Audit report
Send invoices to Fakturoid.cz
TrustedReach : moderateSensitive Accessby Josef Rousek · Orders and shipping · Shopify App Store
Simplify your wire transfer workflow
Key insights
- ◆Built for Shopify badge holder, established 2017, 5.0 rating with 44 reviews.
- ◆Publisher Digismoothie is a Czech company with multiple Shopify apps; no known breaches or CVEs found.
- ◆Invoicing integration handles order/customer PII for EU stores; data routed through hosted environments (Heroku, AWS, Hetzner).
- ◆Privacy policy is detailed and GDPR/CCPA compliant; publisher website serves valid TLS with HSTS via Cloudflare.
Top findings
Analysis summary
Simplify your wire transfer workflow
- ◆Built for Shopify badge holder, established 2017, 5.0 rating with 44 reviews.
- ◆Publisher Digismoothie is a Czech company with multiple Shopify apps; no known breaches or CVEs found.
- ◆Invoicing integration handles order/customer PII for EU stores; data routed through hosted environments (Heroku, AWS, Hetzner).
- ◆Privacy policy is detailed and GDPR/CCPA compliant; publisher website serves valid TLS with HSTS via Cloudflare.
- ◆No AI/LLM usage disclosed; no write_* on storefront/theme is implied by product description (read order/customer + send invoice document).
- ◆Note: listing publisher shown as 'Digismoothie' on storefront page; metadata records publisher as 'Josef Rousek' (likely founder/developer of record).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to fetch order data for invoice generation; includes PII and financial info. |
read_customers | High | Required to populate customer billing details on invoices; PII exposure. |
read_products | Medium | Likely needed for line-item details and tax/VAT classification on invoices. |
read_shop | Low | Standard scope for store metadata (currency, locale). |
read_ordersRequired to fetch order data for invoice generation; includes PII and financial info.
read_customersRequired to populate customer billing details on invoices; PII exposure.
read_productsLikely needed for line-item details and tax/VAT classification on invoices.
read_shopStandard scope for store metadata (currency, locale).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- digismoothie.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS max-age=31536000; CSP only restricts frame-ancestors (no full content-security-policy directive); served via Cloudflare with HTTP/2 and h3.
Compliance & certifications
GDPR and CCPA explicitly referenced; no SOC2/ISO27001/PCI DSS/HIPAA certifications mentioned. EU data residency posture stated with caveat for partner facilities.
Privacy policyPublisher reputation
- Publisher
- Josef Rousek
- Verified Shopify Partner
- Yes
- Years active
- 9
- Other apps
- 0