TL;DR
Get business pricing on garage and car supplies
- Business-only prices and quantity discounts
- Tax-exempt purchasing
- Multiple users, one account, clear invoices
A study by Northeastern University and Consumer Reports examined data flows from 21 vehicles and 30 companion apps. Researchers found that many apps contacted advertising, tracking and analytics domains, and seven apps transmitted personal information, including vehicle identification numbers, to third parties. The study does not establish that every automaker or app shares the same data in the same way.
A study by Northeastern University and Consumer Reports found that companion apps for many tested vehicles contacted advertising, tracking and analytics domains, sometimes sharing personal information such as vehicle identification numbers. The researchers tested 21 vehicles and 30 apps, raising questions about how drivers can understand or limit data flows tied to connected-car features.
In the study, 70% of the companion apps contacted more than five distinct advertising, tracking and analytics domains. For most of the tested vehicles, counting the automaker or third-party app at least doubled the number of such companies that could receive data. The report says apps commonly shared information such as location and timing. Cadillac’s myCadillac app contacted 51 domains, while the Envista and Nissan Ariya each reached more than 20 when their apps were included.
Vehicle connections also varied. Over Wi-Fi, the tested cars contacted no more than four automaker domains, while averaging about nine integrated third-party domains. The Tesla Model 3 contacted 34 advertising, tracking and analytics domains and the Cybertruck contacted 23; the Mercedes EQS and Buick Envista contacted none in that category. Thirteen vehicles contacted Google domains, including DoubleClick. These observations describe the tested vehicles and conditions, rather than every model or software configuration.
The researchers found that seven apps associated with 19 of the 21 cars sent personal information to third parties. Those apps were the four GM apps, HondaLink, Lincoln and MyNissan. The report says vehicle identification numbers were the most common personal information sent and names Google, Microsoft and Meta among recipients. It also found that app behavior could change when a vehicle opened a browser on a connected phone, bringing phone browser settings, cookies and browsing data into the flow.
VINs Can Link Data to Drivers
A vehicle identification number (VIN) is tied to a specific vehicle and cannot be reset like a phone advertising ID. The study says a VIN combined with an email address, phone number or location could help an advertising company connect a person to browsing or purchase history. That is a potential privacy concern identified by the researchers; the reported tests do not establish how each recipient used the data or whether every combination was made.
Connected features can also make data collection difficult to avoid in practice. The report says automakers disclosed that data might go to third parties but generally did not specify which recipients would get it or why. Some manufacturers warned that opting out could reduce features or make services inoperable, leaving drivers to weigh privacy settings against functions such as navigation and software updates.
Testing Connected Cars and Apps
The research covered 21 vehicles from 19 brands, with model years ranging from 2022 to 2025, and 30 companion mobile apps. It examined how vehicles and apps contacted outside domains under test conditions. The report emphasizes that data flows could differ between the car itself and its app, and that adding the companion app often changed the number of companies contacted.
Researchers contacted 17 automakers, and 14 responded. According to the report, manufacturers said vendor contracts covered data flows. Five pointed to embedded browsers in their apps, while seven said consumers were responsible for reviewing third-party terms. The report says Honda had Amplitude delete location data it received and stopped the app from sending it.
“Opting out may disable navigation and over-the-air updates.”
— Rivian, as summarized in the study
Recipients and Uses Remain Unclear
The findings do not identify the complete data practices of every current vehicle, app version or automaker. Testing covered a defined set of cars and apps, and data flows may change with software updates, settings, region or how a phone is connected. The report also does not establish what each third party did with the information it received or whether it linked VINs to named individuals.
Automakers’ broad disclosures left specific recipients and purposes unclear, according to the study. The source material does not provide a complete recipient-by-recipient account of the data collected, how long it was retained or what deletion options apply across all companies.
Privacy Disclosures Under Scrutiny
The study’s findings put attention on whether automakers and app vendors will give drivers clearer information about who receives vehicle data, what data is sent and how to opt out. The report documents Honda’s response to location data handled by Amplitude, but it does not describe a broader industry change or a timeline for additional policy updates.
Drivers seeking to understand their own car’s data flows can review the vehicle and app privacy settings and policies, while keeping in mind that the study found those disclosures may not name every recipient. Whether other manufacturers will change their practices, and whether opting out can be done without losing useful features, remains unsettled.
Key Questions
What did the study examine?
Researchers from Northeastern University and Consumer Reports tested data flows involving 21 vehicles from 19 brands and 30 companion apps.
Which personal information did apps send?
The report says vehicle identification numbers were the most common personal information sent to advertising, tracking and analytics recipients. It names Google, Microsoft and Meta among those recipients.
Does the report show what companies did with the data?
No. The reported findings identify domains contacted and information transmitted in the tests, but do not establish how each recipient used the data or whether it linked information to named individuals.
Can drivers opt out without losing features?
That depends on the vehicle and service. The report says Tesla warned of reduced functionality or inoperability, and Rivian warned that navigation and over-the-air updates could be disabled.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
