Your Car’s Secret Conversation With Third Parties

Another report with some additional information.

https://reclaimthenet.org/your-cars-secret-conversation-with-third-parties

Convenience comes bundled with a surprisingly expansive audience.
Illustration of a modern car connected by dotted lines to floating icons for user profile, location, mail, and data.

By Ken Macon

In reality, it’s not your phone that is the second most personal piece of property you own, after your home; it’s your car. At least that’s the claim that can be made based on the data that modern cars, especially those with “infotainment” systems, are leaking to third parties, and that includes personal identifiable information (PII).

The claim that cars have become like phones is not new, but the depth of the problem is not often spelled out. One way to look at it is that while phones are designed to be regularly replaced and/or reset and have their operating systems updated, cars are not. But what is most often cited as the difference is that while phones are, for the most part, chosen by their users, cars are not – at least not with data collection and tracking in mind.

Now, a new study conducted by Northeastern University researchers and Consumer Reports, a US non-profit, and presented at an ACM conference in October, paints a picture of the car as a device that is not only collecting and transmitting a great deal of data, but also doing it in a way that is not at all transparent to the owner/driver.

This is not the first study to reveal that cars are spying on their owners, but its authors say it is the most comprehensive to date, looking at 21 US vehicles from 19 brands, and 30 companion apps, and the data they transmit to third parties.

The data is not insignificant, either: the researchers found that seven of the apps are transmitting PII such as phone numbers, email addresses, and vehicle identification numbers (VINs), with VINs being the most commonly shared piece of PII.

In the study, titled Automatic Transmission, the authors note that while some data is collected by manufacturers, a lot of it is then shared with third parties, and that is where the real danger to privacy and security of car owners lies.

“VINs are the most commonly shared PII within our sample, including to Google, Microsoft,” the study’s authors said, adding that the seven apps that are transmitting PII to third parties are HondaLink, Lincoln, MyNISSAN, myCadillac, myChevrolet, myBuick, and myGMC.

The study also found that while the number of third parties with which vehicle manufacturers are sharing data is relatively low, the number of third parties that apps for cars are sending data to is much higher.

The authors also note that the data that is transmitted by cars and their apps can reveal “an individual’s ownership status or interactions with a particular vehicle to companies that use this data for advertising, tracking, and analytics.”

The researchers were able to see what data was transmitted by driving the cars on private roads at Consumer Reports’ facility, and then analyzing the traffic. The study reveals that of the 21 vehicles tested, all but two sent traffic to at least one third party, while seven out of 30 apps transmitted sensitive identifiers to third-party companies.

Diagram showing data transmissions between a vehicle, companion mobile app, and first and third-party servers.

The scale of the problem is not the only thing that the study was able to reveal; the authors were also able to determine that the practice is not uniform across the board, with some manufacturers and their apps sending much more data to third parties than others.

The 2021 enforcement action by the US Federal Trade Commission against General Motors as an example of what has been happening with the data collected by cars. The agency at the time acted on reports that several major manufacturers were sharing data from connected vehicles with data brokers and insurers. But this is where the car as a second phone comparison becomes particularly pertinent: a license plate can be used to identify a car to the state, but a VIN and an email address can be used to identify the owner to the advertising industry – without the need to scan anything.

The apps are the worse half of the data collection and ad profiling equation that is the connected car.

Some cars are better than others, but the apps are always the part of the system that the user/owner can, at least in theory, control, by choosing not to install them, or uninstalling them. But given the “convenience” they bring, such as remote start, climate control, and the ability to check on the car’s state, few owners are likely to give them up. Even if they knew, and the study reveals, that some of these apps can be used to remotely open the trunk of the car, and that the researchers were able to verify this capability by using an app to open a car’s trunk.

As for the apps that were tested, and the companies they were sending data to, we have HondaLink sending to Amplitude, Lincoln to ContentSquare, MyNISSAN to Alchemer, and four General Motors apps – myCadillac, myChevrolet, myBuick, and myGMC – to a host of companies, including Adobe, Acxiom, ContentSquare, FullStory, Google, Meta, Microsoft, Pinterest, Snap, and Yahoo.

The study, which looked at 21 US vehicles from 19 brands, and was conducted between October 2024 and August 2025, found that seven of the 30 apps transmit sensitive identifiers to third-party companies. While the study refers to Amplitude as “a product analytics and event tracking platform, not an advertiser,” that does not mean it doesn’t receive identifying information, such as VINs, which are sent by the Honda app.

The categories of personal information the researchers looked for in app traffic were owner-specific, location, and network information. Network information was Wi-Fi SSID and Wi-Fi password.

The study found that HondaLink, the app that accompanies the Honda vehicle, shared the car’s VIN and precise location with Amplitude, a company that provides analytics and tracking services.

The authors note that the data they found was that of the Consumer Reports employee who completed the vehicle purchase, and was found in the app’s traffic in plain text, as well as in hashed form.

The study’s authors said that their first key takeaway was that certain companion apps “share consumer PII with ATA third parties including geolocation, VIN, email” and more.

Another key takeaway is that the study could not decrypt every flow, so what they found is a floor and not a ceiling. In other words, it is likely that the apps and vehicles are sharing more data than the study was able to detect.

The authors of the Automatic Transmission study cannot be accused of burying the lede: “all but two of the vehicles tested send traffic to at least one third party, and seven of 30 apps transmit sensitive identifiers to third-party companies, with wide variation across brands and models.” But who comes out on top – or at the bottom – of this particular table?

