Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The webhook example persists user-linked revenue events using app_user_id together with product, price, currency, and timestamp, creating a behavioral purchase history tied to an individual identifier. Without any mention of webhook signature verification, minimization, retention limits, or disclosure to users, this pattern can lead to unnecessary exposure of potentially identifiable financial telemetry and increases privacy/compliance risk if the database is accessed or reused improperly.
