Why websites request your location and ways to manage it
You're browsing from your couch in Adelaide, half-watching the cricket, when a site pops up a little prompt: "We need your location." It's tempting to just tap allow and get on with it. Most Australians do, often without thinking about what that single click actually reveals.
Behind that prompt sits a surprisingly layered technology stack, and the data exchanged can be far more personal than a suburb name. Understanding what gets shared, and why, is the first step toward browsing on your own terms rather than the site's.
The good news is that you have more control than the prompt suggests. From the browser to the operating system, from your home NBN connection to the dodgy pub Wi-Fi you joined in Cairns, there are practical levers you can pull without turning the internet into a dial-up wasteland.
How a website actually pinpoints you
When a site asks for your location, it usually isn't reaching for satellites. The most common method is the browser API, which combines several signals to produce a coordinate. Your device's GPS chip is one input, but indoors at a Melbourne cafe the signal is weak, so the browser leans on Wi-Fi fingerprinting: it checks the names and signal strengths of nearby networks and matches them against a database maintained by Google or Apple.
Your IP address plays a role too. Australian ISPs like Telstra, Optus, iiNet and TPG hand out IP ranges that map to particular regions, which is why a Sydney news site might quietly log your state even if you block every script. Combined with cell tower triangulation on mobile, these signals create a remarkably accurate picture.
The site never sees all of that directly. It receives either a precise latitude and longitude (only if you grant permission) or a coarse estimate derived from your network. The distinction matters, because granular coordinates can identify your house, while an IP-level guess usually cannot.
Legitimate reasons for the prompt
Not every location request is a marketing grab. Weather services genuinely need your suburb to show the right radar. Maps obviously work better when they know where you are. Streaming platforms use your region to honour licensing agreements, which is why Netflix libraries shift between Brisbane and Bali.
Banking and government sites also lean on location signals as a fraud check. If a login attempt suddenly appears to come from an IP block normally associated with Eastern Europe, your bank's fraud team wants to know. Local councils, transport apps in Perth or Hobart, and even some small business delivery services use location data to function rather than to profile.
There are regional legal reasons too. Australia has the Privacy Act 1988 and the Notifiable Data Breaches scheme, which means a site asking for your location has obligations about what it does with the answer. None of this removes the need for caution, but it explains why a thoughtful prompt isn't always an ad network in disguise.
When a request crosses the line
The trouble starts when a site asks for more than it needs. A news article has no business knowing your GPS coordinates. A coupon page doesn't need your precise latitude to show a 10 percent discount at the local servo. These requests are usually about building a profile, selling it to data brokers, or feeding an ad bidding system that pays fractions of a cent per query.
Some sites also use subtle workarounds. They might not ask the browser at all and instead infer location from your IP, your timezone, the language of your operating system, or even the fonts you've installed. None of those require a prompt, which is why you might never see a request and still be geolocated.
If a site asks persistently after you declined, that's a red flag. Legitimate services remember your answer for the session and move on. Sites that push back are often harvesting data for resale, and that's the moment to walk away or tighten your settings.
Browser-level controls worth using
Every modern browser gives you a permission manager, and most Australians ignore it. Chrome, Edge, Firefox and Safari each let you revoke location access per site, with a toggle that defaults to off for new domains. Spending five minutes in those settings clears a surprising amount of accumulated permission.
A second layer is the global default. You can usually tell your browser to never share precise location, only share a rough approximation, or ask every single time. The "ask every time" option feels annoying but is genuinely the safest for casual browsing. For trusted sites like your bank or a mapping tool you use weekly, set an exception.
Privacy-focused browsers go further. Firefox strips many fingerprinting signals by default, and Brave blocks scripts that would otherwise sniff your network details. You can also install extensions that spoof your timezone and language, which makes IP-based geolocation less reliable without breaking the sites you actually want to use.
Mobile settings and the app problem
Phones are where most location leakage happens. Even with a browser prompt declined, apps often have their own location permission, and Android and iOS make it easy to grant blanket access and forget. The fix is straightforward: open Settings, find Privacy or Location Services, and switch most apps to "while using" or "never."
Background location is the silent drain. A weather app tracking you in the background consumes battery and pings Apple's or Google's location services constantly. Restricting it to foreground only usually has no practical downside and noticeably extends battery life on a long drive across the Nullarbor.
Be wary of "always allow" requests that arrive during setup. Many apps ask for it by default because it improves their metrics, not yours. The Australian regulator OAIC has published guidance reminding users that location is sensitive information, and that they have the right to say no without losing core functionality.
Network-level and Wi-Fi considerations
Your router contributes to the picture as well. Home NBN connections usually have a stable IP that maps cleanly to a city or suburb, which is why a stranger who guesses your IP can often place you within a few kilometres. Most modern routers let you change DNS providers, and using a privacy-focused resolver or a reputable VPN adds another layer between your IP and the sites you visit.
Public Wi-Fi is its own beast. Joining a hotspot at a Brisbane airport lounge or a Sydney hotel bar hands the local network operator your device's MAC address and traffic patterns, both of which can be linked to a location profile. A useful primer on public and private hotspots walks through how those networks actually identify you, and what changes when encryption isn't end-to-end.
The simplest habit is also the most overlooked: turn Wi-Fi off when you aren't using it. A phone that keeps probing for known SSIDs in your pocket is broadcasting a list of places you've been. Switching it off during a quiet arvo at home, on the train down to Geelong, or during a run around Coles silences a surprisingly chatty channel.
Building habits that actually stick
Privacy isn't a one-off settings audit. It's the small repeated choices that compound. Before granting a location prompt, ask yourself whether the site actually needs it, and whether a postcode field would do the same job. For most content sites, it would.
Review your permissions every couple of months. Apps you forgot you installed often still hold location rights, and operating system updates occasionally change how permissions behave. A ten-minute check each quarter keeps the picture tidy without becoming a chore.
Finally, treat location data like any other personal detail: useful when genuinely needed, risky when shared casually. The internet works perfectly well for reading the news, watching the footy highlights, or buying a birthday present with a postcode, a suburb selection, or simply "Australia" as the location. Anything more precise is a gift to the site.
| Method | Typical accuracy | Privacy risk | How to control it |
|---|---|---|---|
| GPS coordinates | Within 5–20 metres | High | Browser permission toggle |
| Wi-Fi fingerprinting | Indoor, dense areas | Medium-High | Disable Wi-Fi scanning |
| IP geolocation | City or suburb | Medium | VPN or privacy DNS |
| Cell tower triangulation | Hundreds of metres | Medium | Mobile network settings |
| Timezone & language signals | Country or region only | Low | Spoof via browser settings |
The most useful thing to take away from all of this is that location sharing is rarely all-or-nothing. A precise "deny" on a news article, a thoughtful "allow once" on a weather radar, and a blanket "off" for the background apps you never open gives you most of the benefit of geolocation with a fraction of the exposure. Pick one lever today, the permission manager in your browser, and work from there.