Privacy Policy
Written to be read. If anything here is unclear, ask us and we will explain it.
Last updated 3 September 2026
Who we are
Footfall provides guest WiFi software to venues — cafés, hotels, gyms, retailers, clinics and event spaces. This policy covers both the people who use our platform (our customers) and the guests who connect to WiFi at a venue running Footfall.
For guests: the venue you connected at is the data controller for your information. Footfall is their processor — we handle the data on their instructions. If you want your data removed, you can contact either the venue or us, and we will act on it.
What we collect
- Contact details you enter
- Email address, phone number, and name, when you provide them at a WiFi login page.
- How you signed in
- Whether you used email, a one-time code, a social account, or a voucher.
- Session data
- When you connected, which venue and access point, how long you stayed, and how much data you used.
- Marketing permissions
- Whether you agreed to be contacted, recorded separately for email, SMS and WhatsApp.
- Anything the venue asks for
- A venue can add its own fields — a room number, a membership ID. You can see exactly what is being asked before you submit it.
Devices we detect
Where a venue has enabled presence analytics, access points count nearby devices to measure how many people pass through — not just those who log in.
We do not store device addresses. Each one is converted on arrival into an irreversible cryptographic digest, salted per venue. The original address cannot be recovered from what we hold, and the same device produces a different digest at every venue, so it cannot be tracked between them. These raw records are deleted after 30 days.
This measures counts and dwell times. It does not identify you, and it is not linked to your name or contact details unless you separately log in.
Why we use it
- To give you internet access
- Authenticating your device and applying the venue's session limits.
- To send you messages you asked for
- Only on channels you specifically agreed to, and only from the venue you visited.
- To help venues understand their footfall
- Aggregate counts, busy periods, dwell times and return rates.
- To keep the service running and secure
- Detecting abuse, preventing fraud, and diagnosing faults.
How long we keep it
- Device detection records
- 30 days, then deleted automatically.
- Session records
- For as long as the venue keeps its account, unless they delete them sooner.
- Contact details and marketing permissions
- Until you withdraw consent or ask for deletion, or the venue closes its account.
- Audit records
- Retained for the life of the account, because they exist to show what happened to your data.
Your rights
Depending on where you live — including under the GDPR in the UK and EU, and the CCPA in California — you can ask for a copy of your data, ask us to correct or delete it, object to how it is used, or withdraw consent at any time. Withdrawing marketing consent does not disconnect you from WiFi.
Every marketing message we send carries an unsubscribe link. You can also email us and we will action it directly.
How we protect it
- Separation between venues
- Every record is scoped to one venue, and enforced on every query.
- Encryption in transit
- All traffic to our platform uses TLS.
- Hashing, not storage
- Passwords, device identifiers and API tokens are stored as one-way hashes.
- Recorded access
- Changes to consent, permissions and credentials are written to an audit log.
Contact
Questions, requests, or complaints: privacy@footfall.cloud. Security issues: security@app.footfall.cloud.
If you are not satisfied with our response, you can complain to your local data protection authority.