Starship
starship / search / acumbamail

Audit report

Acumbamail

Broad accessReach : moderateSensitive Access

by Acumbamail · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Improve your shop with automated email marketing

Key insights

  • Spanish (EU) email marketing SaaS based in Ciudad Real, Spain; data residency is primarily EU
  • Shopify app is brand-new: 0 reviews, no Built for Shopify badge
  • Privacy policy is detailed, GDPR-aligned, lists DPO (Audisec/GlobalSuite) and TeamSystem group sub-processors
  • Publisher domain serves HTTPS with HSTS but lacks CSP

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Improve your shop with automated email marketing

Key insights
  • Spanish (EU) email marketing SaaS based in Ciudad Real, Spain; data residency is primarily EU
  • Shopify app is brand-new: 0 reviews, no Built for Shopify badge
  • Privacy policy is detailed, GDPR-aligned, lists DPO (Audisec/GlobalSuite) and TeamSystem group sub-processors
  • Publisher domain serves HTTPS with HSTS but lacks CSP
  • Mentions 'AI-based functionalities' (phishing detection, content assist) without naming specific LLM providers
  • Historical WordPress plugin CVE exists for the publisher, no Shopify-specific incidents found
  • Categories: Email marketing, Pop-ups, typical scope expectation: read_customers, read_products (not explicitly declared on listing page)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Email marketing requires customer email/profile data; typical scope for this category (not explicitly declared on listing)

read_products
Low

Required to sync product catalog into email templates per app description

read_orders
High

Likely needed for transactional/abandoned-cart email triggers per category norms

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
acumbamail.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HTTPS clean with HSTS (max-age=31536000) and X-Frame-Options SAMEORIGIN; no Content-Security-Policy header observed

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR-aligned (EU-based), ENS certification badge displayed, EU-US Data Privacy Framework for transfers; no SOC2/ISO27001/PCI DSS claimed

Privacy policy
Track record

Publisher reputation

Publisher
Acumbamail
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
  • WordPress plugin Acumbamail v1.0.4 information disclosure / MitM vulnerability (CWE-200), legacy, not Shopify
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Privacy policy mentions AI systems used for phishing detection in SMS/email and content creation assistance; specific data shared and providers not disclosed

Retention policy

Inherits platform retention: contractual data kept for service duration + statute of limitations; marketing data until objection