Audit report
shipcloud Connector
Broad accessReach : broadSensitive Accessby shipcloud Connector · Orders and shipping · Shopify App Store
Print shipping labels directly from your orders
Key insights
- ◆Publisher shipcloud GmbH is an established German shipping aggregator (founded 2015, Hamburg-based) operating in the EU under GDPR jurisdiction.
- ◆Privacy policy is thorough and explicit about retention windows and sub-processors, but no SOC2/ISO27001/PCI certifications are claimed publicly.
- ◆No CVEs or breach reports were found tying shipcloud directly to a security incident.
- ◆Listing does not carry the 'Built for Shopify' badge.
Top findings
Analysis summary
Print shipping labels directly from your orders
- ◆Publisher shipcloud GmbH is an established German shipping aggregator (founded 2015, Hamburg-based) operating in the EU under GDPR jurisdiction.
- ◆Privacy policy is thorough and explicit about retention windows and sub-processors, but no SOC2/ISO27001/PCI certifications are claimed publicly.
- ◆No CVEs or breach reports were found tying shipcloud directly to a security incident.
- ◆Listing does not carry the 'Built for Shopify' badge.
- ◆Publisher primary domain redirects shipcloud.io -> shipcloud.com; both serve over HTTPS but lack HSTS and CSP.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to generate shipping labels for orders. |
write_orders | High | Likely needed to update order tags / metadata on fulfillment. |
read_fulfillments | Medium | Tracking management. |
write_fulfillments | High | Creating and updating fulfillments / tracking numbers. |
read_customers | High | Customer name / address required for shipping labels. |
read_shipping | Medium | Shipping zones and rates. |
read_ordersRequired to generate shipping labels for orders.
write_ordersLikely needed to update order tags / metadata on fulfillment.
read_fulfillmentsTracking management.
write_fulfillmentsCreating and updating fulfillments / tracking numbers.
read_customersCustomer name / address required for shipping labels.
read_shippingShipping zones and rates.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shipcloud.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS works cleanly with HTTP/2; nginx sets X-Content-Type-Options and X-XSS-Protection but no HSTS, no CSP. shipcloud.io 301-redirects to shipcloud.com.
Compliance & certifications
German publisher subject to GDPR; privacy notice is detailed with retention periods (server logs 10 days, accounting 10 years, analytics 14 months). No SOC2/ISO27001/PCI certifications are publicly claimed.
Privacy policyPublisher reputation
- Publisher
- shipcloud Connector
- Verified Shopify Partner
- No
- Years active
- 11
- Other apps
- 0