Blacklane - Chauffeur Service Security & Privacy Scorecard
Android
Your bookings, location, and usage patterns are shared with AppsFlyer and RudderStack for marketing attribution, and Braze handles CRM messaging via EU servers. Facebook also receives behavioral signals from your in-app activity. Payment data flows through Braintree and Cardinal Commerce for transaction processing.
Best for
Frequent travelers comfortable with standard analytics
Findings
- 0 critical
- 0 high
- 1 medium
- 3 low
- 7 info
1 issue identified across security and privacy analysis.
Top security issues
- Hardcoded OAuth2 Client Secret in Release APK
- Intercom WebView JavaScript Bridge Active Without Origin Validation
- Firebase Realtime Database URL Present — Runtime Rules Unverifiable
Top privacy issues
- Trip Itinerary and Exact Booking Price Forwarded to AppsFlyer Attribution SDK
- Datadog RUM/APM Initialized with Hardcoded Tracking Consent GRANTED
- Analytics SDK Inventory — Five Data Collection Platforms
Full analysis
Blacklane - Chauffeur Service
What This Means for You
Your booking details, including exact pickup and dropoff addresses, travel dates, and fare amounts, are shared with advertising and attribution companies each time you complete a ride.
Recommendation: Use With Caution
Embedded service keys in the app create a risk of unauthorized API access, and booking details are shared with advertising platforms. Stored sign-in data is protected with strong encryption. Recommended for business travelers; privacy-conscious users should review data sharing practices.
Best For: Business travelers who prioritize a polished booking experience and trust Blacklane's security posture
Key Findings
Data Security - 2 findings (2 info)
Network Security - 1 finding (1 low)
Code Safety - 3 findings (1 medium, 2 info)
Privacy - 5 findings (2 low, 3 info)
Privacy Concerns
What Data is Collected
- Personal information: name, email address, account identifier, email verification status
- Location data: precise GPS location, pickup and dropoff addresses
- Booking data: travel dates, fare amounts, payment method, country of travel
- Device information: advertising ID, device type, operating system
- Usage data: app interactions, ride history, in-app support conversations
Third-Party Data Sharing
The following third parties may receive your data:
- RudderStack - customer data platform; receives login and profile events including email domain and account type
- AppsFlyer - advertising attribution; receives booking completion data including pickup and dropoff addresses, fare, and payment method
- Firebase Analytics - usage and event analytics
- Braze - marketing communications (EU data region)
- Datadog - performance and session monitoring; begins collecting data on app launch before consent is shown
- Facebook SDK - advertising and analytics
Understanding the Scores
Security: 93/100
Privacy: 90/100
Security Breakdown
- Data Security: 98/100 - Sign-in and session data are stored with hardware-backed encryption, well above typical app standards
- Network Security: 96/100 - All booking API communication is strongly protected; one third-party support component lacks strict origin checking
- Code Safety: 93/100 - Service keys are embedded in the app, creating a risk of API abuse if extracted
Privacy Breakdown
- Data Collection: 91/100 - Collects location, booking details, and usage patterns across five analytics and marketing platforms
- Data Sharing: 88/100 - Booking itinerary data including exact addresses and fares is forwarded to an advertising attribution service
- User Control: 91/100 - Advertising ID collection respects your device's opt-out setting; data deletion is available on request
Positive Security Features
- Sign-in and session data are encrypted using hardware-backed key storage, preventing extraction even by other apps
- In-app messaging data is stored using strong encryption via Android's security library
- Your device's ad tracking preference is checked and honored before any advertising ID is collected
- Braze marketing data is routed through EU servers in Germany, supporting GDPR compliance
- Signing out removes all locally stored authentication data across all storage locations
- Booking API communications are protected with transport-layer security
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Consent Before Analytics Collection
Session monitoring begins collecting data immediately on app launch, before any consent dialog is presented. Industry best practice recommends deferring collection until the user has given explicit consent.Booking Data Minimization
Exact pickup and dropoff street addresses and fare amounts are forwarded to an advertising attribution service. Sharing only booking confirmation events, without precise location or financial details, would better protect user privacy.
Security Enhancements
Service Key Protection
Service keys embedded in the app could be moved to a server-side proxy so they are not accessible from the installed app.Support Chat Origin Validation
The Intercom support chat component loads web content without verifying the source origin. Adding origin checks would reduce the risk of unauthorized actions if the content delivery service were compromised.
Technical Context
App Type: Premium transportation and booking service handling location and financial data
Classes Analyzed: 30,426
Third-Party Services: 22
Context Tags: financial, location, transport, sensitivedata, thirdparty_risk
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: Blacklane GmbH
Version: 8.0.0 (Build 17902)
Analysis Date: 2026-04-11
Package: com.blacklane.passenger
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 8.0.0 analyzed on 2026-04-11
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 91/100 |