← IoT Privacy Database

Stellantis Uconnect (Jeep / Ram / Chrysler / Dodge)

Stellantis · Connected Car

✓ Reviewed

5.3Surveillance
Index
Policy — what its policy permitsF
Evidence — what research provesD

Uconnect links Jeep, Ram, Chrysler and Dodge vehicles to a cloud account that collects precise location, trip and driving-behavior data, voice commands, and vehicle diagnostics tied to your identity, powering remote start, SOS and stolen-vehicle location. Stellantis's policy permits sharing personal data with partners for marketing, but unlike several rivals it told the Senate it requires a warrant before releasing location data to police. The bigger documented risk here is security: Uconnect was the platform behind the landmark 2015 remote Jeep hijack recall, and Stellantis suffered a large 2025 third-party breach of customer contact records.

Why this rating

Policy permits marketing sharing and broad partner disclosure (sells-data, broker-disclosure), collects precise location (sensitive-collection), and lacks a universal US deletion right (no-deletion-right); notably it does NOT trigger law-enforcement-loose because Stellantis told the Senate it requires a warrant. Evidence: 2025 Salesforce supply-chain breach exposed ~18M customer contact records (major-breach), and Uconnect was the vector for the 2015 remote Jeep Cherokee hijack that forced a 1.4M-vehicle recall (security-negligence, aged/remediated so counted at reduced weight); Mozilla failed the Stellantis brands (ngo-review). Warrant stance is a genuine positive versus peers.

What it is

Manufacturer
Stellantis
Category
Connected Car
Model years
2018-present
Market status
Current
Companion app
Uconnect / Jeep / Ram / Dodge / Chrysler brand apps

The evidence 3

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Breach report · BleepingComputer · 2025-09

    ShinyHunters exfiltrated ~18 million records of North American customer contact information (names, addresses, phone, email) from a Stellantis third-party Salesforce platform.

    Why it matters here: Compromised the customer records tied to Uconnect / brand-app accounts, though no financial data was reported taken.

  2. Security advisory · Wired · 2015-07

    Researchers Miller and Valasek remotely took over a Jeep Cherokee via a Uconnect cellular flaw, killing the engine and brakes, prompting a 1.4M-vehicle FCA recall.

    Why it matters here: Demonstrated a severe security failure in the Uconnect platform itself; older and patched, so weighted at half.

  3. Ngo review · Mozilla Foundation · 2023-09

    Mozilla flunked all 25 car brands reviewed, including Volkswagen and Audi, for over-collection and selling/sharing personal data.

    Why it matters here: The Stellantis US brands were individually reviewed and failed.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database