Audit report
Acumbamail
Broad accessReach : moderateSensitive Accessby Acumbamail · Store design · Shopify App Store
Improve your shop with automated email marketing
Key insights
- ◆Spanish (EU) email marketing SaaS based in Ciudad Real, Spain; data residency is primarily EU
- ◆Shopify app is brand-new: 0 reviews, no Built for Shopify badge
- ◆Privacy policy is detailed, GDPR-aligned, lists DPO (Audisec/GlobalSuite) and TeamSystem group sub-processors
- ◆Publisher domain serves HTTPS with HSTS but lacks CSP
Top findings
Analysis summary
Improve your shop with automated email marketing
- ◆Spanish (EU) email marketing SaaS based in Ciudad Real, Spain; data residency is primarily EU
- ◆Shopify app is brand-new: 0 reviews, no Built for Shopify badge
- ◆Privacy policy is detailed, GDPR-aligned, lists DPO (Audisec/GlobalSuite) and TeamSystem group sub-processors
- ◆Publisher domain serves HTTPS with HSTS but lacks CSP
- ◆Mentions 'AI-based functionalities' (phishing detection, content assist) without naming specific LLM providers
- ◆Historical WordPress plugin CVE exists for the publisher, no Shopify-specific incidents found
- ◆Categories: Email marketing, Pop-ups, typical scope expectation: read_customers, read_products (not explicitly declared on listing page)
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Email marketing requires customer email/profile data; typical scope for this category (not explicitly declared on listing) |
read_products | Low | Required to sync product catalog into email templates per app description |
read_orders | High | Likely needed for transactional/abandoned-cart email triggers per category norms |
read_customersEmail marketing requires customer email/profile data; typical scope for this category (not explicitly declared on listing)
read_productsRequired to sync product catalog into email templates per app description
read_ordersLikely needed for transactional/abandoned-cart email triggers per category norms
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- acumbamail.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HTTPS clean with HSTS (max-age=31536000) and X-Frame-Options SAMEORIGIN; no Content-Security-Policy header observed
Compliance & certifications
GDPR-aligned (EU-based), ENS certification badge displayed, EU-US Data Privacy Framework for transfers; no SOC2/ISO27001/PCI DSS claimed
Privacy policyPublisher reputation
- Publisher
- Acumbamail
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0
- ●WordPress plugin Acumbamail v1.0.4 information disclosure / MitM vulnerability (CWE-200), legacy, not Shopify
AI / LLM usage
Privacy policy mentions AI systems used for phishing detection in SMS/email and content creation assistance; specific data shared and providers not disclosed
Inherits platform retention: contractual data kept for service duration + statute of limitations; marketing data until objection