Starship
starship / search / shopify-mobile-apps

Audit report

Tapcart ‑ Mobile App

WatchReach : moderate

by Tapcart Inc. · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Watch
Executive summary

Retain your customers with a beautiful mobile app

Key insights

  • Tapcart is an established Shopify mobile-app builder (launched April 2017, 337 reviews, 4.6 rating) with a broad data surface across orders, customers, inventory and analytics.
  • Publisher domain is Cloudflare-fronted with HSTS enabled; TLS posture is healthy though CSP is minimal.
  • No public CVEs, breach disclosures or incidents tied to Tapcart Inc. were found in open sources.
  • Privacy policy is light on compliance certifications and sub-processor transparency relative to peers of similar scale.

Top findingsview all

  • High
    Broad write-level access to customer PII and commerce surface
Synthesis

Analysis summary

Retain your customers with a beautiful mobile app

Key insights
  • Tapcart is an established Shopify mobile-app builder (launched April 2017, 337 reviews, 4.6 rating) with a broad data surface across orders, customers, inventory and analytics.
  • Publisher domain is Cloudflare-fronted with HSTS enabled; TLS posture is healthy though CSP is minimal.
  • No public CVEs, breach disclosures or incidents tied to Tapcart Inc. were found in open sources.
  • Privacy policy is light on compliance certifications and sub-processor transparency relative to peers of similar scale.
  • App markets itself as AI-powered (Tapcart AI) but does not name LLM providers or describe data-sharing/retention for AI features in its public policy.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers / write_customers
High

Customer PII (name, email, physical address) is explicitly declared; required for personalized mobile shopping but a top exfiltration target.

read_orders / write_orders
High

Full order history including line items and shipping data; expansive PII surface.

read_products / write_products
Medium

Product catalog access needed to render the mobile storefront.

read_inventory / write_inventory
Medium

Inventory updates can affect storefront accuracy and downstream fulfillment.

read_fulfillments / write_fulfillments
Medium

Fulfillment data declared; needed for order tracking in app.

read_discounts / write_discounts
Medium

Discount management in-app; abuse risk if compromised.

read_analytics
Low

Store analytics declared; aggregate data.

read_metaobjects / write_metaobjects
Low

Metaobjects for storefront customization.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
tapcart.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age=31536000; CSP limited to frame-ancestors 'self'; X-Frame-Options SAMEORIGIN; Cloudflare fronted.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No explicit certifications stated in privacy policy. A separate Data Processing Policy is published at tapcart.com/data-processing but was not parsed for this audit.

Privacy policy
Track record

Publisher reputation

Publisher
Tapcart Inc.
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Tapcart markets AI-powered personalization (Tapcart AI) but does not disclose LLM providers or what shopper data is shared with them.

Retention policy

unknown