Picnic Online Supermarket Security & Privacy Scorecard

Android

69
Overall trust score
Acceptable
56
Security
82
Privacy

Shopping habits and in-app activity are monitored by several analytics services, including Adjust, Braze, and Snowplow, to personalise the experience. Data is not sold or passed to outside advertisers. Account and payment information stored on-device may not be fully protected for users who save payment details.

Best for

Grocery shoppers who want ad-free delivery

Avoid if

Users who save payment cards in the app

Findings

  • 1 critical
  • 4 high
  • 6 medium
  • 1 low
  • 10 info

1 issue identified across security and privacy analysis.

Top security issues

  • Authentication Tokens Stored in Unencrypted SharedPreferences
  • Android Backup Enabled Without Restrictions
  • Insecure SSL/TLS Configuration in RNFetchBlob Library

Top privacy issues

  • Pre-Consent SDK Initialization via ContentProviders
  • Default-True Consent Logic
  • Advertising ID Collection

Full analysis

Picnic Online Supermarket

Overall Security Score: 56/100 | Privacy Score: 82/100

What This Means for You

Shopping habits and in-app activity are monitored by several analytics services, including Adjust, Braze, and Snowplow, to personalise the experience. Data is not sold or passed to outside advertisers. Account and payment information stored on-device may not be fully protected for users who save payment details.

Recommendation: Use With Caution

Best For: Grocery shoppers who want ad-free delivery
Avoid If: Users who save payment cards in the app

Key Findings

Data Security - 4 findings (1 critical, 2 high, 1 info)

Network Security - 3 findings (1 high, 1 medium, 1 info)

Code Safety - 0 findings

Privacy - 5 findings (1 high, 2 medium, 2 info)

Privacy Concerns

What Data is Collected

The app collects order history, in-app browsing behaviour, device identifiers, and location data to support delivery and personalise the shopping experience.

Third-Party Data Sharing

Activity data is shared with the following third-party services:

  • Adjust - Mobile analytics and campaign attribution
  • Braze - Customer messaging and push notifications
  • Snowplow - Behavioural analytics
  • Sentry - Error and crash reporting
  • Datadog RUM - Real-time app performance monitoring
  • Firebase - App infrastructure and analytics
  • VGS Collect - Secure payment data collection
  • PayPal - Payment processing
  • Google Maps - Delivery address and mapping
  • Google ML Kit - On-device feature processing

Understanding the Scores

Category Score
Security 56/100
Privacy 82/100
Data Security 57/100
Network Security 88/100
Code Safety 95/100
Data Collection 82/100
Data Sharing 100/100
User Control 87/100

Positive Security Features

  • Data is not passed to advertising networks or ad-targeting platforms, keeping purchase behaviour away from ad brokers.
  • Code safety practices score 95/100, reflecting well-structured and consistently maintained app code.
  • Payment handling is routed through dedicated, specialised payment services rather than processed directly inside the app.

Areas for Improvement

  • Payment card details saved in the app may not be fully protected on the device. Storing a payment card in the app carries additional risk if the device is ever compromised.
  • Some connections the app makes could use stronger protections to keep data secure while it travels between the device and the server.
  • Behavioural and activity data is shared across several analytics platforms. Giving users more direct control over this sharing would improve transparency and the ability to manage personal data.

About This Analysis

This scorecard is generated from automated static analysis of the app's code and data handling practices. Findings reflect the app as released at the version noted below.

App Details

  • App: Picnic Online Supermarket
  • Package: com.picnic.android
  • Version: 1.227.0 (build 15474)
  • Platform: Android
  • Analysis Date: 13 March 2026

Versions & scan history

ScanDateOverall score
#1 (current) 69/100