The FTC managed to take legal action against a startup from New York (Nomi Technologies) that covertly tracks the movements of Americans in stores via the Wi‑Fi signals of their smartphones.
The FTC published a PDF in late 2013 that said Nomi Technologies was violating the law by not notifying buyers in advance.
Nomi's surveillance service is used by retail chains (usually Super Markets) to analyze certain data. Administrators were able in all stores that use Nomi Wi-Fi hotspots to locate all customers who had mobile devices with them, and to record their location.
Buyers (customers) are identified by the MAC addresses of their gadgets. The points where most data were collected from the shelves, the aisles, and even outdoor areas, were extremely useful for store managers, as they indicated how long customers spend in the stores, where they stop, as well as the number of people who walk in front of a display window without entering.
From January through September 2013, Nomi's technology collected records from nine million mobile devices. By October of the same year, the company had 45 customers using the technology.
Nomi reports that it strives for customer anonymity by passing MAC addresses through a hashing function, but because each address always produces the same hash, each buyer is more or less uniquely identified in the company's database.
Nomi said that it accepts the request from the FTC, claiming that an opt‑out mechanism is needed for those who still believe there is privacy protection on this planet (!).
The FTC claims in its official complaint that Americans should be able to opt out and avoid spying so they don’t encounter a Nomi Technologies website in front of them that contains the MAC addresses of their devices.
“The actions and practices of Nomi constitute unfair or fraudulent activities and practices that affect commercial transactions in violation of article 5(a) of the Federal Trade Commission law,” says the FTC.
