports include selected custom properties and association IDs; notes are available through explicit import or refresh because HubSpot app webhooks do not cover them. Pipedrive supports push updates for notes, pipelines, stages, and owners in addition to people, organizations, deals, and activities.

After connecting Mailchimp or Brevo, choose the audiences or contact lists in the connection overview. Mailchimp supports several audiences and keeps member identities separate per audience. Saving the selection repairs push delivery when the connection uses continuous updates.

Mailchimp unsubscribe and cleaned states, plus Brevo unsubscribe, bounce, spam, and channel blacklist states, become restrictive communication evidence on the matched Person. CRM automations use the most restrictive applicable evidence; an ordinary provider update cannot silently clear a prior restriction.

For CSV, first upload the file through Bnder Files and wait for the malware scan to report it as clean. Choose that file in the CSV connection and optionally select a stable ID column. CSV rows then use the same mappings, duplicate handling, jobs, source links, and history as native providers. Free includes one import of up to 25 rows, Starter accepts 1,000 rows per job, and Pro accepts 10,000 rows per job.

Before disconnecting, Bnder shows how many source links, connected snapshots, and proven source-only records are affected. Choose Keep imported data to stop provider access and mark retained source data stale. Choose Remove source links to also remove the connection's source links, snapshots, and field provenance while preserving canonical records and history. Choose Archive source-only records to additionally archive records that this connection created and that have no other source, work item, activity, or CRM dependency. Disconnect never hard-deletes canonical CRM records. Privacy suppressions prevent a deleted Person from being recreated blindly by a later provider event.

Shopify privacy callbacks are handled automatically. Customer redaction removes the retained Shopify source snapshot. Shop redaction disconnects the source and removes its credentials, pending source values, source links, and discovery samples; canonical CRM records remain subject to your workspace retention rules.

Open a Person, Organization, or Record and select Sources to see which connection owns linked data, when it last synchronized, whether it is stale, and the safe connected values retained by Bnder. When supported, Open source goes to the matching object in the provider.

The Sources panel also lists externally managed CRM fields. Hover a field to see its source update time; the label identifies the connection responsible for the current value.

Stripe

Choose Connect with Stripe, install the read-only Bnder Stripe App, then map customers and any payment, invoice, subscription, refund, product, or price context you need. Stripe customer data stays separate from Bnder's own billing account. Continuous mode requires the deployment-managed signed webhook.

Square

Choose Connect with Square, approve the requested read scopes, and select the merchant locations Bnder may use. Location selection also limits pushed orders, payments, and refunds. Use Square's sandbox connection before enabling a production merchant.

Shopify

Enter the store's exact *.myshopify.com domain and complete Shopify OAuth. Select only the objects and historical range you need. Bnder always registers Shopify's mandatory customer and shop privacy callbacks, even when People are not imported.

WooCommerce

Enter the HTTPS WordPress store URL and a WooCommerce REST API consumer key and secret with read access. Bnder creates signed webhooks for supported customer, order, and product changes. Refund refresh remains an explicit administrator action because WooCommerce has no native refund webhook resource.

Shopware

Enter the HTTPS Shopware 6.7 store URL and integration client ID and secret. Test the connection before mapping customers or orders. Bnder obtains a short-lived Admin API token and registers signed per-connection webhooks.

HubSpot

Choose Connect with HubSpot and approve the CRM object scopes shown on the provider page. Map contacts, companies, deals, Tickets, associations, and selected custom properties. Notes are refreshed explicitly because HubSpot app webhooks do not cover note activity.

Pipedrive

Choose Connect with Pipedrive, approve base access plus any selected deal or activity scopes, then map persons, organizations, deals, activities, notes, pipelines, stages, and owners. Bnder registers a Webhooks v2 callback protected with connection-specific HTTP Basic credentials.

Mailchimp

Choose Connect with Mailchimp, then select one or more audiences before previewing an import. Audience IDs remain part of each member's source identity. Subscribe, unsubscribe, cleaned, profile, and email-change events preserve their audience provenance and feed CRM communication evidence.

Brevo

Enter a Brevo API key, test the account, and select the contact lists in scope. Bnder registers a bearer-protected webhook for contact, list, unsubscribe, bounce, and spam changes. Channel blacklist values remain separate and cannot silently clear an existing denial.

CSV

Upload the CSV through Bnder Files and wait for a clean malware-scan result. Create a CSV connection, choose the file and optional stable ID column, then map and preview before importing. CSV imports are explicit, resumable jobs and never become scheduled polling.

Inbound webhook

Create an Inbound webhook connection and save its generated secret securely. The sender must include a stable event ID, timestamp, and HMAC-SHA256 signature over the timestamp and exact request body. Save a mapping before sending live events; repeated delivery IDs are accepted once.

Connector processing is event-driven. Failed internal jobs enqueue one delayed retry at their exact due time; Bnder does not periodically poll providers or scan connector queues.

REST API

Use a workspace API key with the required CRM permissions against the versioned consumer/v1 endpoints. REST callers can create canonical CRM entities, Signals, and normalized Automation events. API keys cannot read connector credentials or bypass workspace and field permissions.