Deliveroo: Food & Shopping Security & Privacy Scorecard
Android
Orders, location, and behavior are shared with advertising and analytics companies including Facebook, Google Ads, AppsFlyer, Braze, and mParticle. Payment details pass through multiple processors: Adyen, Stripe, Braintree, Checkout.com, and PayPal. Users are profiled for targeted advertising across platforms based on their food ordering habits.
Best for
Hungry users comfortable with broad data sharing
Avoid if
You limit financial data to one payment provider
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- WebView JavaScript Interface Exposes ViewModel (Remote Code Execution)
- Hardcoded mParticle API Credentials
- Extensive Unencrypted Sensitive Data in SharedPreferences
Top privacy issues
- Analytics SDKs Initialize Before User Consent (GDPR/ePrivacy Violation)
- mParticle Data Aggregation Hub with Hardcoded Credentials
- Excessive User Profiling via Braze Marketing Automation
Full analysis
Deliveroo: Food & Shopping
What This Means for You
Orders, location, and behavior are shared with advertising and analytics companies including Facebook, Google Ads, AppsFlyer, Braze, and mParticle. Payment details pass through multiple processors: Adyen, Stripe, Braintree, Checkout.com, and PayPal. Users are profiled for targeted advertising across platforms based on their food ordering habits.
Recommendation: Use With Caution
Best For: Hungry users comfortable with broad data sharing
Avoid If: Users who limit financial data to one payment provider
Key Findings
Data Security - 6 findings (3 critical, 2 high, 1 medium)
Network Security - 1 finding (1 high)
Code Safety - 0 findings
Privacy - 5 findings (1 critical, 3 high, 1 medium)
Privacy Concerns
What Data is Collected
Deliveroo collects precise location, order history, device identifiers, in-app browsing behavior, and payment information. This data is used across order fulfillment, personalization, and targeted advertising.
Third-Party Data Sharing
Data is shared with a broad range of third-party services:
- Analytics and advertising: mParticle, Braze, AppsFlyer, Facebook SDK, Google Ads, Firebase
- Payment processing: Adyen, Stripe, Braintree, Checkout.com, Google Pay, PayPal
- Performance monitoring: Datadog RUM
- Security: Promon SHIELD
- Consent management: OneTrust
- Commerce: Rokt
Understanding the Scores
- Security: 35/100
- Privacy: 40/100
- Data Security: 30/100
- Network Security: 75/100
- Code Safety: 35/100
- Data Collection: 45/100
- Data Sharing: 40/100
- User Control: 50/100
Positive Security Features
- No positive security practices were identified for this version.
Areas for Improvement
- Payment data flows through five separate processors, multiplying the number of parties that hold financial details.
- Location and behavioral data is shared with multiple advertising platforms, with limited controls over how users are profiled across services.
- Data collection extends well beyond order fulfillment, reaching commerce and advertising partners whose relationship to user orders is indirect.
About This Analysis
App Details
- App: Deliveroo: Food & Shopping
- Package: com.deliveroo.orderapp
- Version: 3.258.0 (53710642)
- Scan Date: 2026-01-23
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 38/100 |