Starship
starship / search / edrone

Audit report

edrone

WatchReach : broad

by edrone · Reporting · Shopify App Store

Reporting
Risk level
Watch
Executive summary

First eCRM for e-commerce

Key insights

  • EU-headquartered (Krakow, Poland) marketing automation platform with email, SMS, WhatsApp, AI Sales Chat and reviews
  • Requests write access to script tags, web pixels, customers, orders, discounts, gift cards, marketing, metaobjects
  • Shares data with AWS (US), SparkPost (US), EmailLabs (PL), SMS API (PL), FullContact (US enrichment), PayLane (PL)
  • Rating 4.7 / 31 reviews on Shopify App Store

Top findingsview all

  • High
    Broad write access including Online Store script tags and web pixels
Synthesis

Analysis summary

First eCRM for e-commerce

Key insights
  • EU-headquartered (Krakow, Poland) marketing automation platform with email, SMS, WhatsApp, AI Sales Chat and reviews
  • Requests write access to script tags, web pixels, customers, orders, discounts, gift cards, marketing, metaobjects
  • Shares data with AWS (US), SparkPost (US), EmailLabs (PL), SMS API (PL), FullContact (US enrichment), PayLane (PL)
  • Rating 4.7 / 31 reviews on Shopify App Store
  • Privacy policy is detailed but does not list SOC2/ISO27001/PCI DSS certifications
  • No public security breach, CVE, or incident found via web search

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII including name, email, phone, address

write_customers
High

Can modify customer records and browsing behavior data

read_orders
High

All order history including financial details

read_products
Low

Catalog data, low sensitivity

write_discounts
Medium

Can create/modify discount codes, financial impact if abused

write_gift_cards
High

Gift cards are cash equivalents; write access is financially sensitive

write_marketing_events
Medium

Marketing events, expected for marketing automation

write_pixels
High

Web pixels execute JS in customer context; tracking and potential exfiltration surface

write_script_tags
Critical

Script tags inject arbitrary JS into storefront pages; full XSS-equivalent power if vendor compromised

write_metaobjects
Medium

Custom data definitions, structural store data

read_locales
Info

Locale and Markets settings, low sensitivity

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
edrone.me
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS via CloudFront returns 200 OK but root document lacks HSTS and CSP headers.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR alignment implicit (EU operator, detailed privacy policy). No SOC2/ISO27001/PCI DSS/HIPAA certifications listed publicly.

Privacy policy
Track record

Publisher reputation

Publisher
edrone
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Listing markets AI Sales Chat and 'AI-powered' marketing automation; specific LLM providers not disclosed in privacy policy.

Retention policy

Not specified for AI training/inference; general retention is duration of service plus statute-of-limitations period.