I Know What You Bought Last Summer: Investigating User Data Leakage in E-Commerce Platforms

📅 2025-04-16
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study reveals a widespread privacy risk wherein mainstream e-commerce platforms indiscriminately leak sensitive personal information to third-party entities (e.g., Facebook) even during lightweight user interactions—such as page browsing—enabling cross-site, holistic user profiling. Method: We propose the first semi-automated empirical framework for cross-platform privacy leakage analysis, integrating HTTP traffic monitoring, third-party domain tracking, and behavioral log correlation modeling to enable reproducible, quantitative assessment. Contribution/Results: Empirical evaluation identifies that 30% of sampled e-commerce sites engage in non-compliant data sharing; we precisely identify 12 high-risk third-party recipients; and we provide the first empirical evidence that lightweight interactions across multiple sites suffice to trigger full-dimensional user profile linkage. Our findings deliver verifiable technical evidence and an objective evaluation benchmark to inform regulatory oversight and platform compliance remediation.

Technology Category

Application Category

📝 Abstract
In the digital age, e-commerce has transformed the way consumers shop, offering convenience and accessibility. Nevertheless, concerns about the privacy and security of personal information shared on these platforms have risen. In this work, we investigate user privacy violations, noting the risks of data leakage to third-party entities. Utilizing a semi-automated data collection approach, we examine a selection of popular online e-shops, revealing that nearly 30% of them violate user privacy by disclosing personal information to third parties. We unveil how minimal user interaction across multiple e-commerce websites can result in a comprehensive privacy breach. We observe significant data-sharing patterns with platforms like Facebook, which use personal information to build user profiles and link them to social media accounts.
Problem

Research questions and friction points this paper is trying to address.

Investigating user data leakage in e-commerce platforms
Examining privacy violations by third-party data sharing
Analyzing cross-platform user interaction leading to privacy breaches
Innovation

Methods, ideas, or system contributions that make the work stand out.

Semi-automated data collection approach
Examines popular e-shops for privacy violations
Reveals data-sharing patterns with third parties
🔎 Similar Papers
No similar papers found.
I
Ioannis Vlachogiannakis
Foundation for Research and Technology - Hellas (FORTH), Heraklion, Greece; University of Crete, Heraklion, Greece
Emmanouil Papadogiannakis
Emmanouil Papadogiannakis
University of Crete / Foundation for Research and Technology Hellas
Web MeasurementsComputer SystemsPrivacy & AnonymityWeb Transparency
P
P. Papadopoulos
Foundation for Research and Technology - Hellas (FORTH), Heraklion, Greece
Nicolas Kourtellis
Nicolas Kourtellis
Operational R&D Manager of Core AI Team, Keysight Labs
Distributed SystemsPrivacy & Web TransparencyPrivacy-Preserving MLUser Behavior Modeling
E
E. Markatos
Foundation for Research and Technology - Hellas (FORTH), Heraklion, Greece; University of Crete, Heraklion, Greece