← Food Delivery
C

Uber Eats

Notable issues
Uber · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.ubercab.eats
Manufacturer: Uber Technologies

The bottom line

Hackers stole 57 million Uber users' data -- names, emails, phone numbers, and 600,000 driver license numbers. Uber's Chief Security Officer Joe Sullivan paid the hackers $100,000 to delete the data and keep quiet. He disguised the ransom as a bug bounty reward. He made the hackers sign NDAs. He hid the breach from the FTC, which was already investigating Uber for a previous breach. In October 2022, Sullivan became the first C-suite executive in American history criminally convicted for covering up a data breach. Obstruction of justice. Misprision of felony. The security officer's job was to protect user data. Instead, he protected Uber's stock price. Uber built a tool called "God View." It showed every rider's real-time location on a map. Employees used it to stalk ex-partners. They used it to track celebrities. They used it to watch journalists. When BuzzFeed reporter Johana Bhuiyan visited Uber's office, an executive tracked her arrival using God View -- then told her about it. Another executive, Emil Michael, suggested spending $1 million to investigate journalists who criticized the company. At launch parties, Uber showed God View to guests as entertainment -- real people, tracked live, without consent, for fun. The FTC ordered 20 years of privacy audits. Uber had turned its riders into a surveillance screensaver.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
B
Parent company: Uber
$148M breach cover-up
1 structural risks · 2 products →
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
8Contradictions
0Critical
6High
2Medium
12Sources
Findings by concern
Spying 4/4 EXTREME 4 findings
⚡ highpolicy claims vs third party research
Uber built a tool called "God View." It showed every rider's real-time location on a map. Employees used it to stalk ex-partners. They used it to track celebrities. They used it to watch journalists. When BuzzFeed reporter Johana Bhuiyan visited Uber's office, an executive tracked her arrival using God View -- then told her about it. Another executive, Emil Michael, suggested spending $1 million to investigate journalists who criticized the company. At launch parties, Uber showed God View to guests as entertainment -- real people, tracked live, without consent, for fun. The FTC ordered 20 years of privacy audits. Uber had turned its riders into a surveillance screensaver.

What they claim: Uber's privacy policy states that user location data is accessed only for "legitimate business purposes" with "strict access controls."

What we found: Uber built an internal tool called "God View" that displayed the real-time location of every Uber rider on a map. Employees used it recreationally -- tracking ex-partners, monitoring celebrities, and watching journalists. BuzzFeed reporter Johana Bhuiyan was tracked arriving at Uber's office using God View by an Uber executive who then bragged about it. Executive Emil Michael suggested spending $1 million to hire opposition researchers to dig up dirt on journalists investigating the company. God View was demonstrated at Uber launch parties as entertainment -- showing attendees the live movements of real riders without their knowledge. The FTC settlement required Uber to submit to 20 years of privacy audits.

⚡ highpolicy claims vs app permissions
You order dinner on Uber Eats. Uber tracks your location. Not just when you order -- Uber previously tracked you for five minutes after delivery, just to see where you went next. Drivers are tracked continuously. All this location data flows across Uber's entire ecosystem -- rides, eats, freight -- building a comprehensive map of everywhere you go. The FTC already caught Uber lying about location tracking once. The company that built "God View" to watch riders in real-time now collects location data for "personalization, marketing, analytics, and fraud detection." You ordered food. Uber ordered your movements.

What they claim: Uber Eats states it collects location data "to connect you with nearby restaurants" and "facilitate deliveries."

What we found: The Uber Eats app shares Uber's ride-hailing location infrastructure, collecting precise GPS data continuously. Uber previously tracked rider location for five minutes after trip completion until backlash forced a change. The Uber driver app tracks driver location continuously during active hours. Uber settled with the FTC over deceptive location tracking practices. Location data flows across Uber's entire platform ecosystem -- rides, eats, freight -- creating a comprehensive movement profile. Uber's privacy policy permits using location data for "personalization, marketing, analytics, and fraud detection" beyond the stated delivery purpose.

