Audit report
Aiva Pop‑ups, Slide‑ins & Bars
TrustedReach : limitedby Aiva Labs Inc · Store design · Shopify App Store
Free Targeted Pop ups. Easiest Design Tool to Boost Conversion
Key insights
- ◆App listing now operated by Bevy Commerce (was Aiva Labs Inc); 'Built for Shopify' badge present.
- ◆Data stored in US and Canada per privacy policy; no EU residency option declared.
- ◆No documented security breaches or CVEs found for Aiva Labs or Bevy Commerce.
- ◆Privacy policy covers GDPR rights for EEA residents but does not claim SOC2, ISO27001, PCI DSS, or HIPAA certification.
Top findings
Analysis summary
Free Targeted Pop ups. Easiest Design Tool to Boost Conversion
- ◆App listing now operated by Bevy Commerce (was Aiva Labs Inc); 'Built for Shopify' badge present.
- ◆Data stored in US and Canada per privacy policy; no EU residency option declared.
- ◆No documented security breaches or CVEs found for Aiva Labs or Bevy Commerce.
- ◆Privacy policy covers GDPR rights for EEA residents but does not claim SOC2, ISO27001, PCI DSS, or HIPAA certification.
- ◆Listing does not disclose OAuth scopes pre-install; functional scope (pop-up rendering, theme integration) likely requires theme/script-tag and customer/email scopes.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
undisclosed | Medium | Scopes are not published on the listing page; pop-up apps typically request read_themes/write_themes or script_tags plus read_customers/write_customers for email capture, which is medium-sensitivity. |
undisclosedScopes are not published on the listing page; pop-up apps typically request read_themes/write_themes or script_tags plus read_customers/write_customers for email capture, which is medium-sensitivity.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- bevycommerce.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
Cloudflare-fronted, Heroku origin; no HSTS or CSP headers returned on root HEAD; HTTP/2 negotiated.
Compliance & certifications
Policy enumerates GDPR rights for EEA residents (Section 8). No SOC2/ISO27001/PCI DSS/HIPAA certifications claimed. Data stored in US and Canada.
Privacy policyPublisher reputation
- Publisher
- Aiva Labs Inc
- Verified Shopify Partner
- Yes
- Years active
- 0
- Other apps
- 0