Starship
starship / search / adroll-retargeting

Audit report

AdRoll Ads & Retargeting

Broad accessReach : moderateSensitive Access

by AdRoll · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Reach more shoppers with automated Web, Mobile & Social Ads

Key insights

  • Publisher NextRoll (parent of AdRoll) holds SOC2 Type 2 and follows GDPR/CCPA/IAB TCF frameworks.
  • Privacy policy explicitly discloses use of LLMs and AI/ML for ad bidding and chatbots.
  • Primary publisher domain adroll.com serves HTTPS with HSTS (max-age=604800; includeSubDomains; preload) and a frame-ancestors CSP.
  • No confirmed public breach attributed to AdRoll/NextRoll; one historical CVE relates to a WordPress AdRoll for WooCommerce plugin, not the Shopify integration.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Reach more shoppers with automated Web, Mobile & Social Ads

Key insights
  • Publisher NextRoll (parent of AdRoll) holds SOC2 Type 2 and follows GDPR/CCPA/IAB TCF frameworks.
  • Privacy policy explicitly discloses use of LLMs and AI/ML for ad bidding and chatbots.
  • Primary publisher domain adroll.com serves HTTPS with HSTS (max-age=604800; includeSubDomains; preload) and a frame-ancestors CSP.
  • No confirmed public breach attributed to AdRoll/NextRoll; one historical CVE relates to a WordPress AdRoll for WooCommerce plugin, not the Shopify integration.
  • Heavy ad-tech data-sharing model: numerous named sub-processors (LiveRamp, Bombora, Experian, Eyeota, ad exchanges, SSPs).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Inferred for dynamic product ads / catalog ingestion (scope block not exposed on listing page).

read_orders
High

Inferred for conversion tracking and ROAS attribution.

read_customers
High

Inferred for audience segmentation and hashed-email matching to ad networks.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
adroll.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age=604800 includeSubDomains preload; CSP limited to frame-ancestors directive (no script-src/default-src enforced via header at root).

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Fail
PCI DSS Fail

SOC2 Type 2 (Security & Privacy) audited; GDPR + CCPA addressed; IAB TCF participant. ISO27001 / PCI DSS / HIPAA not stated.

Privacy policy
Track record

Publisher reputation

Publisher
AdRoll
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

AI/ML used for ad bidding and chatbot interactions; specific LLM providers not disclosed.

Retention policy

Bidding requests retained 7 days; chatbot data falls under general privacy retention windows.