Guest Wi-Fi collects personal data about people who are, legally speaking, someone else's guests, and every country answers differently on what you must keep and for how long. GDPR sets the consent rules across Europe, Thailand and Singapore have their own PDPA, and Indonesia wants five years of connection records where Germany wants none. That's a design problem, so we designed for it: your property's country sets the rules, and the platform follows them.
Pick your country during setup and the retention periods, opt-in mode and logging behaviour follow from it. No legal research required on your part.
| Where the property is | What the law expects | What we do |
|---|---|---|
| Thailand | Venues offering internet access must keep traffic records for at least 90 days under the Computer Crime Act, extendable by order. | Identifiable session logs retained for 90 days by default, with synchronised clocks and a longer period available. |
| Philippines | No fixed retention period, but the Data Privacy Act requires marketing consent kept strictly separate from network access. | Session logs kept 90 days as a considered default; marketing consent is always its own separate tick, never bundled with sign-in. |
| Singapore | No fixed logging period outside specific licences. The PDPA requires breach notification within three days once 500 people are affected. | A 90-day retention pack as a considered default, with breach reporting built to the PDPA's three-day window. |
| Indonesia | Connection records kept for five years under MOCI Reg 20/2016 and GR 71/2019, with a sign-in notice in Bahasa Indonesia. | A 5-year retention pack — twenty times the ninety-day default — and the sign-in page shown in Bahasa Indonesia, with English alongside for international guests. |
| India | The CERT-In directions require one year of connection logs, with breach reporting inside six hours rather than the usual seventy-two. | A 365-day retention pack, with breach notification built to the six-hour window. |
| Australia | The Telecommunications Act's two-year retention duty applies to carriage service providers, and a hotel outsourcing its guest Wi-Fi most likely isn't one, but the rule is untested. | A 2-year retention pack, taken as the cautious reading rather than assuming the shorter period applies. |
| France | Connection data retained for roughly twelve months. | A 365-day retention pack. |
| Germany, Austria, Switzerland | No duty to identify or log guests. Double opt-in is the expected standard for marketing email. | Minimal logging, and double opt-in switched on by default. |
| Italy | No general identification or retention mandate for venue Wi-Fi. | Minimise: shortest defensible retention. |
| United Kingdom | The Investigatory Powers Act can reach twelve months, but only for an operator formally served a retention notice. | A 365-day retention pack, matching the cautious reading even though a notice is unlikely. |
| United States | No federal retention mandate. State privacy laws such as CCPA/CPRA require honouring "do not sell or share," and treat Wi-Fi-inferred location as sensitive data needing opt-in. | A 90-day retention pack, matching common commercial practice, with opt-in respected as those state laws require. |
| Everywhere else | Varies. | A 90-day default pack, adjustable, and we'll happily build the pack for your country. |
Indonesia in full → · Thailand in full →
This page is a description of how the product behaves, not legal advice. Your own counsel decides what your property must do; the platform's job is to make doing it straightforward.
Guests don't have to accept marketing to use the Wi-Fi. The two are always kept separate. That's not just good manners: tying them together is the most common reason a guest list turns out to be legally unusable, and it spoils the whole list, not just a few entries.
If a guest — or a regulator — ever asks "when did I agree to this?", you'll have a proper answer, not a shrug. Every yes is kept with its full story, and so is every "please stop".
No single lock is trusted with your guests' details. Everything personal is protected in independent layers, so if one protection ever failed, the others would still be standing, and what anyone found would be unreadable.
Encrypted storage volumes, and — the part usually forgotten — encrypted backups and archive logs, with keys held away from the database host.
Names, emails, phone numbers, dates of birth, addresses and every custom answer are individually encrypted. Even a copy of the database would not be a readable guest list.
Your data is encrypted with your own key, held in a managed key vault. One property's compromise is not everyone's.
Because each property has its own key, off-boarding destroys the key, and every historical backup of that data becomes unreadable at the same moment. Erasure that doesn't depend on rewriting archives.
Every connection is encrypted, wherever the data is travelling: to the sign-in page, to your Wi-Fi, or on to anywhere we send it for you.
Any system connection can see only what it needs to, and every use of it is recorded. Access to the console itself needs a second step to sign in, not just a password.
Today the platform runs from a single hosting region serving every country, with the appropriate cross-border transfer safeguards described in the processing agreement and your guest privacy notice.
Regional hosting is a deliberate future option rather than an afterthought: every record is keyed to its property, every property has its own encryption key, and country rules are configuration, so moving a property to a regional deployment later needs no change to how the product works. If data residency is a hard requirement for you now, tell us before you sign up rather than after.
Short answers. The sections above carry the detail.
It depends on the country the property is in. Indonesia asks for five years of connection records under MOCI Reg 20/2016 and GR 71/2019, Thailand for at least ninety days under the Computer Crime Act, Germany for none. Pick the country at setup and the retention period follows. This page describes how the product behaves; your own counsel decides what your property must do.
No. Marketing consent is a separate box, never pre-ticked, one per channel, and a guest who says no gets online at the same speed as everyone else. Tying the two together is the most common reason a guest list turns out to be legally unusable.
Yes. Every consent is kept with the date and time, the sign-in page it was given on, the exact wording the guest saw, and whether they confirmed it by clicking the email. Withdrawals are kept the same way and passed on to any system that received the guest’s details.
Erasure cancels their access, deletes their personal data, strips identifying details from the records the property is legally required to keep, and tells every connected system to do the same. Export is free on every plan, so giving a guest a copy of their own record is a download from the console.
In a single hosting region serving every country, with the cross-border safeguards described in the processing agreement. Every property’s data is encrypted with its own key, held in a managed key vault. If data residency in a particular country is a hard requirement, say so before signing up rather than after.
If your legal team has a list, send it. We'd rather answer it now than discover the gap after you've gone live.