Audit report
Spreadr App ‑ Amazon Importer
Broad accessReach : moderateSensitive Accessby Thalia · Finding and adding products · Shopify App Store
Dropship Amazon products or earn affiliate commissions.
Key insights
- ◆Built for Shopify badge holder with strong rating (4.6/231 reviews) and active product (Cloudflare-fronted infra).
- ◆Privacy documentation is thin: no data residency, no named sub-processors, no SOC2/ISO27001/GDPR claims.
- ◆Scopes include write access to themes/scripts and 60-day order data, broader than the 'product import' core function.
- ◆No public CVEs, breaches, or security incidents found for Thalia or Spreadr.
Top findings
Analysis summary
Dropship Amazon products or earn affiliate commissions.
- ◆Built for Shopify badge holder with strong rating (4.6/231 reviews) and active product (Cloudflare-fronted infra).
- ◆Privacy documentation is thin: no data residency, no named sub-processors, no SOC2/ISO27001/GDPR claims.
- ◆Scopes include write access to themes/scripts and 60-day order data, broader than the 'product import' core function.
- ◆No public CVEs, breaches, or security incidents found for Thalia or Spreadr.
- ◆Third-party safety report (protective.ai) did not flag cloud/infra risks.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products / write_products | Medium | Core function: import and sync Amazon products into the Shopify catalog. |
read_orders | High | 60-day order history access exposes customer PII; required for affiliate commission attribution. |
read_themes / write_themes (Online Store scripts) | High | Storefront code modification capability creates injection risk if app or its supply chain is compromised. |
read_locales / geolocation | Low | Used for multi-language and geo-localization features. |
read_shop / store owner info | Low | Standard merchant identification and billing. |
read_products / write_productsCore function: import and sync Amazon products into the Shopify catalog.
read_orders60-day order history access exposes customer PII; required for affiliate commission attribution.
read_themes / write_themes (Online Store scripts)Storefront code modification capability creates injection risk if app or its supply chain is compromised.
read_locales / geolocationUsed for multi-language and geo-localization features.
read_shop / store owner infoStandard merchant identification and billing.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- spreadr.co
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
Cloudflare-fronted HTTPS. Session and XSRF cookies set with Secure, HttpOnly (session), SameSite=None, Partitioned. No HSTS or CSP header observed on root response.
Compliance & certifications
Privacy agreement exists but contains no explicit GDPR/SOC2/ISO27001/PCI claims, no residency, no named sub-processors. Generic retention clause ('as long as necessary').
Privacy policyPublisher reputation
- Publisher
- Thalia
- Verified Shopify Partner
- Yes
- Years active
- 10
- Other apps
- 0