Scan results

    Williams Sonoma

    Android

    Find everything you love about Williams Sonoma in one convenient place — from shopping to building your dream wedding registry, exclusive recipes, inspiration and more. Download today!

    CITT SCORE
    60
    out of 100
    TRUSTish

    Quick Verdict

    Best for: Williams Sonoma shoppers comfortable with broad marketing

    What It Means For You

    Browsing, purchase activity, and registry choices are shared with multiple marketing and analytics companies, including Adobe Audience Manager and Tealium, to build an advertising profile. User behavior is tracked across sessions by Quantum Metric and Salesforce Marketing Cloud. Users have limited control over what data is collected or how long it is retained.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (26)

    Data Security

    8 total
    1 Medium
    3 Low
    4 Info

    Network Security

    5 total
    1 Medium
    1 Low
    3 Info

    Code Security

    6 total
    2 High
    2 Medium
    1 Low
    1 Info

    Privacy

    3 total
    2 High
    1 Medium

    Third-Party Risk

    3 total
    1 Low
    2 Info

    Permission Usage

    1 total
    1 Medium

    Third-Party Services

    Salesforce Marketing Cloud, Quantum Metric, Tealium, Adobe Audience Manager, PingOne Signals, Akamai BotMan, Braintree, Firebase Crashlytics, Firebase Remote Config, Firebase Cloud Messaging, Firebase Performance, Scandit, ExoPlayer / Media3, Coil, Constructor.io, Bing Maps

    Security Strengths

    • Certificate pinning on all five WSI domains with SHA-256 hashes
    • Cleartext traffic globally blocked (no HTTP in production)
    • Password encrypted with AES-256-GCM backed by Android KeyStore with biometric authentication
    • Backup disabled — no cloud data exposure risk
    • WebView SSL errors correctly cancelled, debugging disabled
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    retail
    shopping
    sensitive data
    location
    ads
    payment

    Package

    com.ws.giftregistry

    Version

    15.18.5 (versionCode: 15180505)

    Analysis Date

    Feb 17, 2026

    Classes Analyzed

    26,023

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 8 findings (1 medium, 3 low, 4 info)

    Network Security - 5 findings (1 medium, 1 low, 3 info)

    Code Safety - 0 findings

    Privacy - 3 findings (2 high, 1 medium)

    Privacy Concerns

    What Data is Collected

    The app collects browsing behavior, purchase history, gift registry selections, and device identifiers. This information is routed into multiple analytics and marketing platforms that build profiles of shopping habits and preferences over time.

    Third-Party Data Sharing

    User activity is shared with the following third parties:

    • Salesforce Marketing Cloud - email marketing and customer engagement targeting
    • Quantum Metric - session replay and behavioral analytics
    • Tealium - data management and audience orchestration
    • Adobe Audience Manager - advertising audience profiling
    • PingOne Signals - identity and fraud detection signals
    • Akamai BotMan - bot and traffic protection
    • Braintree - payment processing
    • Firebase Crashlytics - crash and error reporting
    • Firebase Remote Config - remote app configuration
    • Firebase Cloud Messaging - push notifications
    • Firebase Performance - performance monitoring
    • Constructor.io - product search and discovery analytics
    • Bing Maps - mapping and location services

    Understanding the Scores

    CategoryScore
    Security68/100
    Privacy52/100
    Data Security78/100
    Network Security82/100
    Code Safety72/100
    Data Collection48/100
    Data Sharing55/100
    User Control45/100

    Positive Security Features

    • Braintree handles payment card data through a reputable third-party processor, keeping financial details separate from the app's own systems
    • Akamai BotMan provides protection against automated attacks on login and checkout flows
    • Firebase services (Crashlytics, Performance) are well-established platforms with a strong operational security record

    Areas for Improvement

    • Shopping behavior and registry activity are distributed across more than a dozen third-party companies, several of which use that data for advertising purposes well beyond Williams Sonoma's direct control.
    • There are no clear in-app options to limit behavioral tracking or advertising profiling, leaving users with little practical say over how their data is used after collection.
    • Data retention periods are not disclosed within the app, making it difficult to know how long activity history is kept or which third parties continue to hold access to it.

    About This Analysis

    This scorecard is generated through automated static analysis of the app's code and configuration. Scores reflect security and privacy practices identified at the time of the scan and may change across app versions.

    App Details

    FieldValue
    Package IDcom.ws.giftregistry
    Version15.18.5 (build 15180505)
    PlatformAndroid
    Scan Date2026-02-17

    Right of Reply

    Developer not yet contacted