Wolt Delivery: Food and more Security & Privacy Scorecard
Android
User activity, location, and purchase history are shared with multiple analytics and advertising companies including Facebook and AppsFlyer. Payment data passes through several third-party processors. Users have limited ability to opt out of data collection.
Best for
Food delivery users comfortable with broad data sharing
Avoid if
You want control over how your data is used
Findings
- 4 critical
- 7 high
- 2 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Hardcoded HTTP Credentials in WebView Client
- Instabug Debug Token Exposed in Production Build
- Unencrypted OAuth Tokens in SharedPreferences
Top privacy issues
- Pre-Consent Analytics Tracking (GDPR Violation)
- Precise GPS Coordinates Sent in Every Analytics Event
- Exported Fraud Detection Service (Device Fingerprinting)
Full analysis
Version: 25.54.0 (Build 132026540)
Scan Date: 2026-01-19
What This Means for You
User activity, location, and purchase history are shared with multiple analytics and advertising companies including Facebook and AppsFlyer. Payment data passes through several third-party processors. Users have limited ability to opt out of data collection.
Recommendation: Use With Caution
Best For: Food delivery users comfortable with broad data sharing
Avoid If: You want control over how your data is used
Key Findings
Data Security - 5 findings (2 critical, 2 high, 1 medium)
Network Security - 5 findings (1 high, 3 medium, 1 low)
Code Safety - 0 findings
Privacy - 9 findings (1 critical, 3 high, 5 medium)
Privacy Concerns
What Data is Collected
The app collects precise location, order history, in-app browsing behavior, device identifiers, and payment information. This data is used for order fulfillment, personalized recommendations, fraud detection, and behavioral advertising.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Firebase Analytics - Usage analytics and behavioral tracking
- AppsFlyer - Marketing attribution and behavioral profiling
- Facebook SDK - Advertising and social tracking
- Sentry - Error and crash reporting
- Iterable - Marketing communications and messaging
- Instabug - In-app feedback and diagnostics
- DoorDash Telemetry - Usage telemetry
- Stripe, Adyen, Braintree/PayPal, Klarna - Payment processing
- VGS, Hyperswitch - Payment data handling
- Ravelin, Riskified - Fraud detection and risk scoring
- Google Maps - Location and mapping
- Firebase Crashlytics - Crash diagnostics
- HCaptcha - Bot and fraud detection
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 25/100 |
| Data Security | 30/100 |
| Network Security | 65/100 |
| Code Safety | 60/100 |
| Data Collection | 30/100 |
| Data Sharing | 35/100 |
| User Control | 20/100 |
Positive Security Features
- No notable positive security features were identified in this version of the app.
Areas for Improvement
- Behavioral and location data is distributed across a large number of advertising and analytics companies, with little visibility into how user profiles are built and monetized.
- Payment information is handled by multiple third-party processors, expanding the number of parties with access to financial data.
- The app offers minimal controls for limiting data collection or opting out of tracking, leaving users with very little ability to manage their own data.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect observed behaviors and data practices at the time of the scan.
App Details
- Package: com.wolt.android
- Version: 25.54.0 (Build 132026540)
- Scan Date: 2026-01-19
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 30/100 | |
| #2 | 42/100 | |
| #1 | 42/100 |