Starship
starship / search / aiva-labs

Audit report

Aiva Pop‑ups, Slide‑ins & Bars

TrustedReach : limited

by Aiva Labs Inc · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

Free Targeted Pop ups. Easiest Design Tool to Boost Conversion

Key insights

  • App listing now operated by Bevy Commerce (was Aiva Labs Inc); 'Built for Shopify' badge present.
  • Data stored in US and Canada per privacy policy; no EU residency option declared.
  • No documented security breaches or CVEs found for Aiva Labs or Bevy Commerce.
  • Privacy policy covers GDPR rights for EEA residents but does not claim SOC2, ISO27001, PCI DSS, or HIPAA certification.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Free Targeted Pop ups. Easiest Design Tool to Boost Conversion

Key insights
  • App listing now operated by Bevy Commerce (was Aiva Labs Inc); 'Built for Shopify' badge present.
  • Data stored in US and Canada per privacy policy; no EU residency option declared.
  • No documented security breaches or CVEs found for Aiva Labs or Bevy Commerce.
  • Privacy policy covers GDPR rights for EEA residents but does not claim SOC2, ISO27001, PCI DSS, or HIPAA certification.
  • Listing does not disclose OAuth scopes pre-install; functional scope (pop-up rendering, theme integration) likely requires theme/script-tag and customer/email scopes.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

undisclosed
Medium

Scopes are not published on the listing page; pop-up apps typically request read_themes/write_themes or script_tags plus read_customers/write_customers for email capture, which is medium-sensitivity.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
bevycommerce.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

Cloudflare-fronted, Heroku origin; no HSTS or CSP headers returned on root HEAD; HTTP/2 negotiated.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Policy enumerates GDPR rights for EEA residents (Section 8). No SOC2/ISO27001/PCI DSS/HIPAA certifications claimed. Data stored in US and Canada.

Privacy policy
Track record

Publisher reputation

Publisher
Aiva Labs Inc
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.