Starship
starship / search / omnisend-email-sms

Audit report

Omnisend Email Marketing & SMS

Broad accessReach : broadSensitive Access

by Omnisend · Email Marketing · Shopify App Store

Built for ShopifyEmail Marketingv5.6.1
Risk level
Broad access
Executive summary

Omnisend est une ESP UE (Lituanie) bien notée. Risque Medium lié à l'étendue inhérente du PII traité, mitigé par GDPR-native, SOC 2 Type II et résidence UE native.

Key insights

  • Email + SMS + push web. Automatisations pré-construites.
  • Risque Medium, broad PII scope, mais posture GDPR-native.
  • Éditeur UE (Vilnius). Built for Shopify.
  • SOC 2 Type II + GDPR. DPA publique.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Omnisend est une ESP UE (Lituanie) bien notée. Risque Medium lié à l'étendue inhérente du PII traité, mitigé par GDPR-native, SOC 2 Type II et résidence UE native.

Key insights
  • Email + SMS + push web. Automatisations pré-construites.
  • Risque Medium, broad PII scope, mais posture GDPR-native.
  • Éditeur UE (Vilnius). Built for Shopify.
  • SOC 2 Type II + GDPR. DPA publique.
  • Plus de 125k installs, note 4,8 sur 5 970 avis.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Segmentation.

write_customers
High

Sync consentement marketing.

read_orders
Medium

Flows post-achat.

read_checkouts
High

Abandon de panier.

read_products
Low

Blocs produits.

write_marketing_events
Medium

Attribution campagnes.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
omnisend.com
TLS grade
A+
HSTS
Enabled
CSP
Enabled

TLS 1.3, HSTS preload, CSP stricte.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Pass
PCI DSS Fail

SOC 2 Type II + ISO 27001 + GDPR. DPA publique. Résidence UE native.

Privacy policy
Track record

Publisher reputation

Publisher
Omnisend
Verified Shopify Partner
Yes
Years active
9
Other apps
1
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
OpenAI
Data shared with providers

Sujets et contenu d'emails générés à partir de briefs marchand. PII exclue.

Retention policy

API OpenAI standard, pas d'entraînement.