Global chauffeur service offering airport transfers, city journeys, and hourly bookings across 60+ countries with professional drivers, premium vehicles, real-time tracking, and 24/7 support.
Quick Verdict
Best for: Frequent travelers comfortable with standard analytics
What It Means For You
Your bookings, location, and usage patterns are shared with AppsFlyer and RudderStack for marketing attribution, and Braze handles CRM messaging via EU servers. Facebook also receives behavioral signals from your in-app activity. Payment data flows through Braintree and Cardinal Commerce for transaction processing.
Quick Verdict
Best for: Frequent travelers comfortable with standard analytics
What It Means For You
Your bookings, location, and usage patterns are shared with AppsFlyer and RudderStack for marketing attribution, and Braze handles CRM messaging via EU servers. Facebook also receives behavioral signals from your in-app activity. Payment data flows through Braintree and Cardinal Commerce for transaction processing.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
1 totalCode Security
3 totalPrivacy
3 totalThird-Party Risk
1 totalPermission Usage
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.blacklane.passenger
Version
8.0.0 (versionCode 17902; Play Store lists 7.21.0 — APK is newer)
Analysis Date
Apr 11, 2026
Classes Analyzed
30,426
Feedback helps us improve our analysis
Embedded service keys in the app create a risk of unauthorized API access, and booking details are shared with advertising platforms. Stored sign-in data is protected with strong encryption. Recommended for business travelers; privacy-conscious users should review data sharing practices.
Data Security - 2 findings (2 info)
Network Security - 1 finding (1 low)
Code Safety - 3 findings (1 medium, 2 info)
Privacy - 5 findings (2 low, 3 info)
The following third parties may receive your data:
Security: 93/100
Privacy: 90/100
The app's privacy practices could be strengthened by:
Consent Before Analytics Collection
Session monitoring begins collecting data immediately on app launch, before any consent dialog is presented. Industry best practice recommends deferring collection until the user has given explicit consent.
Booking Data Minimization
Exact pickup and dropoff street addresses and fare amounts are forwarded to an advertising attribution service. Sharing only booking confirmation events, without precise location or financial details, would better protect user privacy.
Service Key Protection
Service keys embedded in the app could be moved to a server-side proxy so they are not accessible from the installed app.
Support Chat Origin Validation
The Intercom support chat component loads web content without verifying the source origin. Adding origin checks would reduce the risk of unauthorized actions if the content delivery service were compromised.
App Type: Premium transportation and booking service handling location and financial data
Classes Analyzed: 30,426
Third-Party Services: 22
Context Tags: financial, location, transport, sensitive_data, third_party_risk
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Blacklane GmbH
Version: 8.0.0 (Build 17902)
Analysis Date: 2026-04-11
Package: com.blacklane.passenger
Developer not yet contacted