Audit report
Notifications
Broad accessReach : broadSensitive Accessby eShopAdmin Inc. · Store design · Shopify App Store
Send messages to anyone, anywhere, anytime
Key insights
- ◆Small Canadian publisher (eShopAdmin Inc.) operating a single Shopify app focused on event-driven email/notification automation.
- ◆Privacy policy explicitly limits data retention of resulting/event data to 2 weeks, which is a positive signal.
- ◆Data is hosted/transferred to Canada and the United States; no EU residency option disclosed.
- ◆No public CVEs, no public breach disclosures, no news of security incidents associated with publisher.
Top findings
Analysis summary
Send messages to anyone, anywhere, anytime
- ◆Small Canadian publisher (eShopAdmin Inc.) operating a single Shopify app focused on event-driven email/notification automation.
- ◆Privacy policy explicitly limits data retention of resulting/event data to 2 weeks, which is a positive signal.
- ◆Data is hosted/transferred to Canada and the United States; no EU residency option disclosed.
- ◆No public CVEs, no public breach disclosures, no news of security incidents associated with publisher.
- ◆No mention of AI/LLM use in the app or privacy policy.
- ◆Publisher root domain eshopadmin.com is served via GitHub Pages (static) while the product runs on a self-managed nginx host at notifications.eshopadmin.com.
- ◆OAuth scopes are not listed on the App Store landing page extracted, so scope sensitivity cannot be fully evaluated; per category (Staff notifications) the app plausibly needs read access to orders/customers/products and write access for tags/notes.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Likely required to trigger notifications on order events; orders include PII and financial context. |
read_customers | High | Likely required to address emails to customers and include customer attributes; customer data is PII subject to GDPR/CCPA. |
read_products | Medium | Likely required to enrich notifications with product details; low-sensitivity catalog data. |
write_orders | High | Inferred from feature set 'add tags and trigger actions'; write access to orders enables tag/note mutation and historically flagged by a merchant as broader than needed. |
read_ordersLikely required to trigger notifications on order events; orders include PII and financial context.
read_customersLikely required to address emails to customers and include customer attributes; customer data is PII subject to GDPR/CCPA.
read_productsLikely required to enrich notifications with product details; low-sensitivity catalog data.
write_ordersInferred from feature set 'add tags and trigger actions'; write access to orders enables tag/note mutation and historically flagged by a merchant as broader than needed.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- notifications.eshopadmin.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS served via nginx/1.18.0 (Ubuntu); session cookie is HttpOnly; no HSTS or CSP headers observed; redirects HTTP root to /install over HTTPS.
Compliance & certifications
Privacy policy exists and discloses cross-border transfers to CA/US and a 2-week retention of resulting data. No formal certifications or framework attestations named.
Privacy policyPublisher reputation
- Publisher
- eShopAdmin Inc.
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0