Private apps are the normal starting point. For a single integration that doesn't need to be installed by other HubSpot accounts, a private app gives you a scoped API token in a few clicks, no OAuth redirect flow required. That's enough for most of what we build: reading and writing contacts, companies, deals, and tickets, and firing off the custom objects a business has defined for itself.
OAuth matters once an integration leaves your own account. Building something that connects to other people's HubSpot portals, not just your own, means going through HubSpot's OAuth flow and requesting the specific scopes that integration needs. More setup, but it's what a real multi-tenant integration requires.
Custom objects and properties are fully reachable. If a business has extended its CRM with its own object types or custom fields, the API reads and writes those the same way it reads and writes a standard contact or deal, which matters a lot once a HubSpot setup has grown past the default data model.