Every Step You Take, Someone's Getting Paid: The Shadow Market Trading Your Movements in Real Time
You unlocked your phone this morning. Maybe you checked the weather, scrolled Instagram for a few minutes, opened a maps app to beat traffic. Routine stuff. What you probably didn't notice is that somewhere between all of that, your precise latitude and longitude — accurate to within a few meters — was packaged, timestamped, and sold. Possibly several times over.
Welcome to the real-time location data market. It's worth billions of dollars annually, it operates almost entirely out of public view, and the people whose movements are being traded rarely have any idea it's happening.
The Plumbing Nobody Talks About
Most people understand, in a vague way, that apps collect data. What's less understood is the industrial-scale infrastructure that moves that data from your phone to buyers you've never heard of.
Here's the rough anatomy of it. A free app — a weather app, a game, a coupon aggregator — embeds a third-party software development kit, or SDK, from a data broker. That SDK quietly harvests location pings in the background. Those pings flow back to the broker's servers, get matched against a persistent device identifier, and are bundled into a stream of movement data tied to what's effectively a permanent profile of you.
That profile then gets licensed out. To hedge funds running alternative data strategies. To retailers doing foot traffic analysis on their competitors. To political campaigns targeting voters by the neighborhoods they frequent. The buyers are sophisticated, the prices are high, and the whole transaction is invisible to the person at the center of it.
Firms like Veraset, SafeGraph, and Placer.ai have built substantial businesses on exactly this model. Some of them have faced scrutiny — SafeGraph made headlines in 2022 when Motherboard reported it was selling location data tied to visits to abortion clinics — but the industry itself has kept growing.
Wall Street's Dirty Little Data Edge
Hedge funds have been buying alternative data for years. Satellite imagery of retailer parking lots. Credit card transaction feeds. Shipping container manifests. But real-time geolocation has become one of the most coveted inputs in quantitative finance, and for good reason: it's fast, it's granular, and it tells you things that traditional financial data simply can't.
Consider what a fund can learn by tracking foot traffic at a chain of stores before quarterly earnings drop. Or by monitoring how many devices are pinging inside a pharmaceutical company's research campus on nights and weekends — a potential signal that something significant is in development. Or by watching migration patterns out of a city in the weeks before a major economic event.
This is legal. Controversial, yes. Ethically murky, absolutely. But the SEC hasn't drawn a clear line between alternative data and insider trading, and the data brokers selling the feeds are careful to argue that their data is aggregated and anonymized — even when researchers have repeatedly demonstrated that anonymization is largely a fiction at the individual level.
A 2013 MIT study showed that just four location data points are enough to uniquely identify 95% of individuals in a dataset. The math hasn't changed. The data has only gotten more precise.
The Legal Swiss Cheese
So how is any of this allowed?
The short answer is that the United States doesn't have a comprehensive federal privacy law. Unlike the European Union's GDPR, which imposes strict requirements on how personal data can be collected, processed, and sold, American consumers are largely governed by a patchwork of state laws and sector-specific regulations that leave enormous gaps.
The primary legal fig leaf the industry hides behind is consent — specifically, the buried language in app terms of service and privacy policies that technically authorizes data collection. Courts have generally upheld these agreements, even when it's obvious that no reasonable person reads them. The Federal Trade Commission has been increasingly vocal about the location data industry, and a handful of data brokers have settled enforcement actions in recent years. But settlements haven't slowed the market.
California's Consumer Privacy Act and its 2020 expansion give residents some rights — including the ability to opt out of data sales — but enforcement is inconsistent and the opt-out mechanisms are deliberately cumbersome. Most other states offer even less. A federal privacy bill has been debated in Congress for years. It hasn't passed.
Prediction Before Action
What makes the current generation of location data particularly unsettling isn't just the volume. It's what machine learning can do with it.
Data brokers and their clients aren't just looking at where you've been. They're building predictive models that anticipate where you're going. Feed enough historical location data into the right model, and you can identify patterns that the individual themselves isn't consciously aware of — the coffee shop you stop at every Tuesday, the gym you visit when you're stressed, the route you take when you're running late. Layer in demographic data, purchase history, and social graph information, and those predictions get sharper.
Retailers use this to time targeted ads for the moments you're most likely to be receptive. Political campaigns use it to identify persuadable voters based on the physical spaces they inhabit — which churches they attend, which union halls they walk past, which campaign offices they've been near. Insurance companies have explored using mobility patterns to assess risk. Employers have looked at it for workforce monitoring.
The phrase that keeps appearing in investor decks for these companies is "behavioral intelligence." It's a polished way of describing something more blunt: a system that knows you well enough to influence you.
What's Actually Coming
There are a few forces that could reshape this market, though none of them are moving fast enough to matter much right now.
Apple's App Tracking Transparency framework, introduced in 2021, dealt a real blow to the mobile advertising ecosystem by requiring apps to ask users for permission before tracking them across other apps. Many users said no. But location data collection within a single app largely continued, and the data broker industry adapted.
On the legislative front, the American Privacy Rights Act came closer than most previous attempts to establishing a federal standard in 2024, but it stalled before reaching a vote. State-level momentum is building, with more than a dozen states passing or advancing privacy legislation in the past two years.
Meanwhile, privacy-focused technology — from VPNs to apps that feed false location data to trackers — is finding a growing audience among consumers who've figured out what's happening. It's a cat-and-mouse dynamic that the data industry, with its resources and regulatory relationships, currently wins more often than not.
Your Location, Their Asset
There's something worth sitting with here. The infrastructure described above wasn't built by rogue actors. It was built by engineers, funded by venture capital, and blessed by lawyers. It operates in the open, pitches itself at industry conferences, and counts some of the most sophisticated institutions in American finance among its customers.
Your daily movements — the ordinary geography of your life — have been quietly reclassified as a commodity. The question of whether that should be legal, or whether you should have meaningful say in it, is one that the technology moved on without waiting for an answer.
Somewhere right now, a server is logging where you are. Someone is paying for that information. And the transaction is happening faster than you can read this sentence.