Skip to content
https://rgearshop.com/

Resistance Kitty

The sassiest cat fighting fascism

  • Home
  • About
  • News
  • Comics
  • Survival Guides
  • EpsteinWiki
  • Resistance Directory
  • The Butterfly Bureau
  • Merch & Mayhem
  • Toggle search form

RSG #337: How To Investigate Government Purchases of Commercial Location Data

Posted on August 24, 2026August 24, 2026 Dr. Harmony By Dr. Harmony No Comments on RSG #337: How To Investigate Government Purchases of Commercial Location Data

Your phone knows where you sleep, work, worship, shop, protest, receive medical care, and spend Tuesday evenings when you told everyone you were staying home.

That location history can travel through mobile applications, advertising systems, software development kits, data aggregators, and commercial brokers. Government agencies have purchased access to commercially available information rather than obtaining it directly from a phone provider through traditional legal process.

Officials may describe this as buying ordinary commercial data. That phrase performs an impressive amount of emotional labor. Precise location records can expose a person’s home, relationships, medical decisions, religious practices, political activity, and daily routines.

This Resistance Survival Guide explains how to identify government purchases of commercial location data, trace the information back to its source, examine how investigators search it, and test whether the program complies with current constitutional protections.

How Commercial Location Data Is Created

Mobile applications may collect precise location information through GPS, nearby wireless networks, Bluetooth signals, and other device services. Some applications need location information to perform a requested function. Others collect more than users reasonably expect.

Advertising systems can attach location signals to a mobile advertising identifier. Data companies may combine those signals with other information, package them into products, and sell access to advertisers, analysts, contractors, or government agencies.

A government customer may receive raw coordinates, movement histories, geographic search tools, device identifiers, or analytical reports. Some products allow users to draw a boundary around a location and identify devices detected there. Others begin with a device and display where it traveled.

The word anonymous should be treated as an opening claim, not a closing argument. Repeated visits to a residence and workplace may make a supposedly unidentified device considerably less mysterious.

Why the Legal Landscape Matters

In Carpenter v. United States, the Supreme Court held in 2018 that government acquisition of historical cell site location records was a Fourth Amendment search. The government generally needed a warrant supported by probable cause.

Some agencies argued that Carpenter applied when the government compelled a company to surrender information, but not when an agency purchased similar information from a commercial broker.

The Supreme Court significantly expanded location privacy protections in Chatrie v. United States on June 29, 2026. The Court held that police conduct a search when they obtain historical cell phone location information from a third party, even for a limited period.

Chatrie strengthens arguments against warrantless purchases of location data. However, individual programs may involve different information, purposes, users, and legal authorities. Do not announce that every purchase is automatically unlawful. Identify the exact data and obtain the agency’s legal reasoning first. Constitutional analysis deserves more than interpretive jazz hands.

What Federal Regulators Have Already Found

The Federal Trade Commission’s action against Gravy Analytics and Venntel addressed allegations involving location data connected to health facilities, places of worship, and other sensitive sites. The agency alleged that consumer consent was not properly verified for commercial and government uses.

The FTC has also taken action involving X Mode and Outlogic, InMarket, and Mobilewalla.

These cases do not prove that every government customer misused data. They do establish that consent, sourcing, sensitive locations, retention, and downstream use deserve scrutiny.

Step by Step Guide

Step One: Identify Every Possible Purchasing Agency

Begin with police departments, sheriffs, prosecutors, corrections agencies, fusion centers, homeland security offices, inspector general units, tax agencies, and emergency management departments.

Search the agency website and public meeting records for location intelligence, geospatial analysis, mobile advertising data, commercial telemetry, device intelligence, movement analysis, and commercially available information.

Record the offices and contractors that may use the product. A subscription purchased by one department may quietly serve an entire regional network.

Step Two: Search Procurement Records

Search contracts, purchase orders, invoices, vendor payment registers, council agendas, grant records, subscription renewals, and procurement card expenses.

Use the vendor’s name, parent company, subsidiaries, product names, former names, and resellers. Search federal spending records through USAspending.gov and federal procurement information through SAM.gov.

Look for purchases hidden inside analytical services, investigative support, software licenses, intelligence subscriptions, or consulting agreements. Government surveillance occasionally arrives wearing a fake mustache labeled professional services.

Step Three: Reconstruct the Data Supply Chain

Determine where the vendor obtains its location data. Search privacy policies, software development kit documentation, consent language, advertising disclosures, regulatory complaints, contracts, and vendor presentations.

Map the chain from application to advertising exchange, data supplier, aggregator, broker, reseller, contractor, and government customer.

