Audit report
Ultimate Special Offers
Broad accessReach : moderateSensitive Accessby Pixel Union · Marketing · Shopify App Store
All your sales, discounts, and promotions in one place.
Key insights
- ◆Established Shopify app under Orbit (formerly Pixel Union), a Canadian publisher with a long-standing Shopify portfolio - rebrand from Pixel Union -> Orbit is documented.
- ◆Carries the Built for Shopify badge, which implies meeting Shopify's app quality and security baseline.
- ◆Privacy policy is reasonably detailed but lacks formal third-party security certifications (no SOC2/ISO27001 attestation referenced).
- ◆Data residency split between Canada and the U.S.; EU customer data transfer is disclosed but specific GDPR transfer mechanisms are not documented.
Top findings
Analysis summary
All your sales, discounts, and promotions in one place.
- ◆Established Shopify app under Orbit (formerly Pixel Union), a Canadian publisher with a long-standing Shopify portfolio - rebrand from Pixel Union -> Orbit is documented.
- ◆Carries the Built for Shopify badge, which implies meeting Shopify's app quality and security baseline.
- ◆Privacy policy is reasonably detailed but lacks formal third-party security certifications (no SOC2/ISO27001 attestation referenced).
- ◆Data residency split between Canada and the U.S.; EU customer data transfer is disclosed but specific GDPR transfer mechanisms are not documented.
- ◆No CVEs, breaches, or security incidents directly attributable to Orbit Apps / Pixel Union / Ultimate Special Offers were found in public sources.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to list products eligible for promotional offers, BOGO, bundles, volume discounts. |
write_products | Medium | Likely needed to attach discount metadata or create promo product variants; write access to catalog increases blast radius if compromised. |
read_orders | Medium | Reads customer order history to evaluate offer conditions and post-purchase upsells; exposes PII. |
write_discounts | High | Creating/modifying discount codes is high-impact: a compromised token could issue arbitrary discounts causing direct revenue loss. |
read_customers | Medium | Customer segmentation for exclusive promotions requires reading customer records (PII). |
read_themes / write_script_tags | High | Storefront promo widgets and upsell UI typically require theme/script injection - script tags execute on storefront pages and can read shopper data. |
read_productsRequired to list products eligible for promotional offers, BOGO, bundles, volume discounts.
write_productsLikely needed to attach discount metadata or create promo product variants; write access to catalog increases blast radius if compromised.
read_ordersReads customer order history to evaluate offer conditions and post-purchase upsells; exposes PII.
write_discountsCreating/modifying discount codes is high-impact: a compromised token could issue arbitrary discounts causing direct revenue loss.
read_customersCustomer segmentation for exclusive promotions requires reading customer records (PII).
read_themes / write_script_tagsStorefront promo widgets and upsell UI typically require theme/script injection - script tags execute on storefront pages and can read shopper data.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- orbitapps.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
HTTP/2 with X-Content-Type-Options: nosniff and X-XSS-Protection set; no Strict-Transport-Security and no Content-Security-Policy headers observed on root. Server: nginx, WordPress-backed (wp-json link rels present).
Compliance & certifications
Privacy policy addresses data handling, retention (60d post-uninstall, 30d for Alliance Pro uploads), and EU->Canada/US transfer disclosure, but cites no formal certifications or audit attestations.
Privacy policyPublisher reputation
- Publisher
- Pixel Union
- Verified Shopify Partner
- Yes
- Years active
- 10
- Other apps
- 0