Audit report
Campaignified
Broad accessReach : moderateSensitive Accessby Lucid · Marketing · Shopify App Store
Sync detailed customer and order data to Campaign Monitor
Key insights
- ◆Bridge app: Shopify <-> Campaign Monitor for email marketing list sync of opted-in customers
- ◆Solo developer publisher (Kelsey Judson, NZ), single app on the store, listed since 2014, no reviews
- ◆Privacy policy exists and is clear about data shared, but light on residency, retention durations, and certifications
- ◆No AI/LLM usage, no PCI/payment data handled
Top findings
Analysis summary
Sync detailed customer and order data to Campaign Monitor
- ◆Bridge app: Shopify <-> Campaign Monitor for email marketing list sync of opted-in customers
- ◆Solo developer publisher (Kelsey Judson, NZ), single app on the store, listed since 2014, no reviews
- ◆Privacy policy exists and is clear about data shared, but light on residency, retention durations, and certifications
- ◆No AI/LLM usage, no PCI/payment data handled
- ◆No publicly known security incidents tied to this app or publisher
- ◆Publisher site on Netlify with HSTS; CSP header not set
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Required to read customer names/emails for syncing to Campaign Monitor; sensitive PII. |
read_orders | High | Used to build order-based custom fields (amounts spent, products ordered, shipping addresses). |
read_products | Medium | Used to enrich subscriber records with product information. |
read_content | Low | Likely used to inject newsletter signup form / theme content. |
read_customersRequired to read customer names/emails for syncing to Campaign Monitor; sensitive PII.
read_ordersUsed to build order-based custom fields (amounts spent, products ordered, shipping addresses).
read_productsUsed to enrich subscriber records with product information.
read_contentLikely used to inject newsletter signup form / theme content.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- kelseyjudson.dev
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Missing
Netlify-hosted; HSTS max-age=31536000 present; no CSP header observed in response.
Compliance & certifications
Privacy policy is published and reasonably clear; no compliance certifications declared. Handles GDPR-relevant PII but no explicit GDPR statement.
Privacy policyPublisher reputation
- Publisher
- Lucid
- Verified Shopify Partner
- No
- Years active
- 12
- Other apps
- 0