Researchers at Northeastern University and the nonprofit consumer group Consumer Reports measured the traffic between connected cars and their companion smartphone apps. They found cases in which an app sent a vehicle identification number (VIN) and the owner's personal information to the same outside company.

The study, which the university described on September 29, shows that examining a vehicle's own communications is not enough to capture the data flows that link a car to its owner. Honda says that after researchers raised the issue, it stopped HondaLink from sending location data to a usage-analytics service.

The number of recipients is not the only concern. What matters is which pieces of information are combined before being sent out, and whether users can choose whether that sharing happens. University announcement

AD

Vehicles and apps reveal different information

The paper, titled "Automatic Transmission," has been peer-reviewed and accepted to ACM's Internet Measurement Conference (IMC) 2026.

The study covered 21 vehicles from 19 brands sold in the U.S. market, plus 30 iOS apps. The vehicles were 2022–2025 models, and measurements ran from October 2024 to August 2025. The app analysis used 32 vehicles, which only partly overlap with those used in the vehicle-traffic tests. Paper

For the vehicle tests, researchers routed traffic through a Wi-Fi connection they provided and recorded where it went. They measured 30 minutes while the car was parked, 30 minutes while in-car features were being used, and 15 minutes of driving on a private course.

Of the 21 vehicles, 19 connected to at least one third-party service. Eleven of them connected to services involved in advertising, tracking, or usage analytics.

The contents of that traffic were encrypted, however, so the researchers could not read them. Knowing which service a car connected to is not the same as confirming that location or driving history was sent there.

For the apps, the researchers installed a verification certificate on an iPhone and examined the contents of traffic they could decrypt. They logged into existing vehicle accounts and granted every permission, including location and tracking.

Some authentication traffic used "certificate pinning," which trusts only specific certificates, and its contents could not be inspected.

What the study could confirm differs across vehicle destinations, personal data sent by apps, and what happens to data after it is received.

Stage examined What the measurements confirmed What these results alone cannot show
Traffic from the vehicle Destinations of Wi-Fi traffic; third-party connections in 19 of 21 vehicles Personal data inside encrypted traffic; the contents of most cellular traffic
Traffic from companion apps Contents of decryptable traffic; VINs sent externally by 7 of 30 apps Contents of traffic that could not be decrypted; behavior when permissions are denied or in other regions or operating systems
After an outside company receives data Not directly observed in the traffic measurements Resale or onward sharing after receipt; profiling of users

This table organizes the paper's methods, limits, and results into three stages. Testing where a vehicle's traffic goes and checking what personal data an app sends cover different scope. Paper: methods and results, Research team's published results

The vehicle-side measurements were also mainly of Wi-Fi traffic.

The researchers also ran tests with a signal-blocking tent on 11 electric vehicles. They captured cellular traffic only from a 2024 Tesla Model 3, and could not decrypt its contents.

So for vehicles where no third-party connection was found, it cannot be said that there is no data sharing at all once other routes, such as cellular, are included.

Nor can these results be assumed to apply to services in Japan, to Android versions, or to the latest versions of the apps as of 2026.

The most notable finding in the app analysis is that VINs and other personal information were going to the same companies.

A VIN is a unique identifier assigned to each vehicle and generally stays the same throughout its life. That makes it a handle for continuously identifying the same car.

A VIN can sometimes be read from outside the car, so it is not entirely secret. But a VIN alone does not normally reveal the owner's email address.

According to Table 6 of the paper, HondaLink sent the VIN and location data to Amplitude, and MyNISSAN sent the VIN and email address to Alchemer.

External VIN transmission was also confirmed in GM's myCadillac and myChevrolet apps, and similar transmission was found in myBuick and myGMC. In these apps, some recipients also received information such as email addresses.

For example, myGMC sent the VIN to Contentsquare, which also received location data, a phone number, and an email address. Paper: app measurement results

Of the seven apps found sending VINs, six also sent other personal information to the same service. VIN transmission was also confirmed for Lincoln's app.

Not all seven apps sent location data or email addresses, though. The types of information and the recipients vary by app.

If a recipient receives a VIN and an email address together, that can help tie a specific car to its user. A VIN combined with location data can associate a specific vehicle with where it is.

The paper warns that such combinations could enable tracking across multiple services.

That said, this describes a risk created by combining multiple identifiers. The measurements did not prove that recipients actually built detailed profiles of users or sold the information.

Using a companion app also increased the number of companies contacted.

