Scan results

    Picnic Online Supermarket

    Android

    Picnic is the supermarket on wheels delivering groceries directly to your home with always low prices and free home delivery. Download the app to check delivery availability and order your groceries online from local farmers and suppliers.

    CITT SCORE
    69
    out of 100
    TRUSTish

    Quick Verdict

    Best for: Grocery shoppers who want ad-free delivery

    Not For: Users who save payment cards in the app

    What It Means For You

    Shopping habits and in-app activity are monitored by several analytics services, including Adjust, Braze, and Snowplow, to personalise the experience. Data is not sold or passed to outside advertisers. Account and payment information stored on-device may not be fully protected for users who save payment details.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (21)

    Data Security

    4 total
    1 Critical
    2 High
    1 Info

    Network Security

    3 total
    1 High
    1 Medium
    1 Info

    Code Security

    7 total
    3 Medium
    1 Low
    3 Info

    Privacy

    5 total
    1 High
    2 Medium
    2 Info

    Third-Party Risk

    1 total
    1 Info

    Permission Usage

    1 total
    1 Info

    Third-Party Services

    Adjust, Braze, Sentry, Datadog RUM, Snowplow, Firebase, VGS Collect, PayPal, Google Maps, Google ML Kit

    Security Strengths

    • VGS Collect for payment security - PCI-compliant payment handling
    • All production APIs use HTTPS with proper TLS
    • Room database uses parameterized queries preventing SQL injection
    • Consent-gated analytics architecture
    • No advertising display SDKs (AdMob, Facebook Audience Network)
    • Proper file permissions (MODE_PRIVATE) for SharedPreferences and databases
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    location
    ads
    analytics

    Package

    com.picnic.android

    Version

    1.227.0 (versionCode 15474)

    Analysis Date

    Mar 13, 2026

    Classes Analyzed

    13,366

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 4 findings (1 critical, 2 high, 1 info)

    Network Security - 3 findings (1 high, 1 medium, 1 info)

    Code Safety - 0 findings

    Privacy - 5 findings (1 high, 2 medium, 2 info)

    Privacy Concerns

    What Data is Collected

    The app collects order history, in-app browsing behaviour, device identifiers, and location data to support delivery and personalise the shopping experience.

    Third-Party Data Sharing

    Activity data is shared with the following third-party services:

    • Adjust - Mobile analytics and campaign attribution
    • Braze - Customer messaging and push notifications
    • Snowplow - Behavioural analytics
    • Sentry - Error and crash reporting
    • Datadog RUM - Real-time app performance monitoring
    • Firebase - App infrastructure and analytics
    • VGS Collect - Secure payment data collection
    • PayPal - Payment processing
    • Google Maps - Delivery address and mapping
    • Google ML Kit - On-device feature processing

    Understanding the Scores

    CategoryScore
    Security56/100
    Privacy82/100
    Data Security57/100
    Network Security88/100
    Code Safety95/100
    Data Collection82/100
    Data Sharing100/100
    User Control87/100

    Positive Security Features

    • Data is not passed to advertising networks or ad-targeting platforms, keeping purchase behaviour away from ad brokers.
    • Code safety practices score 95/100, reflecting well-structured and consistently maintained app code.
    • Payment handling is routed through dedicated, specialised payment services rather than processed directly inside the app.

    Areas for Improvement

    • Payment card details saved in the app may not be fully protected on the device. Storing a payment card in the app carries additional risk if the device is ever compromised.
    • Some connections the app makes could use stronger protections to keep data secure while it travels between the device and the server.
    • Behavioural and activity data is shared across several analytics platforms. Giving users more direct control over this sharing would improve transparency and the ability to manage personal data.

    About This Analysis

    This scorecard is generated from automated static analysis of the app's code and data handling practices. Findings reflect the app as released at the version noted below.

    App Details

    • App: Picnic Online Supermarket
    • Package: com.picnic.android
    • Version: 1.227.0 (build 15474)
    • Platform: Android
    • Analysis Date: 13 March 2026

    Right of Reply

    Developer not yet contacted