Uber - Request a ride Security & Privacy Scorecard
Android
Ride history, location, and usage patterns are collected and shared with Firebase Analytics and Braze to improve the service and target promotions. Payment processing relies on third-party providers who handle user card data. Precise location is tracked throughout trips and may be retained after the ride ends.
Best for
Frequent riders comfortable with usage analytics
Findings
- 3 critical
- 5 high
- 10 medium
- 3 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Authentication Tokens Stored Without Encryption
- Payment JavaScript Interface Exposed Without Origin Validation
- Certificate Pinning Can Be Disabled via Feature Flags
Top privacy issues
- Firebase Analytics Auto-Initialization Before User Consent
- Location Data Stored Without Encryption
- Extensive Firebase Data Sharing with Google
Full analysis
Uber - Request a ride
What This Means for You
Ride history, location, and usage patterns are collected and shared with Firebase Analytics and Braze to improve the service and target promotions. Payment processing relies on third-party providers who handle user card data. Precise location is tracked throughout trips and may be retained after the ride ends.
Recommendation: Use With Caution
Best For: Frequent riders comfortable with usage analytics
Key Findings
Data Security - 6 findings (1 critical, 1 high, 2 medium, 2 low)
Network Security - 3 findings (2 critical, 1 high)
Code Safety - 0 findings
Privacy - 4 findings (1 high, 3 medium)
Privacy Concerns
What Data is Collected
Uber collects precise location throughout every trip, along with ride history, device identifiers, and app usage patterns. Payment details are handled by third-party processors. In-app behavior is monitored continuously to personalize the experience and serve targeted promotions.
Third-Party Data Sharing
User data is shared with multiple third-party services: Firebase Analytics and Firebase Performance receive usage and performance data, Braze receives behavioral data to target promotions, and Braintree and Adyen process payment information under their own data retention policies.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 55/100 |
| Data Security | 40/100 |
| Network Security | 35/100 |
| Code Safety | 50/100 |
| Data Collection | 60/100 |
| Data Sharing | 60/100 |
| User Control | 50/100 |
Positive Security Features
No standout security practices were identified for this version of the app.
Areas for Improvement
- Location data and usage patterns are sent without full protection on public Wi-Fi, meaning user data may not be fully protected during transit.
- Payment details flow through multiple third-party processors, each operating under their own data retention policies beyond Uber's direct control.
- Precise location may be stored well after a trip ends, with limited options available for users to review or remove that data from third-party systems.
About This Analysis
App Details
| Field | Value |
|---|---|
| App | Uber - Request a ride |
| Package | com.ubercab |
| Version | 4.614.10002 (Build 262343) |
| Scan Date | 2026-01-29 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 50/100 |