Audit report
ShippyPro Labels and Tracking
Broad accessReach : broadSensitive Accessby ITALIAN VALLEY SRLS · Orders and shipping · Shopify App Store
Generate all your couriers labels in seconds, track shipments
Key insights
- ◆Publisher Italian Valley SRLS (ShippyPro) is a Florence-based shipping platform with mature compliance posture: GDPR, ISO 27001, SOC 2 Type II claimed.
- ◆Hosting primarily on AWS EMEA (EU residency); Cloudflare fronts the publisher domain with HSTS and CSP frame-ancestors header.
- ◆No public CVEs, breaches, or security incidents found against ShippyPro or Italian Valley SRLS as of search date.
- ◆Privacy policy contains no mention of LLM/AI/ML sub-processors.
Top findings
Analysis summary
Generate all your couriers labels in seconds, track shipments
- ◆Publisher Italian Valley SRLS (ShippyPro) is a Florence-based shipping platform with mature compliance posture: GDPR, ISO 27001, SOC 2 Type II claimed.
- ◆Hosting primarily on AWS EMEA (EU residency); Cloudflare fronts the publisher domain with HSTS and CSP frame-ancestors header.
- ◆No public CVEs, breaches, or security incidents found against ShippyPro or Italian Valley SRLS as of search date.
- ◆Privacy policy contains no mention of LLM/AI/ML sub-processors.
- ◆App Store rating 4.5/74 reviews; no 'Built for Shopify' badge detected.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to fetch order line items, addresses, and fulfillment data for shipping label generation (inferred from app function; not explicitly listed on store page). |
write_orders | High | Required to update fulfillment status and attach tracking numbers (inferred from app function). |
read_customers | High | Required to obtain recipient PII (name/address/phone/email) for carrier manifests (inferred). |
read_fulfillments | Medium | Required for tracking/return workflows (inferred). |
write_fulfillments | High | Required to create/update fulfillments after label creation (inferred). |
read_ordersRequired to fetch order line items, addresses, and fulfillment data for shipping label generation (inferred from app function; not explicitly listed on store page).
write_ordersRequired to update fulfillment status and attach tracking numbers (inferred from app function).
read_customersRequired to obtain recipient PII (name/address/phone/email) for carrier manifests (inferred).
read_fulfillmentsRequired for tracking/return workflows (inferred).
write_fulfillmentsRequired to create/update fulfillments after label creation (inferred).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shippypro.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS max-age=31536000 includeSubDomains; CSP limited to frame-ancestors directive only (no default-src/script-src); X-Frame-Options SAMEORIGIN; Cloudflare-fronted.
Compliance & certifications
Privacy policy explicitly claims GDPR, ISO 27001, and SOC 2 Type II. Retention rules differentiated (general necessity, 30d Amazon customer anonymization, 19mo pseudonymized impersonation logs). No PCI DSS claim; payment handling delegated to Stripe.
Privacy policyPublisher reputation
- Publisher
- ITALIAN VALLEY SRLS
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0