Picnic Online Supermarket Security & Privacy Scorecard
Android
Shopping habits and in-app activity are monitored by several analytics services, including Adjust, Braze, and Snowplow, to personalise the experience. Data is not sold or passed to outside advertisers. Account and payment information stored on-device may not be fully protected for users who save payment details.
Best for
Grocery shoppers who want ad-free delivery
Avoid if
Users who save payment cards in the app
Findings
- 1 critical
- 4 high
- 6 medium
- 1 low
- 10 info
1 issue identified across security and privacy analysis.
Top security issues
- Authentication Tokens Stored in Unencrypted SharedPreferences
- Android Backup Enabled Without Restrictions
- Insecure SSL/TLS Configuration in RNFetchBlob Library
Top privacy issues
- Pre-Consent SDK Initialization via ContentProviders
- Default-True Consent Logic
- Advertising ID Collection
Full analysis
Picnic Online Supermarket
Overall Security Score: 56/100 | Privacy Score: 82/100
What This Means for You
Shopping habits and in-app activity are monitored by several analytics services, including Adjust, Braze, and Snowplow, to personalise the experience. Data is not sold or passed to outside advertisers. Account and payment information stored on-device may not be fully protected for users who save payment details.
Recommendation: Use With Caution
Best For: Grocery shoppers who want ad-free delivery
Avoid If: Users who save payment cards in the app
Key Findings
Data Security - 4 findings (1 critical, 2 high, 1 info)
Network Security - 3 findings (1 high, 1 medium, 1 info)
Code Safety - 0 findings
Privacy - 5 findings (1 high, 2 medium, 2 info)
Privacy Concerns
What Data is Collected
The app collects order history, in-app browsing behaviour, device identifiers, and location data to support delivery and personalise the shopping experience.
Third-Party Data Sharing
Activity data is shared with the following third-party services:
- Adjust - Mobile analytics and campaign attribution
- Braze - Customer messaging and push notifications
- Snowplow - Behavioural analytics
- Sentry - Error and crash reporting
- Datadog RUM - Real-time app performance monitoring
- Firebase - App infrastructure and analytics
- VGS Collect - Secure payment data collection
- PayPal - Payment processing
- Google Maps - Delivery address and mapping
- Google ML Kit - On-device feature processing
Understanding the Scores
| Category | Score |
|---|---|
| Security | 56/100 |
| Privacy | 82/100 |
| Data Security | 57/100 |
| Network Security | 88/100 |
| Code Safety | 95/100 |
| Data Collection | 82/100 |
| Data Sharing | 100/100 |
| User Control | 87/100 |
Positive Security Features
- Data is not passed to advertising networks or ad-targeting platforms, keeping purchase behaviour away from ad brokers.
- Code safety practices score 95/100, reflecting well-structured and consistently maintained app code.
- Payment handling is routed through dedicated, specialised payment services rather than processed directly inside the app.
Areas for Improvement
- Payment card details saved in the app may not be fully protected on the device. Storing a payment card in the app carries additional risk if the device is ever compromised.
- Some connections the app makes could use stronger protections to keep data secure while it travels between the device and the server.
- Behavioural and activity data is shared across several analytics platforms. Giving users more direct control over this sharing would improve transparency and the ability to manage personal data.
About This Analysis
This scorecard is generated from automated static analysis of the app's code and data handling practices. Findings reflect the app as released at the version noted below.
App Details
- App: Picnic Online Supermarket
- Package: com.picnic.android
- Version: 1.227.0 (build 15474)
- Platform: Android
- Analysis Date: 13 March 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 69/100 |