Starship
starship / search / advanced-registration

Audit report

Advanced Registration

Broad accessReach : broadSensitive Access

by Talon Commerce · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Customize registry, approval, customer fields, & shop locks

Key insights

  • App collects sensitive identity / business documents (VAT, tax IDs, licenses) before purchase approval
  • 4.8 stars / 43 reviews indicate small but well-rated install base; no Built for Shopify badge
  • Publisher Talon Commerce hosts in US/Canada via Cloudflare; TLS valid (grade A)
  • Privacy policy is short and lacks named sub-processors and certifications

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Customize registry, approval, customer fields, & shop locks

Key insights
  • App collects sensitive identity / business documents (VAT, tax IDs, licenses) before purchase approval
  • 4.8 stars / 43 reviews indicate small but well-rated install base; no Built for Shopify badge
  • Publisher Talon Commerce hosts in US/Canada via Cloudflare; TLS valid (grade A)
  • Privacy policy is short and lacks named sub-processors and certifications
  • No public CVE, breach, or incident history found for Talon Commerce or this app

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Inferred, app gates customer access and collects PII at registration

write_customers
High

Inferred, must create/update customer records with custom approval status and metafields

write_customer_tags
Medium

Inferred, approval workflows commonly tag customers (approved/pending/rejected)

read_themes
Low

Inferred, likely required to inject registration form on storefront

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
taloncommerce.com
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted HTTPS responds 200; no HSTS or CSP headers observed on root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not claim any certification, name sub-processors, or describe a specific retention window beyond 'as long as necessary'.

Privacy policy
Track record

Publisher reputation

Publisher
Talon Commerce
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.