Connected Car Data Study: Which Truck and SUV Apps Share Your VIN

Quick Facts:

  • Topic: Connected car data study from Northeastern University and Consumer Reports.
  • Released: September 29, 2026.
  • Scope: 21 vehicles and 30 companion apps tested.
  • Main finding: 7 of 30 apps sent a VIN to outside companies.
  • Flagged apps: myCadillac, myChevrolet, myBuick, myGMC, HondaLink, MyNissan and Lincoln.
  • Trucks and SUVs tested: Chevrolet Blazer, Ford F-150 Lightning, Ram 1500 Bighorn, Rivian R1S and Tesla Cybertruck.
  • Automaker change reported: Honda only.

 7 min read

Connected Car Data Study Overview

New connected car data research names the truck and SUV apps sending your VIN to advertising and analytics companies. Northeastern University researchers worked with Consumer Reports and released the results on September 29, 2026. They tested 21 vehicles and 30 companion apps. Specifically, seven of the apps sent a VIN to outside companies.

Four of the seven belong to General Motors: myCadillac, myChevrolet, myBuick and myGMC. The others are HondaLink, MyNissan and the Lincoln app. However, no FordPass, Ram, Jeep, Rivian or Tesla app made the list.

Still, a clean app does not mean a quiet truck. For example, the Tesla Cybertruck itself contacted 23 advertising and tracking domains over Wi-Fi. Infotainment design drove much of the difference. The Cybertruck and Chevrolet Blazer were among the vehicles with the most outside contacts, and mapping companies such as TomTom, HERE and Mapbox showed up in four or five vehicles each.

Because TomTom, HERE and Mapbox appeared in four or five vehicles each, navigation deserves a backup. Instead, a dedicated handheld GPS like the Garmin eTrex 22x keeps your route off the truck’s internet connection. Likewise, the Rand McNally 2027 Large Scale Road Atlas needs no connection at all. Finally, the eTrex runs on two AA batteries, so pack the Energizer Ultimate Lithium AA 8 Pack as spares.

Offline navigation gear for off-roaders

We earn a commission if you make a purchase, at no additional cost to you.

What the Researchers Found About Connected Car Data

The team collected two kinds of evidence. First, they logged the servers each vehicle contacted over Wi-Fi while parked, idling and driving. Next, they ran each app on an iPhone and decrypted its traffic. Vehicle traffic stayed encrypted, so the researchers saw which domains the trucks contacted, not what the packets carried.

Overall, 19 of 21 vehicles contacted at least one third party, including known advertising and tracking domains. Apps made the picture worse. On average, pairing an app roughly doubled a vehicle’s exposure to advertising and tracking companies. Some pairings added more than 20.

Also, Consumer Reports says 28 of 30 apps sent data to at least one outside advertising or analytics company. Seven sent a VIN, and six of those paired it with an email address or a precise location. The study did not examine driving data such as braking and speed. Consumer Reports covered it in earlier reporting.

One detail changes how you read these numbers. The testers accepted every permission and tracking prompt during setup. Therefore, the results show the accept-everything case, and a more careful setup on your own phone is not covered.

Hand touching a dashboard touchscreen showing a navigation map
Vehicles with full infotainment systems contacted the most outside domains in the study.

Which Truck and SUV Apps Share Your VIN

Notably, General Motors has the longest list of VIN recipients. The study’s table shows each of the four GM apps sending VINs to ten outside companies. Those include Adobe, Google, Meta, Microsoft, Snap and Yahoo, plus Acxiom, which Northeastern calls a data broker.

Because I drive a 2025 Chevy Colorado ZR2, the Chevrolet line hit close to home. The study did not test a Colorado, so I have no way to say what any specific truck sends.

HondaLink sent VINs and location data to Amplitude, an analytics vendor. After the findings reached Honda, it told Amplitude to delete the location data. It also updated its app to stop sending geolocation. Meanwhile, MyNissan sent VINs to Alchemer, and the Lincoln app sent VINs to ContentSquare.

The tested vehicles show a wide spread. Because four of the five are electric, treat these as snapshots, not brand rankings. Over Wi-Fi, the Cybertruck contacted 23 advertising and tracking domains and the Chevrolet Blazer contacted 7. In contrast, the Rivian R1S contacted 2, the F-150 Lightning 1 and the Ram 1500 Bighorn 0. Pairing an app then added more companies: 23 for the Blazer and 13 for the Lightning. The R1S gained 9 and the Ram 4.

Among Stellantis vehicles, the researchers tested a Dodge Hornet, a Fiat 500e and a Ram 1500 Bighorn. No Stellantis app made the flagged list, the Jeep app included. However, the study tested a Jeep app but no Jeep vehicle. I have owned five Jeeps. Because the vehicle itself went untested, I would not read the Stellantis result as a clean bill of health for a Wrangler or Gladiator.

