TL;DR
Get business pricing on garage and car supplies
- Business-only prices and quantity discounts
- Tax-exempt purchasing
- Multiple users, one account, clear invoices
A study of 21 vehicles and 30 companion apps found that many contacted advertising, tracking and analytics companies. Seven apps sent personal information, including vehicle identification numbers, to third parties. The study does not establish that every automaker or recipient uses the data in the same way.
A study by Northeastern University and Consumer Reports found that companion apps for many of 21 tested vehicles contacted advertising, tracking and analytics companies, sometimes transmitting personal information such as a vehicle identification number. The findings matter because drivers may have limited ways to use connected features without exposing data flows, while the researchers say automakers’ privacy disclosures often did not identify which third parties received data or why.
The researchers examined 21 vehicles from 19 brands and 30 companion mobile apps. They monitored connections made over Wi-Fi and by apps, counting contacts with advertising, tracking and analytics, or ATA, domains. The report found that 70% of the companion apps contacted more than five unique ATA domains. Adding an automaker or third-party app at least doubled the number of ATA companies exposed to an owner’s data for most tested vehicles.
App activity varied. The myCadillac app contacted 51 ATA domains, while the Buick Envista and Nissan Ariya were among vehicles that reached more than 20 ATA companies when their apps were included. Seven apps, associated with 19 of the 21 cars, sent personal information to ATA third parties. The report identifies VINs as the most common type of personal information sent, with recipients including Google, Microsoft and Meta.
Vehicle connections also differed. Over Wi-Fi, the tested vehicles contacted an average of about nine integrated third parties, with a maximum of four first-party domains. The Tesla Model 3 contacted 34 ATA domains and the Cybertruck 23; the Mercedes EQS and Buick Envista contacted no third parties in the measured setting. These are observations from the study’s tests, not a complete inventory of every data transfer a vehicle may make in all circumstances.
VINs Can Link Drivers to Data
A VIN is a persistent identifier assigned to a vehicle. The researchers warn that combining it with an email address, phone number or location could help a recipient associate a specific person with browsing or purchase history. Unlike a phone advertising ID, a VIN cannot be reset by the vehicle owner, according to the report’s explanation.
The findings also point to a practical trade-off for drivers. Connected features such as navigation, remote access and software updates can depend on data-sharing arrangements. The source report says Tesla warned that opting out could cause reduced functionality or inoperability, while Rivian warned that navigation and over-the-air updates could be disabled. The study does not establish that every opt-out has the same effect, but these warnings show why avoiding data collection may be difficult for people who want those services.
Apps Expand the Data Path
The study covered vehicles including the 2022 Ford F-150 Lightning, 2023 models such as the Toyota Corolla Cross and Tesla Model 3, and 2024 and 2025 vehicles. Researchers also tested the related mobile apps, which can add data connections beyond those made by a vehicle on its own. Thirteen of the 21 vehicles contacted Google ATA domains, including doubleclick.net, which the report says is not needed for core services.
Researchers contacted 17 manufacturers and received responses from 14. According to the source report, all 14 said vendor contracts covered data flows; five pointed to embedded browsers in their apps, and seven said consumers were responsible for reviewing third-party terms. The report says privacy policies disclosed that data might be shared but did not specify all recipients or purposes. Honda was the exception described: it asked Amplitude to delete location data it had received and stopped the app from sending it.
Testing these flows was not straightforward. The report says an official app could connect to a phone and open its browser, shifting some data handling to the phone’s browser settings. That can mean the flow includes cookies or browsing data, rather than only information generated by the car. The reported results therefore depend on the tested vehicle, app and connection path.
Recipients’ Uses Remain Unspecified
The study documents domain contacts and certain information sent during its tests; it does not show how every recipient later used, stored or combined that information. It also does not establish that all drivers’ data is handled identically, or that every connection observed represents data tied to an identifiable person. The extent of collection can depend on settings, app behavior and vehicle configuration.
Manufacturers’ responses, as summarized in the report, did not resolve which vendors received each data type or the specific purposes for each transfer. The source material also does not provide a complete account of whether companies beyond Honda changed their practices after being contacted. Those details remain unclear from the published findings.
More Detail Depends on Automakers
The next steps described in the source report are limited. It does not name a scheduled regulatory review, enforcement action or follow-up study. Further clarity would require manufacturers to identify the vendors receiving vehicle and app data, explain the purposes, and describe what happens when drivers change settings or opt out.
For now, drivers can review their vehicle and companion-app privacy settings and the terms for connected services, while recognizing that the tested manufacturers’ opt-out warnings indicate some features may be affected. The study’s findings give consumers and policymakers a measured account of data connections in specific tests; broader conclusions about current practices will require more information from automakers and vendors.
Key Questions
What did the study examine?
Researchers tested 21 vehicles from 19 brands and 30 companion apps, monitoring connections to advertising, tracking and analytics domains.
Did the study find that every car shared a VIN?
No. The report says seven apps associated with 19 of the 21 cars transmitted personal information to ATA third parties, and VINs were the most common information type. It does not say every tested vehicle sent a VIN.
Who received information in the tests?
The report names Google, Microsoft and Meta among recipients of VINs. It does not provide a complete account of every recipient’s later use of the data.
Can drivers opt out without losing features?
The source report says Tesla warned of reduced functionality or inoperability, while Rivian warned navigation and over-the-air updates could be disabled. Effects depend on the vehicle and service; the findings do not establish a single outcome for all drivers.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
