Starship
starship / search / amazon-to-shopify

Audit report

Spreadr App ‑ Amazon Importer

Broad accessReach : moderateSensitive Access

by Thalia · Finding and adding products · Shopify App Store

Finding and adding products
Risk level
Broad access
Executive summary

Dropship Amazon products or earn affiliate commissions.

Key insights

  • Built for Shopify badge holder with strong rating (4.6/231 reviews) and active product (Cloudflare-fronted infra).
  • Privacy documentation is thin: no data residency, no named sub-processors, no SOC2/ISO27001/GDPR claims.
  • Scopes include write access to themes/scripts and 60-day order data, broader than the 'product import' core function.
  • No public CVEs, breaches, or security incidents found for Thalia or Spreadr.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Dropship Amazon products or earn affiliate commissions.

Key insights
  • Built for Shopify badge holder with strong rating (4.6/231 reviews) and active product (Cloudflare-fronted infra).
  • Privacy documentation is thin: no data residency, no named sub-processors, no SOC2/ISO27001/GDPR claims.
  • Scopes include write access to themes/scripts and 60-day order data, broader than the 'product import' core function.
  • No public CVEs, breaches, or security incidents found for Thalia or Spreadr.
  • Third-party safety report (protective.ai) did not flag cloud/infra risks.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products / write_products
Medium

Core function: import and sync Amazon products into the Shopify catalog.

read_orders
High

60-day order history access exposes customer PII; required for affiliate commission attribution.

read_themes / write_themes (Online Store scripts)
High

Storefront code modification capability creates injection risk if app or its supply chain is compromised.

read_locales / geolocation
Low

Used for multi-language and geo-localization features.

read_shop / store owner info
Low

Standard merchant identification and billing.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
spreadr.co
TLS grade
unknown
HSTS
Missing
CSP
Missing

Cloudflare-fronted HTTPS. Session and XSRF cookies set with Secure, HttpOnly (session), SameSite=None, Partitioned. No HSTS or CSP header observed on root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy agreement exists but contains no explicit GDPR/SOC2/ISO27001/PCI claims, no residency, no named sub-processors. Generic retention clause ('as long as necessary').

Privacy policy
Track record

Publisher reputation

Publisher
Thalia
Verified Shopify Partner
Yes
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.