Starship
starship / search / notifications

Audit report

Notifications

Broad accessReach : broadSensitive Access

by eShopAdmin Inc. · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Send messages to anyone, anywhere, anytime

Key insights

  • Small Canadian publisher (eShopAdmin Inc.) operating a single Shopify app focused on event-driven email/notification automation.
  • Privacy policy explicitly limits data retention of resulting/event data to 2 weeks, which is a positive signal.
  • Data is hosted/transferred to Canada and the United States; no EU residency option disclosed.
  • No public CVEs, no public breach disclosures, no news of security incidents associated with publisher.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Send messages to anyone, anywhere, anytime

Key insights
  • Small Canadian publisher (eShopAdmin Inc.) operating a single Shopify app focused on event-driven email/notification automation.
  • Privacy policy explicitly limits data retention of resulting/event data to 2 weeks, which is a positive signal.
  • Data is hosted/transferred to Canada and the United States; no EU residency option disclosed.
  • No public CVEs, no public breach disclosures, no news of security incidents associated with publisher.
  • No mention of AI/LLM use in the app or privacy policy.
  • Publisher root domain eshopadmin.com is served via GitHub Pages (static) while the product runs on a self-managed nginx host at notifications.eshopadmin.com.
  • OAuth scopes are not listed on the App Store landing page extracted, so scope sensitivity cannot be fully evaluated; per category (Staff notifications) the app plausibly needs read access to orders/customers/products and write access for tags/notes.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Likely required to trigger notifications on order events; orders include PII and financial context.

read_customers
High

Likely required to address emails to customers and include customer attributes; customer data is PII subject to GDPR/CCPA.

read_products
Medium

Likely required to enrich notifications with product details; low-sensitivity catalog data.

write_orders
High

Inferred from feature set 'add tags and trigger actions'; write access to orders enables tag/note mutation and historically flagged by a merchant as broader than needed.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
notifications.eshopadmin.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS served via nginx/1.18.0 (Ubuntu); session cookie is HttpOnly; no HSTS or CSP headers observed; redirects HTTP root to /install over HTTPS.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists and discloses cross-border transfers to CA/US and a 2-week retention of resulting data. No formal certifications or framework attestations named.

Privacy policy
Track record

Publisher reputation

Publisher
eShopAdmin Inc.
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.