Some Dating Websites Do Not Remove Location Data From Pictures

While the majority of dating websites do a good job of managing the privacy of their users, a class research project at the University of Colorado Boulder’s Leeds School of Business found that 21 of 90 dating websites the class examined did not properly remove location data from pictures uploaded by their users.

As a result of people taking more photographs with cameras and cell phones containing Global Positioning System chips, some dating website profile pictures contain GPS coordinates showing where a picture was taken, said Associate Professor Kai Larsen, who taught the class on Privacy in the Age of Facebook. When such information is not removed by the dating website, commonly available tools can be used to detect the location of a person’s residence or other locations frequented by the user.

This gap in privacy protection leaves women users especially vulnerable to online predators, the CU-Boulder student researchers said. Users of dating websites share a plethora of private details but generally will not share their addresses or real names unless a stronger relationship develops through multiple online and offline interactions.

The largest dating sites, such as Match.com and PlentyofFish.com, were found to remove location metadata from user profile pictures. But 23 percent of the 90 websites were found to leave metadata attached to the profile photo. All of these specialized dating sites were based on such attributes as age, disability, hobby or religion.

Twelve of the 21 websites were run by a single Canadian company, SuccessfulMatch.com. According to the SuccessfulMatch website, the company runs 24 dating websites on the same platform, 12 of which were not examined as part of the research project.

“While we were pleased to see such a high level of responsible behavior by online dating companies, an online predator would require no more than one website to act irresponsibly,” Larsen said. “The fact that we found more than 20 websites that do not carefully maintain user privacy is cause for concern, in that individual users are left to maintain their own privacy by carefully confirming that any uploaded picture does not contain GPS coordinates.”

Metadata is “a set of data that describes and gives information about other data,” Larsen said. Such information that can be derived from online photos includes camera type, date of capture, whether the picture has been altered and GPS coordinates of where the photo was taken.

Dating websites have the ability to “scrub” or eliminate such metadata from their member photos and most do because misuse of the information could compromise the safety of their users, Larsen said.

The research method of the study included the creation of user profiles of two individuals, the personal information of which was fabricated except for the photos, which contained location information and other metadata, Larsen said. The photo uploaded by one user then was downloaded by the other user and the existence of the location information confirmed.

The websites found not to remove location metadata were contacted on Dec. 29, 2011, and the Leeds School team has since worked with several of those dating website companies to ensure that location metadata is removed before the survey results were publicly announced.

“It was clear that some companies did not know about this issue,” Larsen said. “The feedback ranged from appreciative to reluctantly removing the metadata to no response.” Several of the companies immediately reported that they were taking action to resolve the issue, including SuccessfulMatch and the companies behind CatholicSingles, DeafSinglesMeet and MeetingMillionaires.

A company that tracks online consumer behavior, Experian Hitwise, recently listed more than 1,100 websites in its “lifestyle dating” category.

“Technology is so important today and many companies deal with very private data,” Larsen said. “Company decisions about how to deal with data privacy can affect their valuation.”

The information management class was offered jointly by the Leeds School’s Division of Management and Center for Education on Social Responsibility.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.