PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Google Play privacy breach (updated with Google’s response)

Posted on February 13, 2013July 1, 2025 by Dissent

Dan Nolan writes:

About a month ago I put my money where my mouth was and built a version of the Paul Keating insult generator for Android (after the iOS version hit number 1 in the Australian App Store [tell your friends]). We sold a few hundred copies on Android in the last month, so that’s all good. Today I decided to log into my google play account to update my payment details. I jumped over to the ‘merchant account’ section to see the orders and realised one absolutely insane thing.

If you bought the app on Google Play (even if you cancelled the order) I have your email address, your suburb, and in many instances your full name. Each Google Play order is treated as a Google wallet transaction and as such software developers get all of the information (sans exact address) for an order of an app that they would get from the order of something physical. Even underneath the order information there is a flag that says ‘Email Marketing’ with a value next to it, because of course scrupulous developers would always obey that flag.

Let me make this crystal clear, every App purchase you make on Google Play gives the developer your name, suburb and email address with no indication that this information is actually being transferred.

Read more on Internet Hugbox.

via The Register, who, so far, has not gotten a reply from Google about Nolan’s claims.

UPDATE:  Google tells Reuters, “Google Wallet shares the information needed to process transactions, and this is clearly stated in the Google Wallet Privacy Notice.”

No related posts.

Category: BreachesBusiness

Post navigation

← The Privacy Legal Implications of Big Data: A Primer
Lawmakers reintroduce cyberthreat information-sharing bill →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia
  • EU court says websites on the hook for user privacy harms

RSS Recent Posts at DataBreaches.net

  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
  • Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies
  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Update on Dos-OP’s report on Nova RaaS
©2025 PogoWasRight.org. All rights reserved.