When you order dinner through DoorDash or pick up groceries through Instacart, the transaction that happens on your phone is much larger than the one that shows up on your credit card statement. You’re not just exchanging money for food. You’re exchanging a detailed, timestamped record of your dietary habits, your home address, your work schedule, your neighborhood, and in some cases, intimate inferences about your health for a delivery service.
Independent privacy audits have given DoorDash a score of 30 out of 100 and Instacart a score of 22 out of 100 on privacy practices. For context, those rankings put food delivery apps among the worst-performing consumer app categories for user privacy — scoring below even most social media platforms on certain dimensions.
This isn’t an accident. It reflects a business model where user data is as valuable as the delivery revenue itself.
What Food Delivery Apps Actually Collect
The data collection starts before you place your first order and continues long after the app is closed.
Location Data
Food delivery apps need to know where to deliver food, which means they collect your precise GPS coordinates. But most of them collect location data far more broadly than delivery routing requires.
DoorDash’s privacy policy discloses that it collects “precise or approximate location information” — including when the app is running in the background. Instacart similarly collects location data and uses it to power services beyond routing, including personalization and advertising targeting.
The distinction matters because a location history over weeks or months reveals patterns that go well beyond your delivery address. It shows where you sleep, where you work, which gym you go to, whether you visit medical clinics, which religious buildings you attend, and what bars you frequent. A delivery address is one data point. A location history is a behavioral profile.
Order History
Every order you’ve ever placed is retained and linked to your identity. That order history isn’t just a record of what you ate — it’s a database of your dietary patterns, your budget, how often you cook versus order, and which products you buy repeatedly.
For grocery delivery platforms like Instacart, the order history is particularly sensitive. Grocery purchases reveal far more than food preferences. They can indicate pregnancy (prenatal vitamins, specific produce categories), chronic health conditions (diabetic-specific products, blood pressure monitors, low-sodium items), mental health status (sleep aids, anti-anxiety supplements), religious practices (halal or kosher categories), and household composition (baby food, children’s medications, multiple dietary profiles).
None of this requires the platform to make explicit inferences. The raw purchase history, retained indefinitely and linked to your identity, contains that information implicitly.
Device and Behavioral Data
Beyond location and orders, these apps collect device identifiers, IP addresses, browsing behavior within the app, which listings you viewed without ordering, how long you spent on certain menus, and engagement patterns across sessions.
Instacart’s privacy disclosure reveals the app integrates 11 third-party SDKs — software libraries that independently collect and transmit data to their respective companies. According to the privacy audit, around 40% of the data points collected by DoorDash are used to track users across other companies’ apps and websites, including email address, precise location, and purchase history shared with advertising intermediaries.
Who Gets This Data
The short answer: many more parties than you’ve agreed to share it with by name.
Advertising Partners
The major food delivery platforms are, at their core, advertising businesses with delivery functionality. Uber Eats explicitly discloses sharing advertising identifiers, hashed email addresses, approximate location data, and ad interaction data with advertising intermediaries including Google and The Trade Desk. DoorDash and Grubhub follow similar practices.
This sharing enables retargeting: if you browse a specific restaurant category without ordering, you may see ads related to that interest across other apps and websites. The mechanism requires a persistent link between your identity on the delivery platform and your identity in the broader ad ecosystem — a link built from device identifiers, email hashes, and behavioral signals.
Analytics and Measurement Providers
Session recording tools, A/B testing frameworks, crash reporting services, and attribution platforms all receive behavioral data about how you use the app. These are disclosed as “service providers” in most privacy policies, but the data flows to companies whose primary business is measuring and analyzing user behavior, not delivering food.
Data Brokers (Indirectly)
Instacart’s privacy audit found evidence of cross-app tracking — using your usage data to follow your behavior across companies’ apps and websites. When advertising partners receive this data, some of those partners are data brokers or work closely with them. The path from your grocery order to a third-party database of behavioral profiles isn’t always one step, but it exists.
Law Enforcement
Food delivery apps respond to law enforcement requests, including subpoenas and court orders. Your order history, location data, and account information can be disclosed in criminal investigations, civil litigation, and government inquiries. In 2022, a DoorDash delivery driver was identified and arrested using location data from his account. The same data infrastructure that enables delivery routing enables law enforcement access.
The Dietary Profile Problem
The convergence of order history, location data, and third-party data creates a dietary profile problem that most users haven’t thought through.
Health insurers are legally prohibited in many jurisdictions from using certain health data to set rates. But a detailed grocery order history from a third-party platform — combined with data purchased from brokers — creates an indirect window into health status that isn’t covered by those prohibitions.
Employers can’t ask about medical conditions in most contexts. But consumer data, purchased from advertising data brokers, has been used in hiring and screening contexts that regulators are only beginning to examine.
