Audit report
Care Cart Abandoned Recovery
Broad accessReach : broadSensitive Accessby Care Cart · Sales and conversion optimization · Shopify App Store
Recover Abandon Cart Orders by Sales & Marketing Automation
Key insights
- ◆Established cart-recovery app (launched Oct 2017) with strong rating (4.8/240 reviews) but no Built for Shopify badge.
- ◆Privacy policy is GDPR-aware but light on concrete commitments: no named sub-processors, no specific retention windows, no third-party security attestations.
- ◆Data is stated to be stored in US or EU hosting facilities, while Care Cart apps run on Canadian hosting per the policy, split residency.
- ◆No public CVEs, breaches, or security incidents tied to Care Cart / carecart.io were found in open sources.
Top findings
Analysis summary
Recover Abandon Cart Orders by Sales & Marketing Automation
- ◆Established cart-recovery app (launched Oct 2017) with strong rating (4.8/240 reviews) but no Built for Shopify badge.
- ◆Privacy policy is GDPR-aware but light on concrete commitments: no named sub-processors, no specific retention windows, no third-party security attestations.
- ◆Data is stated to be stored in US or EU hosting facilities, while Care Cart apps run on Canadian hosting per the policy, split residency.
- ◆No public CVEs, breaches, or security incidents tied to Care Cart / carecart.io were found in open sources.
- ◆Scope set (customers, orders, checkouts, themes, price rules) is consistent with the abandoned-cart use case; broadest concern is the breadth of customer PII (IP, geo, browser) collected for marketing.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Customer PII (name, email, address, geo, IP) needed to target recovery emails; high impact on compromise. |
write_customers | High | Implied to update customer marketing-consent/subscriber state; write access to PII is sensitive. |
read_orders | High | 60-day order history used for follow-up campaigns; reveals revenue and buyer behavior. |
read_checkouts | High | Abandoned-checkout data including line items and contact details is core to the product. |
write_checkouts | High | Needed to trigger/modify recovery flows; can influence storefront conversion path. |
read_products | Medium | Product catalog used to render recovery emails/popups. |
read_themes | Medium | Theme read access to inject web-push and on-site widgets. |
write_themes | High | Theme write needed for asset/snippet injection; widely abused vector if compromised. |
read_price_rules | Medium | Discount/spin-wheel feature uses price rules. |
write_price_rules | High | Creating discount codes for recovery campaigns; financial impact if abused. |
read_customersCustomer PII (name, email, address, geo, IP) needed to target recovery emails; high impact on compromise.
write_customersImplied to update customer marketing-consent/subscriber state; write access to PII is sensitive.
read_orders60-day order history used for follow-up campaigns; reveals revenue and buyer behavior.
read_checkoutsAbandoned-checkout data including line items and contact details is core to the product.
write_checkoutsNeeded to trigger/modify recovery flows; can influence storefront conversion path.
read_productsProduct catalog used to render recovery emails/popups.
read_themesTheme read access to inject web-push and on-site widgets.
write_themesTheme write needed for asset/snippet injection; widely abused vector if compromised.
read_price_rulesDiscount/spin-wheel feature uses price rules.
write_price_rulesCreating discount codes for recovery campaigns; financial impact if abused.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- carecart.io
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Missing
HSTS enabled (max-age=31536000; includeSubDomains). No CSP header observed on landing page. Server discloses PHP 8.2.29 via X-Powered-By and exposes WordPress wp-json endpoint.
Compliance & certifications
Only GDPR explicitly referenced. Payment data not stored by Care Cart (handled by Shopify). No SOC 2 / ISO 27001 / PCI DSS / HIPAA attestations disclosed publicly.
Privacy policyPublisher reputation
- Publisher
- Care Cart
- Verified Shopify Partner
- No
- Years active
- 9
- Other apps
- 7