Home Reviews About
Twenty of Time

The Hidden Data Brokers Selling Your Location to Police

Your phone can reveal where you sleep, work, worship, seek medical care, and spend your evenings. That information may be collected by an app, passed through an advertising exchange, packaged by a data broker, and sold to a government agency without a police officer ever asking a telecommunications company for a warrant.

This system is difficult to see because location surveillance is usually buried inside ordinary digital activity. A weather app, game, navigation tool, shopping service, or social platform may request access to location data. The resulting records can then travel through a chain of companies whose names are unfamiliar to the people being tracked.

The issue is larger than one controversial contract or one especially invasive app. It is a market structure in which personal movements become commercial signals, and public authorities can sometimes buy access to those signals. Understanding that structure is essential for anyone concerned with privacy, due process, and the growing dependence of policing on private technology.

How Location Data Enters The Market

Most commercial location tracking begins with a mobile device identifier. Advertising companies may use a mobile advertising ID, IP address, cookie, account identifier, or a combination of signals to connect a device with places and behaviors. GPS data is particularly valuable, but Wi-Fi networks, Bluetooth beacons, cell towers, and app activity can also help estimate where a person is.

An application may collect precise coordinates for a legitimate feature, such as turn-by-turn directions. In other cases, an embedded software development kit gathers location information for advertising, analytics, fraud detection, or audience measurement. The privacy notice may disclose this possibility in broad language without making clear which downstream companies receive the data.

Data brokers aggregate these streams with information from retailers, public records, loyalty programs, websites, and credit-related sources. They may claim to sell audience segments rather than names. A record labeled as a device or household profile can still be highly revealing, especially when it contains repeated visits to a particular home, workplace, clinic, or place of worship.

The legal and commercial distinction between “anonymous” and “identified” data is therefore unstable. A persistent device appearing at a home overnight can often be linked to an address. Repeated movement patterns can identify an individual even when a broker has removed their name from the original file.

The Companies Behind The Surveillance Pipeline

Location intelligence companies occupy different positions in this ecosystem. Some collect data directly from apps. Some buy it from advertising exchanges. Others analyze or resell information to marketers, financial institutions, security contractors, and government customers. The companies may describe their products as aggregated, pseudonymous, or focused on patterns rather than people.

Fog Data Science became a prominent example after reporting documented its sale of location-based products to law enforcement agencies. Its tools were described as allowing investigators to search large collections of mobile location records and draw connections between devices and places. Reports also examined contracts involving agencies that used the service without public debate proportional to its surveillance capabilities.

Venntel has likewise drawn scrutiny for selling access to commercial location data to federal agencies. Public reporting and congressional investigations raised questions about how agencies acquired mobile location information and whether purchasing it from a broker was being used to avoid the protections associated with a warrant.

These firms are not the entire market. Other data companies have offered location analytics, foot-traffic intelligence, or advertising profiles that can potentially be repurposed for investigations. The names change, products are rebranded, and ownership can move between larger corporations. That fluidity makes oversight difficult and allows responsibility to become diffuse.

Why Police Purchases Raise Constitutional Questions

The central concern is often called the “data broker loophole.” If police obtain location records directly from a phone provider, constitutional rules may require legal process. The Supreme Court’s decision in Carpenter v. United States recognized that government access to historical cell-site location information generally requires a warrant because such records can reveal an extensive chronicle of a person’s movements.

Commercial location data complicates that framework. Agencies may argue that information voluntarily shared with an app or advertising network is held by private companies and is therefore available for purchase. Yet the individual may have had no meaningful understanding that a casual app interaction could contribute to a searchable government surveillance database.

A purchase can also bypass the transparency that normally accompanies a warrant. A judge may never review the request. The person whose movements are examined may never receive notice. A court record may not identify the broker, the source apps, the retention period, or the number of innocent people whose data was swept into an investigation.

The constitutional analysis can vary according to the type of information, how it was obtained, and the government’s stated purpose. That uncertainty itself is a problem. Government agencies should not be able to obtain sensitive records through a commercial route merely because the technology industry created a complicated chain of intermediaries.

What A Location Profile Can Reveal

A single coordinate is rarely the whole story. The real power of a location database comes from repetition. A sequence can show a person’s regular commute, a child’s school, a partner’s home, a support group, a political meeting, or a visit to an abortion provider. It can expose relationships between devices that repeatedly appear together.

Police may use these records to generate leads, identify a device near a crime scene, or examine movement before and after an event. A location match can be useful for an investigation, but it is not proof that the device owner committed wrongdoing. Phones are shared, left behind, carried by passengers, or associated with crowded public spaces.

Mass location searches also create risks for people who are not targets. A request for every device near a protest, religious service, clinic, or crime scene can collect information about many innocent individuals. Even when investigators begin with a legitimate purpose, broad access increases the chance of misidentification, secondary use, and future surveillance.

There is a social cost beyond individual cases. When people know that an app ecosystem can expose their movements to authorities, they may avoid protests, sensitive healthcare, legal advice, or community organizations. Privacy is not simply the ability to hide wrongdoing. It provides room for association, exploration, and dissent without constant observation.

Commercial Consent Is Often A Fiction

Companies frequently defend data collection by pointing to consent. In practice, consent may consist of a hurried tap on a permission prompt, acceptance of a long privacy policy, or continued use of an app after settings have been made difficult to understand. That is a weak foundation for transferring intimate movement records to unknown third parties.

There is also a major difference between consenting to receive local weather information and consenting to the sale of a detailed travel history. Many users do not know that advertising identifiers can be combined with precise location, nor that the information may be retained, enriched, and licensed to government customers.

The broader question is addressed in discussions about whether privacy is genuinely being exchanged for convenience or whether people are simply pressured into surrendering it. The essay on privacy and resignation explores that distinction: a choice made inside an opaque, unavoidable system is not equivalent to informed, voluntary agreement.

Regulators have begun challenging some forms of sensitive data commercialization. The Federal Trade Commission has pursued cases and settlements involving the sale or use of precise location information, while state privacy laws increasingly restrict the collection and sharing of sensitive data. These developments matter, but enforcement often arrives after years of collection and may affect only particular companies or practices.

The Different Paths To Government Access

It helps to distinguish several surveillance methods that are often blended together in public discussion. A cell-site location record comes from a wireless carrier and reflects a device’s connection to network infrastructure. A GPS record may originate in an app or operating system service. An advertising exchange record can be less precise in some cases but may cover large populations and connect location with commercial profiles.

Geofence warrants ask providers to identify devices present within a defined area during a specified period. Reverse keyword warrants seek information about people who searched particular terms. Commercial data purchases are different: an agency acquires records from a broker that may have gathered them for advertising or analytics rather than law enforcement.

The practical result can look similar—a list of devices, places, or movements—but the legal safeguards and public visibility may differ. Agencies can also combine sources. A broker’s data might generate a lead, carrier records might be sought later, and information from license-plate readers or social media could fill in the remaining details.

Access route Original source Typical strength Main privacy concern
Carrier location records Cell towers and wireless networks Broad historical movement patterns Long-term tracking through legal process
App-based location data GPS, SDKs, and mobile apps Potentially precise visits and dwell time Commercial collection repurposed for policing
Geofence warrant Provider databases Devices within a defined area Innocent people can be swept into an investigation
Data broker purchase Aggregated commercial datasets Flexible searches across many records Warrant requirements and public oversight may be bypassed
License-plate reader networks Cameras and private data providers Vehicle routes and travel history Persistent monitoring of drivers and associations

Protecting Yourself In A Brokered Data Economy

Individual privacy settings cannot solve a market designed to collect as much information as possible, but they can reduce the amount of data available for resale. Disable location access for apps that do not need it, choose “while using” rather than continuous access, and regularly review which applications have permissions. Delete unused apps and reset advertising identifiers where the operating system permits it.

A virtual private network can obscure some IP-based information, but it does not prevent an app with GPS access from collecting precise coordinates. Similarly, turning off location services may not eliminate every signal derived from Wi-Fi, Bluetooth, or cell networks. Privacy protection works best when it combines technical settings with skepticism about unnecessary apps and services.

Physical habits matter as well. Carrying a phone everywhere creates a detailed record of daily life, while leaving it behind can create different security and practical risks. The guide to physical privacy measures considers steps outside the screen, including how devices, surroundings, and routines can expose information.

Useful actions include:

What Real Accountability Would Require

A meaningful response must address both the government buyer and the commercial supplier. Agencies should disclose which brokers they use, what datasets they purchase, how often searches occur, and whether records are retained. Policies should require a warrant or equivalent judicial authorization for sensitive location information, regardless of whether the data comes from a carrier, app, or broker.

Searches should be narrow, documented, and subject to later notice where appropriate. Information about people who are not relevant to an investigation should be deleted quickly. Audits should test whether officers used location tools for personal, political, or discriminatory purposes. Public procurement records should not be the only source of information about a surveillance program.

The private market needs firm limits too. Precise location data should be treated as sensitive by default, with strict restrictions on sale, combination, retention, and secondary use. Companies should identify every category of recipient and provide a genuine way to refuse collection without losing basic access to a service. “Aggregated” should not be accepted as a magic word when repeated movements can be reconstructed.

Finally, courts and lawmakers need to treat commercial availability as irrelevant to the sensitivity of the information. A person’s movements do not become less intimate because an advertising intermediary stored them first. Police access should be judged by what the data reveals and what power it gives the state, not by the number of corporate hands through which it passed.

The hidden market for location data will continue to expand unless people, regulators, and courts make its operation visible. Review the permissions on your devices, learn how local agencies obtain digital records, and support rules that place judicial oversight before access. Location privacy is a condition of free movement and free association; protecting it requires treating personal mobility as something more valuable than an advertising signal.