Every Step You Take Is for Sale: The Billion-Dollar Market Trading in Your Physical Movements
You locked your front door this morning. You chose a discreet route to your doctor's appointment. You paid cash at the pharmacy. None of it mattered. By the time you returned home, a data broker you have never heard of had already logged, packaged, and sold a precise record of everywhere you went.
This is not a hypothetical scenario. It is the operating reality of the modern smartphone economy — one in which location data has evolved from a technical byproduct of wireless connectivity into a primary commercial asset, generating billions of dollars annually and fueling an ecosystem of surveillance that most Americans have no idea exists.
The Plumbing Beneath Your Screen
Location data does not flow through a single pipe. It is extracted through a sprawling network of collection points: GPS chips embedded in handsets, Wi-Fi triangulation, Bluetooth beacons, cell tower pings, and the software development kits (SDKs) quietly embedded inside thousands of ostensibly unrelated applications — weather apps, coupon aggregators, flashlight utilities, mobile games.
When a developer integrates an advertising SDK into an app, they frequently grant that SDK permission to harvest whatever location access the user has already authorized. The developer earns a small licensing fee or revenue share. The SDK operator collects movement data from potentially millions of devices simultaneously, aggregates it into longitudinal profiles, and sells access to downstream buyers. The consumer, who thought they were simply checking tomorrow's forecast, has become an unwitting data point in a commercial surveillance network.
The technical precision of this data is not trivial. Modern GPS-assisted location records can resolve a user's position to within a few meters. That level of granularity is sufficient to determine not merely that someone visited a hospital, but which specific clinic within it — reproductive health, oncology, addiction treatment. It can distinguish a visit to a gun shop from a visit to the coffee shop two doors down. It can identify recurring overnight locations that reliably indicate a home address, even when no name is attached to the record.
The Fiction of Anonymization
The industry's standard defense against privacy concerns has long rested on the claim that location data is anonymized — stripped of names, phone numbers, and other directly identifying fields before it is sold. Researchers have systematically dismantled this argument.
A landmark study published in Nature demonstrated that just four spatiotemporal data points are sufficient to uniquely identify 95 percent of individuals in a large mobility dataset. When you know that a particular device visits the same residential address every night and the same office building every weekday morning, the notion of anonymity collapses entirely. Re-identification is not a theoretical vulnerability; it is a straightforward exercise for any moderately resourced analyst.
This reality has not escaped law enforcement. Federal and state investigators have purchased commercially available location data — without a warrant — to track individuals' movements, identify protest attendees, and monitor visitors to sensitive sites. A 2023 report from the Office of the Director of National Intelligence acknowledged that U.S. intelligence agencies had acquired commercially sourced location data that "can be used to identify nearly any person."
Real-World Harm: Beyond Targeted Advertising
The consequences of this trade extend well beyond the inconvenience of receiving advertisements for products you recently browsed nearby. Documented cases have revealed a spectrum of harms that range from the commercially predatory to the genuinely dangerous.
Insurance companies and their data partners have experimented with mobility data to infer behavioral risk profiles — how often someone drives late at night, whether they frequent establishments associated with particular health risks, how regularly their schedule deviates from established patterns. While regulatory constraints vary by state, the underlying data pipelines exist and are actively marketed to the financial services sector.
Anti-abortion advocacy groups and related political organizations have been documented purchasing geofenced location data drawn from visitors to reproductive health clinics, using it to serve targeted messaging to individuals at moments of particular personal vulnerability. Following the Dobbs decision in 2022, legal scholars and privacy advocates raised urgent concerns that the same data pipelines could be used to assist prosecutorial investigations in states that criminalize certain medical procedures.
Journalistic investigations — most notably a series by The New York Times and subsequent reporting by Vice Motherboard — have demonstrated that commercial location data can be used to track the movements of military and intelligence personnel, identify the home addresses of individuals based on their commuting patterns, and monitor the attendance of religious services at mosques, churches, and synagogues.
The Regulatory Landscape: Fractured and Lagging
Federal privacy law in the United States remains conspicuously absent in this domain. Unlike the European Union's General Data Protection Regulation, which imposes substantive constraints on the collection and processing of location data, American consumers are largely governed by a patchwork of sector-specific rules and state-level legislation that varies dramatically in scope and enforcement.
California's Consumer Privacy Act and its subsequent amendments represent the most robust domestic framework, granting residents the right to opt out of the sale of their personal data and requiring businesses to disclose collection practices. Several other states — Colorado, Connecticut, Virginia, and Texas among them — have enacted comparable statutes. But enforcement resources are limited, the data broker industry operates across jurisdictions with considerable agility, and the technical complexity of modern data supply chains makes meaningful accountability difficult to establish.
The Federal Trade Commission has brought enforcement actions against specific actors — most notably a 2024 order against data broker X-Mode Social (subsequently rebranded as Outlogic) prohibiting the sale of sensitive location data — but these actions remain episodic rather than systemic.
What Actually Reduces Your Exposure
Given the structural nature of this problem, individual countermeasures are necessarily incomplete. They do not address the underlying market; they reduce, rather than eliminate, personal exposure. With that caveat clearly stated, certain practices offer meaningful protection.
Revoke location permissions for every application that does not require real-time geolocation as a core functional feature. Navigation and ride-sharing apps have a legitimate claim on this access; a recipe application does not. Both iOS and Android now offer "precise" versus "approximate" location options — the latter is sufficient for most purposes and substantially reduces the commercial value of data collected.
Disable advertising identifiers. On iOS, navigate to Settings → Privacy & Security → Tracking and disable cross-app tracking. On Android, the equivalent setting is found under Privacy → Ads. These identifiers are the primary mechanism by which location records are linked across applications and stitched into longitudinal profiles.
Treat app permissions as a recurring audit rather than a one-time decision. Applications update their data practices, and permissions granted during installation may not reflect the access a later version of the same app requests or exercises.
For individuals whose threat model extends beyond commercial data harvesting — activists, journalists, survivors of domestic abuse, medical professionals — more rigorous measures are warranted. Dedicated privacy-focused devices, the use of airplane mode in sensitive locations, and the avoidance of consumer smartphones altogether in high-risk contexts represent the upper end of a practical mitigation spectrum.
The Structural Problem Remains
None of these measures addresses the foundational issue: a regulatory environment that has permitted an industry to commodify the physical movements of hundreds of millions of people without their meaningful knowledge or consent. Until comprehensive federal privacy legislation establishes baseline standards — enforceable rights to access, deletion, and opt-out that apply uniformly across all sectors — the location data market will continue to expand, and the individuals whose lives it maps will remain the product rather than the customer.
The oil analogy that has become common in discussions of data's economic value is instructive in one respect: like petroleum, the extraction of location data generates substantial wealth for those who control the infrastructure, and imposes costs — environmental, social, and in this case deeply personal — on those who do not.