Guest WiFi Security
and Data Protection
When guests log in through your portal, they trust your venue with their details. This page explains exactly how that data is stored, what consent is captured, what rights guests keep, and how the portal stays isolated from your business network.
The three things that matter most
Where guest data lives
Guest records are stored in Supabase, a managed Postgres platform. Every connection to the platform runs over HTTPS with TLS, so guest details are encrypted in transit between the portal, our servers, and your dashboard.
Consent captured at the portal
The captive portal presents consent language before any guest record is created, in line with GDPR principles. Marketing consent is a separate, optional choice, and the consent status is stored with each guest record.
Never sold, never rented
Guest data collected through your portal belongs to your business. We do not sell it, rent it, or share it with advertisers or data brokers. It exists so you can run your own marketing, and for no other purpose.
How Guest Data Is Handled
Six commitments, stated plainly. Where a practice depends on your network setup, we say so.
Minimal collection by design
The portal collects only the fields you configure, such as name, email, and an optional birthday. Nothing is harvested beyond what the guest can see on the login screen. Browsing activity on the guest network is not part of the marketing record.
Encrypted transport everywhere
Portal pages, dashboard sessions, and API calls are served over HTTPS. Guest details never travel between the portal and the database in plain text.
Consent you can evidence
Each guest record carries its consent status, and the full guest list can be exported as CSV from the dashboard. If a regulator or a guest asks what was agreed to, you have an answer you can produce.
Retention and the right to be forgotten
Guests can ask your venue to delete their record, and operators can delete guest records directly from the CRM. Deletion removes the guest from your marketing audience. You stay in control of how long records are kept.
No sale of guest data
We do not sell guest personal information to third parties. Your guest list is not our product. This applies on every plan, including the free Starter tier.
Portal traffic stays off your business LAN
The captive portal and RADIUS authentication flow sit on the guest network side of your Omada or UniFi setup. We recommend, and document, keeping guest WiFi on its own VLAN so guest devices never touch your POS, cameras, or back office systems.
The Guest Network Is Not Your Business Network
The captive portal and the RADIUS style authentication handshake live on the guest side of your TP-Link Omada or Ubiquiti UniFi deployment. Our setup documentation walks through putting guest WiFi on its own SSID and VLAN, so a guest device can reach the internet and the login portal but nothing else.
- Guest devices are isolated from POS terminals, payment networks, cameras, and office machines
- The portal only needs to reach the guest network segment, never your internal LAN
- VoqadoWiFi never processes, stores, or transmits payment card data, so it adds zero PCI scope to your venue
- Client isolation on the guest SSID keeps guest devices from seeing each other