Deliveroo: Food & Shopping Security & Privacy Scorecard

Android

38
Overall trust score
Unsafe
35
Security
40
Privacy

Orders, location, and behavior are shared with advertising and analytics companies including Facebook, Google Ads, AppsFlyer, Braze, and mParticle. Payment details pass through multiple processors: Adyen, Stripe, Braintree, Checkout.com, and PayPal. Users are profiled for targeted advertising across platforms based on their food ordering habits.

Best for

Hungry users comfortable with broad data sharing

Avoid if

You limit financial data to one payment provider

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • WebView JavaScript Interface Exposes ViewModel (Remote Code Execution)
  • Hardcoded mParticle API Credentials
  • Extensive Unencrypted Sensitive Data in SharedPreferences

Top privacy issues

  • Analytics SDKs Initialize Before User Consent (GDPR/ePrivacy Violation)
  • mParticle Data Aggregation Hub with Hardcoded Credentials
  • Excessive User Profiling via Braze Marketing Automation

Full analysis

Deliveroo: Food & Shopping

What This Means for You

Orders, location, and behavior are shared with advertising and analytics companies including Facebook, Google Ads, AppsFlyer, Braze, and mParticle. Payment details pass through multiple processors: Adyen, Stripe, Braintree, Checkout.com, and PayPal. Users are profiled for targeted advertising across platforms based on their food ordering habits.

Recommendation: Use With Caution

Best For: Hungry users comfortable with broad data sharing

Avoid If: Users who limit financial data to one payment provider

Key Findings

Data Security - 6 findings (3 critical, 2 high, 1 medium)

Network Security - 1 finding (1 high)

Code Safety - 0 findings

Privacy - 5 findings (1 critical, 3 high, 1 medium)

Privacy Concerns

What Data is Collected

Deliveroo collects precise location, order history, device identifiers, in-app browsing behavior, and payment information. This data is used across order fulfillment, personalization, and targeted advertising.

Third-Party Data Sharing

Data is shared with a broad range of third-party services:

  • Analytics and advertising: mParticle, Braze, AppsFlyer, Facebook SDK, Google Ads, Firebase
  • Payment processing: Adyen, Stripe, Braintree, Checkout.com, Google Pay, PayPal
  • Performance monitoring: Datadog RUM
  • Security: Promon SHIELD
  • Consent management: OneTrust
  • Commerce: Rokt

Understanding the Scores

  • Security: 35/100
  • Privacy: 40/100
  • Data Security: 30/100
  • Network Security: 75/100
  • Code Safety: 35/100
  • Data Collection: 45/100
  • Data Sharing: 40/100
  • User Control: 50/100

Positive Security Features

  • No positive security practices were identified for this version.

Areas for Improvement

  • Payment data flows through five separate processors, multiplying the number of parties that hold financial details.
  • Location and behavioral data is shared with multiple advertising platforms, with limited controls over how users are profiled across services.
  • Data collection extends well beyond order fulfillment, reaching commerce and advertising partners whose relationship to user orders is indirect.

About This Analysis

App Details

  • App: Deliveroo: Food & Shopping
  • Package: com.deliveroo.orderapp
  • Version: 3.258.0 (53710642)
  • Scan Date: 2026-01-23

Versions & scan history

ScanDateOverall score
#1 (current) 38/100