New: AI-powered Google Review automation is liveLearn more →
VoqadoWiFi
Security
No claims we cannot back

Guest WiFi Security
and Data Protection

When guests log in through your portal, they trust your venue with their details. This page explains exactly how that data is stored, what consent is captured, what rights guests keep, and how the portal stays isolated from your business network.

Start Free Read the Compliance Docs

The three things that matter most

Where guest data lives

Guest records are stored in Supabase, a managed Postgres platform. Every connection to the platform runs over HTTPS with TLS, so guest details are encrypted in transit between the portal, our servers, and your dashboard.

Consent captured at the portal

The captive portal presents consent language before any guest record is created, in line with GDPR principles. Marketing consent is a separate, optional choice, and the consent status is stored with each guest record.

Never sold, never rented

Guest data collected through your portal belongs to your business. We do not sell it, rent it, or share it with advertisers or data brokers. It exists so you can run your own marketing, and for no other purpose.

How Guest Data Is Handled

Six commitments, stated plainly. Where a practice depends on your network setup, we say so.

Minimal collection by design

The portal collects only the fields you configure, such as name, email, and an optional birthday. Nothing is harvested beyond what the guest can see on the login screen. Browsing activity on the guest network is not part of the marketing record.

Encrypted transport everywhere

Portal pages, dashboard sessions, and API calls are served over HTTPS. Guest details never travel between the portal and the database in plain text.

Consent you can evidence

Each guest record carries its consent status, and the full guest list can be exported as CSV from the dashboard. If a regulator or a guest asks what was agreed to, you have an answer you can produce.

Retention and the right to be forgotten

Guests can ask your venue to delete their record, and operators can delete guest records directly from the CRM. Deletion removes the guest from your marketing audience. You stay in control of how long records are kept.

No sale of guest data

We do not sell guest personal information to third parties. Your guest list is not our product. This applies on every plan, including the free Starter tier.

Portal traffic stays off your business LAN

The captive portal and RADIUS authentication flow sit on the guest network side of your Omada or UniFi setup. We recommend, and document, keeping guest WiFi on its own VLAN so guest devices never touch your POS, cameras, or back office systems.

Network isolation

The Guest Network Is Not Your Business Network

The captive portal and the RADIUS style authentication handshake live on the guest side of your TP-Link Omada or Ubiquiti UniFi deployment. Our setup documentation walks through putting guest WiFi on its own SSID and VLAN, so a guest device can reach the internet and the login portal but nothing else.

  • Guest devices are isolated from POS terminals, payment networks, cameras, and office machines
  • The portal only needs to reach the guest network segment, never your internal LAN
  • VoqadoWiFi never processes, stores, or transmits payment card data, so it adds zero PCI scope to your venue
  • Client isolation on the guest SSID keeps guest devices from seeing each other

Security Questions, Answered Plainly

VoqadoWiFi is built around GDPR principles: explicit consent at the portal, minimal data collection, CSV export for portability, operator controlled deletion, and no sale of guest data. EU customer data can be stored on EU region infrastructure, and we provide signed Data Processing Agreements for paying customers on request. Full details are on our compliance page.

We do not currently hold a formal certification such as SOC 2 or ISO 27001, and we will not claim one we do not have. Our practices follow the principles behind those frameworks: TLS for all transport, encryption at rest on the database layer, role based access, and audit logging. If a certification is a hard requirement for your procurement, tell us and we will be straight with you about the timeline.

Yes. A guest can request deletion through your venue, and you can delete their record from the CRM in the dashboard. Once deleted, the guest is removed from your marketing audience and their contact details no longer appear in exports.

The platform handles the login and marketing layer: the portal page, the consent capture, and the guest record. Guest browsing traffic flows through your own Omada or UniFi network, not through VoqadoWiFi servers. Browsing history is not part of the guest marketing record.

Not if the network is set up the way we document it. Guest WiFi should sit on its own SSID and VLAN, isolated from the business LAN. Omada and UniFi both support this natively, and our setup guides walk through the configuration. The captive portal only needs to reach the guest network side.

Guest Marketing Without the Data Guilt

Consent captured up front, data encrypted in transit, deletion in your hands, and a guest list that is never for sale. Start on the free plan and see the portal for yourself.

Full regulation by regulation detail lives on our compliance page

Start Free, No Card Needed

Free forever plan available. Cancel anytime.