CipherWatch All articles
Cyber Threats & Breaches

Pinned to the Map: How Your Smartphone Quietly Sells Your Every Move

CipherWatch
Pinned to the Map: How Your Smartphone Quietly Sells Your Every Move

Every time you open a weather app, hail a rideshare, or simply carry your phone through a grocery store, you may be generating a data point that ends up in a commercial database thousands of miles away. Location data has become one of the most commercially valuable commodities in the digital economy—and most Americans have little idea how thoroughly their daily movements are being catalogued.

This is not a hypothetical concern. Investigative reporting by major newsrooms over the past several years has repeatedly demonstrated that precise, timestamped location records tied to individual devices are routinely collected, aggregated, and sold to third parties ranging from hedge funds to federal law enforcement agencies. The mechanisms behind this trade are technical, layered, and deliberately difficult for ordinary users to inspect.

How Location Data Is Collected in the First Place

Location collection on modern smartphones operates through several overlapping channels, each with different levels of precision and different disclosure requirements.

The most familiar is GPS, the satellite-based positioning system that can pinpoint a device to within a few meters. GPS is accurate but power-intensive, so many apps supplement it—or replace it entirely—with Wi-Fi triangulation, Bluetooth beacon detection, and cell tower data. These alternatives are less precise but far more persistent, operating even when a user believes location services are disabled for a specific application.

Beyond hardware signals, advertising software development kits (SDKs) embedded inside popular apps serve as silent data collection agents. When a developer integrates a third-party advertising SDK to monetize their app, that SDK may independently collect location data and transmit it to the SDK provider's servers—entirely separate from whatever permissions the user granted the app itself. A flashlight application, a recipe tool, or a mobile game may have no legitimate need for your coordinates, yet if it contains certain advertising SDKs, it may be reporting them anyway.

Operating systems play a dual role. Both iOS and Android have introduced permission prompts that ask users whether an app may access location data always, only while in use, or never. These controls are meaningful, but they are not comprehensive. System-level services, carrier diagnostics, and pre-installed manufacturer applications often operate outside the standard permission framework, collecting location signals through pathways that user-facing settings do not govern.

The Data Broker Pipeline

Once collected, raw location signals flow into a sprawling commercial ecosystem dominated by data brokers—companies whose core business is aggregating personal information and reselling it. Firms such as Foursquare, Near Intelligence, and X-Mode (now Outlogic) have built databases containing billions of location pings tied to persistent device identifiers. These identifiers—known as Mobile Advertising IDs, or MAIDs—are not names, but they function as pseudonymous fingerprints that can be linked back to real individuals through a process called re-identification.

Researchers have demonstrated repeatedly that a dataset of supposedly anonymous location records is not meaningfully anonymous at all. A 2013 study published in Scientific Reports found that just four spatio-temporal data points were sufficient to uniquely identify 95 percent of individuals in a mobility dataset. More recent analyses have confirmed that home and workplace coordinates, derivable from overnight and daytime clustering of pings, can narrow a device's identity to a single person with alarming reliability.

This re-identification risk is not theoretical. In 2020, The New York Times obtained a commercial location dataset and traced the movements of military personnel, Secret Service agents, and other sensitive individuals. In 2021, the Catholic news outlet The Pillar used commercially purchased location data to identify a senior Vatican official's presence at gay bars and a private residence. The data had been acquired legally, from a broker, without a warrant.

Who Is Buying and What They Are Doing With It

The customer base for commercial location data is broader than most people assume. Retailers use it to measure foot traffic and assess competitor performance. Insurance companies have explored its use to evaluate driving behavior and lifestyle risk factors. Political campaigns purchase it to target voters at specific venues. Employers have used it to monitor remote workers.

Law enforcement agencies represent a particularly significant—and legally contested—segment of the market. Because purchasing commercial location data does not constitute a traditional search under existing Fourth Amendment doctrine, federal and state agencies have used it to circumvent the warrant requirements that would otherwise apply to carrier-held records. The Department of Homeland Security, the Internal Revenue Service's criminal division, and various military intelligence components have all been documented purchasing location data from commercial brokers.

The Supreme Court's 2018 ruling in Carpenter v. United States held that the government generally needs a warrant to obtain historical cell-site location information from carriers. However, that decision did not directly address the purchase of data from commercial brokers, leaving a significant legal gap that legislators and courts are still working to close.

Real Consequences for Real People

The abstract nature of data flows can make location tracking feel distant from everyday life. The consequences, however, are concrete. Domestic abuse survivors have been located by abusers who purchased data from people-search sites that aggregate broker records. Journalists operating in sensitive environments have had their movements exposed. Individuals who visited reproductive health clinics in states with restrictive laws have faced the prospect of their location history being subpoenaed or purchased by hostile parties.

In 2023, the Federal Trade Commission took enforcement action against data broker Kochava, alleging that the company's sale of sensitive location data—including visits to reproductive health facilities, addiction treatment centers, and places of worship—caused concrete harm to consumers. The case signaled a shift in regulatory posture, though comprehensive federal privacy legislation governing location data remains absent in the United States.

Practical Steps to Reduce Your Exposure

No consumer-side measure eliminates location data collection entirely, but several actions meaningfully reduce the volume and granularity of what is harvested.

Audit and restrict app permissions. On both iOS and Android, navigate to your privacy or location settings and review which applications have been granted location access. Revoke access for any app that does not have a clear functional need for it. Where available, select "Only While Using" rather than "Always."

Reset your Mobile Advertising ID regularly. Both major mobile operating systems allow users to reset the MAID assigned to their device, breaking continuity in broker databases. On iOS, this is found under Settings > Privacy & Security > Tracking. Android users can find the equivalent under Settings > Privacy > Ads.

Disable precise location where approximate is sufficient. iOS 14 and later versions allow users to share only an approximate location with apps rather than GPS-precise coordinates. Enable this for any app that does not require navigation-level accuracy.

Be selective with app installations. Each application installed is a potential additional data collection surface. Evaluate whether a given app is necessary, and favor applications from developers with clear, restrictive privacy policies.

Use a VPN cautiously. A VPN masks your IP address—a coarse location signal—but does not prevent GPS or SDK-based collection. It is one layer of a broader privacy posture, not a comprehensive solution.

Opt out of ad personalization at the system level. Both iOS and Android offer system-level options to limit ad tracking. While compliance by third-party SDKs is not guaranteed, enabling these settings reduces participation in the most common commercial collection pipelines.

A Market Built on Asymmetry

The location data economy persists because it is profitable, because regulatory frameworks have not kept pace with the technology, and because the collection happens largely below the threshold of user awareness. The permission prompts that appear when an app first launches create an impression of informed consent, but they rarely communicate the downstream commercial uses to which that data will be put.

Until comprehensive federal privacy legislation establishes meaningful limits on the collection, retention, and sale of location data, the burden of defense rests disproportionately on individual users. That is an unfair arrangement—but it is the current reality. Understanding the architecture of this system is not a guarantee of protection. It is, however, the precondition for making genuinely informed choices about the devices that travel with us everywhere we go.

All Articles

Related Articles

Soft Targets, Hard Consequences: Why Ransomware Gangs Are Coming for Main Street America

Soft Targets, Hard Consequences: Why Ransomware Gangs Are Coming for Main Street America

Checked by Default: The Quiet Trick That Hands Over Your Data Before You Read the Fine Print

Checked by Default: The Quiet Trick That Hands Over Your Data Before You Read the Fine Print

Sold Before You Click: The Hidden Economy Profiling You Across Every Website You Visit

Sold Before You Click: The Hidden Economy Profiling You Across Every Website You Visit