Starship
starship / search / buy-button

Audit report

Buy Button channel

TrustedReach : broadSensitive Access

by Shopify · Places to sell · Shopify App Store

First-partyPlaces to sell
Risk level
Trusted
Executive summary

Sell products on any website or blog, or share checkout links

Key insights

  • First-party app published by Shopify itself - inherits Shopify's enterprise security posture (HSTS preload, Cloudflare, dedicated security team, public bug bounty).
  • Built for Shopify badge present, indicating compliance with Shopify's quality and security standards.
  • Data is governed by Shopify's global privacy policy with residency in Canada, Ireland, and Singapore; cross-border transfers use SCCs.
  • No CVEs or breaches attributed to the Buy Button channel app itself; ecosystem incidents trace to unrelated third-party apps.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Sell products on any website or blog, or share checkout links

Key insights
  • First-party app published by Shopify itself - inherits Shopify's enterprise security posture (HSTS preload, Cloudflare, dedicated security team, public bug bounty).
  • Built for Shopify badge present, indicating compliance with Shopify's quality and security standards.
  • Data is governed by Shopify's global privacy policy with residency in Canada, Ireland, and Singapore; cross-border transfers use SCCs.
  • No CVEs or breaches attributed to the Buy Button channel app itself; ecosystem incidents trace to unrelated third-party apps.
  • Shopify operates a public HackerOne bug bounty (since 2013) covering this product surface.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Access to customer name, email, phone, physical address, geolocation - sensitive PII.

write_customers
High

Ability to edit customer records; write access raises blast radius if compromised.

read_products
Low

Required to surface products in embedded buy buttons.

write_products
Medium

Product editing; sensitive but necessary for product management within the channel.

write_checkouts
High

Modifies the online store checkout flow - critical path for revenue and PCI scope.

read_users
Medium

Store owner / staff data access.

write_resource_feedbacks
Low

Channel feedback mechanism, low blast radius.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shopify.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS with includeSubDomains and preload (max-age=15552000); Cloudflare-fronted; x-content-type-options: nosniff present. No CSP header on the marketing root.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Pass
PCI DSS Pass

Shopify is a publicly traded enterprise (NYSE: SHOP) with documented compliance programs (GDPR controller/processor, SOC 2 Type II, ISO 27001, PCI DSS Level 1 for payment processing). Privacy policy delegates certification disclosure to shopify.com/security.

Privacy policy
Track record

Publisher reputation

Publisher
Shopify
Verified Shopify Partner
Yes
Years active
20
Other apps
20
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.