CipherWatch All articles
Threat Intelligence

Coordinates for Sale: Inside the Shadow Market Trading Your Every Move

CipherWatch
Coordinates for Sale: Inside the Shadow Market Trading Your Every Move

Every time your smartphone pings a cell tower, connects to a Wi-Fi network, or allows a weather app to check your position, it generates a data point. Individually, that signal is trivial. Aggregated across weeks, months, and years, it becomes something far more revealing — a precise, timestamped chronicle of where you sleep, where you worship, where you seek medical care, and who you spend time with. That chronicle is, in most cases, being quietly sold.

The location data broker industry operates largely outside public awareness, yet it generates hundreds of millions of dollars in annual revenue inside the United States. Its mechanics are neither secret nor technically illegal. They are, however, deeply opaque — and the consequences for ordinary Americans are only beginning to be understood.

How the Pipeline Actually Works

The chain begins with what the industry calls "first-party data collection." An app developer — building anything from a navigation tool to a coupon aggregator — embeds a software development kit (SDK) provided by a data broker or analytics firm. When a user grants that app location permission, the SDK begins transmitting coordinates back to the broker, often in the background and long after the user has closed the app.

Carriers occupy a separate but equally significant position in this pipeline. For years, major U.S. wireless providers sold aggregated and sometimes individual-level location data to third-party companies. A series of investigative reports between 2018 and 2020 exposed how that data reached bounty hunters who could, for a fee, determine the real-time location of virtually any American with a cell phone. The Federal Communications Commission eventually levied fines against the largest carriers, though critics argued the penalties were insufficient given the scale of the conduct.

Device manufacturers and operating system vendors add yet another layer. Certain forms of location inference — derived from Bluetooth beacons, ultrasonic signals embedded in retail environments, or even barometric pressure sensors — can occur without traditional GPS access, complicating users' ability to meaningfully opt out.

Who Buys This Data — and Why It Matters

The purchaser landscape is far broader than most people assume. Digital advertising remains the dominant use case: brokers sell location-derived audience segments to brands seeking to target consumers who have visited a competitor's store, a particular church, or a medical clinic. The targeting is granular enough that a hospital system can theoretically advertise to individuals who have spent time near an oncology center.

Political campaigns represent a growing segment of the market. During recent election cycles, campaigns on both sides of the aisle purchased location data to identify rally attendees, track movements near campaign offices, and refine voter outreach. Because political advertising is subject to fewer data-use restrictions than, say, financial services advertising, this application has attracted particular scrutiny from civil liberties organizations.

Law enforcement agencies — at the federal, state, and local level — have used commercial data brokers as an end-run around warrant requirements. By purchasing location data commercially, investigators can sometimes reconstruct a suspect's movements without triggering Fourth Amendment protections that would otherwise apply to a direct request to a carrier. The legal status of this practice remains actively contested in the courts.

Perhaps most troubling to privacy advocates is the sale of location data to insurance underwriters, employers conducting background screening, and, as documented in multiple investigative reports, individuals with no legitimate professional purpose whatsoever.

The Consent Fiction

Brokers and their app-developer partners routinely cite user consent as the legal and ethical foundation of their business. The argument is straightforward: users agreed to the app's terms of service, which disclosed that location data might be shared with third parties.

The practical reality is considerably murkier. Research consistently shows that consumers do not read privacy policies, cannot realistically parse the downstream implications of data-sharing disclosures buried in legal boilerplate, and have no mechanism for understanding which of the dozens of SDKs embedded in a given app may be transmitting their coordinates. Consent obtained under these conditions is, many legal scholars argue, consent in name only.

Furthermore, the concept of "anonymized" location data — frequently invoked by brokers to suggest that individual privacy is preserved — has been systematically dismantled by academic research. Studies have demonstrated that as few as four timestamped location points are sufficient to uniquely re-identify an individual from a supposedly anonymized dataset with greater than 95 percent accuracy. A file labeled anonymous is rarely anonymous in any meaningful sense.

The Regulatory Landscape

The United States currently lacks a comprehensive federal privacy law governing the location data broker industry. The FTC has pursued enforcement actions under its Section 5 authority, and the FCC actions against carriers established some precedent, but the statutory framework remains fragmented. California's Consumer Privacy Act and its subsequent amendment, the CPRA, provide residents of that state with opt-out rights and deletion requests, but enforcement has been uneven and geographically limited.

Several states have introduced or passed legislation specifically targeting data brokers, requiring registration and providing consumers with deletion mechanisms. At the federal level, proposals including the American Data Privacy and Protection Act have stalled repeatedly, leaving the regulatory environment in a state of prolonged uncertainty.

Practical Steps to Reduce Your Location Footprint

While systemic reform remains incomplete, individual users can meaningfully reduce their exposure through a combination of platform settings and behavioral adjustments.

Audit location permissions aggressively. On both iOS and Android, navigate to the location permissions section of your settings and review every app that has been granted access. The default posture should be skepticism: if an app does not have an obvious, immediate need for your precise location, revoke the permission or restrict it to "while using the app" rather than granting always-on access.

Prefer "approximate" location where available. iOS 14 and later versions of Android offer an approximate location option that provides a general area rather than precise coordinates. For apps that need only regional context — weather applications, for instance — this setting satisfies functional requirements without exposing granular movement data.

Limit ad tracking identifiers. Both major mobile platforms allow users to reset or limit their advertising identifier, a persistent tag that brokers use to link location pings to a specific device profile over time. On iOS, navigate to Settings > Privacy & Security > Tracking. On Android, the option is found under Settings > Privacy > Ads.

Be selective with app installations. Each new app represents a potential new data collection surface. Before installing, consider whether the application is from a developer with a transparent privacy policy, whether it requires permissions disproportionate to its stated function, and whether a browser-based alternative exists that avoids local installation entirely.

Use a VPN with caution and awareness. A virtual private network can obscure your IP-based location from websites and certain trackers, but it does not prevent GPS or cell-tower-based location collection by apps running on your device. Understand what a VPN does and does not protect.

Submit data broker opt-out requests. A number of established data brokers — including Acxiom, LexisNexis Risk Solutions, and Verisk — maintain opt-out or deletion request mechanisms. Services exist that automate the submission of these requests across dozens of brokers simultaneously, though the process requires ongoing maintenance as data can re-enter broker databases over time.

A Market Built on Asymmetry

The location data economy persists because the costs are diffuse and largely invisible while the profits are concentrated and immediate. The individual whose coordinates are sold may never know it happened. The advertiser, the campaign, or the investigator who purchased those coordinates receives a concrete, actionable benefit.

Closing that asymmetry requires both regulatory intervention and informed individual behavior. Until federal legislation establishes clear baseline protections — including meaningful consent standards, purpose-limitation requirements, and enforceable deletion rights — the burden of self-protection falls disproportionately on the consumer. That is an imperfect arrangement. But it is the current reality, and understanding it is the precondition for navigating it.

All Articles

Related Articles

Your Gateway, Their Gold Mine: How ISPs Are Profiting From Every Website You Visit

Your Gateway, Their Gold Mine: How ISPs Are Profiting From Every Website You Visit

Tapping In Without Asking: How Deceptive Permission Screens Are Quietly Handing Your Camera and Microphone to Strangers

Tapping In Without Asking: How Deceptive Permission Screens Are Quietly Handing Your Camera and Microphone to Strangers

Ambient Intelligence, Ambient Exposure: The Behavioral Dossier Your Smart Home Is Quietly Assembling

Ambient Intelligence, Ambient Exposure: The Behavioral Dossier Your Smart Home Is Quietly Assembling