New: AI-powered Google Review automation is liveLearn more →
VoqadoWiFi
Free tool, no signup

Guest WiFi privacy policy and captive portal consent text

Answer seven questions about your venue and get three pieces of wording you can paste into your captive portal: the consent boxes, the short notice on the splash screen, and a guest WiFi section for your privacy policy. Everything runs in your browser.

This is a starting template, not legal advice

The output is a draft built from the answers you give. It does not guarantee compliance with the GDPR or any other law, and it has not been reviewed for your venue. Have a qualified lawyer check the wording against what your portal and your vendors actually do before you publish it.

Your venue

Business type
Where your guests are

Framing applied: GDPR

What the portal collects
Marketing you intend to send

Draft wording only. Replace every placeholder in square brackets, check the text against what your systems genuinely do, and have counsel review it before it goes live. Nothing here guarantees compliance with the GDPR or any other regime.

1. Consent checkbox text
The wording beside the tick boxes on your login screen.
BLOCK 1. NETWORK ACCESS (required to connect)

[ ] I agree to the WiFi Terms of Use and I have read the Privacy Notice for the [BUSINESS NAME] guest network.

[BUSINESS NAME] uses your email address, your name and your visit history at this venue to create and manage your guest WiFi account, to keep the network secure and to comply with legal obligations.
Lawful basis: performance of a contract for the WiFi service, and legitimate interests in network security.

BLOCK 2. MARKETING (optional, your WiFi works either way)

Leave these boxes empty at all times before the guest sees this screen. Never tick them in advance and never make access depend on them.

[ ] Yes, [BUSINESS NAME] may email me about menu changes, table offers and event nights. I understand this is optional, that my WiFi access does not depend on it, and that I can withdraw my consent at any time using the unsubscribe link in any email or by writing to [PRIVACY CONTACT EMAIL].
Lawful basis: consent, Article 6(1)(a).

BUILD NOTES FOR WHOEVER CONFIGURES THE PORTAL

1. Every box above starts empty. No box is ticked by default.
2. The access box and each marketing box are separate. Never combine them into one tick.
3. The guest can complete Block 1 and skip Block 2 and still get online.
4. Store the timestamp, the portal version and the exact wording shown for every consent you record.
5. Record consent withdrawals with the same detail as consent grants.
2. Splash screen privacy notice
The short summary a guest reads before ticking anything.
PRIVACY NOTICE, SHORT VERSION

[BUSINESS NAME] collects your email address, your name and your visit history at this venue so we can give you access to our guest WiFi and keep the network secure.
If you tick the marketing box, we will also contact you by email with offers and news. That choice is optional and you can change it at any time.
We keep guest records for 24 months after your last visit, then delete or anonymise them.
We do not sell your personal data.
You can ask for a copy of your data, ask us to correct or delete it, or withdraw consent at any time.
Questions: [PRIVACY CONTACT EMAIL]. Full privacy policy: [LINK TO YOUR FULL PRIVACY POLICY]
3. Privacy policy section
The longer guest WiFi section for the policy you host and link to.
GUEST WIFI AND CAPTIVE PORTAL
(section for your full privacy policy)

1. Who is responsible for your data

The data controller is [FULL LEGAL ENTITY NAME], trading as [BUSINESS NAME], of [REGISTERED ADDRESS], company number [COMPANY NUMBER]. You can reach us at [PRIVACY CONTACT EMAIL].
If you have appointed a Data Protection Officer or an EU or UK representative, name them here: [DPO OR REPRESENTATIVE CONTACT]. If you have not appointed one, delete this line rather than leaving a placeholder in a published policy.
We use a captive portal on the guest WiFi at our restaurant. This section explains what happens to your information when you connect.

2. What we collect

Information you give us on the login screen:
  • Email address
  • Name
  • Visit history, meaning the dates and times you connect to the network

Information your device provides automatically:
  • Device identifier such as a MAC address, which may be randomised by your device
  • Connection and disconnection times, session length and approximate data volume
  • IP address assigned on our network

Confirm this list against what your portal and your access point vendor actually record. A privacy policy that understates collection is worse than no policy at all.

3. Why we use it

  • To create your guest WiFi session and let you get online
  • To operate and secure the network, including preventing abuse and troubleshooting faults
  • To meet legal, tax and regulatory obligations that apply to us
  • If, and only if, you gave separate permission, to contact you by email about menu changes, table offers and event nights

4. Our lawful basis

  • Providing WiFi access to you: performance of a contract, Article 6(1)(b)
  • Network security, abuse prevention and troubleshooting: legitimate interests, Article 6(1)(f)
  • Meeting a legal obligation: Article 6(1)(c)
  • Marketing messages: your consent, Article 6(1)(a), which you can withdraw at any time without affecting your WiFi access

This policy is written to reflect the requirements of the General Data Protection Regulation (EU) 2016/679. Legitimate interests claims should be backed by a documented balancing assessment before you publish this section.

5. How long we keep it

We keep guest WiFi records for 24 months after your most recent visit, after which we delete them or reduce them to anonymous statistics that cannot identify you.
If you withdraw marketing permission, we stop sending immediately and keep a minimal suppression record so we do not contact you again by mistake.
Some records may be kept longer where the law requires it. Say which ones, if any, apply to you.

