Skip to content

GDPR & Compliance FAQ ​

Is CaptiFi GDPR compliant? ​

Yes. CaptiFi is fully GDPR compliant. We provide:

  • Clear consent collection at the point of data capture
  • Guests asked separately about marketing, with nothing pre-accepted for them
  • Full audit trail of all consent records
  • Data export capabilities
  • Right to erasure (deletion) support
  • Privacy policy integration on splash pages

Where is data stored? ​

Guest data is stored securely on EU-based servers (Hetzner data centres in Finland and Germany) with encryption at rest and in transit. Email delivery uses Amazon SES in the US; regional email delivery can be arranged on request.

Who owns the data? ​

You do. CaptiFi processes data on your behalf, but you are the data controller. You can export or delete data at any time.

How long is guest data retained? ​

Guest data is retained for as long as your account is active. You can anonymise or delete guest records at any time from the Guest Visits page. If you cancel your account, data is retained for 30 days to allow you to export it, then permanently deleted. During those 30 days the account holder can sign in to my.captifi.io and click Download your guests (CSV). Contact support if you'd like an automatic retention policy (e.g. auto-delete data older than 12 months) set up for your account.

Can guests request deletion of their data? ​

Yes. Under GDPR, guests have the right to request erasure of their personal data. If a guest contacts you with a deletion request, you can remove their data from the CaptiFi dashboard immediately. You should respond to such requests within 30 days as required by GDPR.

Can guests opt out? ​

Yes. Every marketing email includes an unsubscribe link, and mailbox providers such as Gmail, Apple Mail and Outlook also show their own Unsubscribe button at the top of the message. Either route opts the guest out in one click, with no form to complete.

An opt-out is honoured everywhere at once: the address stops receiving campaigns, automations and review requests, across every venue on your account, and it is added to your Suppressions list. Removing the address from that list leaves the guest unsubscribed; they get your marketing again only if they opt in again on your splash page. Guests can also request data deletion by contacting you directly.

Do I need a privacy policy? ​

Yes. You should have a privacy policy that covers your use of guest WiFi data. CaptiFi provides a template you can customise, and it's linked directly on your splash page.

The CaptiFi splash page uses only essential cookies required for the WiFi login to function, and these do not require a cookie banner under GDPR. If you add third-party tracking (e.g. Facebook Pixel, Google Analytics) to your splash page, then yes, you would need a cookie consent mechanism. CaptiFi can help you configure this if needed.

The CaptiFi splash page uses minimal cookies required for the WiFi login to function. Marketing cookies (if any) are only set with consent.

Can I delete a guest's data? ​

Yes. In the dashboard, go to My Venues → Guest Visits, select the guest(s), and use the Delete (GDPR) bulk action, which permanently removes all their data from CaptiFi. There's also Anonymise (GDPR) if you want to keep the anonymous visit statistics.

Deleting or anonymising a guest also removes their name, email address and phone number from any reservation that matched them. The booking itself stays in your reservations list without those details, so your booking history is unchanged.

The same applies to table bookings made through CaptiFi and to booking enquiries: deleting or anonymising a guest removes their name, email address, phone number, occasion and notes from every table booking and enquiry they made, and the link to their booking page stops working. The booking, its party size, times, status and any deposit stay, with the guest shown as Anonymised. Without a request, a booking's guest notes are emptied 90 days after the booking ended and the guest's details 24 months after it, because notes routinely hold allergy and access needs.

What about rewards membership data? ​

Joining your Rewards programme is a separate consent from marketing. The Join checkbox on the sign-in form is unticked by default and is not tied to the marketing question, so a guest can be a member without receiving campaigns. Reward emails and texts are transactional messages the member asked for by joining; campaigns still go only to guests who opted in to marketing.

Erasure covers the membership. Delete (GDPR) or Anonymise (GDPR) on the Guest Visits page also erases that person's rewards membership on your account, and Anonymise (GDPR) on a member's page does the same for one member. Their name, email, phone number, date of birth and every identifier linked to the membership are removed, the links they were sent stop working, unused rewards are cancelled, any pass they added to Apple Wallet or Google Wallet is marked void (an iPhone is told at once, and Google Wallet shows it on its next refresh), and the IP address and browser details on their redemptions are cleared. Their points history and redemption records are kept without anything personal in them, so your settlement and exposure figures do not change after an erasure. Guests can also leave the programme themselves from their rewards page, which stops points and rewards without erasing the record.

What about workflow runs and segment memberships? ​

Erasure covers them. Delete (GDPR) or Anonymise (GDPR) on the Guest Visits page removes that person's workflow runs, so nothing in a workflow can email or text them afterwards, and removes their saved segment memberships. A run that was waiting on a step is removed with the rest. The run and per-step counts on a workflow's overview fall with the erased runs; the lifetime counters of guests turned away at enrolment are unchanged.

Do you share data with third parties? ​

CaptiFi never sells guest data. To run the service we use a small number of vetted sub-processors: Hetzner (hosting, EU), Amazon SES (email delivery, US), Stripe (payments) and Cloudflare (media storage, EU). Guest data is only sent to a marketing platform (such as Klaviyo or Mailchimp) when you connect one from the Integrations page. Beyond that, data is only accessible to you (the venue owner) through your CaptiFi dashboard.

What about data breaches? ​

CaptiFi has security measures including encryption at rest and in transit, access controls and access logging. In the unlikely event of a personal data breach, we notify affected customers without undue delay, as our data processing agreement sets out. GDPR's 72-hour clock is yours as the controller: it runs from when you become aware of a breach to when you must notify your supervisory authority, and our notice to you is what starts it.

Am I the data controller or data processor? ​

You (the venue owner) are the data controller: you decide what data is collected and how it's used. CaptiFi acts as a data processor, handling the data on your behalf according to your instructions. Our Data Processing Agreement (DPA) is published at captifi.io/dpa.

CaptiFi — Guest WiFi Marketing Platform