Aren't you afraid of them trying to come after you? I'm from the EU and had a similar idea for a local retailer. However, legally it's such a grey zone that I decided not to continue.
My price tracker for AliWatcher: https://aliwatcher.com/
Full of bugs, prices are not updated nearly enough, but decided to put it live anyway while I start working on it
Maybe the oauth scope requested edit access to the FB business manager? That way the scammer can remove OP from the business and add himself via the API