Privacy Policy
Last updated: 19 July 2026
This policy explains what personal data WeefyBox and the venues using it ("Account Holders") collect through WeefyBox's guest WiFi captive portal and related services, and how that data is used, stored and protected. It is written for both venue guests and Account Holders, and is deliberately specific about the real data flows in the product rather than a generic template.
Who is responsible for your data
For data collected through a venue's captive portal, the venue (the WeefyBox "Account Holder") is normally the data controller, and WeefyBox Ltd acts as data processor on the venue's behalf — see our Data Processing Agreement. For data WeefyBox collects directly to operate its own platform (e.g. Account Holder billing contacts), WeefyBox is the controller.
What we collect
- Guest contact details: name, email address and/or phone number, submitted at the captive portal.
- Device identifiers: a long-lived signed device cookie, and the device's MAC address as reported by the venue's hotspot hardware (UniFi, Omada or MikroTik), used to recognise a returning guest.
- Consent records: separate, timestamped records of whether a guest agreed to network access and marketing email — each tracked independently.
- Visit data: connection timestamps, session duration ("dwell time"), and which venue was visited.
- Review/feedback data: star ratings and, for low ratings routed to a private form, free-text feedback.
- Buying-concierge data: questions asked on the WeefyBox marketing site, the answers returned, the published product sources used, and anonymous landing-page or campaign attribution. We do not store a raw IP address in the concierge log.
- Account Holder billing data: processed by Stripe on our behalf — WeefyBox stores a Stripe customer/subscription reference, not full card numbers.
Why we collect it
Guest data is collected to provide network access and—only where consent is given—send marketing communications. Visit and dwell-time data is aggregated by Account Holders to understand footfall and repeat-visit patterns; it is not sold to third parties.
How long we keep it
Guest data is retained for as long as the Account Holder's account is active, or until a guest exercises their right to erasure (see below). Consent records are retained even after erasure, as the compliance record that proves what a guest was and wasn't asked to agree to. Buying-concierge conversations are retained for up to 90 days so we can understand buyer questions and improve answer quality.
Your rights
Under UK GDPR and EU GDPR, you have the right to access, correct, and request erasure of your personal data. To exercise these rights for data held by a specific venue, contact that venue directly — they are the data controller. If you're unsure which venue holds your data, or have a question about WeefyBox's own role as processor, contact us via our contact page.
An erasure request anonymises your name, email, phone and any other directly identifying fields, and deletes the device identifiers (cookie/MAC) linking your device to your guest record. Aggregate visit counts and consent records are retained without any identifying information, as permitted under Article 17(3) GDPR for legitimate record-keeping.
Where your data is stored
Guest and Account Holder data is stored on infrastructure located in the UK/EU. Sub-processors used to operate the platform, including payment processing via Stripe and email delivery, are listed in our Data Processing Agreement together with safeguards for data transferred outside the UK/EEA.
Changes to this policy
We'll update the "last updated" date above whenever this policy changes, and notify Account Holders of material changes by email.