The Question Behind the Question
When an operator asks whether to run open WiFi or a captive portal, they are rarely asking a networking question. They are asking a trade question: how much guest friction is a marketing list worth?
That is the right instinct, and it deserves an actual answer rather than a vendor pitch. So this piece does three things. It defines the options precisely, because the terms get used interchangeably and they are not the same. It runs the ROI comparison with real inputs. And it identifies the cases where open WiFi is genuinely the better call, because those cases exist.
Definitions, Precisely
Open WiFi
An unsecured SSID that any device can join without credentials or interaction. The guest selects the network and is online. No password, no landing page, no record beyond what the access point logs at the MAC address level.
Get more WiFi marketing insights
Practical guides, case studies, and growth strategies — delivered weekly.
Password-protected WiFi
A network secured with WPA2 or WPA3 using a shared passphrase, usually printed on a receipt or a card at the counter. It restricts access and provides link-layer encryption, but it captures no identity. From a marketing perspective it behaves exactly like open WiFi. We have covered the specific comparison in captive portal vs password WiFi.
Captive portal WiFi
The network is open at the radio level, but traffic is intercepted until the guest completes an action on a hosted landing page. That action can be a simple terms acceptance, a social login, or a form submission that captures a name, an email address, and explicit marketing consent.
The critical distinction: a captive portal is not a security measure. It is an identity layer. Anyone conflating the two is going to make a bad decision in one direction or the other.
The Honest Case for Open WiFi
Open WiFi is not a mistake in every context, and the case for it is stronger than most vendors admit.
It has zero friction. Nothing stands between the device and the internet. For venues where the WiFi is functionally part of the product, that matters more than data.
It works with everything. Captive portals have real compatibility edges. Devices with randomized MAC addresses can be forced to re-authenticate more often than expected. Some smart TVs, handheld consoles, and older IoT devices cannot render a portal at all. If your guests bring that class of device, an open SSID avoids a support burden.
It requires no consent infrastructure. If you collect nothing, you have nothing to store, secure, disclose, or delete on request. That is a genuine reduction in compliance surface, not a trivial one.
It costs nothing to run. No portal software, no list hygiene, no email platform.
The cost of open WiFi is not visible on any invoice. It is that every guest interaction terminates at the door. You provided value, they consumed it, and the relationship ends when they walk out. Whether that cost matters depends entirely on whether repeat business is part of your economics.
The Case for a Captive Portal
A portal converts an anonymous session into a contactable record, and that record does four things open WiFi cannot.
It builds an owned list. Email is the only mainstream channel where reach is not intermediated by an algorithm. A list of people who have physically visited your business is the most responsive audience you will ever address.
It produces behavioral data. Connection frequency, dwell time, day-part patterns, and time since last visit, per person. This is first-party data generated as a byproduct of a service you already provide.
It enables segmentation. Once you can tell a weekly regular from a one-time visitor, you can stop sending the same message to both. That single distinction typically doubles campaign performance.
It creates an attribution trail. A promo code embedded in a portal-sourced email tells you which campaigns produced which visits. Open WiFi produces no attributable revenue by definition, because it produces no campaigns.
The cost of a portal is one additional screen, a small compatibility tail, and a real obligation to handle personal data properly.
Running the Numbers
Vague ROI claims are worthless, so here are explicit inputs. Adjust them to your venue.
Inputs
- 120 unique guests connect per day, 3,600 per month
- Average transaction value: 24 dollars
- Portal opt-in rate: 50 percent, a realistic mid-range figure for a well-designed two-field form
- Email open rate for venue-sourced lists: 38 percent, which runs well above general retail benchmarks because the recipient has physically been in your business
- Campaign redemption rate on opened emails: 12 percent
- Portal software: 49 dollars per month
- Contribution margin: 65 percent
Open WiFi returns
Marketing revenue attributable to the network: zero. Not low, zero. There is no mechanism by which an anonymous session can produce a follow-up visit that you caused. The network still delivers value, guests stay longer and appreciate the amenity, but it produces no measurable, attributable return.
Captive portal returns
3,600 monthly connections at 50 percent opt-in produce 1,800 new contacts per month, before deduplication. Assume aggressive deduplication down to 900 genuinely new individuals, since regulars connect repeatedly.