According to Figure 6 of the paper, for many vehicles the number of advertising, tracking, and analytics-related companies contacted by the vehicle and app combined was at least double that of the vehicle alone.

Among companies the vehicle alone did not contact, the app newly connected to 26 for the Cadillac Lyriq and 25 for the Toyota Corolla Cross.

That is a count of companies contacted, however, and does not mean the amount of personal data sent doubled. Paper: vehicle and app comparison

This is why examining only the in-car system or the vehicle's traffic is insufficient for assessing connected-car privacy.

Installing the app and registering a vehicle to an account can create a path by which identifiers that were separate on the vehicle and the owner's personal information reach the same outside company.

AD

Honda's halted location transmission and the automakers' explanations

The paper describes Amplitude, the recipient of HondaLink's data, as a service that analyzes product usage and operations rather than an advertising company.

Using an outside analytics service is not the same as selling users' personal data for advertising.

When researchers contacted Honda, the company said it had asked Amplitude to delete all location data already received and had updated the app so that it no longer sends location data.

Honda spokesperson Andrew Quillin confirmed the response to the university. He said Amplitude is contractually prohibited from using or selling the information it receives for its own purposes, and that using HondaLink is optional. Paper: manufacturer inquiries, University article with Honda's response

What can be confirmed about Honda's response is limited to stopping location transmission and requesting deletion of data already received.

No third party has audited whether Amplitude actually completed the deletion, and the research team did not confirm that transmission of all information, including the VIN, has stopped.

Still, the fact that the types of information sent changed after researchers raised the issue suggests that the analytics mechanisms built into apps leave room for review.

A GM spokesperson told the university that the company shares information only with parties necessary to provide services to customers, under strict contracts. The spokesperson added that recipients are prohibited from using, selling, or sharing the information for their own purposes. GM's response

This is an explanation from the manufacturer about the purpose of data sharing and how it is handled after receipt, and it should be considered separately from what researchers observed in actual traffic.

Contracts can restrict how data is used after receipt. But for users to understand which companies receive which information and for what purpose, clear explanations are needed separately.

The paper points out that even when manufacturers' privacy policies mention possible sharing with third parties, the specific recipients and purposes are often not clear enough.

Research that measures actual traffic and systems that govern data use through contracts examine different things.

Can users decline data sharing and still use the features they need?

Some third-party traffic comes from web pages displayed inside companion apps or from services built into in-vehicle software.

In their responses to the researchers, five companies cited in-app browsers, saying that web pages opened there can generate traffic to third parties.

Separately, seven companies said users must check the terms of the providers of third-party software and services used in the in-car system.

In other words, reading an automaker's own privacy policy may not reveal how data is handled by web pages shown in the app or by outside services used in the car. Paper: analysis of manufacturer responses

That raises the question of how far a vehicle's necessary online features can be separated from optional usage analytics and tracking.

As Honda says the app is optional, not using the app at all is one choice.

Whether users can keep the features they need while refusing only data sharing for unrelated purposes is a different question.

The study did not compare cases where app permissions were granted with cases where they were denied. It therefore cannot say across manufacturers which features become unavailable when data sharing is refused.

There is precedent for consent and user choice becoming a concrete regulatory issue.

On January 14, 2026, the U.S. Federal Trade Commission (FTC) announced a final settlement order over allegations that GM and OnStar collected, used, and sold precise location and driving behavior data without sufficient consent.

The order bars disclosing such information to consumer reporting agencies for five years.

This was a separate case from the traffic measurements, and it is not a measure prohibiting all automakers from sharing data with any third party. FTC announcement of final order

The order remains in effect for 20 years. It also requires affirmative express consent when collecting the covered information and a mechanism for U.S. users to request access to or deletion of their data.

It also requires a way to disable precise location collection in vehicles equipped for it.

Exceptions exist, such as providing location information to emergency responders, and the order does not blanket-prohibit data processing essential to providing a service.

The problem the measurement study highlights cannot be solved simply by reducing the number of recipients.

If VINs and owner information must go to the same company, users should be told why. Mechanisms that separate data processing essential to connected services from optional usage analytics and tracking, and let users choose, are also important.

What automakers should make clear is which features remain available if data sharing is declined, and, if sharing is allowed, which companies receive which information and for what purpose.

If retention periods and the scope of deletion can also be checked, users would no longer face a binary choice of using or not using the app. They could decide based on the features they need and the level of data sharing they find acceptable.