What we found
Deliveroo: DDeliveroo requires riders to scan their face before they can start work.
Deliveroo implemented mandatory facial recognition check-ins requiring riders to take selfies before starting shifts. The system used biometric matching against riders' profile photos to verify identity. Independent research and rider reports documented disproportionate failure rates for darker-skinned riders due to algorithmic bias in the facial recognition technology. Riders locked out by false negatives could not work -- losing income with no immediate human appeal process. The algorithmic decision was treated as final. Riders reported being permanently deactivated after the system repeatedly failed to recognize them. A technology designed to "protect" rider accounts became a mechanism that disproportionately prevented Black and brown riders from earning a living.
HelloFresh: CHelloFresh sent 80 million spam messages in seven months.
The UK ICO fined HelloFresh £140,000 for sending 80,893,013 spam messages (79.7M emails + 1.1M SMS) over seven months. The consent mechanism bundled marketing with age verification, and users were not told they would receive messages for 24 months after cancelling.
Marley Spoon: CYou signed up for meal kits.
Marley Spoon implemented mParticle as a Customer Data Platform in 2022 to build "a single customer view" across five brands (Marley Spoon, Dinnerly, Chefgood, Bezzie, Liloomi). The platform unifies data into single customer profiles for cross-selling. If you cancel Marley Spoon, they use your data to target you with promotions for their other brands. Your meal preferences, subscription history, and churn reasons are all combined into one advertising profile.
Uber Eats: CHackers stole 57 million Uber users' data -- names, emails, phone numbers, and 600,000 driver license numbers.
In 2016, attackers stole personal data of 57 million Uber riders and drivers, including 600,000 driver license numbers. Chief Security Officer Joe Sullivan paid the hackers $100,000 through Uber's bug bounty program, disguising the ransom payment as a legitimate security reward. Sullivan directed the hackers to sign NDAs and delete the stolen data. He concealed the breach from the FTC, which was already investigating Uber for a previous breach. Sullivan was convicted of obstruction of justice and misprision of felony in October 2022 -- the first C-suite executive in history criminally convicted for covering up a data breach. He was sentenced to three years' probation. Uber paid $148 million to settle with all 50 US states.
DoorDash: CDoorDash lost 4.9 million customer records.
In May 2019, attackers accessed 4.9 million records belonging to customers, Dashers, and merchants through a third-party service provider. Exposed data included names, email addresses, delivery addresses, order histories, hashed passwords, and the last four digits of payment cards. Approximately 100,000 Dashers had their driver license numbers stolen. DoorDash did not discover the breach until September 2019 -- four months after it occurred. The company had suffered a previous unreported breach in 2018 affecting a similar number of users. DoorDash notified affected users only after the breach became public knowledge.
Grubhub: CThe FTC sued Grubhub for lying.
The FTC sued Grubhub in June 2022 for multiple deceptive practices. Grubhub charged diners surprise fees at checkout that weren't disclosed when browsing -- including delivery fees, service fees, and "small order fees" that appeared only at the final purchase step. Grubhub listed restaurants on its platform without their permission, leading to orders placed with restaurants that had no agreement with Grubhub and couldn't fulfill them properly. Grubhub marketed "free" delivery while charging inflated menu prices and service fees. The company also made deceptive earnings claims to recruit delivery drivers. The FTC settlement required $25 million in payments. Grubhub's business model relied on hidden fees and phantom restaurant listings to create the appearance of a larger, cheaper platform than it actually was.
Menulog: CYou order dinner through Menulog in Sydney.
Menulog is owned by Just Eat Takeaway.com NV, headquartered in the Netherlands, which operates food delivery platforms across 20+ countries. Menulog's privacy policy permits sharing customer data with "related bodies corporate" -- meaning Australian user data flows to the Dutch parent company and across Just Eat Takeaway's global network. Customer information including order history, delivery addresses, payment details, and behavioral data is subject to data practices governed by multiple jurisdictions with varying privacy protections. Australian customers have no practical visibility into which countries process their data, which entities access it, or what protections apply in each jurisdiction. The Australian Privacy Principles require disclosure of overseas data transfers, but Menulog's disclosures provide only generic references to "related bodies corporate" without naming specific countries or entities.
Instacart: CYou ordered groceries.
Instacart's S-1 filing (September 2023 IPO) revealed that advertising is a core revenue driver, not just delivery fees. Instacart's Carrot Ads platform allows CPG brands like Pepsi, Procter & Gamble, Coca-Cola, and Nestlé to target ads to customers based on their purchase history. Your grocery data tells advertisers more about your health than almost any other data source: diabetic food purchases reveal diabetes, gluten-free products reveal celiac disease, prenatal vitamins reveal pregnancy, alcohol purchases reveal drinking habits, baby food reveals a new child. Instacart partners with 1,500+ retailers, creating a unified purchasing database across grocery chains. The company stated in its S-1: "We generate revenue from advertising" -- not just from delivering your groceries. Your shopping list is an advertising product.