Audit report
Gift Registry ‑ Share Registry
Broad accessReach : broadSensitive Accessby AAAeCommerce Inc · Sales and conversion optimization · Shopify App Store
Create & Share Gift Registry for Wedding, Birthday & Event
Key insights
- ◆Small wishlist/gift-registry app, 4.4 rating with only 22 reviews, limited install base signal
- ◆Publisher AAAeCommerce Inc is India-based (Indore) with cross-border processing to Canada/US
- ◆Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
- ◆No 'Built for Shopify' badge
Top findings
Analysis summary
Create & Share Gift Registry for Wedding, Birthday & Event
- ◆Small wishlist/gift-registry app, 4.4 rating with only 22 reviews, limited install base signal
- ◆Publisher AAAeCommerce Inc is India-based (Indore) with cross-border processing to Canada/US
- ◆Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
- ◆No 'Built for Shopify' badge
- ◆No known CVEs or public breaches for AAAeCommerce Inc
- ◆Publisher marketing site runs on outdated PHP 7.4 on Hostinger/LiteSpeed
- ◆No mention of LLM/AI usage in privacy policy
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Required to associate registries with customer accounts; PII access |
read_products | Low | Required to populate registry with catalog items |
read_orders | High | Required for duplicate-purchase prevention; exposes purchase data |
write_themes | High | Typical for storefront wishlist apps to inject registry UI; theme write access is sensitive |
read_customersRequired to associate registries with customer accounts; PII access
read_productsRequired to populate registry with catalog items
read_ordersRequired for duplicate-purchase prevention; exposes purchase data
write_themesTypical for storefront wishlist apps to inject registry UI; theme write access is sensitive
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- aaaecommerce.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Enabled
CSP present but minimal (upgrade-insecure-requests only); no HSTS; server reveals PHP 7.4 EOL
Compliance & certifications
GDPR mentioned for EEA residents. PCI DSS and HIPAA explicitly disclaimed. No SOC2/ISO27001 claims.
Privacy policyPublisher reputation
- Publisher
- AAAeCommerce Inc
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0