Audit report
Buy Button channel
TrustedReach : broadSensitive Accessby Shopify · Places to sell · Shopify App Store
Sell products on any website or blog, or share checkout links
Key insights
- ◆First-party app published by Shopify itself - inherits Shopify's enterprise security posture (HSTS preload, Cloudflare, dedicated security team, public bug bounty).
- ◆Built for Shopify badge present, indicating compliance with Shopify's quality and security standards.
- ◆Data is governed by Shopify's global privacy policy with residency in Canada, Ireland, and Singapore; cross-border transfers use SCCs.
- ◆No CVEs or breaches attributed to the Buy Button channel app itself; ecosystem incidents trace to unrelated third-party apps.
Top findings
Analysis summary
Sell products on any website or blog, or share checkout links
- ◆First-party app published by Shopify itself - inherits Shopify's enterprise security posture (HSTS preload, Cloudflare, dedicated security team, public bug bounty).
- ◆Built for Shopify badge present, indicating compliance with Shopify's quality and security standards.
- ◆Data is governed by Shopify's global privacy policy with residency in Canada, Ireland, and Singapore; cross-border transfers use SCCs.
- ◆No CVEs or breaches attributed to the Buy Button channel app itself; ecosystem incidents trace to unrelated third-party apps.
- ◆Shopify operates a public HackerOne bug bounty (since 2013) covering this product surface.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Access to customer name, email, phone, physical address, geolocation - sensitive PII. |
write_customers | High | Ability to edit customer records; write access raises blast radius if compromised. |
read_products | Low | Required to surface products in embedded buy buttons. |
write_products | Medium | Product editing; sensitive but necessary for product management within the channel. |
write_checkouts | High | Modifies the online store checkout flow - critical path for revenue and PCI scope. |
read_users | Medium | Store owner / staff data access. |
write_resource_feedbacks | Low | Channel feedback mechanism, low blast radius. |
read_customersAccess to customer name, email, phone, physical address, geolocation - sensitive PII.
write_customersAbility to edit customer records; write access raises blast radius if compromised.
read_productsRequired to surface products in embedded buy buttons.
write_productsProduct editing; sensitive but necessary for product management within the channel.
write_checkoutsModifies the online store checkout flow - critical path for revenue and PCI scope.
read_usersStore owner / staff data access.
write_resource_feedbacksChannel feedback mechanism, low blast radius.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shopify.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS with includeSubDomains and preload (max-age=15552000); Cloudflare-fronted; x-content-type-options: nosniff present. No CSP header on the marketing root.
Compliance & certifications
Shopify is a publicly traded enterprise (NYSE: SHOP) with documented compliance programs (GDPR controller/processor, SOC 2 Type II, ISO 27001, PCI DSS Level 1 for payment processing). Privacy policy delegates certification disclosure to shopify.com/security.
Privacy policyPublisher reputation
- Publisher
- Shopify
- Verified Shopify Partner
- Yes
- Years active
- 20
- Other apps
- 20