The location data industry: from app signal to sensitive inference
You can give a weather app permission to use your location and, a few steps later, create a record inside a company you have never heard of.
The chain runs like this. The app, or a software kit built into it, collects your coordinates. A broker joins repeated coordinates to your phone’s advertising identifier. The pattern of places puts the phone into an audience segment, such as likely vehicle shopper. The segment, or the raw trail, is sold or licensed to a buyer you have never dealt with. That company never needs to appear as an icon on your phone.
The broker is usually invisible to the person being described
A consumer app has a name, an icon and a stated reason for asking where you are. A data intermediary can sit several steps behind it.
The Australian Competition and Consumer Commission (ACCC) uses the broad term data firm for businesses that collect, process and supply data-based products and services, which is wider than “data broker”. Its March 2024 interim report found that many such firms have no direct relationship with the consumers whose information they handle (ACCC data-firm report).
So “I never installed their app” is not a complete defence; the broker sits behind the app developer, the advertising exchange or an upstream supplier.
The raw ingredients: coordinates, time and an identifier
A useful location record is small: latitude and longitude, a timestamp, a mobile advertising identifier or another persistent device identifier, the source app, and technical details about the device or request.
A mobile advertising ID exists to tell one device from another for advertising. It is not a name, and one data point does not necessarily identify a person, but it is persistent enough to join observations over months.
That makes pseudonymous the honest word: an obvious name swapped for another identifier. Anonymous data cannot reasonably be linked back to a person. The US Federal Trade Commission (FTC) said in its X-Mode matter that raw location tied to advertising IDs was not anonymised and could match a device with the places it visited (FTC X-Mode final order).
Re-identification is not automatic, but a stable trail makes it easier. A device that rests at one house every night and one workplace on weekdays narrows the field, and a broker or its customer may hold another dataset linking the advertising ID to an account or address.
Four documented collection models
Each US case below reveals a different route into the same market. In each, the FTC set out allegations in a complaint and the matter ended in a final order the company agreed to. The complaint facts are allegations, the orders bind only the named companies, and none of it is Australian law.
1. A software kit inside an app
InMarket built a software development kit, or SDK: ready-made code that other developers add to their own apps. The FTC alleged InMarket received location from its own apps and from more than 300 third-party apps carrying the SDK, combined it with other data for behavioural advertising, and failed to make sure users were adequately informed.
The complaint said the SDK could receive precise latitude and longitude, a timestamp and a unique mobile identifier, and that InMarket kept almost 2,000 audience segments. It could combine a car-dealership visit with purchased attributes such as age, income, family structure and education to predict interest in a vehicle (FTC InMarket complaint).
The May 2024 final order prohibits selling, sharing or licensing precise location and products that categorise or target people by sensitive location, and imposes consent, deletion and privacy-program requirements (FTC final InMarket order).
2. Data exposed during an advertising auction
When an app or website has an ad slot to fill, a real-time bidding exchange sends a bid request to potential buyers so they can decide whether to bid. That request can carry identifiers, device details and location-related data.
The FTC alleged that Mobilewalla collected and kept bid-request data even when it lost the auction. Between January 2018 and June 2020, the complaint said, it collected more than 500 million unique advertising identifiers paired with precise location. The data allegedly fed audience segments, including one based on visits to pregnancy centres, and analysis of people who attended protests in 2020 (FTC Mobilewalla action).
The January 2025 final order bans Mobilewalla from collecting consumer data from bidding exchanges for any purpose other than taking part in the auction, with further restrictions on sensitive-location data (FTC final Mobilewalla order).
It does not follow that every bidder keeps losing bids or that every ad request carries GPS coordinates; it is one alleged route by which data exposed to place an ad became a separate product.
3. Own apps, embedded SDKs and purchased broker data
The FTC said X-Mode Social and its successor Outlogic collected precise location three ways: third-party apps carrying its SDK, its own apps, and purchases from other brokers and aggregators. The data was licensed to customers in industries from finance and real estate to government contracting.
