Starship
starship / search / campaignified

Audit report

Campaignified

Broad accessReach : moderateSensitive Access

by Lucid · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Sync detailed customer and order data to Campaign Monitor

Key insights

  • Bridge app: Shopify <-> Campaign Monitor for email marketing list sync of opted-in customers
  • Solo developer publisher (Kelsey Judson, NZ), single app on the store, listed since 2014, no reviews
  • Privacy policy exists and is clear about data shared, but light on residency, retention durations, and certifications
  • No AI/LLM usage, no PCI/payment data handled

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Sync detailed customer and order data to Campaign Monitor

Key insights
  • Bridge app: Shopify <-> Campaign Monitor for email marketing list sync of opted-in customers
  • Solo developer publisher (Kelsey Judson, NZ), single app on the store, listed since 2014, no reviews
  • Privacy policy exists and is clear about data shared, but light on residency, retention durations, and certifications
  • No AI/LLM usage, no PCI/payment data handled
  • No publicly known security incidents tied to this app or publisher
  • Publisher site on Netlify with HSTS; CSP header not set

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Required to read customer names/emails for syncing to Campaign Monitor; sensitive PII.

read_orders
High

Used to build order-based custom fields (amounts spent, products ordered, shipping addresses).

read_products
Medium

Used to enrich subscriber records with product information.

read_content
Low

Likely used to inject newsletter signup form / theme content.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
kelseyjudson.dev
TLS grade
unknown
HSTS
Enabled
CSP
Missing

Netlify-hosted; HSTS max-age=31536000 present; no CSP header observed in response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy is published and reasonably clear; no compliance certifications declared. Handles GDPR-relevant PII but no explicit GDPR statement.

Privacy policy
Track record

Publisher reputation

Publisher
Lucid
Verified Shopify Partner
No
Years active
12
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.