Audit report
Bundles
TrustedReach : moderateSensitive Accessby Gazebo · Sales and conversion optimization · Shopify App Store
The easiest way to keep inventory in sync when selling bundles
Key insights
- ◆Built for Shopify badge holder with a 9+ year track record (since March 2016) and strong reviews (4.9/5 across 306 reviews).
- ◆No public CVEs, breaches, or security incidents tied to Gazebo or Bundles.app found in WebSearch coverage.
- ◆Core function is inventory sync for bundles, limited customer-PII surface; product/inventory data dominates.
- ◆Sub-processors disclosed: Shopify, Postmarkapp (email), Papertrail (logs), Fastmail. Reasonable, mainstream stack.
Top findings
Analysis summary
The easiest way to keep inventory in sync when selling bundles
- ◆Built for Shopify badge holder with a 9+ year track record (since March 2016) and strong reviews (4.9/5 across 306 reviews).
- ◆No public CVEs, breaches, or security incidents tied to Gazebo or Bundles.app found in WebSearch coverage.
- ◆Core function is inventory sync for bundles, limited customer-PII surface; product/inventory data dominates.
- ◆Sub-processors disclosed: Shopify, Postmarkapp (email), Papertrail (logs), Fastmail. Reasonable, mainstream stack.
- ◆Publisher domain TLS works but lacks HSTS/CSP/security headers, minor hygiene gap.
- ◆Privacy policy not refreshed since 2018; documentation hygiene is the main risk signal.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to read product catalog for bundle composition. Standard for bundle apps. |
write_products | Medium | Bundle apps typically create/update product variants representing the bundle SKU. Necessary for core feature. |
read_inventory | Low | Required to read current stock levels for components. |
write_inventory | Medium | Core inventory sync feature decrements component stock when bundle sells. Justified by use case. |
read_orders | Medium | Needed to observe order events and trigger inventory adjustments. |
read_locations | Low | Multi-location inventory tracking is a core feature. |
read_productsRequired to read product catalog for bundle composition. Standard for bundle apps.
write_productsBundle apps typically create/update product variants representing the bundle SKU. Necessary for core feature.
read_inventoryRequired to read current stock levels for components.
write_inventoryCore inventory sync feature decrements component stock when bundle sells. Justified by use case.
read_ordersNeeded to observe order events and trigger inventory adjustments.
read_locationsMulti-location inventory tracking is a core feature.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- bundles.app
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
TLS is enforced (HTTP/2, secure cookies) but Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers are all absent from the homepage response.
Compliance & certifications
No compliance certifications disclosed. Privacy policy last updated 11-04-2018. Publisher based in Ermelo, Netherlands (EU jurisdiction) but data residency not stated.
Privacy policyPublisher reputation
- Publisher
- Gazebo
- Verified Shopify Partner
- Yes
- Years active
- 10
- Other apps
- 0