Audit report
Point of Sale
TrustedReach : broadSensitive Accessby Shopify · Places to sell · Shopify App Store
Sell anywhere. Accept any payment. Grow your business.
Key insights
- ◆First-party Shopify app, deeply integrated with the Shopify platform - inherits Shopify's security posture and PCI scope for in-person payments.
- ◆'Built for Shopify' badge confirms it meets Shopify's highest performance/security/design standards.
- ◆Privacy handled under Shopify's global privacy policy: data residency split between Canada (Shopify Inc.), Ireland (EEA/UK), and Singapore (APAC).
- ◆No first-party Shopify breach confirmed; the 2024 incident attributed to a third-party app, not POS.
Top findings
Analysis summary
Sell anywhere. Accept any payment. Grow your business.
- ◆First-party Shopify app, deeply integrated with the Shopify platform - inherits Shopify's security posture and PCI scope for in-person payments.
- ◆'Built for Shopify' badge confirms it meets Shopify's highest performance/security/design standards.
- ◆Privacy handled under Shopify's global privacy policy: data residency split between Canada (Shopify Inc.), Ireland (EEA/UK), and Singapore (APAC).
- ◆No first-party Shopify breach confirmed; the 2024 incident attributed to a third-party app, not POS.
- ◆Strong network surface on shopify.com: HSTS with preload, HTTPS-only, Cloudflare-fronted.
- ◆AI usage limited to platform-wide ML and Sidekick assistant; not specific to POS app.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | Medium | Required to display and process orders in POS. |
write_orders | High | Required to create/modify orders at checkout. |
read_products | Low | Required to display catalog at POS. |
write_products | Medium | Required for inventory adjustments from POS. |
read_customers | High | Required to look up loyalty/customer profile at POS - includes PII. |
write_customers | High | Required to create/update customer records from POS. |
read_inventory | Medium | Required for multi-location inventory visibility. |
write_inventory | Medium | Required for stock decrement on sale. |
read_locations | Low | Required for multi-location operations. |
read_ordersRequired to display and process orders in POS.
write_ordersRequired to create/modify orders at checkout.
read_productsRequired to display catalog at POS.
write_productsRequired for inventory adjustments from POS.
read_customersRequired to look up loyalty/customer profile at POS - includes PII.
write_customersRequired to create/update customer records from POS.
read_inventoryRequired for multi-location inventory visibility.
write_inventoryRequired for stock decrement on sale.
read_locationsRequired for multi-location operations.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shopify.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS with includeSubDomains and preload; HTTP/2 + HTTP/3 (alt-svc h3); served via Cloudflare. CSP header not visible on /. X-Content-Type-Options: nosniff present.
Compliance & certifications
Compliance posture inherited from Shopify platform: Shopify is publicly known to hold PCI DSS Level 1 (required for handling payments at POS), SOC 2, ISO 27001, and supports GDPR processing roles. Privacy policy describes data subject rights consistent with GDPR/CCPA. Specific certs not enumerated in this privacy doc - readers are pointed to shopify.com/security.
Privacy policyPublisher reputation
- Publisher
- Shopify
- Verified Shopify Partner
- Yes
- Years active
- 20
- Other apps
- 50