Version 2026-07-15.1 · Effective 2026-07-15 · GuestGate™, Olmstedville, NY, USA
GuestGate™ helps businesses share their guest Wi-Fi password through a branded page and, with the guest's choices, build a customer list. This policy describes what GuestGate actually does today. It covers guestgate.net, the business portal, and guest Wi-Fi pages we host. Where a business uses GuestGate to collect its guests' details, that business is the primary controller of its guest list and GuestGate processes the data on its behalf; the business's own privacy notice also applies.
Business customers: business and contact details you give us when applying, purchasing, or onboarding (name, business name, email, phone, website, address, logo, Wi-Fi network name), account credentials (password stored only as a strong one-way hash), portal settings, and support/feedback messages. Payments: handled by Stripe on Stripe's own pages — we never see or store card numbers; we receive verified subscription status, identifiers, and the email/name from checkout. Guests on a business's Wi-Fi page: the details the guest submits (name, email, optional phone) and their consent choices, stored locally first and delivered only to that business's own configured destinations. Guest Wi-Fi passwords: stored encrypted and shown only on the page after a valid submission — never included in any data delivery.
We run no advertising trackers, no analytics trackers, no heatmaps, and no session replay (our tag loader keeps such tools off unless you consent and they are ever added). We do not sell personal information and do not share it for cross-context behavioral advertising. We do not send SMS marketing (an optional SMS consent checkbox may exist for a future, separately reviewed program — no SMS is sent today). We never email passwords.
We do not sell your personal information. We share information with service providers only when necessary to provide a service you request and authorize. Today that means: Stripe (payments), our hosting provider IONOS (servers), and — only when a business connects them for its own guest leads — that business's HubSpot account, Google Sheets destination, or the automation/webhook destination it configures, each using that business's own credentials. Each business can see only its own records. The current list is in our subprocessor list (also available on request). If a future direct-mail campaign is ever enabled, it requires the business owner's affirmative authorization, transfers only the necessary fields, and is logged — never credentials, payment information, Wi-Fi passwords, tokens, or authentication secrets.
We keep records for as long as needed for the purposes above and as summarized in our data retention schedule (available on request). Passwords are hashed (bcrypt); guest Wi-Fi passwords and tenant integration credentials are encrypted at rest (AES-256-GCM); admin actions and privacy requests are audit-logged.
Cookie choices: Cookie Settings (withdraw any time). We honor applicable Global Privacy Control signals as an opt-out of targeted-advertising categories. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your data, to opt out of sale/sharing or targeted advertising, to limit sensitive-data use, to withdraw consent, and to appeal — use our Privacy Request page (no account needed). Guests can also unsubscribe via the link in any email. We aim to answer within the timelines that apply to you; specific rights vary by jurisdiction, and this policy is not a promise that every law applies to us or a claim of universal compliance.
The service is for adults and businesses. Guest Wi-Fi forms require confirmation that the person submitting is 13 or older or the responsible adult.
We'll update this policy when our actual practices change and adjust the version above. Questions: use the Contact Us form or the Privacy Request page.