Starship
starship / search / shipway-tracking-notification-and-order-reviews

Audit report

Shipway ‑ Shipment Tracking

Broad accessReach : moderateSensitive Access

by Onjection Labs · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Custom Tracking Page & Shipment notifications - Shipway

Key insights

  • Order tracking app sending shipment notifications via SMS, Email, WhatsApp; handles order/customer PII at scale
  • Publisher Onjection Labs operates shipway.in / experience.shipway.com (Apache 2.4.58 on Ubuntu)
  • Privacy policy is minimal and does not disclose sub-processors or data retention
  • No 'Built for Shopify' badge

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Custom Tracking Page & Shipment notifications - Shipway

Key insights
  • Order tracking app sending shipment notifications via SMS, Email, WhatsApp; handles order/customer PII at scale
  • Publisher Onjection Labs operates shipway.in / experience.shipway.com (Apache 2.4.58 on Ubuntu)
  • Privacy policy is minimal and does not disclose sub-processors or data retention
  • No 'Built for Shopify' badge
  • No public breach or CVE found for Shipway/Onjection Labs

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to track shipments and trigger post-purchase notifications

read_customers
High

Needed to email/SMS/WhatsApp customers with tracking updates

read_fulfillments
Medium

Required for shipment status tracking

write_fulfillments
High

Likely required to update tracking info on fulfillments

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shipway.in
TLS grade
A
HSTS
Missing
CSP
Enabled

CSP header present but only 'upgrade-insecure-requests'; no HSTS; Apache 2.4.58 disclosed via Server header

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but lacks specifics on residency, sub-processors, retention, and formal certifications

Privacy policy
Track record

Publisher reputation

Publisher
Onjection Labs
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.