Last updated: 18 August 2026
CaptiFi Limited respects privacy and is committed to protecting personal data in accordance with applicable data protection laws worldwide. This Privacy Policy explains how personal data is collected, used, stored, transferred, and protected when using the CaptiFi platform, services, websites, mobile applications (including the CaptiFi iOS app available on the App Store), and related systems.
CaptiFi Limited
Company number: 15948581
ICO registration number: ZB362985
Registered address: Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
For the purposes of applicable data protection legislation:
CaptiFi acts as a data controller in relation to its customers, prospects, website visitors, and business contacts.
CaptiFi acts as a data processor in relation to guest data processed on behalf of venue operators using the Services.
Venue operators are the data controllers for guest data.
This Privacy Policy applies worldwide.
CaptiFi designs its privacy practices to align with applicable privacy and data protection laws, including but not limited to:
Legal responsibility for compliance with local laws relating to guest data remains with the venue operator acting as data controller.
We collect personal data relating to customers and authorised users including:
Payment card details are processed by third party payment processors and are not stored by CaptiFi.
CaptiFi processes guest data strictly on documented instructions from customers.
Guest data may include:
CaptiFi does not determine the purposes of guest data processing.
We automatically collect technical data including:
Customer data is processed to:
Guest data is processed only:
CaptiFi does not use guest data for independent marketing, profiling, or analytics.
Processing is conducted under one or more of the following bases:
CaptiFi does not independently determine lawful bases for guest data.
CaptiFi uses a small number of vetted service providers (subprocessors) to deliver the Services. The current subprocessors are:
Email marketing campaigns are sent through CaptiFi's own self-hosted campaign system running on CaptiFi's EU infrastructure, not a third party marketing platform.
Where a venue operator enables an optional marketing, loyalty, or point-of-sale integration (for example Mailchimp, Klaviyo, EmailOctopus, HubSpot, Square, Toast, Incentivio, Pepper, Leat, Airship, Twilio, Zapier, or Slack), opted-in guest data is sent to that platform on the venue's instruction. The venue chooses whether to enable these integrations.
Splash pages served to venue guests contain no third party analytics by default. Website analytics tools (Google Analytics, Microsoft Clarity, Meta Pixel) run on the CaptiFi marketing website only, subject to cookie consent.
All subprocessors are subject to contractual obligations regarding confidentiality, security, and data protection. The same list, with notice-of-change commitments, is set out in our Data Processing Agreement.
Application and database servers are located in the European Union (Finland/Germany). Guest and customer data is stored in the EU.
Email delivery is currently routed through Amazon SES in the United States (us-east-1 region), so email addresses and message content transit the US for sending. This transfer is safeguarded by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Regional email delivery (EU or Australia) can be arranged for customers who require it.
Where personal data is transferred outside the UK or EEA, CaptiFi relies on appropriate safeguards including:
For Australian customers, cross-border disclosures are handled in line with Australian Privacy Principle 8 (APP 8) of the Privacy Act 1988. See our Data Processing Agreement for details.
CaptiFi implements administrative, technical, and organisational safeguards including:
No system can be guaranteed to be fully secure.
In the event of a personal data breach, CaptiFi will:
Customer data is retained for the duration of the account and thereafter as required by law.
Guest data retention is controlled by the customer and may be configured, exported, or deleted at any time.
Upon termination, guest data is deleted within thirty days unless retention is legally required.
CaptiFi does not engage in automated decision making or profiling that produces legal or similarly significant effects on individuals.
CaptiFi uses cookies and similar technologies for essential functionality, analytics, and performance monitoring.
CaptiFi does not respond to browser Do Not Track signals due to lack of an industry standard.
Details are provided in the Cookie Policy.
Subject to applicable law, individuals may have rights to:
Requests relating to guest data should be directed to the relevant venue operator.
CaptiFi will assist controllers where required.
Residents of certain US states may have additional rights, including rights to access, delete, correct, and opt out of certain processing activities.
CaptiFi does not sell personal data or engage in targeted advertising based on sensitive personal information.
Requests may be submitted to hello@captifi.io.
The Services are not intended for individuals under sixteen.
CaptiFi does not knowingly process children's personal data.
This Privacy Policy may be updated periodically.
Material changes will be communicated through reasonable means.
Continued use of the Services constitutes acceptance.
You have the right to lodge a complaint with a relevant data protection authority.
CaptiFi encourages users to contact us first to resolve concerns.
CaptiFi Limited
Email: hello@captifi.io
Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE