How Location Data Gets Collected, Sold, and Used Without Your Awareness
Your location is one of the most valuable pieces of data you generate. Here's how it moves from your phone to data brokers and what you can do about it.
Key takeaways
- Apps can collect your location through GPS, Wi-Fi signals, and cell towers, sometimes without GPS being active.
- Many apps share or sell location data to third-party brokers, often disclosed only in lengthy privacy policies.
- Data brokers aggregate location records to build profiles used in advertising, insurance, and political campaigns.
- You can limit collection by auditing app permissions and choosing 'only while using' or denying location access entirely.
- Disabling location services entirely stops GPS, but some passive signals like Wi-Fi scanning may still operate.
Where your location signal comes from
Your phone produces location data through several systems running simultaneously. GPS is the most accurate, pulling signals from satellites to place you within a few meters. Cell towers provide a rougher position based on which antennas your phone is connected to. Wi-Fi scanning goes a step further: even if you are not connected to a network, your phone can detect nearby Wi-Fi access points and compare them against a database of known locations to estimate where you are. Bluetooth beacons placed in stores and airports do something similar at close range.
These signals are not always tied to an app actively asking for your location. The operating system collects some of this data in the background to power features like automatic time zones or emergency services. But apps installed on your phone can also request continuous access, and many do, regardless of whether their core function actually needs it. A flashlight app, for instance, has no functional reason to know your location, yet some have historically requested it.
See what each location permission actually grants for a plain breakdown of how these access levels differ.
How data moves from your phone to brokers
When an app collects your location, it rarely keeps that data to itself. Most free apps are built with advertising software development kits, small pieces of code embedded by ad networks, that automatically transmit location records back to the ad network's servers. The app developer gets paid for including the kit. The ad network gets the data.
From there, the data travels further. Specialized companies called data brokers purchase raw location records from multiple sources, strip or hash obvious identifiers like your name, and then aggregate the records into movement histories. A history might show that a particular device visits a certain church every Sunday, stops at a particular medical clinic twice a month, and spends weeknight evenings at a specific residential address. No name is attached, but the pattern makes the device trivially re-identifiable to anyone who already knows one of those locations.
Brokers sell access to these profiles to advertisers, but also to insurers, employers, political organizations, and, in documented cases, to law enforcement agencies seeking to avoid the warrant process. Privacy policies do technically disclose this chain, but they describe it in language that most people do not have time to parse.
Check app permissions before installing
Before downloading a new app, look at its requested permissions in the App Store or Google Play. If a utility app asks for location access and you cannot think of a reason it would need that, that is worth paying attention to. You can always grant limited access after installing, or deny it entirely and see whether the app still works for your purposes.
For a broader look at how everyday activities feed this ecosystem, see the subtle ways personal data gets gathered.
What companies do with location profiles
Advertisers use location history to infer interests and demographics. If your phone regularly appears at a gym, an outdoor retailer, or a particular neighborhood, that feeds into a targeting category. Insurance actuaries have used location patterns to assess risk. Political campaigns have used movement data to identify potential voters near specific rallies. Retailers use foot traffic patterns to decide where to open new locations and which competitor stores their customers also visit.
The scale matters. A single record of someone visiting a health clinic on one Tuesday is not especially revealing. A pattern showing forty clinic visits over two years, cross-referenced with visits to a pharmacy and late-night searches near hospitals, builds something closer to a medical profile, constructed entirely from location and app behavior, without a single medical record being involved.
Practical steps to reduce what you share
Auditing location permissions is the most direct action available. On iPhone, Settings, then Privacy and Security, then Location Services lists every app with location access and lets you switch each to 'never,' 'ask next time,' or 'only while using the app.' On Android, the same control lives under Settings, then Location, then App permissions. Going through this list and removing access from apps that have no obvious need for it cuts off a large portion of passive collection.
Disabling Wi-Fi scanning when you are not actively using Wi-Fi closes another gap. Both platforms have a setting for this separate from the main Wi-Fi toggle. Turning off 'precise location' for apps that only need an approximate area, such as a weather app, is another adjustment that costs little in functionality while narrowing the data collected.
Background app activity is a separate concern covered in detail at how apps track you when not in use. A full audit of your phone's privacy settings, beyond just location, is worth the time: the privacy settings worth changing today walks through the ones with the biggest practical impact.
Frequently Asked Questions
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.