Starship
starship / search / bundles

Audit report

Bundles

TrustedReach : moderateSensitive Access

by Gazebo · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Trusted
Executive summary

The easiest way to keep inventory in sync when selling bundles

Key insights

  • Built for Shopify badge holder with a 9+ year track record (since March 2016) and strong reviews (4.9/5 across 306 reviews).
  • No public CVEs, breaches, or security incidents tied to Gazebo or Bundles.app found in WebSearch coverage.
  • Core function is inventory sync for bundles, limited customer-PII surface; product/inventory data dominates.
  • Sub-processors disclosed: Shopify, Postmarkapp (email), Papertrail (logs), Fastmail. Reasonable, mainstream stack.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

The easiest way to keep inventory in sync when selling bundles

Key insights
  • Built for Shopify badge holder with a 9+ year track record (since March 2016) and strong reviews (4.9/5 across 306 reviews).
  • No public CVEs, breaches, or security incidents tied to Gazebo or Bundles.app found in WebSearch coverage.
  • Core function is inventory sync for bundles, limited customer-PII surface; product/inventory data dominates.
  • Sub-processors disclosed: Shopify, Postmarkapp (email), Papertrail (logs), Fastmail. Reasonable, mainstream stack.
  • Publisher domain TLS works but lacks HSTS/CSP/security headers, minor hygiene gap.
  • Privacy policy not refreshed since 2018; documentation hygiene is the main risk signal.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to read product catalog for bundle composition. Standard for bundle apps.

write_products
Medium

Bundle apps typically create/update product variants representing the bundle SKU. Necessary for core feature.

read_inventory
Low

Required to read current stock levels for components.

write_inventory
Medium

Core inventory sync feature decrements component stock when bundle sells. Justified by use case.

read_orders
Medium

Needed to observe order events and trigger inventory adjustments.

read_locations
Low

Multi-location inventory tracking is a core feature.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
bundles.app
TLS grade
unknown
HSTS
Missing
CSP
Missing

TLS is enforced (HTTP/2, secure cookies) but Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers are all absent from the homepage response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No compliance certifications disclosed. Privacy policy last updated 11-04-2018. Publisher based in Ermelo, Netherlands (EU jurisdiction) but data residency not stated.

Privacy policy
Track record

Publisher reputation

Publisher
Gazebo
Verified Shopify Partner
Yes
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.