… used in Australian stores
iBeacons are small Bluetooth Low Energy transmitters. They do not usually “see” you directly like a camera. Instead, they broadcast a signal that nearby phones can detect.
If your phone has Bluetooth enabled and a relevant app installed, the app may infer that you are near a particular shelf, store entrance, checkout, display, or shopping-centre zone.
Apple describes iBeacon as a location-awareness technology that lets apps respond when a device is near a beacon.
How stores use them
Australian retailers, shopping centres, and venues may use beacon-style systems for:
| Use | What it means |
|---|---|
| Proximity marketing | Sending offers or alerts when you enter a store or pass a product area. |
| Foot-traffic analytics | Measuring how people move through a store or centre. |
| Dwell-time tracking | Estimating how long customers spend in certain sections. |
| Customer profiling | Linking location patterns to loyalty apps, purchase history, wishlists, demographics, or ad profiles. |
| Indoor navigation | Helping users find products, gates, exhibits, or service desks. |
| Operational analytics | Studying queue times, heat maps, display performance, or staff allocation. |
A key concern is that beacon tracking becomes powerful when combined with :
- store apps,
- loyalty programs,
- payment data,
- Wi-Fi tracking,
- CCTV analytics,
- facial recognition,
- online ad IDs,
- and data brokers.
The beacon alone is often just a signal; the privacy issue emerges when that signal is linked to an identifiable person or profile.
Can they track you without consent?
Technically, Bluetooth beacons can interact with nearby devices, tracking usually “should” requires one or more of these:
- Bluetooth enabled
- A store, shopping-centre, loyalty, rewards, or third-party app installed
- Location/Bluetooth permissions granted
- Background app activity allowed
- A device identifier, advertising ID, app ID, loyalty account, or profile link
CHOICE has warned that retail stores and shopping centres may use Bluetooth beacon systems to track shopper movement when Bluetooth is enabled, and that these systems can support location-based profiling.
The sharper issue is not only “can the beacon detect a phone?” but whether the store can lawfully and transparently convert that detection into personal information.
Australian privacy law angle
In Australia, the relevant framework is mainly the Privacy Act 1988 and the Australian Privacy Principles. The OAIC states that retailers using technology to collect personal information must consider privacy impacts, community expectations, and compliance with privacy law.
The OAIC’s APP 3 guidance deals with collection of solicited personal information and stresses that entities must only collect personal information where reasonably necessary for their functions or activities.
So, for beacon use, the legal questions include:
- Is personal information being collected?
- Is the collection reasonably necessary?
- Has the customer been clearly notified?
- Has consent been obtained where required?
- Is the data minimised, secured, and deleted when no longer needed?
- Is it shared with advertisers, analytics firms, app vendors, or data brokers?
- Can the person opt out?
The ACCC’s Google location-data case is relevant because the Federal Court found Google misled consumers about collection and use of personal location data on Android devices. That case was not specifically about iBeacons, but it shows Australian regulators take misleading location-data practices seriously.
The real concern
The risk is not just a coupon popping up when you walk past shoes.
The deeper concern is the creation of a physical-world behavioural profile:
“This person entered Store A, paused at Product B, compared Section C, returned three times, avoided checkout, later purchased online, and matches a demographic profile.”
That can become part of a broader surveillance-commerce loop:
phone signal → store movement → app profile → loyalty account → purchase history → ad targeting → behavioural prediction → price/promotion manipulation
This is where beacon tracking overlaps with the larger issue of retail surveillance. Australia has already seen regulatory scrutiny around in-store technologies such as facial recognition, with the OAIC emphasising that retailers must meet privacy obligations when deploying technology that collects personal information.
Practical consumer steps
To reduce exposure:
- Turn off Bluetooth when walking through shopping centres or stores.
- Review app permissions, especially for retailer, shopping-centre, rewards, parking, fuel, supermarket, fast-food, and payment apps.
- Disable:
- background location access
- Bluetooth access
- precise location
- ad tracking where possible
- Avoid unnecessary loyalty apps if the trade-off is not worth it.
- Use app-only permissions, not “always allow,” where possible.
- Read privacy policies for references to location, Bluetooth, beacons, analytics, third-party SDKs, or “in-store experience.”
- Use cash or non-linked payment methods where lawful and practical if you want less profile linkage.
Bottom line
iBeacons are not inherently sinister. They can be used for navigation, accessibility, service efficiency, or legitimate customer convenience.
In Australian stores, the concern is justified when they are used invisibly, linked to loyalty identities, merged with purchase data, or shared through advertising and analytics networks.
The ethical line is crossed when stores turn physical movement into behavioural intelligence without clear notice, genuine consent, easy opt-out, and strict data minimisation.