What Automakers Said and a Separate GM Settlement

The researchers contacted 17 automakers and heard back from 14. In response, all 14 pointed to contracts with outside vendors. Seven said the consumer must read and accept each third-party agreement.

For example, General Motors told Northeastern it shares data only with service providers under strict contract limits. It said those providers are barred from selling, sharing or using the data for their own purposes. Honda said the VIN and location data was never available for independent use or sale.

Separately, GM agreed earlier this year to settle a California case for $12.75 million. The case covered OnStar driving data sold to data brokers from 2020 to 2024. This settlement is a different matter from the study, and it needs a court’s approval to become final.

Hand holding a phone with app permission toggles for location and privacy, tied to connected car data opt-outs
Each automaker sets its own route for opt-out requests, usually a form or an app setting.

What This Means for You

First, weigh what you give up. Consumer Reports says opting out usually costs features, such as roadside assistance, crash detection and remote door locks. Tesla, for example, shows owners who decline its data agreement a warning about reduced functionality, serious damage or inoperability.

Next, file the three requests. The first is Right to Opt Out and the second is Right to be Deleted. Third comes Right to Limit the Use and Disclosure of My Sensitive Personal Information. Each automaker sets its own route, usually an online form or a privacy setting in the vehicle’s app. Some also limit the requests to states with privacy laws. In addition, decline optional tracking prompts when you set up an app. The study did not test whether declining reduces what an app sends.

In my view, the VIN pairing is the finding to act on first. A VIN alone looks harmless. Consumer Reports notes a VIN plus an email address lets a company link you to a commercial consumer profile.

Your VIN also has honest uses, such as recall lookups. We cover two in our Silverado airbag recall report and our Ram 1500 backup camera recall guide. Dealer-installed hardware is a separate source of location data, which we covered in our guide to dealer-installed GPS trackers. Keep the app if you use what it does. Before you file, ask each automaker which features a request turns off.

However, opting out usually costs roadside assistance, crash detection and remote door locks. Therefore, carry your own basics, starting with the GOOLOO GP4000 Jump Starter. Next, the VIAIR 300P 12V Portable Tire Inflator refills a soft tire. Finally, the ARB 10000011 Speedy Seal 2 Tire Repair Kit plugs a puncture.

Roadside basics to carry yourself

We earn a commission if you make a purchase, at no additional cost to you.

Final Thoughts

Here is where I land. This study does not prove your truck is spying on you. The researchers were unable to read the vehicle packets and accepted every app prompt. They also tested only 21 vehicles out of millions. Still, it does show how many outside companies sit behind the app you use to lock your doors.

I have owned five Jeeps and now drive a Colorado ZR2. Connected features such as remote locking and tire pressure alerts have real appeal. Even so, I want the choice to be clear. Right now, declining often costs you features.

Therefore, if you own a Chevrolet, GMC, Buick, Cadillac, Honda, Nissan or Lincoln, ask your automaker what an opt-out turns off, then file the requests this week. For any other brand, ask your automaker what its app shares with outside companies. The full paper lists every app tested in its Table 2, so check it for your brand.

Connected Car Data FAQ

Which car apps share your VIN with outside companies?

Seven apps were flagged: myCadillac, myChevrolet, myBuick, myGMC, HondaLink, MyNissan and the Lincoln app. Each sent a VIN to at least one outside company. The study found six of the seven also paired the VIN with an email address or location data.

Does the Ford, Ram or Jeep app share connected car data?

No FordPass, Ram or Jeep app is among the seven flagged apps, though Ford’s Lincoln brand is. The study tested a Jeep app but no Jeep vehicle. However, the Ram app still added four advertising and tracking companies to the Ram 1500 Bighorn. Being unflagged is therefore not the same as being private.

Is opting out of connected car data sharing possible?

Often yes. Consumer Reports lists three requests. The first is Right to Opt Out and the second is Right to be Deleted. Third comes Right to Limit the Use and Disclosure of My Sensitive Personal Information. You usually file them through an online form or the app’s privacy settings. Expect to lose some features.

What happens if you decline a car’s data agreement?

According to Consumer Reports, popular features sometimes stop working. In some cases the vehicle will not drive at all. Tesla shows a warning about reduced functionality, serious damage or inoperability.

Did any automaker change after the study?

Honda is the only automaker the study reports making a change. It told its analytics vendor Amplitude to delete the location data it had received. Its app also stopped sending location. The others pointed to contracts, an embedded browser or the consumer, and three never replied.

Related Articles

Latest Articles

- Advertisement -