Zakaz.md Security & Privacy Scorecard
by Zakaz Investments Limited · iOS
Usage and transaction data is shared with Firebase Analytics, Google Analytics, AppsFlyer, and Facebook SDK for analytics and ad attribution. Crash reports are sent to Firebase Crashlytics. Customer support interactions go through Zendesk, and marketing messages may be delivered via eSputnik.
Best for
Grocery shoppers comfortable with standard analytics
Findings
- 0 critical
- 0 high
- 3 medium
- 1 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Deprecated Keychain Accessibility Class Used (kSecAttrAccessibleAlways)
- App Transport Security Globally Disabled
- CoreData/SQLite Database Uses Weaker File Protection Class
Top privacy issues
- AppsFlyer Attribution Data May Route Through Chinese Infrastructure
- Analytics and Attribution SDK Ecosystem — ATT Correctly Implemented
- SDK Configuration Keys Are All Client-Side Init Tokens
Full analysis
Zakaz.md
What This Means for You
Your order activity and device identifiers are shared with multiple analytics and advertising services, and some of that data may be routed through servers in China depending on network conditions.
Recommendation: Acceptable with Awareness
App has solid security practices with encrypted connections on all first-party services, device integrity checks, and biometric-secured storage. Two configuration choices - a global network security setting that allows less-strict connections for third-party components, and some stored data that remains accessible when your device is locked - create limited but real exposure risks. For everyday grocery shopping in Moldova, this app is acceptable with the awareness that several analytics services are active.
Best For: Moldovan grocery shoppers comfortable with standard analytics tracking
Key Findings
Data Security - 3 findings (1 medium, 1 low, 1 info)
Network Security - 3 findings (1 medium, 2 info)
Code Safety - 2 findings (2 info)
Privacy - 3 findings (1 medium, 2 info)
Privacy Concerns
What Data is Collected
- Personal information: name, phone number, email (used for OTP login and account management)
- Order and purchase history
- Device identifiers and advertising ID (with consent prompt)
- App usage and interaction data
- Location data (for delivery address and order tracking)
Third-Party Data Sharing
The following third parties may receive your data:
- AppsFlyer - mobile attribution and install tracking; may route data through China-region servers
- Facebook (Meta) - SDK present; IDFA collection and auto-event logging are disabled
- Firebase Analytics (Google) - app usage analytics
- Firebase Crashlytics (Google) - crash and stability reporting
- Firebase Cloud Messaging (Google) - push notifications for order updates
- Firebase Remote Config (Google) - feature configuration
- Firebase Dynamic Links (Google) - deep link handling
- Google Ads On-Device Conversion - advertising measurement
- Google Analytics - usage analytics
- Google reCAPTCHA Enterprise - bot and fraud prevention
- Zendesk - in-app customer support
- eSputnik - marketing and messaging
Understanding the Scores
Security: 93/100
Privacy: 93/100
Security Breakdown
- Data Security: 92/100 - Strong biometric and device-bound storage in use; some items stored with weaker protection accessible while the device is locked
- Network Security: 91/100 - All first-party connections are encrypted; a global setting allows third-party components to use less-strict connections
- Code Safety: 100/100 - No unexpected permissions, no risky web view bridges, and no elevated system access detected
Privacy Breakdown
- Data Collection: 98/100 - Tracking consent is correctly requested before collecting advertising identifiers; several analytics services are active
- Data Sharing: 95/100 - Data is shared with multiple third-party services; AppsFlyer attribution data may route through Chinese infrastructure
- User Control: 98/100 - App Tracking Transparency consent correctly implemented; Facebook IDFA collection is disabled; AppsFlyer configured off by default
Positive Security Features
- All first-party connections use encrypted HTTPS with no plain-text alternatives configured
- Device integrity verification (Apple App Attest) is implemented to detect tampered devices
- Strongest available secure storage protection class is in use for sensitive items
- Biometric authentication (Face ID/Touch ID) is supported for secure access
- App Tracking Transparency consent is correctly shown before any advertising identifier is accessed
- Facebook SDK advertising ID collection and automatic event logging are both disabled
- AppsFlyer SDK is toggled off by default in the app configuration
- In-app web views are used only by support and security components, with no JavaScript bridge to app data
- Standard iOS entitlements with no unexpected or elevated system permissions
- Zero security issues detected across all 29 analyzed third-party framework binaries
Areas for Improvement
GDPR / Privacy Compliance
The app's privacy practices could be strengthened by:
Review AppsFlyer China-region routing
The attribution SDK is configured with Chinese server domains as fallback endpoints. For users in Moldova, which holds an EU data adequacy decision, routing personal data to Chinese infrastructure may create regulatory compliance exposure. Reviewing whether China-region endpoints are necessary and adding explicit user notice would strengthen compliance.Clarify data retention for analytics services
Multiple analytics services are active simultaneously. A clear privacy policy section explaining which data each service receives, how long it is retained, and how users can request deletion would improve transparency.
Security Enhancements
Restrict network security settings to specific domains
The current configuration globally relaxes iOS network security for the entire app and all bundled third-party components. Replacing this with per-domain exceptions limited to specific services that require it would remove the blanket relaxation while preserving functionality.Upgrade storage protection for all sensitive data
Some stored items use a protection class that keeps them accessible after first device unlock, even when the device is subsequently locked. Migrating all sensitive data storage to protection classes that require the device to be actively unlocked would close this window.
Technical Context
App Type: Grocery delivery and e-commerce (iOS)
Third-Party Services: 14 third-party services identified
Context Tags: ecommerce, delivery, location, payment, analytics, ads
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.
App Details
Version: 2.1.4 (Build 957)
Analysis Date: 2026-04-17
Package: md.zakaz
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on IPA version 2.1.4 analyzed on 2026-04-17
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 93/100 |