Privacy Policy

Last updated: 18 August 2026

CaptiFi Limited respects privacy and is committed to protecting personal data in accordance with applicable data protection laws worldwide. This Privacy Policy explains how personal data is collected, used, stored, transferred, and protected when using the CaptiFi platform, services, websites, mobile applications (including the CaptiFi iOS app available on the App Store), and related systems.

1. Identity and Roles

CaptiFi Limited
Company number: 15948581
ICO registration number: ZB362985
Registered address: Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE

For the purposes of applicable data protection legislation:

CaptiFi acts as a data controller in relation to its customers, prospects, website visitors, and business contacts.

CaptiFi acts as a data processor in relation to guest data processed on behalf of venue operators using the Services.

Venue operators are the data controllers for guest data.

2. Global Scope and Regulatory Frameworks

This Privacy Policy applies worldwide.

CaptiFi designs its privacy practices to align with applicable privacy and data protection laws, including but not limited to:

  • UK GDPR and Data Protection Act 2018
  • EU General Data Protection Regulation
  • California Consumer Privacy Act and CPRA
  • Other US state privacy laws including Virginia, Colorado, Connecticut, and Utah
  • Canadian PIPEDA
  • Australian Privacy Act 1988
  • Brazilian LGPD
  • Singapore PDPA
  • Other comparable privacy frameworks

Legal responsibility for compliance with local laws relating to guest data remains with the venue operator acting as data controller.

3. Categories of Personal Data Collected

3.1 Customer and Business Data

We collect personal data relating to customers and authorised users including:

  • Names and contact details
  • Business identifiers and addresses
  • Account credentials and preferences
  • Subscription and billing records
  • Communications and support correspondence

Payment card details are processed by third party payment processors and are not stored by CaptiFi.

3.2 Guest Data Processed on Behalf of Customers

CaptiFi processes guest data strictly on documented instructions from customers.

Guest data may include:

  • Names and email addresses
  • Telephone numbers if enabled
  • MAC addresses and device identifiers
  • Session metadata and access logs
  • Device, browser, and operating system data
  • Custom data fields configured by the customer

CaptiFi does not determine the purposes of guest data processing.

3.3 Technical and Usage Data

We automatically collect technical data including:

  • IP addresses
  • System logs and diagnostics
  • Usage analytics
  • Approximate geographic location derived from IP

4. Purposes of Processing

4.1 Customer Data

Customer data is processed to:

  • Provide and administer the Services
  • Manage subscriptions and billing
  • Communicate operational and security notices
  • Provide customer support
  • Improve platform functionality
  • Prevent fraud and misuse
  • Comply with legal obligations

4.2 Guest Data

Guest data is processed only:

  • To provide the Services
  • In accordance with customer instructions
  • To comply with applicable legal obligations

CaptiFi does not use guest data for independent marketing, profiling, or analytics.

5. Legal Bases for Processing

Processing is conducted under one or more of the following bases:

  • Performance of a contract
  • Legitimate interests
  • Compliance with legal obligations
  • Consent obtained by the data controller

CaptiFi does not independently determine lawful bases for guest data.

6. Subprocessors and Third Parties

CaptiFi uses a small number of vetted service providers (subprocessors) to deliver the Services. The current subprocessors are:

  • Hetzner Online GmbH: application and database hosting, European Union (Finland/Germany).
  • Amazon Web Services (Amazon SES): email delivery, currently the United States (us-east-1 region), safeguarded by Standard Contractual Clauses. Regional email delivery (EU or Australia) can be arranged for customers who require it.
  • Stripe, Inc.: payment processing, global, safeguarded by Standard Contractual Clauses. CaptiFi does not store card details.
  • Cloudflare, Inc.: object storage for uploaded media such as logos and splash page images, European Union.

Email marketing campaigns are sent through CaptiFi's own self-hosted campaign system running on CaptiFi's EU infrastructure, not a third party marketing platform.

Where a venue operator enables an optional marketing, loyalty, or point-of-sale integration (for example Mailchimp, Klaviyo, EmailOctopus, HubSpot, Square, Toast, Incentivio, Pepper, Leat, Airship, Twilio, Zapier, or Slack), opted-in guest data is sent to that platform on the venue's instruction. The venue chooses whether to enable these integrations.

Splash pages served to venue guests contain no third party analytics by default. Website analytics tools (Google Analytics, Microsoft Clarity, Meta Pixel) run on the CaptiFi marketing website only, subject to cookie consent.

All subprocessors are subject to contractual obligations regarding confidentiality, security, and data protection. The same list, with notice-of-change commitments, is set out in our Data Processing Agreement.

7. International Data Transfers

Application and database servers are located in the European Union (Finland/Germany). Guest and customer data is stored in the EU.

Email delivery is currently routed through Amazon SES in the United States (us-east-1 region), so email addresses and message content transit the US for sending. This transfer is safeguarded by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Regional email delivery (EU or Australia) can be arranged for customers who require it.

Where personal data is transferred outside the UK or EEA, CaptiFi relies on appropriate safeguards including:

  • UK International Data Transfer Agreement and Addendum
  • EU Standard Contractual Clauses
  • Adequacy decisions
  • Contractual data protection commitments

For Australian customers, cross-border disclosures are handled in line with Australian Privacy Principle 8 (APP 8) of the Privacy Act 1988. See our Data Processing Agreement for details.

8. Information Security Measures

CaptiFi implements administrative, technical, and organisational safeguards including:

  • Encryption in transit and at rest
  • Access controls and authentication mechanisms
  • Monitoring and intrusion detection
  • Secure infrastructure and hosting environments
  • Backup, recovery, and resilience procedures

No system can be guaranteed to be fully secure.

9. Data Breach Management

In the event of a personal data breach, CaptiFi will:

  • Investigate and contain the incident
  • Notify affected customers without undue delay where required
  • Assist data controllers in meeting notification obligations
  • Maintain internal incident records

10. Data Retention

Customer data is retained for the duration of the account and thereafter as required by law.

Guest data retention is controlled by the customer and may be configured, exported, or deleted at any time.

Upon termination, guest data is deleted within thirty days unless retention is legally required.

11. Automated Decision Making and Profiling

CaptiFi does not engage in automated decision making or profiling that produces legal or similarly significant effects on individuals.

12. Cookies and Do Not Track

CaptiFi uses cookies and similar technologies for essential functionality, analytics, and performance monitoring.

CaptiFi does not respond to browser Do Not Track signals due to lack of an industry standard.

Details are provided in the Cookie Policy.

13. Individual Rights

Subject to applicable law, individuals may have rights to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability
  • Withdrawal of consent

Requests relating to guest data should be directed to the relevant venue operator.

CaptiFi will assist controllers where required.

14. US State Privacy Rights

Residents of certain US states may have additional rights, including rights to access, delete, correct, and opt out of certain processing activities.

CaptiFi does not sell personal data or engage in targeted advertising based on sensitive personal information.

Requests may be submitted to hello@captifi.io.

15. Children's Data

The Services are not intended for individuals under sixteen.

CaptiFi does not knowingly process children's personal data.

16. Policy Changes

This Privacy Policy may be updated periodically.

Material changes will be communicated through reasonable means.

Continued use of the Services constitutes acceptance.

17. Supervisory Authorities and Complaints

You have the right to lodge a complaint with a relevant data protection authority.

CaptiFi encourages users to contact us first to resolve concerns.

18. Contact Information

CaptiFi Limited
Email: hello@captifi.io

Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE