Carrefour & sa carte Club Security & Privacy Scorecard
Android
Shopping habits, loyalty activity, and in-app behavior are shared with multiple advertising and analytics companies including AppsFlyer, mParticle, and others. The device can be fingerprinted to track users across apps and services. Network communications are sent with less protection than expected, meaning user data may not be fully protected on public Wi-Fi.
Best for
Carrefour shoppers comfortable with extensive tracking
Avoid if
You want to limit your data shared with advertisers
Findings
- 3 critical
- 3 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- SSL Hostname Verification Disabled
- GitLab Personal Access Token Exposed
- Apigee API Gateway Credentials Exposed
Top privacy issues
- mParticle JavaScript Bridge Exposes User Data
- ContentSquare Session Replay Without Consent
- FingerprintJS Device Fingerprinting Without Consent
Full analysis
Carrefour & sa carte Club
Version: 22.5.0 (Build 1765465299) | Platform: Android | Scanned: 2026-02-11
What This Means for You
Shopping habits, loyalty activity, and in-app behavior are shared with multiple advertising and analytics companies including AppsFlyer, mParticle, and others. The device can be fingerprinted to track users across apps and services. Network communications are sent with less protection than expected, meaning user data may not be fully protected on public Wi-Fi.
Recommendation: Use With Caution
Best For: Carrefour shoppers comfortable with extensive tracking
Avoid If: You want to limit data shared with advertisers
Key Findings
Data Security - 2 findings (1 high, 1 medium)
Network Security - 1 finding (1 critical)
Code Safety - 0 findings
Privacy - 6 findings (1 critical, 2 high, 3 medium)
Privacy Concerns
What Data is Collected
The app collects shopping behavior, loyalty card activity, device identifiers, location data, and in-app interactions. The device is fingerprinted to recognize users across sessions and services.
Third-Party Data Sharing
Data is shared with the following third-party services:
- AppsFlyer - mobile attribution and advertising analytics
- Firebase Analytics - behavioral analytics and event tracking
- ContentSquare - session recording and user experience analytics
- mParticle - cross-channel customer data aggregation
- OneTrack - marketing attribution
- Firebase Cloud Messaging - push notification delivery
- Urban Airship - push notifications and customer engagement
- Rokt - advertising and offer targeting
- OneTrust - consent and privacy management
- FingerprintJS - device fingerprinting
- AppAuth - authentication flows
- Google Maps - mapping and location services
- Apigee - API management
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 40/100 |
| Data Security | 45/100 |
| Network Security | 25/100 |
| Code Safety | 30/100 |
| Data Collection | 50/100 |
| Data Sharing | 45/100 |
| User Control | 55/100 |
Positive Security Features
- No notable positive security practices were identified in this version.
Areas for Improvement
- Network communications are sent with less protection than expected, meaning user data may not be fully protected on public or unsecured networks.
- Data is shared with a large number of advertising and analytics companies, giving users limited control over how it is used once collected.
- Device fingerprinting allows user activity to be tracked beyond this app, across other services and platforms.
About This Analysis
This scorecard is generated from automated static analysis of the app package. Scores reflect the security and privacy practices observed in the analyzed version.
App Details
- App Name: Carrefour & sa carte Club
- Package ID: com.carrefour.fid.android
- Version: 22.5.0 (Build 1765465299)
- Platform: Android
- Scan Date: 2026-02-11
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 38/100 |