Uber promises your data is shared only for Uber's services. Then its CTO tells TechCrunch the company is building a commercial data business selling footage of real people — unblurred — to 25 self-driving companies. When you open the Uber app and book a ride, you don't consent to your face ending up in Wayve's training server in London or Baidu Apollo's model in Dubai. The privacy policy doesn't say that. The CTO did. Uber built an internal tool called "God View" that displayed the real-time GPS location of every rider on a live map — and gave broad employee access with no oversight. Executive Josh Mohrer used it to track a BuzzFeed News journalist investigating the company. At a 2014 dinner, another executive, Emil Michael, floated spending $1 million to hire investigators to dig up dirt on critical journalists' personal lives and families. Employees used God View to stalk ex-girlfriends. Uber knew about the abuse and didn't restrict access until reporters exposed it.
What they claim: Uber says it collects location data to provide and improve its services.
What we found: In 2016, Uber changed its app to collect rider location data for 5 minutes after trips ended. Uber also deployed Greyball — a tool using location data, credit card info, and device identifiers to identify and evade government regulators. Greyball showed fake versions of the Uber app to suspected regulators with ghost cars and non-functional ride requests. Used in Portland, Philadelphia, Boston, and multiple countries.
What they claim: Uber states that driver data is used to improve the driver experience and ensure safety.
What we found: Uber monitors drivers' every acceleration, brake, phone touch, and GPS coordinate while classifying them as independent contractors. Drivers are deactivated by algorithm with no meaningful appeal. The UK Supreme Court ruled in 2021 that Uber drivers are workers, not contractors. Amazon warehouse injury rates parallel: surveillance for extraction, not safety.
What they claim: Uber states it is committed to transparency and promptly reports security incidents as required by law.
What we found: In 2016, hackers stole data of 57 million riders and drivers. CSO Joe Sullivan paid the hackers $100,000 through the bug bounty program and had them sign NDAs to conceal the breach — while Uber was under FTC investigation for a previous breach. CEO Travis Kalanick knew. Sullivan was criminally convicted of obstruction of justice in October 2022 — first corporate executive convicted for concealing a data breach. Uber paid $148 million to settle with all 50 states.
What they claim: Uber states it maintains appropriate security measures.
What we found: In September 2022, an 18-year-old hacker breached Uber through social engineering — texting an employee pretending to be IT support. The hacker gained access to Slack, AWS, financial dashboards, and the HackerOne vulnerability database. The attacker posted in Uber's Slack announcing the breach. This was Uber's third major breach. The Uber Files leak of 124,000 documents revealed CEO Kalanick personally texted Emmanuel Macron to lobby for favorable regulations.
What they claim: Uber states its pricing is transparent and based on time and distance.
What we found: Uber's surge pricing charged riders 4x normal fares during the 2014 Sydney hostage crisis. During Hurricane Sandy, $27 rides surged to $175. Uber also tested route-based pricing — charging different riders different amounts for the same trip based on what the algorithm predicted they were willing to pay rather than actual time and distance.
What they claim: Uber's privacy policy states it shares personal data only to provide and improve services, and limits data sharing to authorised business purposes.
What we found: Uber's CTO publicly described AV Labs as selling labelled sensor data — including unblurred footage of real people — to 25+ AV partners as a commercial product. Riders and bystanders captured by Uber's fleet-mounted sensors have no meaningful consent mechanism and no disclosure that their images are being commercially licensed. Uber's 10-Q flags third-party data risk as material but does not disclose which partners receive what data.
What they claim: Uber's privacy policy states access to personal data is limited to authorized personnel with a business need.
What we found: Uber employees used an internal tool called God View to track real-time locations of riders without authorization. Executive Josh Mohrer used it to track a BuzzFeed News journalist. At a 2014 dinner, executive Emil Michael suggested spending $1 million to investigate critical journalists' personal lives. Multiple employees used God View to stalk ex-girlfriends.
What they claim: Uber's privacy policy states it transfers data internationally in compliance with applicable data protection laws.
What we found: The Dutch DPA fined Uber EUR290 million in 2024 for transferring European drivers' personal data — location, identity documents, criminal records, medical data — to US servers without any legal transfer mechanism for over two years (August 2021 to November 2023). One of the largest GDPR fines ever. A prior EUR10 million fine was issued in 2023 for failing to inform drivers about data practices.