Audit report
Candy Rack – Upsells & Bundles
TrustedReach : broadSensitive Accessby Digismoothie · Store design · Shopify App Store
One click upsell, product upsell, bundle upsell & gift wrap 🎅
Key insights
- ◆Built for Shopify certified, meets Shopify's elevated quality and security review bar.
- ◆EU-built infrastructure with data processed in the EU; GDPR-compliant by design.
- ◆Publisher Digismoothie has no publicly disclosed breaches or CVEs.
- ◆Strong reputation (4.9/5, 196 reviews) and multi-app portfolio.
Top findings
Analysis summary
One click upsell, product upsell, bundle upsell & gift wrap 🎅
- ◆Built for Shopify certified, meets Shopify's elevated quality and security review bar.
- ◆EU-built infrastructure with data processed in the EU; GDPR-compliant by design.
- ◆Publisher Digismoothie has no publicly disclosed breaches or CVEs.
- ◆Strong reputation (4.9/5, 196 reviews) and multi-app portfolio.
- ◆Privacy policy is detailed and discloses sub-processors transparently.
- ◆TLS healthy on publisher site (HSTS 1y, served by Cloudflare); CSP limited to frame-ancestors.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to render product upsells. |
write_products | Medium | May be used to create/manage bundle SKUs; broad write could be misused but consistent with feature set. |
read_orders | Medium | Needed for post-purchase upsell attribution; includes customer PII. |
write_orders | High | Likely used for post-purchase order modification/upsell additions. |
read_customers | High | Customer names, emails, addresses are referenced in app listing data-access disclosure. |
read_discounts | Low | Used to apply/coordinate bundle discounts. |
write_discounts | Medium | May create discount codes tied to upsell offers. |
read_themes | Low | Theme extension integration for slide-out cart and offer placement. |
read_productsRequired to render product upsells.
write_productsMay be used to create/manage bundle SKUs; broad write could be misused but consistent with feature set.
read_ordersNeeded for post-purchase upsell attribution; includes customer PII.
write_ordersLikely used for post-purchase order modification/upsell additions.
read_customersCustomer names, emails, addresses are referenced in app listing data-access disclosure.
read_discountsUsed to apply/coordinate bundle discounts.
write_discountsMay create discount codes tied to upsell offers.
read_themesTheme extension integration for slide-out cart and offer placement.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- digismoothie.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS max-age=31536000 enabled; Cloudflare-fronted with X-Frame-Options SAMEORIGIN and CSP limited to frame-ancestors 'self' (no full content CSP).
Compliance & certifications
GDPR + CCPA referenced. EU data processing. Standard 3-year post-contract retention; 15 years for legal defense. No SOC2/ISO27001 advertised.
Privacy policyPublisher reputation
- Publisher
- Digismoothie
- Verified Shopify Partner
- Yes
- Years active
- 8
- Other apps
- 5
AI / LLM usage
Product and order signals likely used for AI-powered upsell recommendations; specific LLM providers not disclosed in privacy policy.
Not explicitly disclosed for AI training; general policy retains data for contract term + 3 years.