Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly instructs users to send conversion/order data to ad platforms and operational alerts to external messaging services, but it does not warn that these payloads may contain sensitive business or personal data. In this marketing attribution context, order identifiers, conversion values, CIDs, and alert contents can reveal customer behavior and commercial performance, increasing the risk of privacy leakage, accidental over-sharing, or non-compliant data transfers.