The regulator alleged that sensitive locations were not removed from raw data until May 2023 and that safeguards over downstream use were inadequate. The April 2024 final order restricts sharing or selling sensitive-location data and requires supplier assessment, deletion and privacy controls (FTC final X-Mode/Outlogic order).
4. Aggregation and derived sensitive characteristics
Gravy Analytics and its subsidiary Venntel sat further along the supply chain. The FTC alleged they obtained location from other suppliers, drew geofences (virtual boundaries) around sensitive sites to identify visits, and sold inferences about health or medical decisions, political activity and religious views.
Gravy claimed to collect, process and curate more than 17 billion signals from around a billion mobile devices a day: a company claim reported by the FTC, not an audited count of distinct people (FTC Gravy/Venntel action).
The January 2025 final order restricts selling, disclosing or using sensitive-location data except in limited national-security or law-enforcement circumstances, and requires a sensitive-location program (FTC final Gravy/Venntel order).
A visit is a dot. Repeated visits are a pattern
One coordinate says where a device was at one moment. A sequence can suggest:
- where someone sleeps and where they work
- a school or childcare routine
- attendance at worship or a political gathering
- a visit to a medical, fertility or counselling service
- union activity or a military connection
- relationships between devices that regularly move together
These are inferences, not certainties. A phone near a clinic could belong to a patient, a nurse, a courier or someone in the next building. A model can be wrong and still file the identifier under a category.
Combination adds meaning. The InMarket complaint describes place visits cross-referenced with purchased demographic data, and the ACCC describes the same process here: inferred information created by combining volunteered and observed data with other data (ACCC data-firm report).
So deleting the name column does not settle the question. Linkability, precision, time span, other datasets and access all matter.
Who buys it, and what exactly are they buying?
Customers documented across these cases included advertisers, agencies, analytics firms, other brokers, commercial businesses and government contractors. They did not all receive the same product. A broker can offer:
- raw or lightly processed coordinates linked to an identifier
- a list of identifiers observed inside a geofence
- an audience segment, such as likely shoppers or visitors
- aggregated foot-traffic measurement
- an inferred characteristic or propensity
- a risk, identity or fraud signal
Check which product a source is talking about: aggregate counts with safeguards, a raw trail, precise coordinates, an inferred audience, an outright sale or a licence with use restrictions. A ban on selling sensitive-location data leaves other location-derived products on the market. When a broker is reported as “banned”, check what the order actually covers.
What the four US orders actually restrict
| Matter | Route the FTC alleged | What the final order restricts |
|---|---|---|
| InMarket, May 2024 | Its SDK in more than 300 third-party apps, plus its own apps | Selling, sharing or licensing precise location; sorting or targeting people by sensitive location |
| X-Mode / Outlogic, April 2024 | Its SDK, its own apps, purchases from other brokers | Sharing or selling sensitive-location data; supplier checks and deletion required |
| Mobilewalla, January 2025 | Keeping bid-request data from auctions, including ones it lost | Collecting from bidding exchanges for anything but the auction; limits on sensitive-location data |
| Gravy Analytics / Venntel, January 2025 | Obtaining location from other suppliers, geofencing sensitive sites, selling inferences | Selling, disclosing or using sensitive-location data outside limited national-security or law-enforcement cases |
The Australian context
The ACCC inquiry is the Australian anchor. It found an active domestic data-services ecosystem drawing on online and offline activity, transaction and loyalty data, public sources, identifiers, demographics, location and inferred interests, and that consumers had limited visibility of it (ACCC data-firm report).
The Office of the Australian Information Commissioner ran its Australian Community Attitudes to Privacy Survey in 2026. In it, 78 per cent reported very little or no control over how their personal information was collected and used. And 94 per cent regarded location tracking as unfair or unreasonable when it was not needed for a location-based service (OAIC 2026 survey).
