Starship
starship / search / affiliate

Audit report

Affiliate by AAAecommerce

Broad accessReach : moderateSensitive Access

by AAAeCommerce Inc · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Affiliate Marketing - Promote Products with your Affiliates

Key insights

  • Affiliate marketing app published by AAAeCommerce Inc, live since February 2018
  • Very low merchant traction: 2.0 stars / 4 reviews
  • Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
  • Data transferred to Canada, United States, and India

Top findingsview all

  • High
    Publisher self-attests non-compliance with PCI DSS and HIPAA
Synthesis

Analysis summary

Affiliate Marketing - Promote Products with your Affiliates

Key insights
  • Affiliate marketing app published by AAAeCommerce Inc, live since February 2018
  • Very low merchant traction: 2.0 stars / 4 reviews
  • Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
  • Data transferred to Canada, United States, and India
  • Publisher infrastructure runs end-of-life PHP 7.4 on LiteSpeed (Hostinger)
  • No HSTS; CSP limited to upgrade-insecure-requests
  • No public CVEs or breach reports found for publisher or app
  • No AI/LLM usage disclosed

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Affiliate apps typically need customer data to attribute referrals and process commissions (scope inferred from category; not explicitly listed on App Store page accessed).

read_orders
High

Required to detect affiliate-attributed orders and calculate commissions per order (inferred from $0.50 per affiliate order pricing model).

write_discounts
High

App offers 'Instagram discount code sharing' and custom commission setup, implying creation/management of discount codes (inferred).

read_products
Medium

Needed to associate affiliate links/commissions with products (inferred).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
aaaecommerce.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTP/2 reachable, HTTPS upgrade enforced via CSP 'upgrade-insecure-requests' but no HSTS header. Server discloses outdated PHP 7.4.33 (EOL Nov 2022) on LiteSpeed/Hostinger.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy explicitly states services are neither HIPAA nor PCI DSS compliant. No SOC2 or ISO27001 attestation mentioned. GDPR not explicitly addressed for cross-border transfers to India.

Privacy policy
Track record

Publisher reputation

Publisher
AAAeCommerce Inc
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.