After six months the list holds roughly 5,400 contacts. One campaign per month to that list:
- 5,400 sends at 38 percent open equals 2,052 opens
- 2,052 opens at 12 percent redemption equals 246 visits
- 246 visits at 24 dollars equals 5,904 dollars in monthly campaign revenue
- At 65 percent contribution margin, that is 3,838 dollars in monthly contribution
- Against a 49 dollar software cost
Break-even
The program pays for itself when a single campaign drives three redeemed visits at a 24 dollar average check. Three visits. That threshold is typically crossed in the first month with a list of a few hundred contacts, long before any of the numbers above come into play.
Halve the opt-in rate, halve the open rate, and halve the redemption rate simultaneously and the program still returns roughly 480 dollars of monthly contribution against 49 dollars of cost. The conclusion is not sensitive to the assumptions, which is unusual for a marketing ROI argument and is the main reason the answer is as clear as it is. Our ROI benchmarks piece breaks down the ranges by venue type.
The Objections, Answered
"The extra screen will annoy guests." Measured drop-off from a single well-designed portal screen is small, and the guests who abandon are disproportionately those who would never have engaged with marketing anyway. The bigger risk is a badly built portal: slow load, too many fields, no clear value statement, or a form that fails on mobile Safari. Friction is a design problem, not an inherent property of portals.
"We tried it and nobody signed up." Sub-20 percent opt-in rates almost always trace to one of three causes: the form asks for more than a name and an email, the value proposition is generic, or the portal is not rendering properly on a common device class. All three are fixable. See opt-in rate optimization for the diagnostic sequence.
"Isn't collecting emails a privacy problem?" It is a privacy responsibility, which is not the same thing. Under GDPR and CCPA, lawful collection requires that marketing consent be explicit, separate from the act of getting online, logged with a timestamp, and revocable. A portal that unbundles those correctly is compliant. A portal that pre-ticks the consent box or makes marketing consent a condition of network access is not, and that is a genuine legal exposure. The distinction is entirely within your control.
"Won't it slow the network down?" Portal authentication happens once per session at the association stage. It has no bearing on throughput afterward. Perceived slowness after a portal deployment is almost always an unrelated bandwidth or access point placement issue that the portal simply made visible.
The Security Point Nobody Makes Loudly Enough
Open WiFi provides no link-layer encryption. Traffic between a guest device and the access point is transmitted in the clear and is trivially observable by anyone within radio range with freely available tools.
Modern browsing is largely protected by TLS, so the practical risk to an individual guest is lower than it was a decade ago. But it is not zero, and more importantly, an open SSID gives you no mechanism to enforce acceptable use, isolate clients from each other, or produce a record of who was on the network if something goes wrong on it.
A captive portal does not encrypt traffic either, and vendors who imply otherwise are being careless. What it does give you is a terms of service acceptance tied to a session, client isolation as a configurable default, and an audit trail. If your business has any exposure to what happens on its network, that trail is worth more than the marketing list.
The Decision Framework
Choose open WiFi if any of these describe your situation:
- Guests connect once and will not return, such as an airport gate area or a transit hub
- The device population is dominated by hardware that cannot render a portal reliably
- You have no capacity to run even one email campaign per quarter
- Your legal or procurement environment makes personal data collection genuinely impractical
Choose a captive portal if any of these describe your situation:
- Repeat business is part of your economics
- You currently cannot contact the people who walk through your door
- You have quiet periods you would like to fill with people who already like you
- You want to know whether marketing spend produces visits
For the overwhelming majority of restaurants, cafes, bars, hotels, gyms, salons, and retail venues, the second list applies and the first does not. The honest answer is that open WiFi is the right choice in a narrow set of circumstances, and most businesses asking the question are not in them.
What We Would Actually Do
Run the portal, but run it well. Two fields. A specific promise. Explicit consent, separate checkbox, logged and revocable. A welcome email configured before the list exists. One campaign per month, segmented by visit behavior from the beginning.
If the compatibility tail worries you, run a second open SSID alongside the portal network for devices that cannot authenticate. Most controllers support this in a few minutes of configuration, and it removes the last real argument against portals without giving up the list.
The Starter plan is free for a single location and 25 logins a month, which is enough to measure your actual opt-in rate before committing to anything. That measurement is worth more than any benchmark in this article, including ours.
Share this article