Privacy Policy

Last updated: January 9, 2025

1. Introduction

CaptiFi Limited ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our guest WiFi marketing platform and services.

Multi-Jurisdiction Compliance: We comply with:

  • UK: UK GDPR and Data Protection Act 2018
  • EU: General Data Protection Regulation (GDPR)
  • USA: California Consumer Privacy Act (CCPA) and other state privacy laws
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Australia: Privacy Act 1988

2. Information We Collect

2.1 Account Information

When you sign up for CaptiFi, we collect:

  • Name and contact details (email, phone number)
  • Business name and address
  • Payment information (processed securely via Stripe)
  • Account preferences and settings

2.2 Guest Data (Processed on Your Behalf)

As a data processor, we collect guest information that you choose to capture through your WiFi splash pages:

  • Names and email addresses
  • Phone numbers (if you enable this field)
  • WiFi connection data (MAC addresses, connection times)
  • Device information and browser data
  • Any custom fields you configure

2.3 Usage Data

We automatically collect:

  • Log files and analytics data
  • IP addresses and location data
  • Browser type and operating system
  • Pages visited and features used

3. How We Use Your Information

3.1 Your Account Data

  • Provide and maintain the Services
  • Process payments and prevent fraud
  • Send service updates and important notices
  • Provide customer support
  • Improve and optimize our platform

3.2 Guest Data

Guest data is processed solely on your instructions as the data controller. We do not use guest data for our own marketing or sell it to third parties. You control how guest data is collected and used through your CaptiFi account settings.

4. Data Sharing & Disclosure

We may share information with:

  • Service Providers: Stripe (payments), AWS (hosting), email service providers
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In the event of a merger, acquisition, or sale of assets

We never sell your personal data to third parties.

5. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS/SSL) and at rest
  • Regular security audits and penetration testing
  • Access controls and authentication
  • Secure data centers with 24/7 monitoring
  • Regular backups and disaster recovery plans

6. Data Retention

Your Account Data: Retained for the duration of your subscription plus 7 years for tax and legal compliance.

Guest Data: Retained according to your settings. You can export or delete guest data at any time. Upon account cancellation, all guest data is deleted within 30 days unless you request to keep it.

7. Your Rights (UK GDPR)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a machine-readable format
  • Object: Object to certain processing activities
  • Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at hello@captifi.io

8. Cookies & Tracking

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Analyze site usage and performance
  • Provide personalized content
  • Enable essential features like login sessions

See our Cookie Policy for detailed information about the cookies we use and how to manage them.

9. International Data Transfers

Your data may be transferred to and stored in countries outside the UK/EEA. We ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses
  • Adequacy decisions by the UK government
  • Data processing agreements with all third parties

10. Children's Privacy

Our Services are not intended for children under 16. We do not knowingly collect data from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to Privacy Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or through a notice on our platform. Your continued use of the Services after changes indicates acceptance.

12. Additional Rights for US Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request details about personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (Note: We do not sell personal data)
  • Right to Non-Discrimination: You won't be discriminated against for exercising your rights

To exercise these rights, email us at hello@captifi.io with "CCPA Request" in the subject line.

13. Additional Rights for Canadian Residents (PIPEDA)

Canadian residents have rights under PIPEDA including access to your personal information and the right to challenge the accuracy and completeness of your data. Contact us at hello@captifi.io to exercise these rights.

14. Additional Rights for Australian Residents

Australian residents have rights under the Privacy Act 1988 to access and correct their personal information. You may also complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au

15. Complaints & Supervisory Authorities

If you have concerns about how we handle your data, please contact us first at hello@captifi.io

UK/EU Residents: You have the right to lodge a complaint with:

UK ICO: ico.org.uk | Phone: 0303 123 1113
EU Data Protection Authorities: Find your local authority

16. Contact Information

Data Controller: CaptiFi Limited
Email: hello@captifi.io
Address: Bristol, United Kingdom
Company No: 15948581