Starship
starship / search / fakturoid-invoices

Audit report

Send invoices to Fakturoid.cz

TrustedReach : moderateSensitive Access

by Josef Rousek · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Trusted
Executive summary

Simplify your wire transfer workflow

Key insights

  • Built for Shopify badge holder, established 2017, 5.0 rating with 44 reviews.
  • Publisher Digismoothie is a Czech company with multiple Shopify apps; no known breaches or CVEs found.
  • Invoicing integration handles order/customer PII for EU stores; data routed through hosted environments (Heroku, AWS, Hetzner).
  • Privacy policy is detailed and GDPR/CCPA compliant; publisher website serves valid TLS with HSTS via Cloudflare.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Simplify your wire transfer workflow

Key insights
  • Built for Shopify badge holder, established 2017, 5.0 rating with 44 reviews.
  • Publisher Digismoothie is a Czech company with multiple Shopify apps; no known breaches or CVEs found.
  • Invoicing integration handles order/customer PII for EU stores; data routed through hosted environments (Heroku, AWS, Hetzner).
  • Privacy policy is detailed and GDPR/CCPA compliant; publisher website serves valid TLS with HSTS via Cloudflare.
  • No AI/LLM usage disclosed; no write_* on storefront/theme is implied by product description (read order/customer + send invoice document).
  • Note: listing publisher shown as 'Digismoothie' on storefront page; metadata records publisher as 'Josef Rousek' (likely founder/developer of record).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to fetch order data for invoice generation; includes PII and financial info.

read_customers
High

Required to populate customer billing details on invoices; PII exposure.

read_products
Medium

Likely needed for line-item details and tax/VAT classification on invoices.

read_shop
Low

Standard scope for store metadata (currency, locale).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
digismoothie.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000; CSP only restricts frame-ancestors (no full content-security-policy directive); served via Cloudflare with HTTP/2 and h3.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR and CCPA explicitly referenced; no SOC2/ISO27001/PCI DSS/HIPAA certifications mentioned. EU data residency posture stated with caveat for partner facilities.

Privacy policy
Track record

Publisher reputation

Publisher
Josef Rousek
Verified Shopify Partner
Yes
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.