Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains how VenueWiFi ("we", "us", "our") collects, uses, and protects personal data when you use our platform at venuewifi.io or app.venuewifi.io. VenueWiFi is a trading name of Dark Smarts Limited, a company registered in England and Wales (company no. 16698137), registered office 1 Mariners Reach, Chepstow, Wales.
VenueWiFi sits between two different groups of people, and this policy is deliberately explicit about both, because they involve different data and different responsibilities:
- Venue customers — the restaurants, cafés and hospitality venues who subscribe to VenueWiFi and run it on their own WiFi network.
- Guests — the people who connect to a venue's WiFi and see that venue's branded sign-in screen.
1. Data We Collect About Our Venue Customers
When a venue signs up for VenueWiFi, we collect:
- Name, business name, and email address
- Billing information, processed by Stripe — we never store card details ourselves
- Uploaded images (logos, promotion images)
- Router/access point configuration details, encrypted at rest
Purpose: to provide and operate the service the venue has subscribed to, and to process payment.
Lawful basis: contract performance — this data is necessary to provide the subscription the venue has agreed to.
2. Guest WiFi Data — Collected on a Venue's Behalf
This is the part of the service that touches the most people, so we want to be completely plain about how it works:
- When a guest connects to a venue's WiFi, they may be asked to provide an email address (or sign in with Google, Apple, or Facebook) via that venue's branded welcome screen, before they get online.
- Guests actively and knowingly consent to this before connecting — it is a visible, clearly-labelled sign-in step, never hidden or disguised. We also record device type, IP address, MAC address, and connection time, to authorise the device on the network and let the venue see basic usage patterns.
- No passwords or account credentials are ever requested or captured as part of guest WiFi sign-in.
- Guests can opt in to marketing communications from the venue at the point of connecting, and can withdraw that consent or unsubscribe at any time — every opt-in is timestamped and stored separately from ordinary session data.
Who is responsible for this data: the venue is the data controller for its own guests' data — it decides what to collect and why, and it's who a guest's data relationship is actually with. VenueWiFi acts as a data processor, handling that data securely on the venue's behalf and only as instructed.
Lawful basis: consent, for guest sign-in and any marketing communications a guest opts into.
3. How We Use This Information
- To provide and operate the VenueWiFi platform
- To authorise guest devices on venue WiFi networks
- To provide venue owners with guest analytics
- To send transactional emails (account setup, billing)
- To send marketing communications to guests who have opted in
- To detect and prevent fraud and abuse
4. Data Sharing
We share data with the following third-party service providers:
- Stripe — payment processing (Privacy Policy)
- Resend — transactional email delivery
- Neon — database hosting
- Vercel — platform hosting
- Google — user authentication
- Facebook — user authentication
- Apple — user authentication
We do not sell personal data to any third party.
5. Data Retention
We retain data for as long as the relevant account is active. Venue customers may request deletion of their own account data at any time, and guests may request deletion of their data from the venue they connected with, by contacting us at hello@venuewifi.io or through the privacy settings in the dashboard.
6. Your Rights Under UK GDPR
Whether you're a venue customer or a guest, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Withdraw consent at any time (for guests, this includes marketing communications)
- Object to processing of your data
- Data portability
To exercise any of these rights, contact us at hello@venuewifi.io.
7. Cookies
We use essential cookies only, to maintain login sessions. We do not use tracking, advertising, or analytics cookies.
8. Security
We protect data using HTTPS encryption, secured database storage, and access controls. In the event of a data breach we will notify the relevant authorities within 72 hours, as required by UK GDPR.
9. Contact
For any privacy-related questions or requests, contact us at hello@venuewifi.io.
VenueWiFi is a trading name of Dark Smarts Limited, a company registered in England and Wales, company no. 16698137. Registered office: 1 Mariners Reach, Chepstow, Wales.
This policy is a plain-language description of our data practices, not formal legal advice.