Starship
starship / search / shopify-pos

Audit report

Point of Sale

TrustedReach : broadSensitive Access

by Shopify · Places to sell · Shopify App Store

First-partyPlaces to sell
Risk level
Trusted
Executive summary

Sell anywhere. Accept any payment. Grow your business.

Key insights

  • First-party Shopify app, deeply integrated with the Shopify platform - inherits Shopify's security posture and PCI scope for in-person payments.
  • 'Built for Shopify' badge confirms it meets Shopify's highest performance/security/design standards.
  • Privacy handled under Shopify's global privacy policy: data residency split between Canada (Shopify Inc.), Ireland (EEA/UK), and Singapore (APAC).
  • No first-party Shopify breach confirmed; the 2024 incident attributed to a third-party app, not POS.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Sell anywhere. Accept any payment. Grow your business.

Key insights
  • First-party Shopify app, deeply integrated with the Shopify platform - inherits Shopify's security posture and PCI scope for in-person payments.
  • 'Built for Shopify' badge confirms it meets Shopify's highest performance/security/design standards.
  • Privacy handled under Shopify's global privacy policy: data residency split between Canada (Shopify Inc.), Ireland (EEA/UK), and Singapore (APAC).
  • No first-party Shopify breach confirmed; the 2024 incident attributed to a third-party app, not POS.
  • Strong network surface on shopify.com: HSTS with preload, HTTPS-only, Cloudflare-fronted.
  • AI usage limited to platform-wide ML and Sidekick assistant; not specific to POS app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

Required to display and process orders in POS.

write_orders
High

Required to create/modify orders at checkout.

read_products
Low

Required to display catalog at POS.

write_products
Medium

Required for inventory adjustments from POS.

read_customers
High

Required to look up loyalty/customer profile at POS - includes PII.

write_customers
High

Required to create/update customer records from POS.

read_inventory
Medium

Required for multi-location inventory visibility.

write_inventory
Medium

Required for stock decrement on sale.

read_locations
Low

Required for multi-location operations.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shopify.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS with includeSubDomains and preload; HTTP/2 + HTTP/3 (alt-svc h3); served via Cloudflare. CSP header not visible on /. X-Content-Type-Options: nosniff present.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Pass
PCI DSS Pass

Compliance posture inherited from Shopify platform: Shopify is publicly known to hold PCI DSS Level 1 (required for handling payments at POS), SOC 2, ISO 27001, and supports GDPR processing roles. Privacy policy describes data subject rights consistent with GDPR/CCPA. Specific certs not enumerated in this privacy doc - readers are pointed to shopify.com/security.

Privacy policy
Track record

Publisher reputation

Publisher
Shopify
Verified Shopify Partner
Yes
Years active
20
Other apps
50
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.