Pinned: How Your Location History Becomes a Tool for Harassment, Stalking, and Targeted Crime
Photo: U.S. Department of Defense, NORAD Graphic/Released, Public domain, via Wikimedia Commons
Your phone knows where you sleep. It knows where you worship, which medical facilities you visit, whether you spend nights at an address that is not your home, and how often you deviate from your usual routine. This knowledge is not incidental — it is the product of dozens of data collection systems operating simultaneously, most of them functioning with little meaningful notice to the person being tracked.
For the majority of people, most of the time, this ambient surveillance produces nothing worse than targeted advertising. For a meaningful and growing number of Americans, however, that same location record has been weaponized — by abusive partners, by stalkers, by commercial data brokers whose customers include people with harmful intentions, and by criminals who use movement patterns to plan thefts or worse.
Understanding where your location data goes — and who can reach it — is no longer a matter of abstract privacy philosophy. It is a practical safety question.
The Collection Landscape: More Sources Than You Realize
Most people are aware that their phone's GPS can reveal their location. Far fewer appreciate the breadth of other mechanisms contributing to their location profile.
GPS is the most precise but not the only vector. Your device also triangulates position using cell tower signals, which your carrier logs continuously as a matter of network operation. Wi-Fi positioning — using the known locations of nearby wireless networks — adds another layer. Bluetooth beacons deployed in retail environments, airports, and sports venues can pinpoint your position within a few feet when your phone's Bluetooth is active.
Beyond the device itself, applications collect and transmit location data at a rate that frequently exceeds what users expect. A 2021 investigation by The Markup found that dozens of popular apps — including weather applications, gas price finders, and coupon services — were sharing precise GPS coordinates with third-party data brokers, often based on consent disclosures buried in lengthy terms of service that few users read. The data was then aggregated, timestamped, and sold.
Social media check-ins and geotagged photos add a voluntary layer that users often underestimate. A photo posted to Instagram or Facebook carries embedded metadata that can include precise GPS coordinates unless that data is stripped before upload — something most platforms do not do automatically for all content types.
Finally, payment and loyalty card transactions create a location record linked to your identity every time you make a purchase. Your credit card issuer, the merchant, and any loyalty program operator all hold a timestamped record of where you were and what you spent.
How Abusers and Stalkers Exploit Location Data
Domestic violence advocates and law-enforcement professionals have documented a well-established pattern: location tracking technology is one of the most commonly deployed tools in intimate partner abuse and stalking cases.
The methods range from technically sophisticated to alarmingly simple. At the low-tech end, an abusive partner who previously shared a family phone plan retains access to carrier location-sharing features — such as AT&T's FamilyMap or Verizon's Smart Family — even after a separation, unless the tracked person explicitly removes themselves from the account or switches carriers. Shared cloud accounts, including Apple's Find My and Google's location sharing, present the same problem.
More targeted surveillance involves the covert installation of stalkerware: commercially available applications marketed under names like "parental monitoring" or "employee tracking" software that run invisibly on a device and report continuous location data to a controlling party. The Coalition Against Stalkerware, a nonprofit organization, documented thousands of stalkerware installations in the United States in its most recent annual report, with the highest concentrations in states with large urban populations.
At the more technically sophisticated end, some abusers purchase location data directly from data brokers. A 2021 Vice investigation demonstrated that a journalist was able to purchase the precise location history of a US military base for a few hundred dollars from a commercial data broker — no legal authority required. The same market is accessible to anyone willing to pay, including individuals with harmful intentions toward a specific person.
Criminal Applications Beyond Domestic Abuse
Location data exploitation is not limited to intimate partner contexts. Law-enforcement agencies and security researchers have documented several distinct criminal use patterns.
Burglary targeting using social media geolocation is well-documented. Criminals monitor public posts for geotagged vacation photos, which signal that a home is unoccupied. Some operations have used location data from public check-ins to time residential burglaries with near-surgical precision.
Robbery and carjacking operations have used location patterns — derived from stalkerware or purchased data — to identify high-value targets and intercept them at predictable points in their routines, such as regular ATM visits or parking garage arrivals.
Corporate espionage represents a less-publicized but serious application. Tracking the location history of executives or engineers can reveal which competitors they are meeting with, which law firms or regulatory offices they are visiting, and what facilities they are accessing — all without intercepting a single communication.
The Legal Framework and Its Gaps
Federal law has not kept pace with the commercial location data industry. The Electronic Communications Privacy Act, the primary federal statute governing digital surveillance, was enacted in 1986 and does not address the commercial sale of location data in any meaningful way. The Federal Trade Commission has taken enforcement action against some egregious data broker practices, but its authority is limited and its resources are finite.
A handful of states have enacted stronger protections. California's Consumer Privacy Act gives residents the right to opt out of the sale of their data, including location data. Illinois and Virginia have passed related legislation. But a federal framework providing uniform protection for all Americans does not yet exist.
For victims of stalking and harassment, the legal recourse is largely reactive. A restraining order prohibits contact but does not automatically sever access to shared accounts or carrier location features. Victims often must navigate a fragmented set of technical and legal remedies simultaneously, frequently without adequate institutional support.
A Practical Guide to Reducing Location Exposure
The following steps address the most significant collection vectors and are applicable across the major device platforms in common use in the United States.
On your iPhone: Navigate to Settings > Privacy & Security > Location Services. Review every application listed and revoke location access for any app that does not require it for core functionality. For apps that legitimately need location — navigation, weather — select "While Using" rather than "Always." Disable "Precise Location" for any app that does not require GPS-level accuracy.
On Android devices: Open Settings > Location > App Permissions. Apply the same review process. Additionally, disable "Wi-Fi scanning" and "Bluetooth scanning" under Location > Location Services, as these allow apps to infer your position even when GPS is off.
Review and revoke location sharing on cloud platforms. Check Apple's Find My app, Google Maps' location sharing, and any family-tracking applications you may have previously enabled. Remove any parties who should not have ongoing access to your whereabouts.
Audit your carrier account. Log into your wireless carrier's account portal and review any location-sharing or family-tracking features that may be active. If you have recently left a shared plan, confirm that your number is no longer enrolled in tracking services associated with the former account holder.
Strip metadata from photos before sharing. On iOS, sharing a photo directly from the Photos app to a message or social platform typically strips GPS metadata. Verify this behavior for each platform you use. On Android, the Google Photos sharing function also strips location metadata by default, but third-party apps may not.
Check your device for stalkerware. Unexpected battery drain, elevated data usage, and a device that remains warm when idle can all indicate unauthorized background processes. The Coalition Against Stalkerware maintains a list of detection resources at stopstalkerware.org. If you suspect your device is compromised and you are in an unsafe situation, consult with a domestic violence advocate before taking action, as removing stalkerware can alert an abuser.
Opt out of data broker location sales. Several data broker opt-out services — including Privacy Rights Clearinghouse's directory and commercial services such as DeleteMe — can submit removal requests to the major location data brokers on your behalf. This is not a complete solution, but it reduces the size of your commercial location profile.
Location Privacy as a Safety Imperative
The framing of location privacy as a preference — something nice to have for people who care about such things — fundamentally misrepresents the stakes. For survivors of intimate partner violence, for individuals with stalkers, for people in professions that attract unwanted attention, and for anyone whose routine movements could make them a target, location data is not an abstraction. It is a safety variable.
The infrastructure that generates, stores, and sells that data was built without adequate consideration of these harms. Addressing the gap requires both policy reform and individual action. The policy reform will take time. The individual steps are available now.