Starship
starship / search / about-us

Audit report

Our Story

Broad accessReach : limited

by apps2GROW · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Tell your brand story through an outstanding About Us page

Key insights

  • App is a storefront 'About Us / Team' page builder, limited attack surface, no write_orders or write_customers scopes declared
  • Publisher domain optinify.ai differs from the publisher name 'apps2GROW', possible rebrand or umbrella publisher
  • Data residency in Hong Kong with no certifications is a notable jurisdictional concern for EU/US merchants
  • Privacy policy is generic and does not name sub-processors

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Tell your brand story through an outstanding About Us page

Key insights
  • App is a storefront 'About Us / Team' page builder, limited attack surface, no write_orders or write_customers scopes declared
  • Publisher domain optinify.ai differs from the publisher name 'apps2GROW', possible rebrand or umbrella publisher
  • Data residency in Hong Kong with no certifications is a notable jurisdictional concern for EU/US merchants
  • Privacy policy is generic and does not name sub-processors
  • No known CVEs, breaches, or security incidents found for apps2GROW or the Our Story app
  • TLS is healthy (CloudFront-fronted), basic security headers present but HSTS and CSP missing

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_staff_information
Medium

Access to store owner name, email, phone, and physical address, staff PII that should not be exposed beyond what's needed to render an About Us page.

read_blog_contributors
Medium

Access to contributor email, IP address, and browser/OS, personal data with GDPR implications.

read_products
Low

Products and collections, public catalog data, standard for storefront apps.

read_online_store_pages
Low

Online Store pages and theme access, needed to inject the About Us page.

read_files
Low

File access, likely for team photos/media uploaded to the page.

read_online_store_navigation
Low

Navigation menu read, needed to link the About Us page from the storefront menu.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
optinify.ai
TLS grade
A
HSTS
Missing
CSP
Missing

X-Frame-Options=SAMEORIGIN, X-Content-Type-Options=nosniff, Referrer-Policy=strict-origin-when-cross-origin, Permissions-Policy restrictive. Missing HSTS and CSP. Fronted by CloudFront.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not claim any compliance certifications. Data retention up to 90 days post-account-closure, indefinite for anonymized data. Sub-processors not named individually.

Privacy policy
Track record

Publisher reputation

Publisher
apps2GROW
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.