They Sold Your Movement for a Menu Scan

You pointed your phone at the QR code on a menu. The app asked for your location. You tapped Allow.

That tap sent your location to an advertising company inside the scanner. They sold it. Brokers bought it. That is the story: the sale of where you were standing.

I am tired of this. You are tired of this. Location tracking as a business model, sold out of an app that was supposed to read a QR code.

How a QR scanner gets to sell your location

On Android, there is no separate location permission for an ad library. When you grant an app access to your GPS, every third-party kit bundled inside that app gets the same access. The Electronic Frontier Foundation published that finding in July. Staff technologists Lena Cohen and Bill Budington intercepted the traffic. Exodus Privacy showed them which kit was sitting in the apps.

QR Scanner has been downloaded more than 50 million times. GPS Speedometer has been downloaded more than 10 million times. Both were sending precise coordinates to BidMachine. Neither app warned you. Neither listed location sharing with third parties in its Play Store Data safety section.

Precise location on Android can be accurate to about 160 feet, and sometimes as close as 10 feet. That is not a city. That is a table, a driveway, a church parking lot.

The scanner asked for location. The ad kit used that permission to put your coordinates into a real-time bidding auction. In that auction, ad companies broadcast user data to thousands of potential buyers. Location brokers do not only bid on the ad space. They collect the personal information inside the bid request. That is how a menu scan becomes a line in someone else's map.

The companies that left the switch on

InMobi claims more than two billion users across more than 150 countries. Its Android integration guide tells developers the SDK automatically forwards location signals when available, and that location-enriched impressions typically yield higher revenue. In 2016, InMobi settled with the Federal Trade Commission for bypassing user permissions and tracking people through Wi-Fi network data.

BidMachine claims over 600 million direct SDK users. Before EFF contacted them, their Google Play privacy guidance said precise location was not collected. The traffic said otherwise. After EFF reached out, BidMachine updated the docs to admit they collect precise location by default once the app has permission. They still do not clearly tell a developer how to turn it off. They told EFF they cannot get location unless the user granted the app permission through the operating system, and that publishers are responsible for the consent flow.

Verve's HyBid kit tells developers location tracking is enabled by default if the user gave the app permission. Verve told EFF it uses network-provider location, not GPS, and coarsens it to no less than 1,850 feet. That is still a sale of where you are. Huawei's Petal Ads kit, which Huawei says sits in more than 85,000 apps, also shares location by default when the app has permission. The off switch is buried in a compliance guide, not on the main setup pages.

These companies make more money when your location is attached to the ad. That is why the collection ships turned on.

Who buys the map

Location brokers sell the movements of billions of people. The data comes from phones. Some apps sell it directly. Other apps leak it through advertising kits in those auctions.

EFF is plain about what that data has already been used for: ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking U.S. military personnel. In 2025, a hack of location broker Gravy Analytics turned up thousands of apps that may have been sources of its data. When journalists called the developers, many said they had no relationship with Gravy and no idea their users were in that pile.

The person who built the QR scanner may not have meant to sell you. The library did it anyway. You still got sold.

We are tired of the sale

You allowed a QR scanner to read a menu. You did not allow a broker to keep a file on where you eat. App-level Allow is not consent to that. Most people do not know the kit is even in the app.

If you can scan a QR code without giving the app your location, do not give it your location. Read the Play Store Data safety section and look for location shared with third parties. If the app needs location to work, assume the ad kit can use that same permission unless someone turned it off.

Developers who dropped in a banner to keep the lights on got used too. They should audit the kits they ship and shut location sharing off. That does not make the ad company innocent. The default is how they take it. The product is your movement.

People are tired of being tracked. Tired of the data sale. A QR code on a menu should open the menu.

0 comments

Leave a comment