# Security & Privacy Scorecard

## Lidl Plus

**Version:** 16.46.4 | **Scan Date:** 2026-03-25

**Overall Security Score: 88/100 | Privacy Score: 78/100**

## What This Means for You

In-store purchases, location, and shopping habits are linked to the user profile and shared with marketing and analytics partners including Salesforce and Adjust. Users may be tracked across sessions to personalize offers and target ads. OneTrust is present for consent management, giving users some control over data preferences.

## Recommendation: Trustworthy

**Best For:** Regular Lidl shoppers who want coupons and receipts

## Key Findings

**Data Security** - 5 findings (1 high, 1 medium, 3 info)

**Network Security** - 2 findings (2 info)

**Code Safety** - 0 findings

**Privacy** - 4 findings (2 high, 1 medium, 1 low)

## Privacy Concerns

### What Data is Collected

The app collects location data, purchase history, shopping behavior, and device identifiers. This data is linked to the user account profile and used to personalize offers and in-store experiences.

### Third-Party Data Sharing

User data is shared with multiple third-party services:

- **Salesforce Marketing Cloud** - Marketing engagement and customer messaging
- **Adjust** - Advertising attribution and mobile analytics
- **Firebase** - App analytics and performance monitoring
- **ThreatMetrix** - Device risk and fraud assessment
- **Huawei Mobile Services** - Platform services for Huawei devices
- **AltBeacon** - In-store proximity detection
- **Google Maps** - Store location and mapping features
- **Google ARCore** - Augmented reality features
- **OneTrust** - Consent and privacy preference management

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 88/100 |
| Privacy | 78/100 |
| Data Security | 85/100 |
| Network Security | 100/100 |
| Code Safety | 97/100 |
| Data Collection | 80/100 |
| Data Sharing | 100/100 |
| User Control | 78/100 |

## Positive Security Features

- All network communications are secured, with no insecure traffic configurations detected
- The app code meets high safety standards, with minimal risk from code-level attacks
- Secure, standard authentication flows are used via AppAuth
- Consent management through OneTrust gives users options to review their data preferences

## Areas for Improvement

- Some data stored locally on the device has limited protection, which could allow other apps to access it on a compromised device.
- Behavioral and location data is shared with advertising partners, but the app provides limited visibility into how that data is used after it is shared.
- Options for reviewing, exporting, or deleting personal data could be more accessible and clearly communicated within the app.

---

## About This Analysis

This scorecard reflects analysis of the app's code and configuration. It covers practices observable in the app package and does not account for server-side behavior.

### App Details

- **App Name:** Lidl Plus
- **Package ID:** com.lidl.eci.lidlplus
- **Version:** 16.46.4 (build 1470409272)
- **Scan Date:** 2026-03-25
- **Platform:** Android
