Starship
starship / search / also-bought-1

Audit report

Also Bought Cross Sell

Broad accessReach : broadSensitive Access

by Arctic Grey, Ltd. · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Also Bought just like you see on Amazon.

Key insights

  • Publisher Arctic Grey Ltd is a NYC-based Shopify agency; arcticgrey.com is itself a Shopify-hosted storefront with HSTS, X-Frame-Options DENY, and a basic CSP, reasonable hygiene.
  • App self-describes as LLM + collaborative filtering, but the privacy policy is the agency's generic merchant policy with zero AI/LLM disclosure, a notable gap.
  • Scopes requested span customer PII, store content (write), and order history, moderate sensitivity, no high-risk write_orders/write_customers/write_payment_terms surfaced.
  • No public CVEs, breaches, or incidents found for Arctic Grey or the Also Bought app.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Also Bought just like you see on Amazon.

Key insights
  • Publisher Arctic Grey Ltd is a NYC-based Shopify agency; arcticgrey.com is itself a Shopify-hosted storefront with HSTS, X-Frame-Options DENY, and a basic CSP, reasonable hygiene.
  • App self-describes as LLM + collaborative filtering, but the privacy policy is the agency's generic merchant policy with zero AI/LLM disclosure, a notable gap.
  • Scopes requested span customer PII, store content (write), and order history, moderate sensitivity, no high-risk write_orders/write_customers/write_payment_terms surfaced.
  • No public CVEs, breaches, or incidents found for Arctic Grey or the Also Bought app.
  • Single 5-star review since 2018 indicates very low install base; reputational signal is weak in both directions.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer names and emails enable behavior-based recommendations but are PII subject to GDPR/CCPA.

read_orders
High

Order history feeds the collaborative filtering model; exposes purchase patterns and order values.

read_products
Low

Product catalog data is largely public; required for recommendation surfaces.

write_themes / write_online_store_content
High

Storefront write access required to inject widgets across PDP/cart/checkout/thank-you, high blast radius if compromised.

read_analytics / read_visitor_data
Medium

IP address and geolocation collection for behavioral signals, PII under GDPR.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
arcticgrey.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

Publisher site is Shopify-hosted with HSTS (max-age ~7.9M), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, X-XSS-Protection, and a minimal CSP (block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests). App backend was not separately measured.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Policy references GDPR/CCPA rights but no audited certifications are claimed. Retention is open-ended.

Privacy policy
Track record

Publisher reputation

Publisher
Arctic Grey, Ltd.
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Customer signals (orders, products viewed, basic identifiers) fed into LLM-augmented collaborative filtering for recommendations; specific LLM provider and data-sharing terms not disclosed.

Retention policy

Not specified for AI/LLM pipeline; general policy retains data indefinitely until user erasure request.