Starship
starship / search / candyrack

Audit report

Candy Rack – Upsells & Bundles

TrustedReach : broadSensitive Access

by Digismoothie · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

One click upsell, product upsell, bundle upsell & gift wrap 🎅

Key insights

  • Built for Shopify certified, meets Shopify's elevated quality and security review bar.
  • EU-built infrastructure with data processed in the EU; GDPR-compliant by design.
  • Publisher Digismoothie has no publicly disclosed breaches or CVEs.
  • Strong reputation (4.9/5, 196 reviews) and multi-app portfolio.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

One click upsell, product upsell, bundle upsell & gift wrap 🎅

Key insights
  • Built for Shopify certified, meets Shopify's elevated quality and security review bar.
  • EU-built infrastructure with data processed in the EU; GDPR-compliant by design.
  • Publisher Digismoothie has no publicly disclosed breaches or CVEs.
  • Strong reputation (4.9/5, 196 reviews) and multi-app portfolio.
  • Privacy policy is detailed and discloses sub-processors transparently.
  • TLS healthy on publisher site (HSTS 1y, served by Cloudflare); CSP limited to frame-ancestors.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to render product upsells.

write_products
Medium

May be used to create/manage bundle SKUs; broad write could be misused but consistent with feature set.

read_orders
Medium

Needed for post-purchase upsell attribution; includes customer PII.

write_orders
High

Likely used for post-purchase order modification/upsell additions.

read_customers
High

Customer names, emails, addresses are referenced in app listing data-access disclosure.

read_discounts
Low

Used to apply/coordinate bundle discounts.

write_discounts
Medium

May create discount codes tied to upsell offers.

read_themes
Low

Theme extension integration for slide-out cart and offer placement.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
digismoothie.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 enabled; Cloudflare-fronted with X-Frame-Options SAMEORIGIN and CSP limited to frame-ancestors 'self' (no full content CSP).

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR + CCPA referenced. EU data processing. Standard 3-year post-contract retention; 15 years for legal defense. No SOC2/ISO27001 advertised.

Privacy policy
Track record

Publisher reputation

Publisher
Digismoothie
Verified Shopify Partner
Yes
Years active
8
Other apps
5
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Product and order signals likely used for AI-powered upsell recommendations; specific LLM providers not disclosed in privacy policy.

Retention policy

Not explicitly disclosed for AI training; general policy retains data for contract term + 3 years.