The careful conclusion is not “the FTC banned data brokers here”. It is that Australians use the same app and advertising systems, while rights, exemptions and enforcement must be checked under Australian law.
What you can do about it
Most of this is phone settings, which are yours to change; the network side comes last, with its limits.
Review location access, not just installed apps
On Android, open the privacy dashboard and go through each app’s permission. Android 12 introduced a view of recent location, camera and microphone access, and a choice between precise and approximate location (Google’s Android 12 announcement). Menus vary by version and manufacturer.
For each app, ask: does it need precise location, does it need it in the background, and is the benefit worth it? “While using the app” plus approximate location cuts exposure wherever the feature still works.
Limit cross-company tracking on Apple devices
Apple says App Tracking Transparency lets you deny an app permission to track you across other companies’ apps and websites, and blocks its access to the advertising identifier (IDFA). Apple’s definition of tracking includes sharing your data with data brokers (Apple ATT support). ATT does not stop first-party collection, account activity, fraud controls or data already disclosed; it is one boundary, not an invisibility switch.
Remove unnecessary sources
Delete apps you no longer use, revoking their permissions first, and review location history and advertising settings in the accounts you keep. A torch, wallpaper or simple game should have to justify a precise-location request. An app can still infer a broad area from your IP address, and a service you ask to find nearby places needs some location.
Treat deletion as a separate job
Turning off a permission stops future access by that route; it does not retrieve copies already sent to an SDK, exchange, broker or buyer. Use the deletion processes offered by the app, the platform and any intermediary you can identify, and keep a record of what you asked and what came back. Entitlements and exceptions vary.
Understand what the network can and cannot do
Pi-hole, an internet address book with a blocklist, can refuse a known tracking domain when the phone is on your Wi-Fi and using your resolver. It cannot see inside encrypted traffic, cannot stop software that connects straight to an IP address, cannot help once the phone switches to mobile data, cannot block an SDK that talks to the same domain the app itself needs, and cannot delete records a broker already holds. A VPN changes who observes your traffic and the IP address they see; it does not stop account-based collection or an app sending GPS data you permitted. What Pi-hole can and cannot block goes deeper.
What no checklist can promise
A permission audit cannot erase records already distributed. An advertising-ID control cannot stop linkage through accounts. Self-hosting one service still leaves the phone’s operating system, the mobile carrier and other third-party components in the path. Approximate location can still reveal a suburb and a routine.
It is still worth doing, because privacy is not all or nothing. Fewer apps with precise background access, fewer embedded recipients and shorter retention each reduce the material available for combination.
The phone settings above are yours to change today. The network side, at home or at work, is what Alien IT helps with. Call 02 9707 0999 or use the contact page.
Frequently asked questions
Is a mobile advertising ID anonymous?
Not automatically. It is a pseudonymous identifier, and repeated location data or another dataset can make the device and its owner linkable even though no name is attached.
Does every app sell precise location?
No. It depends on the app, its SDKs, your permissions, the contracts behind it and your settings; the cases here are documented examples, not a statement about every app.
Can an ad company receive my data if it loses the auction?
It receives the bid request it needs to decide whether to bid. The FTC alleged that Mobilewalla kept data from those requests even when it lost; that was alleged against one company, not every bidder.
Does approximate location solve the problem?
It reduces precision and is often enough for weather or local content, but it can still reveal a broad area, and repeated coarse observations remain informative.
Will resetting my advertising ID delete broker data?
No. Resetting can interrupt some future linkage, but it does not delete earlier records or prevent linkage through accounts and other identifiers.
Does a VPN hide my GPS location from an app?
No. A VPN changes the network path and the public IP address others see; it does not alter GPS readings or stop an app with location permission from sending them.
Are the FTC orders Australian law?
No. They are US matters involving named companies: useful evidence of how the technology and market work, but Australian rights and obligations need Australian analysis.