⚡ highpolicy claims vs app permissions
You download Uber Eats to order dinner. The app wants your location, camera, microphone, contacts, and phone state. Your ordering data joins your ride data in Uber's ecosystem -- where you live, work, eat, travel, and spend. Uber sells this to advertisers. This is the company where employees stalked people with "God View," where the security chief was convicted of hiding a breach, where 124,000 leaked documents showed executives calling people "expendable." They have your home address, your workplace, your eating habits, and your daily routine. They've already proven what they do with that kind of access.

What they claim: Uber Eats states it collects data "necessary to provide you with the Uber Eats service."

What we found: The Uber Eats app requests: precise location, camera, microphone, contacts, phone state, and storage access. Data collected through Uber Eats is shared across Uber's entire platform -- rides, freight, and advertising. Uber launched an advertising division that monetizes rider and eater behavior data, selling targeted ads to restaurants and retailers. The combined Uber ecosystem creates a profile covering: where you live, where you work, where you eat, what you eat, when you travel, how much you spend, and your daily movement patterns. This is the same platform where employees used "God View" to stalk people, the CSO was convicted of covering up a data breach, and 124,000 leaked documents showed the CEO called users of the platform "expendable."

⚫ mediummarketing claims vs third party research
Uber tells drivers they're independent. The algorithm tells them where to go, what to charge, and which orders to accept. Decline too many? The algorithm punishes you with fewer orders. The company that called drivers "expendable" in leaked documents spent $200 million to ensure they couldn't access health insurance or minimum wage. Drivers can be "deactivated" -- permanently fired -- by algorithm, with no warning and no appeal. You're independent the way a puppet is independent: free to move in any direction the strings allow.

What they claim: Uber Eats promotes the driver experience as "flexible work" where drivers "choose when, where, and how long" they work.

What we found: Uber Eats drivers are subject to algorithmic management that controls virtually every aspect of the delivery process. Surge pricing algorithms manipulate earnings in real-time. Declining orders reduces a driver's priority in the dispatch algorithm. Uber's "upfront pricing" system obscures how fares are calculated, reducing driver transparency about their own earnings. Drivers report sudden "deactivation" -- permanent account suspension -- with no warning, no explanation, and no meaningful appeal process. The Uber Files revealed CEO Travis Kalanick considered drivers "expendable." Uber spent over $200 million on California's Prop 22 (with DoorDash and Lyft) to ensure these "independent" workers couldn't access employment benefits.

Security 4/4 EXTREME 3 findings
⚡ highpolicy claims vs regulatory findings
Hackers stole 57 million Uber users' data -- names, emails, phone numbers, and 600,000 driver license numbers. Uber's Chief Security Officer Joe Sullivan paid the hackers $100,000 to delete the data and keep quiet. He disguised the ransom as a bug bounty reward. He made the hackers sign NDAs. He hid the breach from the FTC, which was already investigating Uber for a previous breach. In October 2022, Sullivan became the first C-suite executive in American history criminally convicted for covering up a data breach. Obstruction of justice. Misprision of felony. The security officer's job was to protect user data. Instead, he protected Uber's stock price.

What they claim: Uber states it is "committed to protecting the data of our users" and maintains "industry-leading security practices" with transparent incident disclosure.

What we found: In 2016, attackers stole personal data of 57 million Uber riders and drivers, including 600,000 driver license numbers. Chief Security Officer Joe Sullivan paid the hackers $100,000 through Uber's bug bounty program, disguising the ransom payment as a legitimate security reward. Sullivan directed the hackers to sign NDAs and delete the stolen data. He concealed the breach from the FTC, which was already investigating Uber for a previous breach. Sullivan was convicted of obstruction of justice and misprision of felony in October 2022 -- the first C-suite executive in history criminally convicted for covering up a data breach. He was sentenced to three years' probation. Uber paid $148 million to settle with all 50 US states.

⚡ highmarketing claims vs third party research
Uber's former chief lobbyist Mark MacGann leaked 124,000 internal documents. He told the BBC: "We sold people a lie." The documents showed Uber lobbied Emmanuel Macron, Joe Biden, and Olaf Scholz personally. When police raided Uber offices, employees activated a "kill switch" that cut off access to company systems -- destroying evidence in real time. CEO Travis Kalanick texted that "violence guarantee[s] success" when discussing driver protests. He called drivers "expendable." This is the company that delivers your dinner. Its CEO considered the people who bring it to your door disposable, lobbied world leaders to keep them that way, and built a kill switch to hide the evidence.

