Starship
starship / search / ampify-me

Audit report

Ampify Me AMP

Broad accessReach : moderateSensitive Access

by Ampify Me · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

"Amp up" performance and get more customers with Google AMP

Key insights

  • App carries the 'Built for Shopify' badge indicating compliance with Shopify platform standards.
  • Strong rating (4.9/5 from 41 reviews) and long-standing presence (launched May 2018).
  • Primary risk vector: app sends store/brand data to multiple external AI/LLM providers (ChatGPT, Claude, Gemini, Co-Pilot, Perplexity) with no clear disclosure of what data is shared or retention controls.
  • Publisher Ampify Pte. Ltd. is a Singapore-based entity; site appears to be hosted on Shopify infrastructure (powered-by: Shopify header).

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

"Amp up" performance and get more customers with Google AMP

Key insights
  • App carries the 'Built for Shopify' badge indicating compliance with Shopify platform standards.
  • Strong rating (4.9/5 from 41 reviews) and long-standing presence (launched May 2018).
  • Primary risk vector: app sends store/brand data to multiple external AI/LLM providers (ChatGPT, Claude, Gemini, Co-Pilot, Perplexity) with no clear disclosure of what data is shared or retention controls.
  • Publisher Ampify Pte. Ltd. is a Singapore-based entity; site appears to be hosted on Shopify infrastructure (powered-by: Shopify header).
  • No CVE history or publicly known security incidents tied to publisher.
  • Privacy policy uses standard SCCs for international transfers but lacks named sub-processors and explicit retention windows.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

Implied by app functionality (visibility tracking), not explicitly confirmed in listing but typical for SEO/optimization apps.

read_products
Low

Explicitly listed: app accesses product and collection data to optimize for AI assistant visibility.

read_customers
High

Implied by access to store owner PII (name, email, phone, address) as disclosed in listing.

read_content
Low

Likely needed to access custom metaobjects mentioned in app description.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
ampifyme.com
TLS grade
unknown
HSTS
Enabled
CSP
Enabled

Publisher domain hosted on Shopify (Cloudflare-fronted). HSTS max-age=7889238 (~91 days, below the recommended 1 year). CSP is minimal, only block-all-mixed-content, frame-ancestors 'none', upgrade-insecure-requests. No script-src or default-src restrictions.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy mentions Standard Contractual Clauses for EEA/UK transfers but no formal certifications (SOC2, ISO27001, PCI-DSS, HIPAA) are listed. GDPR compliance not explicitly claimed.

Privacy policy
Track record

Publisher reputation

Publisher
Ampify Me
Verified Shopify Partner
Yes
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
OpenAI (ChatGPT)Anthropic (Claude)Google (Gemini)Microsoft (Co-Pilot)Perplexity
Data shared with providers

Brand and product information sent to multiple LLM providers via API queries to test AI visibility, no specific data minimization disclosure in privacy policy.

Retention policy

unknown