Record whether the agency purchased raw data or merely accessed a vendor platform. Also determine whether the vendor combines location records with names, addresses, demographics, vehicle information, or online activity.

Step Four: Obtain the Contract and Product Materials

Request the complete contract, statement of work, proposal, pricing schedule, amendments, renewals, user manuals, training materials, demonstrations, and technical documentation.

Identify the geographic coverage, historical depth, update frequency, number of authorized users, search limits, export functions, and available identifiers.

A contract saying data services tells you almost nothing. The statement of work and training slides often explain what officials actually bought.

Step Five: Request Search and Access Logs

Request audit logs showing which users accessed the system, when they searched, what functions they used, and whether they exported information.

Ask for aggregate statistics if specific searches involve active investigations. Useful totals include the number of searches, devices examined, geographic searches, exports, investigations supported, warrants obtained, and accounts disciplined for misuse.

If the vendor claims it cannot produce logs, document that carefully. An immensely powerful surveillance platform without reliable audit records is not sophisticated. It is a liability wearing expensive software.

Step Six: Find the Legal Justification

Request legal memoranda, counsel opinions, privacy assessments, constitutional reviews, approval records, and communications discussing Carpenter, Chatrie, warrants, subpoenas, consent, or commercially available information.

Pay special attention to opinions written before June 29, 2026. Ask whether the agency reviewed its practices after Chatrie and whether access now requires a warrant.

Separate the authority to purchase a subscription from the authority to conduct a particular search. Procurement approval does not magically become constitutional permission.

Step Seven: Examine Searches Around Sensitive Locations

Request policies and aggregate records concerning searches near medical facilities, reproductive health providers, places of worship, schools, shelters, labor organizations, political gatherings, military facilities, and private residences.

Determine whether the agency blocks these searches, requires heightened approval, or allows them without special safeguards.

Do not request or publish information identifying patients, survivors, children, worshippers, or protesters. The investigation should reveal government practices without recreating the privacy harm.

Step Eight: Trace Internal and External Sharing

Request dissemination logs, intelligence reports, exports, emails, and agreements showing where purchased data traveled.

Map sharing with federal agencies, local police, prosecutors, fusion centers, task forces, contractors, and foreign partners. Determine whether recipients could conduct new searches or retain exported information after the original subscription ended.

A deletion policy at the purchasing agency means very little if seventeen partners already downloaded copies.

Step Nine: Test Consent Claims

Locate the disclosures presented to people whose applications supplied the data. Record whether consent was informed, specific, optional, and connected to government use.

Compare the vendor’s claims with findings in relevant FTC complaints and orders. Determine whether suppliers were audited or simply promised that everyone clicked something somewhere.

Consent for weather alerts is not obviously consent for a government movement database. The tiny button did not receive a law degree overnight.

Step Ten: Measure Outcomes

Request records showing how often commercial location data produced a verified lead, warrant, arrest, charge, conviction, emergency response, or exoneration.

Also request false matches, abandoned leads, complaints, suppression motions, disciplinary findings, and investigations in which the data could not be corroborated.

Compare results with subscription costs and the number of people whose information was searched. A program should not receive credit merely because it generated a tremendous quantity of investigation flavored paperwork.

Step Eleven: Check Retention and Deletion

Identify how long the vendor, agency, and partner organizations retain queries, coordinates, reports, exports, and device identifiers.

Request deletion schedules, destruction certificates, litigation holds, backup policies, and records concerning terminated contracts. Determine whether the agency can delete information held by the vendor and whether the vendor continues receiving new data after the contract ends.

Step Twelve: Publish a Defensible Findings Table

Create a table listing the agency, vendor, product, cost, data source, search capability, legal authority, warrant requirement, retention period, sharing partners, oversight, and documented outcomes.

Label confirmed facts, vendor claims, agency claims, reasonable inferences, and unanswered questions separately.

Do not publish raw location data about private people. Resistance Kitty is investigating the watchers. She is not opening a competing surveillance boutique.

Red Flags That Deserve Immediate Attention

Major warning signs include purchases made through contractors, vague contract descriptions, missing search logs, searches unrelated to an active investigation, and legal reviews that predate Chatrie.

Other red flags include data linked to sensitive locations, indefinite retention, searches by untrained personnel, information shared without written agreements, and vendor consent claims that the agency never independently verified.

Watch for officials claiming the data is both anonymous and useful for identifying people. Those positions may coexist in a sales brochure, but they become rather awkward when seated beside each other at an oversight hearing.

