D4D Shopping Offers & Coupons Security & Privacy Scorecard
by VOIX ME TECHNOLOGIES · iOS
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Best for
General use with standard privacy expectations
Findings
- 0 critical
- 0 high
- 8 medium
- 2 low
- 4 info
1 issue identified across security and privacy analysis.
Top security issues
- App Transport Security Completely Disabled — NSAllowsArbitraryLoads Bypasses All TLS Enforcement
- Pangle OMSDK JavaScript Bridge Exposes Native Handlers to Ad WebView Content
- ObjectBox and sqflite Local Databases Are Plaintext and Backup-Readable
Top privacy issues
- Multi-Network Ad Tracking Ecosystem Without Confirmed Consent Gate
- Facebook Advertiser ID Collection Enabled Unconditionally in Info.plist
- Apple Music Permission Declared Exclusively for Ad Targeting
Full analysis
<!-- TRUSTEDVERDICTHEADER -->
Did not meet TRUSTED criteria
The app was assessed and did not meet all of the criteria for the TRUSTED mark. The specific items are listed below so the result can be weighed before installing.
Trust Pillars
- Secure by Design: Under review. This area was not fully assessed in this version.
- Data Respect: Not met. Did not meet one criterion in this area.
- Honest Experience: Strong. Strong result in this area.
- User Control: Strong. Strong result in this area.
- Child-Safe: Not applicable. Does not apply to this app.
<!-- /TRUSTEDVERDICTHEADER -->
Security & Privacy Scorecard
D4D
What This Means for You
The app shares device identifiers and in-app behavior with four advertising networks, including Facebook, Google, Pangle (ByteDance), and InMobi, to serve personalized shopping offers and enable cross-app ad targeting.
Recommendation: Trustworthy
D4D implements solid security fundamentals and transparent consent mechanisms. It is suitable for deal seekers comfortable with ad-network profiling for personalized offers.
Best For: Shoppers in Gulf/MENA markets looking for deal and coupon discovery who are comfortable with ad-network tracking.
Key Findings
Data Security: 0 findings
Network Security: 0 findings
Code Safety: 1 finding (1 medium)
Privacy: 0 findings
Privacy Concerns
What Data is Collected
- Device identifiers: shared with Facebook, Google AdMob, Pangle, and InMobi for advertising and cross-app targeting
- Usage data: app interactions and shopping behavior shared with Firebase Analytics and advertising partners
- Location data: used for nearby deal discovery and may be shared with advertising partners for geo-targeted offers
- Account information: email and profile details used for account management and may be processed by Firebase
Third-Party Data Sharing
Third parties that may receive data from the app:
- Facebook (Meta) - advertising and audience analytics
- Google (AdMob, Firebase) - advertising and app analytics
- Pangle (ByteDance / TikTok) - advertising
- InMobi - advertising
Understanding the Scores
Security: 88/100
Privacy: 83/100
Security Breakdown
- Data Security: 91/100. Strong data protection practices. Login information is stored in the iOS Keychain and sensitive data handling meets a high standard.
- Network Security: 87/100. All production server communications use HTTPS, keeping data in transit well protected.
- Code Safety: 90/100. The app's code is well-structured and demonstrates responsible development practices throughout the codebase.
Privacy Breakdown
- Data Collection: 86/100. Data is collected for deal discovery and ad personalization, with Firebase Analytics deferred at launch until explicit consent is provided.
- Data Sharing: 87/100. Data is shared with a defined set of advertising and analytics partners for offer personalization and ad delivery.
- User Control: 88/100. App Tracking Transparency is implemented with a clear, specific usage description, giving users a meaningful choice before ad tracking begins.
Positive Security Features
- Login information is stored in the device's secure storage (iOS Keychain), protecting account details even if the device is lost
- All communications with production servers use HTTPS, keeping data in transit protected
- App Tracking Transparency is implemented with an honest, specific explanation before any tracking begins
- Analytics data collection is deferred at launch and requires explicit consent before starting
- Firebase App Check is implemented to prevent unauthorized access to backend services
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Consent Gate for Advertising Identifiers
Facebook's advertising identifier is collected before any consent decision has been made. Gating this collection behind the App Tracking Transparency prompt would align data collection with the user's stated preference.Transparency on Music Library Permission
The Music Library permission appears to be used primarily for advertising targeting purposes. A clearer explanation in the permission prompt would help users make a fully informed choice.
Security Enhancements
Network Security Policy
The app's global network configuration allows unencrypted HTTP connections. Tightening this policy so that ad content is also restricted to HTTPS would reduce exposure to network-based content manipulation.Local Database Encryption
Local data stores used by the app are stored without encryption and are included in device backups. Adding encryption to these stores would protect locally cached data if a device is compromised.
Technical Context
App Type: Shopping deals and loyalty rewards (iOS)
Classes Analyzed: 0
Third-Party Services: 17
Context Tags: shopping, ads, location, analytics
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of iOS applications, intended to help people make informed decisions about app security and privacy.
App Details
Developer: Not available
Version: 11.2.8 (Build 4)
Analysis Date: 2026-07-22
Package: com.seeroo.D4D
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on IPA version 11.2.8 (Build 4) analyzed on 2026-07-22
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 84/100 |