A few months ago Uber came out with Family Profile which allows you to pay for another Uber riders fare.
Initially, when you try to intercept the information when you create the profile it won’t show much but once you intercept the information after you create the profile some interesting information shows up.
In the response the userUUID is shown along with the users first and last name. Now we have the users userUUID, first name, last name and phone number.
If the phone number is not associated with any account no information will be provided besides a text invite to that phone number.
Throughout testing, there was no rate limiting present at the time.
Uber removed the userUUID from the response
Rate limiting was implemented allowing only 20 requests
Uber has resolved this issue and a bounty was given.