Blacklane - Chauffeur Service Security & Privacy Scorecard

Android

91
Overall trust score
Very Secure
93
Security
90
Privacy

Your bookings, location, and usage patterns are shared with AppsFlyer and RudderStack for marketing attribution, and Braze handles CRM messaging via EU servers. Facebook also receives behavioral signals from your in-app activity. Payment data flows through Braintree and Cardinal Commerce for transaction processing.

Best for

Frequent travelers comfortable with standard analytics

Findings

  • 0 critical
  • 0 high
  • 1 medium
  • 3 low
  • 7 info

1 issue identified across security and privacy analysis.

Top security issues

  • Hardcoded OAuth2 Client Secret in Release APK
  • Intercom WebView JavaScript Bridge Active Without Origin Validation
  • Firebase Realtime Database URL Present — Runtime Rules Unverifiable

Top privacy issues

  • Trip Itinerary and Exact Booking Price Forwarded to AppsFlyer Attribution SDK
  • Datadog RUM/APM Initialized with Hardcoded Tracking Consent GRANTED
  • Analytics SDK Inventory — Five Data Collection Platforms

Full analysis

Blacklane - Chauffeur Service

What This Means for You

Your booking details, including exact pickup and dropoff addresses, travel dates, and fare amounts, are shared with advertising and attribution companies each time you complete a ride.

Recommendation: Use With Caution

Embedded service keys in the app create a risk of unauthorized API access, and booking details are shared with advertising platforms. Stored sign-in data is protected with strong encryption. Recommended for business travelers; privacy-conscious users should review data sharing practices.

Best For: Business travelers who prioritize a polished booking experience and trust Blacklane's security posture

Key Findings

Data Security - 2 findings (2 info)

Network Security - 1 finding (1 low)

Code Safety - 3 findings (1 medium, 2 info)

Privacy - 5 findings (2 low, 3 info)

Privacy Concerns

What Data is Collected

  • Personal information: name, email address, account identifier, email verification status
  • Location data: precise GPS location, pickup and dropoff addresses
  • Booking data: travel dates, fare amounts, payment method, country of travel
  • Device information: advertising ID, device type, operating system
  • Usage data: app interactions, ride history, in-app support conversations

Third-Party Data Sharing

The following third parties may receive your data:

  • RudderStack - customer data platform; receives login and profile events including email domain and account type
  • AppsFlyer - advertising attribution; receives booking completion data including pickup and dropoff addresses, fare, and payment method
  • Firebase Analytics - usage and event analytics
  • Braze - marketing communications (EU data region)
  • Datadog - performance and session monitoring; begins collecting data on app launch before consent is shown
  • Facebook SDK - advertising and analytics

Understanding the Scores

Security: 93/100
Privacy: 90/100

Security Breakdown

  • Data Security: 98/100 - Sign-in and session data are stored with hardware-backed encryption, well above typical app standards
  • Network Security: 96/100 - All booking API communication is strongly protected; one third-party support component lacks strict origin checking
  • Code Safety: 93/100 - Service keys are embedded in the app, creating a risk of API abuse if extracted

Privacy Breakdown

  • Data Collection: 91/100 - Collects location, booking details, and usage patterns across five analytics and marketing platforms
  • Data Sharing: 88/100 - Booking itinerary data including exact addresses and fares is forwarded to an advertising attribution service
  • User Control: 91/100 - Advertising ID collection respects your device's opt-out setting; data deletion is available on request

Positive Security Features

  • Sign-in and session data are encrypted using hardware-backed key storage, preventing extraction even by other apps
  • In-app messaging data is stored using strong encryption via Android's security library
  • Your device's ad tracking preference is checked and honored before any advertising ID is collected
  • Braze marketing data is routed through EU servers in Germany, supporting GDPR compliance
  • Signing out removes all locally stored authentication data across all storage locations
  • Booking API communications are protected with transport-layer security

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Consent Before Analytics Collection
    Session monitoring begins collecting data immediately on app launch, before any consent dialog is presented. Industry best practice recommends deferring collection until the user has given explicit consent.

  2. Booking Data Minimization
    Exact pickup and dropoff street addresses and fare amounts are forwarded to an advertising attribution service. Sharing only booking confirmation events, without precise location or financial details, would better protect user privacy.

Security Enhancements

  1. Service Key Protection
    Service keys embedded in the app could be moved to a server-side proxy so they are not accessible from the installed app.

  2. Support Chat Origin Validation
    The Intercom support chat component loads web content without verifying the source origin. Adding origin checks would reduce the risk of unauthorized actions if the content delivery service were compromised.

Technical Context

App Type: Premium transportation and booking service handling location and financial data
Classes Analyzed: 30,426
Third-Party Services: 22
Context Tags: financial, location, transport, sensitivedata, thirdparty_risk


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

App Details

Developer: Blacklane GmbH
Version: 8.0.0 (Build 17902)
Analysis Date: 2026-04-11
Package: com.blacklane.passenger

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 8.0.0 analyzed on 2026-04-11
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#1 (current) 91/100