Audit report
OrderlyEmails
WatchReach : moderateby FORSBERG+two · Store design · Shopify App Store
Email templates that match your store design, and sell more
Key insights
- ◆Real historical incident in March 2026 where the app's update bug irreversibly deleted Shopify store collections
- ◆App accesses broad PII (customer name/email/phone/address/geo/IP) plus store data (products, orders 60-day, marketing events, analytics, files, locations)
- ◆Publisher is hosted in US and Denmark (EU); GDPR compliance claimed
- ◆No AI/LLM usage declared in privacy policy
Top findingsview all
- HighIncorrect Collection Deletions Incident (March 2026)
Analysis summary
Email templates that match your store design, and sell more
- ◆Real historical incident in March 2026 where the app's update bug irreversibly deleted Shopify store collections
- ◆App accesses broad PII (customer name/email/phone/address/geo/IP) plus store data (products, orders 60-day, marketing events, analytics, files, locations)
- ◆Publisher is hosted in US and Denmark (EU); GDPR compliance claimed
- ◆No AI/LLM usage declared in privacy policy
- ◆Publisher domain has clean TLS (Cloudflare), HSTS enabled, CSP enabled
- ◆No 'Built for Shopify' badge
- ◆App launched 2016 (~10 years in market)
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Customer PII access (name, email, phone, address, geo, IP) |
read_orders | High | Order history last 60 days for transactional email content |
read_products | Medium | Products/collections for template content |
write_products | High | Inferred from March 2026 incident where the app deleted collections - implies write/delete on product taxonomy |
read_marketing_events | Medium | Marketing events for email triggers |
read_reports | Medium | Store analytics reports |
read_files | Low | Files for template imagery |
read_locations | Low | Locations for templates |
read_customersCustomer PII access (name, email, phone, address, geo, IP)
read_ordersOrder history last 60 days for transactional email content
read_productsProducts/collections for template content
write_productsInferred from March 2026 incident where the app deleted collections - implies write/delete on product taxonomy
read_marketing_eventsMarketing events for email triggers
read_reportsStore analytics reports
read_filesFiles for template imagery
read_locationsLocations for templates
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- forsbergplustwo.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS max-age ~91 days, CSP includes frame-ancestors none and upgrade-insecure-requests; served via Cloudflare with Shopify origin (GCP europe-west1)
Compliance & certifications
GDPR mentioned with adequate-protection language for EU-US transfers; no SOC2/ISO/PCI/HIPAA claims. Data retention: product data 30 days, analytics 60 days, archived copies retained for legitimate business purposes.
Privacy policyPublisher reputation
- Publisher
- FORSBERG+two
- Verified Shopify Partner
- No
- Years active
- 10
- Other apps
- 0
- ●March 2026 collection deletion incident (irreversible data loss for subset of users)