Turning the Findings Into Accountability

Send documented findings to privacy commissions, inspectors general, legislative oversight committees, public defenders, civil liberties organizations, and independent journalists.

Ask the agency to suspend searches that lack appropriate legal process. Recommend warrants where constitutionally required, strict limits on sensitive locations, written approval standards, short retention periods, complete audit logs, independent reviews, and public reporting.

Communities can also adopt ordinances requiring public notice and legislative approval before agencies acquire surveillance technology. Oversight works much better before the invoice than after the scandal.

Closing RK Thoughts

Commercial location data allows government agencies to follow movements without installing a tracking device or contacting a phone company directly. The surveillance may begin in an application, pass through several private companies, and arrive at a government desk looking suspiciously clean.

Your investigation must follow that entire journey.

Find the purchase. Reconstruct the supply chain. Obtain the search rules. Trace the sharing. Test the results. Then ask whether the government bought information it would otherwise have needed judicial permission to obtain.

The Constitution should not disappear because someone found a reseller.

Sources

  1. Carpenter v. United States
  2. Chatrie v. United States
  3. FTC Order Concerning Gravy Analytics and Venntel
  4. FTC Order Concerning X Mode and Outlogic
  5. FTC Order Concerning InMarket
  6. FTC Order Concerning Mobilewalla
  7. ODNI Policy Framework for Commercially Available Information
  8. Brennan Center Report on Government Data Purchases
  9. Electronic Frontier Foundation Surveillance Technologies Database
  10. MuckRock Public Records Tools

Support Resistance Kitty’s Work

  • Merch & Mayhem
  • Buy Resistance Kitty a Treat
Resistance Survival Guide Tags:Carpenter v United States, Chatrie v United States, commercial location data, data brokers, Fourth Amendment, geolocation records, government purchases of location data, location surveillance, mobile advertising data, privacy rights, public records investigation, Resistance survival guide, surveillance contracts, warrantless surveillance

Post navigation

Previous Post: RSG#336: How To Investigate Government Use of Social Media Monitoring Tools

Related Posts

  • RSG #197 How to Archive Web Pages and Social Media Posts So They Hold Up as Evidence Resistance Survival Guide
  • #92 How to Expose Local Corruption Without Getting Scratched Resistance Survival Guide
  • #150 How to Turn Rage into Results: The Shutdown Sellout Edition Resistance Survival Guide
  • RSG #204 How to Talk to Moderates and Apolitical Neighbors Without Triggering Defensiveness Resistance Survival Guide
  • RSG #243: Oh Look, You’ve Got a Fan… Now Let’s Make That Their Problem Resistance Survival Guide
  • #57 How to Sabotage a Prison Build with Reviews, Boycotts, and Local Uproar Resistance Survival Guide

More Related Articles

#55 How to Form a Rapid Response Team for Street Action Resistance Survival Guide
#19 How to Email Government Employees and Make It Count Resistance Survival Guide
RSG #207 When NOT to Publish Information Resistance Survival Guide
RSG#333: How To Audit Secret Government Watchlists and Risk Scores Resistance Survival Guide
#92 How to Expose Local Corruption Without Getting Scratched Resistance Survival Guide
RSG#263: How To Stay Safe If You Are Implanted Within the Enemy Resistance Survival Guide

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RSS FEED

Categories

  • Call to Action
  • Civic Mischief HQ
  • Executive Orders
  • Featured Resisters
  • Knives Out Activities
  • Resistance Kitty Comics
  • Resistance Survival Guide
  • Resistance Wins
Sign Up To Get Resistance Kitty in your inbox!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Recent Posts

  • RSG #337: How To Investigate Government Purchases of Commercial Location Data
  • RSG#336: How To Investigate Government Use of Social Media Monitoring Tools
  • Day 576: CIA Drone Questions, Nuclear Fears, a $40 Trillion Debt, and Abbott’s ICE Extradition Standoff
  • Day 576  THE NUCLEAR BUTTON GETS PARENTAL CONTROLS
  • RSG#335: How To Audit Predictive Policing Systems and Their Hidden Feedback Loops

Recent Comments

  1. Dr. Harmony on RSG#199 Creating a Personal Legal Emergency Card
  2. Dr. Harmony on RSG#199 Creating a Personal Legal Emergency Card
  3. Monica on RSG#199 Creating a Personal Legal Emergency Card
  4. Monica on How to Prepare for War-Related Disruption Without Panicking
  5. Dr. Harmony on Request for Emergency Medical and Constitutional Review of Presidential Fitness

Copyright © 2026 Resistance Kitty.