Starship
starship / search / email-templates

Audit report

OrderlyEmails

WatchReach : moderate

by FORSBERG+two · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

Email templates that match your store design, and sell more

Key insights

  • Real historical incident in March 2026 where the app's update bug irreversibly deleted Shopify store collections
  • App accesses broad PII (customer name/email/phone/address/geo/IP) plus store data (products, orders 60-day, marketing events, analytics, files, locations)
  • Publisher is hosted in US and Denmark (EU); GDPR compliance claimed
  • No AI/LLM usage declared in privacy policy

Top findingsview all

  • High
    Incorrect Collection Deletions Incident (March 2026)
Synthesis

Analysis summary

Email templates that match your store design, and sell more

Key insights
  • Real historical incident in March 2026 where the app's update bug irreversibly deleted Shopify store collections
  • App accesses broad PII (customer name/email/phone/address/geo/IP) plus store data (products, orders 60-day, marketing events, analytics, files, locations)
  • Publisher is hosted in US and Denmark (EU); GDPR compliance claimed
  • No AI/LLM usage declared in privacy policy
  • Publisher domain has clean TLS (Cloudflare), HSTS enabled, CSP enabled
  • No 'Built for Shopify' badge
  • App launched 2016 (~10 years in market)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII access (name, email, phone, address, geo, IP)

read_orders
High

Order history last 60 days for transactional email content

read_products
Medium

Products/collections for template content

write_products
High

Inferred from March 2026 incident where the app deleted collections - implies write/delete on product taxonomy

read_marketing_events
Medium

Marketing events for email triggers

read_reports
Medium

Store analytics reports

read_files
Low

Files for template imagery

read_locations
Low

Locations for templates

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
forsbergplustwo.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age ~91 days, CSP includes frame-ancestors none and upgrade-insecure-requests; served via Cloudflare with Shopify origin (GCP europe-west1)

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR mentioned with adequate-protection language for EU-US transfers; no SOC2/ISO/PCI/HIPAA claims. Data retention: product data 30 days, analytics 60 days, archived copies retained for legitimate business purposes.

Privacy policy
Track record

Publisher reputation

Publisher
FORSBERG+two
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
  • March 2026 collection deletion incident (irreversible data loss for subset of users)
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.