Car Apps Share VINs and Location: What a New Privacy Study Actually Found

Stephanie Adlam
6 Min Read
Car on a magenta data trail emerging from a smartphone, representing car app privacy
Car on a magenta data trail emerging from a smartphone, representing car app privacy

A car app that unlocks a door can also open a route for personal information to reach advertising and analytics companies. Northeastern University researchers, working with Consumer Reports, found seven of 30 tested companion apps sending sensitive identifiers to such third parties. Their September 29 disclosure puts a concrete data trail behind a familiar privacy warning—and shows why traffic from the car and traffic from its app must be examined separately.

The study covered 21 vehicles from 19 brands and 30 apps. It is a snapshot of US-market systems tested between October 2024 and August 2025, not a live inventory of what every model sends today.

Two routes out of the same vehicle ecosystem

The team connected vehicles to a controlled Wi-Fi access point and exercised them while stationary and driving. A car-sized Faraday tent blocked cellular connections for 11 electric vehicles, letting the researchers check whether communications moved to Wi-Fi. Some vehicles changed routes; others lost connected functionality instead.

Encryption prevented the team from reading the vehicles’ message contents. They could still observe destinations and traffic patterns. Companion apps provided a second vantage point: the researchers controlled the test iPhones, installed certificates for interception and inspected decrypted app communications while using features such as vehicle location and remote controls.

Observed path What the evidence establishes
19 of 21 vehicles contacted third parties over Wi-Fi A network connection to an outside destination; encrypted contents remained unreadable.
7 of 30 apps sent sensitive identifiers to advertising or tracking companies Specific personal data appeared in decrypted app traffic.

Those findings answer different questions. Contacting an advertising domain does not reveal exactly what a car transmitted. Reading a VIN or email address in app traffic provides stronger evidence about that particular transfer. Combining the two into a claim that every tested car leaked every driver’s location would overstate the results.

[1] [2]

Why a VIN can make the trail personal

A vehicle identification number identifies a particular car. Pair it with an email address or location, and a recipient can potentially connect the vehicle to a person or their movements. The privacy issue is the association, even when no password or payment card appears in the transmission.

The researchers found different combinations across apps, including HondaLink, Lincoln, MyNISSAN and four General Motors apps. The paper’s table records HondaLink sending a VIN and location to Amplitude; it records myChevrolet sending VIN data to several companies and email and location data to Adobe. These are findings about tested versions, not evidence that all seven apps sent every data type.

This extends the familiar problem of tracking across websites into a vehicle account. A phone permission describes one access decision; it does not, by itself, explain every recipient of information already held in an account.

Honda changed a flow; contracts remained part of the response

Northeastern reports that Honda asked Amplitude to delete the shared data and changed its app to stop sending precise geolocation to that company. Honda said contractual restrictions barred independent use or sale of the information. GM likewise told the university that recipients operated under contractual limits.

The distinction matters: observing a transfer is evidence that information left the app. It does not establish a later sale, a stolen account or a malware infection. Contractual restrictions address permitted use; they do not make the original transfer disappear.

[3]

Check the app and the connected service separately

For an owner, the useful starting point is to review the automaker account’s data-sharing choices alongside the app’s permissions and the car’s connected-service settings. Check which optional features you use and what you lose by disabling one before changing it. Removing a phone app does not demonstrate that the car’s built-in connection has stopped.

The app tests accepted requested permissions and exercised available features. They therefore do not tell every owner what happens after a particular opt-out. The researchers also did not measure every model, market or later app update. Our online privacy guide provides broader account and tracking checks; this study adds a reason to include the vehicle ecosystem in that review.

The finding is specific enough to act on without turning it into a universal spying claim: convenience features can create additional data paths, and the manufacturer is not necessarily the only recipient.

References

  1. N. Zagson et al. Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem. IMC ’26 research paper, publicly available by September 29, 2026; accessed October 1, 2026. Research paper.
  2. Northeastern University research team. Automatic Transmission: methods and findings. Project website, accessed October 1, 2026. Study overview.
  3. Cesareo Contreras. Your car is collecting more data about you than you think. Northeastern Global News, September 29, 2026. University report and manufacturer responses.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?