What they claim: Uber positions itself as a technology platform that empowers drivers and riders while working constructively with regulators.

What we found: In July 2022, the International Consortium of Investigative Journalists published the "Uber Files" -- 124,000 leaked internal documents from 2013-2017. The documents revealed: Uber directly lobbied heads of state including Emmanuel Macron, Joe Biden, and Olaf Scholz to weaken taxi regulations. An internal "kill switch" allowed Uber to remotely cut off access to its systems during police raids on Uber offices, preventing law enforcement from accessing evidence. CEO Travis Kalanick texted that "violence guarantee[s] success" regarding driver protests against taxi regulation. Kalanick wrote that drivers were "expendable." Mark MacGann, Uber's former chief lobbyist for Europe, was the whistleblower. He told the BBC: "We sold people a lie."

⚡ highpolicy claims vs third party research
Walk into any pub in Australia looking over 25 and nobody asks for ID. Order a beer on Uber Eats and a driver photographs your entire licence, sends it to a company in the United States you've never heard of, and they copy your name, birthday, and licence details. The photo gets deleted "shortly after" — but your identity data stays in the US forever, or at least "as long as needed." There's no "just look at my ID" option. Your partner can't accept it for you. The law says a glance is enough. Uber says hand over the data or go thirsty.

What they claim: Uber frames its mandatory ID photo scan on every alcohol delivery as required by Australian law, and states that consumer law rights are preserved under its terms of use.

What we found: Australian Responsible Service of Alcohol law requires age verification only if the recipient appears under 25 — the same standard used in pubs and bottle shops. The Retail Drinks Code of Conduct (v4, February 2026) confirms this. Uber exceeds the legal standard in every dimension: the driver app photographs the customer's full government-issued licence on every delivery regardless of age, transmits the image to a US-based contractor who extracts name, date of birth, ID type, and expiry date, then stores the extracted data encrypted in the United States with no defined retention period — just "as long as needed." The name on the ID must match the order, so a partner or housemate cannot accept the delivery — a restriction absent from RSA law. There is no option for the driver to perform a visual check instead of a photo scan. Uber states: "If you are unable to present an approved evidence of age document, you should not order alcohol via the Uber Eats App." The law requires a glance at an ID. Uber requires a photograph, overseas data transfer, and indefinite storage — and frames it as compliance.

Honesty 3/4 HIGH 1 finding
⚫ mediummarketing claims vs third party research
Susan Fowler was propositioned by her manager on her first day at Uber. She reported it to HR. HR told her the harasser was a "high performer" and it was probably "his first offense." Other women told Fowler they had reported the same man -- it wasn't his first offense. HR gave Fowler a choice: transfer to another team, or stay and accept a bad performance review. She wrote a blog post. It triggered an investigation by former Attorney General Eric Holder that found 215 complaints, including 47 for sexual harassment. Twenty people were fired. CEO Travis Kalanick was forced out. Board member Arianna Huffington said "one woman" didn't prove a pattern. There were 215 complaints.

What they claim: Uber states it fosters a "diverse and inclusive workplace" and takes employee complaints seriously through established HR processes.

What we found: In February 2017, engineer Susan Fowler published a blog post describing systematic sexual harassment at Uber. Her manager propositioned her on her first day. When she reported it to HR, she was told the harasser was a "high performer" and it was "his first offense" -- but other women told Fowler they had reported the same person. HR's response: transfer Fowler or accept that her performance review would suffer. Fowler's blog triggered an investigation led by former US Attorney General Eric Holder. The investigation found 215 complaints including 47 for sexual harassment. Twenty employees were fired. CEO Travis Kalanick was forced to resign in June 2017. Board member Arianna Huffington told a press conference that "one woman" complaining didn't prove a pattern -- while sitting on a report documenting 215 complaints.

Sources