Starship
starship / search / facebook-product-catalog

Audit report

Flexify: Facebook Product Feed

Broad accessReach : limited

by Flexify · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Sync your store with your Facebook Product Catalog

Key insights

  • Built for Shopify certified app, active since 2015 with 4.0/5 rating (145 reviews)
  • Swiss publisher (Bottighofen, Switzerland), Cloudflare-fronted infrastructure
  • Scope of data handling is moderate: product catalog, collections, store identifiers, owner email
  • Sub-processors limited to Google Analytics and Facebook (expected given the app's purpose)

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Sync your store with your Facebook Product Catalog

Key insights
  • Built for Shopify certified app, active since 2015 with 4.0/5 rating (145 reviews)
  • Swiss publisher (Bottighofen, Switzerland), Cloudflare-fronted infrastructure
  • Scope of data handling is moderate: product catalog, collections, store identifiers, owner email
  • Sub-processors limited to Google Analytics and Facebook (expected given the app's purpose)
  • No known security incidents, breaches, or CVEs found in public sources
  • Privacy policy is brief and lacks specifics on retention, SCCs, and data residency controls

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to sync product catalog to Facebook/Meta, core function

read_product_listings
Low

Required to read collections and product listings for segmentation

read_collection_listings
Low

Required for collection-based product segments

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
flexify.net
TLS grade
unknown
HSTS
Missing
CSP
Missing

Domain fronted by Cloudflare; HSTS and CSP headers not present on root HTML response. NEL/Report-To configured.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy acknowledges European resident rights (access, correct, delete) but no formal GDPR/SOC2/ISO27001/PCI/HIPAA certification claimed. Mentions transfers outside Europe without specifying SCCs.

Privacy policy
Track record

Publisher reputation

Publisher
Flexify
Verified Shopify Partner
Yes
Years active
11
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.