Starship
starship / search / buzzsubs

Audit report

FREE pop up

Broad accessReach : limited

by TK Digital Ltd · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Pop up 4 FREE. Interactive Exit Intent pop up. Gamified popup

Key insights

  • Built for Shopify badge present, has passed Shopify's elevated quality + security review.
  • App scope is email-capture popups; no payment, no PII beyond email/IP/geo of shoppers, low intrinsic data sensitivity.
  • Vendor is a small Polish/Estonian operator (Warsaw / Estonia compliance language), limits enterprise assurance signals.
  • Privacy policy hosted on Cloudflare Pages free-tier subdomain rather than tk-digital.com, suggesting a lightweight infra footprint.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Pop up 4 FREE. Interactive Exit Intent pop up. Gamified popup

Key insights
  • Built for Shopify badge present, has passed Shopify's elevated quality + security review.
  • App scope is email-capture popups; no payment, no PII beyond email/IP/geo of shoppers, low intrinsic data sensitivity.
  • Vendor is a small Polish/Estonian operator (Warsaw / Estonia compliance language), limits enterprise assurance signals.
  • Privacy policy hosted on Cloudflare Pages free-tier subdomain rather than tk-digital.com, suggesting a lightweight infra footprint.
  • No public breaches, CVEs, or incidents attributed to TK Digital or BuzzSubs found via search.
  • One user-review claim of unauthorized script/URL injection, worth merchant monitoring post-install.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

unknown
Info

App listing page did not surface granular OAuth scope list; typical scopes for an email-popup app include read_themes/write_themes (script tag or theme app extension), read_customers/write_customers or read_discounts/write_discounts. Cannot confirm without installing or vendor disclosure.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
tk-digital.pages.dev
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted (HTTP/2, modern TLS), referrer-policy strict-origin-when-cross-origin and x-content-type-options nosniff present, but no HSTS and no CSP headers observed on root response. Adequate for a static marketing site, sub-optimal for security-conscious vendors.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR, CCPA, LGPD and Estonian DP law referenced; no SOC2/ISO27001/PCI DSS. Retention: inactive visitors purged after 12 months; analytics purged within 12 months; customer data while subscription active.

Privacy policy
Track record

Publisher reputation

Publisher
TK Digital Ltd
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.