Geofencing is a way of drawing a virtual boundary around a real place, such as a shopping centre, a stadium or a competitor’s car park, and triggering a marketing action when a mobile device enters, leaves or stays inside it. The action might be an advert, an app notification or adding that device to an audience for later ads.
How geofencing works
The boundary is set as a radius around a point or as a drawn shape on a map. The hard part is knowing where a phone is. Precise location usually comes from a phone’s GPS, Wi-Fi and mobile signal, and it only reaches an advertiser if an app on that phone collects it with the user’s permission and passes it on, either directly or through an ad exchange. Coarser location can be estimated from an IP address, which is often accurate only to a town or postcode area.
There are broadly two kinds of product sold as geofencing. The first is the radius targeting built into Google Ads and Meta Ads, where the platform uses its own location signals to show ads to people in or regularly in an area. The second is specialist programmatic vendors that buy ad space on apps and websites and target devices seen inside a small fence, sometimes as tight as a single building, and then retarget those devices for days or weeks afterwards.
A related idea is the app notification: a retailer’s own app, with location permission switched on, can send a message when a customer walks near a branch.
Why it matters
For a UK business with physical locations, geofencing can put an offer in front of people when they are close enough to act on it: an event venue reaching people at a nearby station, or a car dealer reaching visitors to a rival’s forecourt. It can also be used to measure footfall, by comparing which ad viewers later visited the premises.
The legal side matters just as much. Precise location data that can be linked to a device is personal data under UK GDPR, and it can reveal very sensitive things, such as visits to a clinic or a place of worship. Reading location from a device also falls under PECR, which requires consent. The Information Commissioner’s Office has published guidance on location data and on online tracking, and it expects the people in the data to have agreed to this use in a meaningful way.
Common mistakes
- Buying from a vendor without asking where its location data comes from and how consent was collected.
- Drawing fences so small that the audience is a few dozen phones, which makes reporting unreliable and edges towards tracking individuals.
- Fencing sensitive places, such as hospitals or schools, for commercial targeting.
- Treating “footfall uplift” reports as proof of sales without a control group.
- Paying a premium for geofencing when a simple radius in Meta Ads or Google Ads would reach the same people.
How to act on it
Start with the question you want answered. If you want people within a few miles of your shop to see your ads, the radius targeting in the main ad platforms is usually enough, cheaper and easier to report on. Test that first.
If you consider a specialist geofencing vendor, ask for the source of its location data, how consent was obtained and recorded, which apps supply it, the minimum fence size and audience size, and how it measures visits. Record your own lawful basis and check your privacy notice covers the activity. If the answers are vague, walk away.
Local campaigns on Facebook and Instagram that reach people near a business, within sensible limits, are part of the Facebook ads for local businesses work I run.
