AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Buying for a business?Offer from Amazon

Get business pricing on garage and car supplies

  • Business-only prices and quantity discounts
  • Tax-exempt purchasing
  • Multiple users, one account, clear invoices
As an affiliate, we earn on qualifying purchases.

A study of 21 vehicles and 30 companion apps by Northeastern University and Consumer Reports found that many apps contacted advertising, tracking and analytics domains. Seven apps transmitted personal information to third parties, with vehicle identification numbers among the data sent; the researchers say a VIN can be linked with details such as an email address or location.

A study by Northeastern University and Consumer Reports found that companion apps for tested vehicles often contacted advertising, tracking and analytics domains, and that seven apps sent personal information to third parties. The findings raise questions about how automakers and their vendors handle data tied to drivers, including vehicle identification numbers, or VINs.

The researchers examined 21 vehicles from 19 brands and 30 related mobile apps. According to the report, 70% of the apps contacted more than five distinct advertising, tracking and analytics domains. For most tested vehicles, including the app in the analysis at least doubled the number of such companies exposed to owner data. The myCadillac app contacted 51 domains.

Data sent by apps included VINs, which the study said were the most common personal information observed going to third parties. Seven apps associated with 19 of the 21 cars transmitted personal information: four GM apps, HondaLink, Lincoln and MyNissan. Recipients included Google, Microsoft and Meta, according to the report. Researchers warn a VIN combined with an email address, phone number or location could help a recipient connect a vehicle to a person and their browsing or purchasing history.

Vehicle connections varied. Over Wi-Fi, the cars contacted at most four first-party domains and averaged about nine integrated third parties, the report said. The Tesla Model 3 contacted 34 advertising, tracking and analytics domains and the Cybertruck 23; the Mercedes EQS and Buick Envista contacted none. Thirteen vehicles contacted Google domains, including DoubleClick, which the report said was not needed for core services.

At a glance
reportWhen: Study findings recently reported; vehic…
The developmentA Northeastern University and Consumer Reports study examined data flows from 21 vehicles and their companion apps, finding that apps often contacted tracking domains and some sent VINs to third parties.

VINs Link Cars to Drivers

A VIN is tied to a particular vehicle and cannot be reset like a phone advertising ID, the study noted. If it is combined with contact details or location data, companies may be able to associate activity with an identifiable owner. The research therefore puts a specific identifier at the center of a broader privacy issue: connected features can involve data transfers beyond what drivers might expect from a car service.

For consumers, the findings also point to a tradeoff around convenience. Some automakers warn that opting out of data collection can reduce features or make them inoperable. Tesla, for example, warned of reduced functionality or inoperability; Rivian cited possible loss of navigation and over-the-air updates. The study does not establish that every recipient used the data for advertising or that every driver was personally identified.

How the Data Flows Were Tested

The study covered a mix of cars from model years 2022 through 2025, including electric vehicles, hybrids and gasoline models. Researchers examined vehicle network traffic as well as companion apps, which can add connections that are not visible when looking at a vehicle alone. The report said vehicles with Android Automotive and Google services contacted more trackers, while even vehicles from related brands did not always behave alike.

App behavior could also involve a phone browser. The Drive’s account of the research says an app may open a browser after connecting with a car; that changes the data flow because browser settings and cookies can become part of the process. Of 17 manufacturers contacted, 14 responded. All said vendor contracts covered data flows; five pointed to embedded app browsers, and seven said consumers were responsible for reading third-party terms. Those responses describe manufacturers’ positions, not independent confirmation that users understood each transfer.

“70% of companion apps contacted more than five unique advertising, tracking and analytics domains.”

— The Northeastern University and Consumer Reports study, as summarized by The Drive

What the Study Cannot Establish

The reported results cover 21 tested vehicles and 30 apps; they do not establish that every vehicle of the same model behaves identically or describe all connected cars. The summary also does not quantify how much data each third party retained, how it was used, or whether it was linked to an individual driver. Privacy policies disclosed that data could go to third parties, but, according to the report, generally did not identify those recipients or explain why each received data.

It is also unclear from the available account how long the observed data was kept, whether all transfers were tied to active use of a feature, or what protections applied after it reached vendors. The researchers’ findings document network contacts and information transmitted in their tests; they do not by themselves prove misuse.

Automaker Responses and Changes

The next developments depend on whether automakers clarify their data practices or change app behavior. The report says Honda stopped sending location data to Amplitude after asking the company to delete data it had received. It does not describe comparable changes by the other manufacturers.

Drivers seeking details can review their automaker’s privacy policy and app settings, while recognizing that the study found disclosures may not name each vendor or explain each transfer. Further reporting or testing would be needed to show whether companies changed their practices after the findings and whether those changes apply across models and regions.

Key Questions

What did the researchers study?

They examined 21 vehicles from 19 brands and 30 companion apps, tracking connections to advertising, analytics and other domains.

Which apps sent personal information to third parties?

The report identified four GM apps, HondaLink, Lincoln and MyNissan. It said VINs were the most common personal information observed in these transfers.

Does the study prove that companies misused driver data?

No. The findings describe data flows observed in testing. The account does not establish how recipients used or retained the information, or whether a particular driver was identified.

Can drivers opt out of data collection?

Some manufacturers offer opt-outs, but the report says companies warned that limiting data collection could reduce or disable features such as navigation or over-the-air updates.

Source: rss

EVERGREEN BESTSE

Evergreen bestsellers Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Expedia Group Surges In Global Coverage

Expedia Group has experienced a notable surge in its global coverage, with 28 mentions within a recent monitoring window, indicating increased international activity.

Maserati Surges In Global Coverage

Maserati’s media mentions have increased significantly, with 25-fold rise in recent coverage, highlighting growing global interest in the brand.

Car Emergency Kit: A Back to school Guide

Discover essential items, latest innovations, and tips to build a reliable car emergency kit. Be prepared for any roadside surprise with this practical guide.

Volkswagen Surges In Global Coverage

Volkswagen’s media coverage has surged internationally, with mentions increasing sharply. The cause of this spike remains unconfirmed, but it signals heightened public and media interest.