Blacklane is a premium on-demand chauffeur and private car service app offering airport transfers, city rides, and hourly bookings in major cities worldwide.
Quick Verdict
Best for: Business travelers booking premium rides
What It Means For You
Ride booking activity, location, and payment information are shared with AppsFlyer, Facebook, Braze, and RudderStack for analytics, attribution, and customer communications. Advertising and tracking features require explicit user consent before activating. Braze data is routed through EU infrastructure, relevant for users in Europe.
Quick Verdict
Best for: Business travelers booking premium rides
What It Means For You
Ride booking activity, location, and payment information are shared with AppsFlyer, Facebook, Braze, and RudderStack for analytics, attribution, and customer communications. Advertising and tracking features require explicit user consent before activating. Braze data is routed through EU infrastructure, relevant for users in Europe.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
4 totalCode Security
4 totalPrivacy
1 totalThird-Party Risk
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.blacklane.iphone.passenger
Version
8.0.1 (Build 36795)
Analysis Date
Apr 14, 2026
Feedback helps us improve our analysis
Strong connection security and a well-implemented sign-in system are undercut by two areas of concern: payment screens that load content remotely without verified navigation controls, and precise location data shared with a marketing platform under a permission prompt that only mentions ride pickups. Three medium-risk findings require awareness before trusting this app with your location and payment details.
Data Security - 1 finding (1 low)
Network Security - 2 findings (2 medium)
Code Safety - 3 findings (3 low)
Privacy - 3 findings (1 medium, 2 low)
The following third parties may receive your data:
Security: 93/100
Privacy: 91/100
The app's privacy practices could be strengthened by:
Accurate Location Permission Disclosure
The location permission prompt says your location is used for Blacklane pickups. It does not disclose that your precise GPS coordinates are also sent to Braze for marketing analytics. Users deserve a complete picture before granting location access.
Background Location Use Transparency
Background location collection is active even when the app is not open. This should be clearly explained to users in the permission request, including which third parties receive that background location data.
Advertising Tracking Scope
AppsFlyer links your device identity to your account for advertising purposes across Chinese-region servers in addition to standard domains. This scope could be disclosed more prominently in the privacy policy.
Payment Screen Content Controls
The payment result screens (confirmation, error, cancel, pending) load their display content from an external content delivery server. Industry best practice recommends restricting the payment overlay so it cannot navigate away from that specific server, and serving content with a strict policy that limits what scripts can run.
Remove Development Testing Artifacts
A testing stub compiled into the production app contains code that, under specific conditions, would send authentication data to an unencrypted local address and print session information to the device console. This code should be excluded from production builds.
Remove Dormant Staging Domain
A decommissioned test domain is still listed as a trusted source in the production app's signed configuration. If that domain were ever re-registered by a third party, it could be used to route users to unexpected destinations. It should be removed from the production configuration.
App Type: Premium transportation and ride booking (iOS)
Third-Party Services: 32 identified
Context Tags: transportation, location, payment, financial, ads, social
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.
Developer: Blacklane
Version: 8.0.1 (Build 36795)
Analysis Date: 2026-04-14
Package: com.blacklane.iphone.passenger
Developer not yet contacted