This isn’t speculative — it’s the predictable consequence of a system where detailed behavioral data is collected at scale, retained indefinitely, and sold to parties whose downstream uses are outside the platform’s control or disclosure.
What the Privacy Scores Reveal
The privacy audit methodology that assigned Instacart a 22/100 and DoorDash a 30/100 evaluates platforms across five dimensions: data collection scope, third-party sharing practices, data retention policies, user control mechanisms, and transparency of disclosures.
Instacart’s specific weaknesses:
- Data collection scope: 17/100 — collects purchases, financial info, location, and contact info plus eight additional data types
- Third-party sharing: 15/100 — active cross-app tracking and extensive partner sharing
- Data retention: 22/100 — vague retention timelines, no commitment to deletion
DoorDash’s specific weaknesses:
- Third-party sharing: disclosed sharing with advertising intermediaries for retargeting
- Cross-app tracking: approximately 40% of collected data used to follow users across external platforms
- Opt-out mechanisms: exist, but require navigating settings that default to maximum data sharing
These scores reflect disclosed practices — what the companies themselves acknowledge in their privacy policies. Undisclosed practices, informal data-sharing arrangements, and secondary uses that occur after data reaches third parties are outside the scope of any audit based on policy review alone.
Practical Steps to Reduce Exposure
You don’t have to stop using food delivery apps to be more deliberate about the data they hold.
Audit your account settings. Most delivery apps include a privacy settings section that defaults to maximum data sharing for advertising. Opting out of interest-based advertising and cross-app tracking reduces — though doesn’t eliminate — the scope of data shared with advertising partners.
Request your data. Under CCPA (California), GDPR (EU and UK), and equivalent laws in an increasing number of jurisdictions, you have the right to request a copy of all personal data the platform holds on you. The data export reveals what’s actually collected and retained — often more than users assume.
Submit a deletion request when you stop using a service. Simply deleting the app from your phone does not delete your data from the company’s servers. A formal data deletion request, submitted in writing through the platform’s privacy request form, initiates a legally required deletion process in jurisdictions covered by consumer privacy law.
Use guest checkout where available. Some platforms allow order placement without creating a persistent account. Guest purchases don’t accumulate into a long-term profile linked to your identity. This trades away order history and saved preferences for meaningfully lower data retention.
Be thoughtful about connecting accounts. Linking your food delivery account to a credit card rewards program, a grocery loyalty card, or a health insurance wellness program expands the data-sharing surface substantially. Each integration is an additional party receiving data from the connection.
Why Grocery Delivery Is a Distinct Risk
App-based grocery delivery deserves particular attention because grocery purchase data is uniquely sensitive relative to restaurant orders.
A restaurant order might reveal that you ordered pizza on a Thursday. A grocery order over three months reveals your complete dietary profile, your household medications, your personal care product preferences, your baby’s food stage, and your budget constraints. Grocery stores have long recognized the value of this data — loyalty card programs have collected it for decades. App-based delivery platforms do the same, at scale, linked to GPS location and behavioral data that physical store loyalty programs never had.
Instacart’s business model includes an advertising segment that uses its purchase history data to target ads both within the Instacart platform and on external platforms. CPG (consumer packaged goods) brands pay Instacart to reach people who have purchased competitors’ products, or to reach people with purchase patterns that suggest they’d be receptive to specific products. Your grocery history is a targeting signal in that ad marketplace, whether or not you’ve opted into anything explicitly.
Where Your Food and File Data Shouldn’t Mix
The data generated by food delivery apps — order histories, exported receipts, dietary logs, spending summaries — often ends up stored wherever people store their files by default. A screenshot of a DoorDash order, an Instacart purchase export, a grocery spending analysis: these files end up in Google Drive, iCloud, or a general photo library where they sit alongside everything else, subject to whatever AI analysis, indexing, and sharing those platforms apply by default.
If you’re pulling your own data — whether for budgeting, dietary tracking, or just keeping records — where you store it matters. daftei keeps personal files and documents separate from platforms that run advertising businesses or index files for AI training. Files are encrypted in transit with TLS 1.3 and at rest with AES-256, never sold, never used to train AI models, and never shared with advertisers. Account deletion results in permanent, irreversible erasure after a 30-day grace window.
The contrast with food delivery platforms isn’t incidental. It reflects a different business model: one where the product is the storage service, not a vehicle for monetizing your behavioral data.
The Bottom Line
Food delivery apps have built some of the most detailed behavioral databases in consumer technology, covering where you live, where you work, what you eat, how often you cook, and what your health situation might be — inferred from the products you buy.
The privacy scores — 22 and 30 out of 100 — aren’t outliers or flukes. They reflect a category of app where data collection is a core business function, not a side effect of providing a service. Understanding that is the first step to making more deliberate choices about what you share and where it goes.