What actually happens between the guest sitting down and the address arriving
A guest joins your open network. Their phone runs its usual connectivity check, notices the response is not what it expected, and opens the portal in a small in-app browser without the guest doing anything. They see your splash page: your logo, one sentence explaining the offer, an email field, and a consent checkbox that is unticked by default. They submit. The portal writes the record to your guest database, tells the controller to authorise that device, and the phone drops onto the internet. From the guest side the whole thing is one screen and about eight seconds. From your side you now hold an email address, a venue, a device identifier and a consent timestamp.
Why the wording on that one screen decides your capture rate
The splash page is the entire funnel. There is no second chance and no retargeting. Every extra field you add is another reason to bounce, and every unexplained field feels like a data grab. The portals that perform best ask for the minimum they will actually use, state plainly what the guest is signing up for, and make the benefit concrete before the field rather than after it. "Get the WiFi password and our Friday specials" is a trade. "Enter your email to continue" is a toll booth.
- One primary field. Email only, unless you have a real campaign that needs a first name.
- Consent unticked by default, with the wording next to the box rather than buried in a linked policy.
- Say what you will send and roughly how often. Vagueness is what produces fake addresses.
- Offer a social login as the alternative path for guests who will not type an address, and treat it as a separate consent decision.
- Design for a 320px wide window with no address bar, because that is the window most guests will see.
A worked example, with the assumptions stated
Numbers on this page are illustrative arithmetic, not measured results from any venue. Suppose 200 devices connect to your guest network in a month. If 60 percent of those guests complete the form rather than abandoning it, that is 120 submissions. If 85 percent of those addresses are real and deliverable, you finish the month with roughly 102 usable contacts. Change any assumption and the answer changes: a portal that asks for four fields will not hold 60 percent, and a portal that offers nothing in return will not hold 85 percent deliverability. The point of the arithmetic is to show which lever matters, not to promise an outcome.
Consent is the part that makes the list worth having
An address collected without a clear opt-in is a liability rather than an asset. Under GDPR and comparable regimes, consent has to be freely given, specific, informed and demonstrable, which in practice means a separate unticked checkbox, plain wording, and a stored record of what was agreed and when. VoqadoWiFi logs the consent text version, the timestamp and the location alongside every capture, so that if a guest or a regulator asks, the answer is a row in a database rather than a shrug. Guests who decline marketing still get WiFi. Tying access to marketing consent is exactly what makes consent not freely given.
Getting the addresses out of the portal and into something that sends
A captured address is worth nothing until it reaches the tool that emails people. VoqadoWiFi keeps the guest record in your account with export to CSV, and pushes new captures onward through webhooks so they can land in an email platform, a CRM, or an automation tool the moment they arrive rather than in a monthly batch. The practical advice is to wire the destination before you turn the portal on. Venues that collect for three months and then decide where the data goes usually discover their most engaged guests went cold while the list sat still.
How to set it up
In order. Skipping a step here is usually why a portal ends up showing a spinner instead of a login screen.
- 1
Confirm your hardware is supported
VoqadoWiFi runs as an external captive portal on TP-Link Omada and Ubiquiti UniFi. You need controller access, either a hardware controller, a cloud controller or a software controller on your own machine. If you run something else, this is the step that decides the project.
- 2
Create the location and get your portal URL
Add the venue in VoqadoWiFi, choose Omada or UniFi as the vendor, and the platform issues the portal URL and the credentials the controller will use to hand sessions over.
- 3
Point the controller at the portal and open the walled garden
In the controller, set the guest SSID to use an external portal and paste the URL. Then add the portal domain to the walled garden, along with any social login domains you enable. This is the single most common reason a new portal shows a spinner instead of a login screen.
- 4
Build the splash page and write the consent line
Upload your logo, set the colours, write one sentence of benefit copy, and enable the email field. Write the consent wording yourself rather than accepting a default, because it is the sentence a regulator would read first.
- 5
Wire the destination and test on a real phone
Connect a webhook or export path to wherever you send email from. Then forget your own network on an actual phone, reconnect, and complete the form as a guest would. Check the record arrived with its consent timestamp before you tell staff to stop giving out the password.
Who this suits
The venue types where this job comes up most often, and where the data the portal produces is dense enough to act on.
Run this on your own network first
The Starter plan is free forever: one location, 25 logins a month, a branded splash page and consent logging. Growth is $49 a month and covers up to three locations. Works with TP-Link Omada and Ubiquiti UniFi.
Common questions
Is collecting emails from WiFi legal?
Collecting an email address to provide the service is one thing; emailing marketing to that address is another, and the second needs its own consent. Use a separate unticked checkbox with plain wording, keep a timestamped record of what was agreed, give guests WiFi whether or not they tick it, and include an unsubscribe link in everything you send. That structure is what GDPR and similar regimes are asking for.
How many of the addresses will be fake?
Some always will be. The fix is not validation gymnastics, it is the offer: guests type a real address when they expect something they want to receive. A confirmation or welcome email sent immediately after capture also tells you quickly which addresses bounce, so the bad ones leave the list before they hurt your sending reputation.
Do I have to remove the WiFi password?
The guest network needs to be open for a captive portal to intercept and redirect. Most venues run the guest SSID open with the portal in front of it, and keep a separate WPA2 or WPA3 protected SSID for staff and payment terminals. That separation is good practice regardless of marketing.
Can I try this without paying?
Yes. The Starter plan is free forever and covers one location with 25 guest logins a month, which is enough to prove the redirect works, the consent record is stored, and the data reaches your email tool. Growth is $49 a month and covers three locations when you are ready to run it at real volume.
Read next
These jobs share the same plumbing, so operators normally set them up in sequence rather than one at a time.
Build a Restaurant Email List From Scratch
Go from having no way to contact your guests to owning a list you can fill a quiet Tuesday with.
Automate Google Review Requests From WiFi
Ask every satisfied guest for a Google review at the right moment, without a staff member ever having to say the words out loud.
Measure How Many Customers Actually Come Back
Replace a gut feeling about regulars with a number you can compare month to month.
Terms used on this page
Related pages