Schiphol Security & Privacy Scorecard

Android

80
Overall trust score
Acceptable
91
Security
70
Privacy

Usage patterns and app behavior are shared with Firebase Analytics and Google for performance monitoring and crash reporting. The device receives personalized content via Firebase Remote Config. Auth0 handles login, meaning authentication data flows through a third-party service.

Best for

Travelers comfortable with standard analytics

Findings

  • 1 critical
  • 2 high
  • 3 medium
  • 2 low
  • 2 info

1 issue identified across security and privacy analysis.

Top security issues

  • Unencrypted OAuth Token Storage
  • Deep Link Input Validation Missing
  • No Android KeyStore Usage for Cryptographic Keys

Top privacy issues

  • Pre-Consent Analytics Tracking Initialization
  • Advertising ID Collection Without Explicit Consent
  • Opt-Out Analytics Design Instead of Opt-In

Full analysis

Schiphol Amsterdam Airport

Version: 12.3.0
Scan Date: March 4, 2026
Security Score: 91/100
Privacy Score: 70/100

What This Means for You

Usage patterns and app behavior are shared with Firebase Analytics and Google for performance monitoring and crash reporting. The device receives personalized content via Firebase Remote Config. Auth0 handles login, meaning authentication data flows through a third-party service.

Recommendation: Acceptable

Best For: Travelers comfortable with standard analytics

Key Findings

Data Security - 4 findings (1 high, 1 medium, 2 info)

Network Security - 0 findings

Code Safety - 0 findings

Privacy - 3 findings (1 critical, 1 high, 1 medium)

Privacy Concerns

What Data is Collected

The app collects behavioral and usage data through multiple analytics services. Firebase Analytics builds a record of how users interact with the app. Firebase Crashlytics and Firebase Performance Monitoring gather device and session data when the app encounters issues or slowdowns. Mapbox Maps processes location data to render maps. Usabilla may collect in-app feedback responses and interaction patterns.

Third-Party Data Sharing

Data flows to the following third-party services:

  • Firebase Analytics / Google - In-app behavior and usage patterns
  • Firebase Crashlytics - Crash reports and device diagnostic data
  • Firebase Remote Config - Configuration data for personalized content delivery
  • Firebase Cloud Messaging - Data required to deliver push notifications
  • Firebase Performance Monitoring - Performance metrics tied to user sessions
  • Auth0 - Login and authentication data
  • Mapbox Maps - Location and map interaction data
  • Usabilla - In-app feedback and survey responses
  • Google ML Kit - Processed data for on-device features

Understanding the Scores

Category Score
Security 91/100
Privacy 70/100
Data Security 82/100
Network Security 100/100
Code Safety 92/100
Data Collection 72/100
Data Sharing 78/100
User Control 85/100

Positive Security Features

  • All network communications use secure protocols, achieving a perfect network security score
  • The app's code passes all safety checks, reflecting careful development practices

Areas for Improvement

  • Reduce the number of analytics and tracking services so user data is shared with fewer third parties
  • Review data collection practices to align more closely with what the app's features actually require
  • Provide clearer in-app controls so users can limit which data is shared with analytics and advertising partners

About This Analysis

Scores reflect the state of the app at the time of analysis and may change as the app is updated.

App Details

  • App Name: Schiphol Amsterdam Airport
  • Package ID: org.schiphol
  • Version: 12.3.0
  • Scan Date: March 4, 2026

Versions & scan history

ScanDateOverall score
#3 (current) 80/100
#2 85/100