“Of the 21 vehicles we tested, 13 contacted Google-associated ATA SLDs,” the study, conducted by Northeastern University researchers in cooperation with the non-profit US consumer product testing organization Consumer Reports, and presented at an ACM conference in October 2026, reveals. And while the paper goes into the technical and business differences between how the various cars’ infotainment systems are built and how that affects data collection, the table with the actual numbers is clear.

It shows that it is not a vehicle with limited-to-full Google integration that ends up contacting the most advertising, tracking, and analytics (ATA) domains – but rather, it is Tesla, and by a large margin. The study found that the Tesla Model 3 contacted 34 unique ATA second-level domains over Wi-Fi, and had 36 integrated third parties, while the Cybertruck had 23 and 37, respectively.

Meanwhile, the Lucid Air and Rivian R1S – which the study said had limited-to-full Google integration – had 9 and 15, and 7 and 18, respectively.

At the other end of the table are the Nissan Ariya, Land Rover Range Rover, Mercedes EQS, and Buick Envista, which contacted no ATA domains over Wi-Fi.

The study explains this by saying that the vehicles at the bottom of the table had “relatively limited functionality in their infotainment system.” And the less your car “talks” to the outside world, the less it leaks. But that’s not a selling point car manufacturers are likely to be eager to promote. And the study found that some of the domains the cars contact are providing services the driver has asked for, such as maps and traffic information. For this reason, the study differentiates between integrated and advertising third parties.

Third parties named in the paper as appearing in the study’s tables are Cloudflare, Microsoft, TomTom, HERE, Mapbox, Meta Platforms, and ByteDance.

Refusing to consent to data collection and sharing by car manufacturers comes with a price – and it’s a high one. A new study shows that, in some cases, it means giving up safety features like lane keeping assistance.

The study, Automatic Transmission, by Northeastern University researchers working with Consumer Reports, a non-profit US consumer product testing organization, looked into 21 US vehicles from 19 brands, and 30 companion mobile apps. And while it may be easy to brush off navigation and over-the-air updates that bring new features and better performance as not essential – “safety enhance” is something that should not be taken lightly. But that’s exactly how it’s presented as a bargaining chip by Rivian – either you let the company collect and share your data, or you “limit or disable” these features.

The study’s authors say that this is one of the ways in which manufacturers make it hard for car owners to opt out of data collection and sharing. Another is to make the process difficult to navigate. And when they do provide a way to opt out, it is often incomplete, the study found.

The researchers also note that while the companies say that contracts with third parties using the data for advertising, tracking, and analytics purposes (referred to as ATA in the study) limit that use to the scope defined in privacy policies – those policies are often “overbroad and expansive.”

In fact, the study says, the privacy policies are often difficult to read and understand, and may not even reflect the actual behavior of the vehicle.

The authors also found that “many” manufacturers do not provide “meaningful” ways to opt out of data collection and sharing, and that privacy policies often do not align with what the device (in this case, the vehicle) actually does.

To make matters worse, the study found that the data collected from cars, including sensitive personal information, is transmitted to third parties, who may then go out of business – taking that data with them. One of the third parties the researchers tried to contact “went out of business before our outreach,” the study reveals.

The study’s second key takeaway is that “many manufacturers do not provide the consumer with meaningful or easy ways to opt out of data collection and sharing.”

The authors looked at the data that is transmitted to third parties and found that most often it is the Vehicle Identification Number (VIN), followed by email addresses, phone numbers, and location.

Honda considers VINs to be “commercial information” that can be used for marketing and advertising, the study said, adding that while manufacturers say that third parties are contractually prevented from using personal data beyond what is set out in privacy policies – those contracts are not available to the public.

As for the third parties, the study said that seven out of 30 apps transmit sensitive identifiers to them, and that 70% of the apps contact more than five unique ATA second-level domains.

The study tested 21 vehicles and found that 13 of them contacted Google-associated ATA second-level domains. The cars with the least amount of data transmitted to third parties were the Toyota Corolla Cross, Nissan Ariya, Land Rover Range Rover, and Mercedes EQS, which had either one or no unique ATA SLDs.

The study’s authors said that this was likely due to these vehicles having less infotainment functionality.

Honda has responded to a study into how cars and their companion apps handle personal data of their users, and that of the vehicle, by saying it has taken steps to “correct” the situation.

The study, “Automatic Transmission” was presented at an ACM conference last month and is based on research conducted by Northeastern University scholars working with non-profit US consumer product testing organization Consumer Reports.

The study tested 21 US vehicles from 19 brands, and 30 companion mobile apps, and found that all but two of the cars sent data to at least one third party, while seven of the apps transmitted sensitive identifiers to third-party companies.

The identifiers include VINs, emails, phone numbers, and location, and the researchers said that VINs were the most commonly shared personally identifiable information (PII) that they found.

The study also showed that seven of the apps sent this data to companies whose business is advertising, tracking, and analytics (ATA).

The researchers said that their study was “opportunistic” because it was limited to vehicles Consumer Reports had on site, and that they were unable to decrypt every data flow since they could not modify the software of the cars.

Another limitation was that the study was not able to establish whether the data collected from vehicles and their apps was actually used by third parties, or if it was sold.

The study also found instances of vehicles and apps contacting servers located in the EU and Canada, which have stricter consumer data rules than the US.

After the researchers disclosed their findings, Honda requested that Amplitude delete all received location data and updated the HondaLink app to no longer send geolocation to Amplitude.

The study also revealed that the Federal Trade Commission brought an enforcement action against General Motors following reporting that said car manufacturers were sharing vehicle data with data brokers and insurers.

The authors of the study published the full lists of the domains they used to label advertising, integrated, and first-party domains on GitHub.

If it still needs to be said: as for what car owners can do, at the least you can think twice before using companion apps, and instead use the car’s physical controls.