Audit report
ShipHero Inventory & Shipping
Broad accessReach : broadSensitive Accessby ShipHero · Inventory management · Shopify App Store
The complete inventory, order management and shipping solution
Key insights
- ◆Built for Shopify badge present; rating 4.5/5 with 99 reviews; launched February 14, 2014 (12+ years on the App Store).
- ◆Privacy policy is detailed and discloses sub-processors including AWS and Anthropic.
- ◆Primary domain shiphero.com is on Cloudflare with valid TLS, HSTS (max-age=31536000; includeSubDomains; preload).
- ◆ShipHero runs a public Bug Bounty Program, positive vulnerability disclosure signal.
Top findingsview all
- HighBroad write scopes (customers, products, orders)
Analysis summary
The complete inventory, order management and shipping solution
- ◆Built for Shopify badge present; rating 4.5/5 with 99 reviews; launched February 14, 2014 (12+ years on the App Store).
- ◆Privacy policy is detailed and discloses sub-processors including AWS and Anthropic.
- ◆Primary domain shiphero.com is on Cloudflare with valid TLS, HSTS (max-age=31536000; includeSubDomains; preload).
- ◆ShipHero runs a public Bug Bounty Program, positive vulnerability disclosure signal.
- ◆No publicly reported breach or CVE attributable to ShipHero found in web searches.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
write_customers | High | Edit customers, PII access required to sync recipient details to warehouse/shipping labels. |
write_products | High | Edit products, inventory, collections, publications, core WMS function to push inventory levels back to Shopify. |
write_orders | High | Edit orders, fulfillments, order edits, shipping info, required for a fulfillment/3PL platform. |
read_locations | Low | View locations, needed to route inventory to correct warehouse/store location. |
write_customersEdit customers, PII access required to sync recipient details to warehouse/shipping labels.
write_productsEdit products, inventory, collections, publications, core WMS function to push inventory levels back to Shopify.
write_ordersEdit orders, fulfillments, order edits, shipping info, required for a fulfillment/3PL platform.
read_locationsView locations, needed to route inventory to correct warehouse/store location.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shiphero.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS present with 1-year max-age + includeSubDomains + preload. Only frame-ancestors CSP directive set; no script-src/default-src restrictions on marketing site.
Compliance & certifications
Policy explicitly addresses GDPR, CCPA, PIPEDA, Quebec Law 25. SOC2/ISO27001/PCI DSS/HIPAA not named in the audited privacy policy document.
Privacy policyPublisher reputation
- Publisher
- ShipHero
- Verified Shopify Partner
- Yes
- Years active
- 12
- Other apps
- 0
AI / LLM usage
Customer support chat content sent to Anthropic Claude API for AI Help Bot responses; vendor contractually does not train on customer data.
12 months for AI Help Bot conversations