Audit report
AdRoll Ads & Retargeting
Broad accessReach : moderateSensitive Accessby AdRoll · Marketing · Shopify App Store
Reach more shoppers with automated Web, Mobile & Social Ads
Key insights
- ◆Publisher NextRoll (parent of AdRoll) holds SOC2 Type 2 and follows GDPR/CCPA/IAB TCF frameworks.
- ◆Privacy policy explicitly discloses use of LLMs and AI/ML for ad bidding and chatbots.
- ◆Primary publisher domain adroll.com serves HTTPS with HSTS (max-age=604800; includeSubDomains; preload) and a frame-ancestors CSP.
- ◆No confirmed public breach attributed to AdRoll/NextRoll; one historical CVE relates to a WordPress AdRoll for WooCommerce plugin, not the Shopify integration.
Top findings
Analysis summary
Reach more shoppers with automated Web, Mobile & Social Ads
- ◆Publisher NextRoll (parent of AdRoll) holds SOC2 Type 2 and follows GDPR/CCPA/IAB TCF frameworks.
- ◆Privacy policy explicitly discloses use of LLMs and AI/ML for ad bidding and chatbots.
- ◆Primary publisher domain adroll.com serves HTTPS with HSTS (max-age=604800; includeSubDomains; preload) and a frame-ancestors CSP.
- ◆No confirmed public breach attributed to AdRoll/NextRoll; one historical CVE relates to a WordPress AdRoll for WooCommerce plugin, not the Shopify integration.
- ◆Heavy ad-tech data-sharing model: numerous named sub-processors (LiveRamp, Bombora, Experian, Eyeota, ad exchanges, SSPs).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Inferred for dynamic product ads / catalog ingestion (scope block not exposed on listing page). |
read_orders | High | Inferred for conversion tracking and ROAS attribution. |
read_customers | High | Inferred for audience segmentation and hashed-email matching to ad networks. |
read_productsInferred for dynamic product ads / catalog ingestion (scope block not exposed on listing page).
read_ordersInferred for conversion tracking and ROAS attribution.
read_customersInferred for audience segmentation and hashed-email matching to ad networks.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- adroll.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS max-age=604800 includeSubDomains preload; CSP limited to frame-ancestors directive (no script-src/default-src enforced via header at root).
Compliance & certifications
SOC2 Type 2 (Security & Privacy) audited; GDPR + CCPA addressed; IAB TCF participant. ISO27001 / PCI DSS / HIPAA not stated.
Privacy policyPublisher reputation
- Publisher
- AdRoll
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0
AI / LLM usage
AI/ML used for ad bidding and chatbot interactions; specific LLM providers not disclosed.
Bidding requests retained 7 days; chatbot data falls under general privacy retention windows.