6. Who else sees it

  • Our WiFi and captive portal provider, which processes guest data on our instructions
  • Our network hardware vendor, where the login screen is served through their equipment
  • Our messaging provider, which sends the campaigns you agreed to receive
  • Professional advisers, and public authorities where we are legally required to disclose

We do not sell your personal data and we do not rent or trade guest lists.
List your actual providers by name, and note any transfer outside your region together with the safeguard you rely on. [PROVIDER NAMES AND TRANSFER SAFEGUARDS]

7. Your choices and rights

  • Access: ask for a copy of the personal data we hold about you
  • Rectification: ask us to correct anything inaccurate
  • Erasure: ask us to delete your data
  • Restriction and objection: ask us to pause or stop certain processing
  • Portability: receive your data in a machine readable format
  • Withdraw consent: at any time, with no effect on your ability to use the WiFi

Write to [PRIVACY CONTACT EMAIL] and we will respond within one month.
If you are unhappy with our response you can complain to the data protection authority in your country.

8. Changes to this section

If we change how the guest WiFi handles your data, we will update this section and the notice shown on the login screen. Last updated: [DATE].
The standard to aim at

What makes captive portal consent valid

Most portal templates fail on the same handful of points. None of them are technically hard. They are just easy to skip when the goal is a bigger list this quarter.

1

Freely given

The guest can say no and still get online. If refusing marketing blocks access, throttles the connection or shortens the session, the consent was bought rather than given.

2

Specific

One permission per purpose. Access is one decision, email marketing is another, SMS is a third. A single tick that covers all three tells you nothing about what the guest actually wanted.

3

Informed

Before ticking, the guest can see who is collecting the data, what is collected, why, for how long, and how to change their mind. That is what the short notice on the splash screen is for.

4

Unambiguous

A clear affirmative action. An empty box the guest ticks counts. A box that arrives already ticked, a greyed out box, or wording buried in terms nobody opens does not.

5

No boxes ticked in advance

Every consent box on the portal loads empty. This is the detail that most portal templates get wrong, and it is the easiest one for anyone auditing you to spot in ten seconds.

6

Withdrawable

Stopping must be as easy as starting. An unsubscribe link in every email, STOP on every SMS, and a route for a guest who simply asks the venue directly.

Separate the access agreement from the marketing permission

A guest agreeing to your terms so they can get online is not the same person agreeing to receive campaigns. Bundling the two into one box makes the marketing consent hard to defend and makes the resulting list worse: you cannot tell who wanted to hear from you and who just wanted the internet. Two boxes, two records, two decisions.

Questions operators actually ask

No, and any tool that claims otherwise is selling you something. This generator produces a starting template based on the answers you give it. Compliance depends on what your portal actually collects, which vendors touch the data, how long your systems really retain it, how you record and honour withdrawals, and the law that applies where you operate. Treat the output as a first draft to hand to a qualified adviser, not as a finished legal document.

The consent text is the wording next to the tick boxes on your login screen. It is what the guest agrees to. The short privacy notice is the plain summary shown on that same screen so the guest understands what is happening before they tick anything. The privacy policy section is the longer document you host on your website and link to from the portal. All three should describe the same processing. If they contradict each other, the shortest one is usually the one a regulator quotes back at you.

Under the GDPR, consent must be freely given, which means it cannot be a price of entry for a service the guest expects. Bundling marketing into the access tick is the single most common mistake on captive portals. Keep the access agreement and the marketing permission as separate boxes, and let a guest who ticks only the first one get online normally. Outside the EU and the UK the legal analysis differs, but the practical result is the same: a list built from forced consent performs badly and complains loudly.

Yes. Email permission and SMS permission are different channels with different expectations and, in the United States, different statutes. A guest who is happy to receive a monthly newsletter may not want text messages at all. Give SMS its own box, its own wording and its own stop instruction. If you do not plan to text guests, do not collect the permission and do not collect the mobile number.

Keep it for as long as you have a reason to, and no longer. Most venues find that twelve to twenty four months covers the realistic window for a returning guest, after which the record is dead weight that still carries risk. Whatever period you choose, make sure your systems actually enforce it. A retention promise your database ignores is worse than a longer promise you keep.

At minimum: what the guest agreed to, the exact wording shown to them, the version of the portal that displayed it, and the timestamp. If you later change your consent wording, the old records need to point at the old text. Regulators asking about consent generally want to see evidence of the moment, not a current screenshot of a screen that has since been redesigned.

You still need to tell the guest what you are doing with it, which is what the privacy notice does. Whether you need consent as your lawful basis depends on the purpose. Using an email to create the WiFi session is different from using it to send campaigns. The first can rest on providing the service the guest asked for. The second is marketing, and marketing is where consent and the relevant electronic communications rules come in.

It is free and it needs no account. The generator runs entirely in your browser, so the business details you enter are used to build the text on screen and are not sent to VoqadoWiFi.

Put this wording on a live portal

The free plan records each permission on its own and keeps the timestamp with the guest.

Free forever plan. No credit card and no sales call.

Keep reading

How VoqadoWiFi handles guest data, and what to do with a list once you have permission to use it.

A portal that records consent properly

VoqadoWiFi captures each permission separately, timestamps it, and keeps the record with the guest. Free Starter plan, no card required.

VoqadoWiFi provides this generator as a free educational resource. The wording it produces is a starting template, not legal advice, and no lawyer has reviewed it for your venue. Using it does not create a solicitor or attorney client relationship and it does not guarantee compliance with the GDPR, the UK GDPR, any United States state privacy law, or any other regulation. Have a qualified adviser review your final portal wording before you publish it.