• Tickets + QR code, Email, Phone, Password, Screenshot of any app windows (iOS only) • Network data [Weak] • Email, Phone, Password, Unique UserID, Last Login Time, email & phone confirmed, DeviceID, • OrderID, Base64(hash of Order), Order URL, Order date, Trip date, cost of order, • TicketID, Route Info, ticket GUID, token, ticket QR Code • Bank Card info (number, cvv, name, expiration), tokens, *aeroexpress.ru, *ruru, *bank (AlfaBank) • According to release notes & PCI DSS, App doesn’t store bank card info (payment data). You can’t input that data type manually. However, • iOS: Doesn’t store data after successful payment • Android: Stores data after successful payment • Both: Continue stores data after update - if previous version wasn’t removed and data not wiped 2013 2014 2015 2016 Weak Weak Weak Weak, Expect to remove local card info but fail