A sign-up form on a phone
WiggleWifi (Pty) Ltd

Privacy policy

Last updated 21 August 2026

1. About this policy

Wigglewifi provides guest WiFi to venues — restaurants, hotels, guest houses, retail stores, clinics, gyms, schools, buses and taxis. That means two very different groups of people give us personal information, and this policy is written for both:

  • Venue customers — the business that buys our service, and the people who administer its account.
  • Guests — anyone who connects to WiFi at a venue that runs on Wigglewifi, and anyone who visits wigglewifi.com or enquires through it.

This policy explains what we collect, why, who we share it with, how long we keep it, and what you can do about it. It is written to meet the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”).

Personal information means information that identifies you or could identify you. Under POPIA that includes your name, email address, phone number, physical address, location, and online identifiers — which is important here, because a device MAC address and an IP address are personal information even when we never learn your name.

2. Who we are

Responsible party Wigglewifi (Pty) Ltd
Registration number 2022/436636/07
Registered address 89 Roodebloem, Woodstock, Cape Town, Western Cape, 7925
Telephone +27 (0)21 565 0888
General enquiries accounts@wigglewifi.com
Information Officer Daniel Titton
Privacy enquiries admin@wigglewifi.com

Our Information Officer is registered with the Information Regulator and is accountable for our compliance with POPIA. Any request under this policy — access, correction, deletion, objection, or a complaint — should go to admin@wigglewifi.com.

3. Our two roles: when we decide, and when the venue decides

This is the most important thing to understand about how guest WiFi works, so we have put it up front rather than burying it.

When you connect to WiFi at a venue, that venue is the responsible party for the guest data collected at its site. The venue decides what its splash page asks for, whether it runs a survey, and whether it sends marketing — and the venue sends that marketing itself, from its own systems (see section 7). Wigglewifi acts as the venue’s operator: we run the platform, we store the data on the venue’s behalf, and we act on the venue’s instructions under a written agreement, as required by sections 20 and 21 of POPIA.

We are the responsible party in our own right for:

  • running, securing and troubleshooting the network itself;
  • our relationship with the venue as our customer — accounts, support, invoicing;
  • our own website and enquiry forms;
  • meeting our own legal obligations.

Practically, this means: if you want your details removed from a particular venue’s list, the venue controls that list, and we will remove you from it on the platform. If you want to know what the network itself logged about your device, that is ours to answer. You can send either request to admin@wigglewifi.com and we will route it correctly. You are never expected to work out which of us to ask.

4. What we collect

We collect only what the service needs. What actually gets collected at any given venue depends on how that venue has configured its splash page, so not all of the following will apply to you.

4.1 Website visitors and enquiries

When you use the enquiry or sign-up form on wigglewifi.com we collect your name, email address, telephone number, the industry you select and any message you write. We use this to respond to you and, if you become a customer, to set up your account.

4.2 Venue customer accounts

Business name, VAT number, contact name, email address, telephone number, physical or billing address, site addresses, and the login credentials of each person you authorise to administer the account (passwords are stored hashed, never in plain text). We keep the invoicing and account records we are required to keep.

We do not take card payments anywhere on the Wigglewifi platform, and we hold no card or bank card details — not from venues, and not from guests.

4.3 Connection and session data (every guest, automatically)

Whenever a device connects to a Wigglewifi network, our access points and controller record technical data. This happens automatically — it is how a network works — and it applies even if the venue asks you for nothing at all:

  • the device’s MAC address (a hardware identifier) and the IP address assigned to it;
  • device type, operating system, browser and preferred language;
  • which access point and venue you connected to, and when you connected and disconnected;
  • session duration, and data uploaded and downloaded;
  • signal strength and connection quality, and roaming between access points;
  • the internet plan or access limit applied to your session.

We treat the MAC address as personal information. Where we use this data for our own reporting and for venue analytics, we work with it in aggregated or pseudonymised form wherever the purpose allows.

4.4 Login and identity data (depends on the venue’s splash page)

Guest WiFi on a Wigglewifi network is free to the guest. We never ask you to pay for access and we never ask for payment details.

A venue can choose one or more of the following login methods. Each collects different information:

  • Free access / click-through — no personal details beyond the connection data in 4.3.
  • Email with a one-time PIN (OTP) — your email address, plus the code we send and whether it was used. Verification proves the address is real and reachable.
  • Name and contact form — the fields the venue has chosen to make required or optional. Optional fields are genuinely optional; you can leave them blank and still get online.
  • Social login (Facebook, Google and similar) — when you choose this, the social network shares a defined set of profile data with the venue’s account. Depending on the platform and your own privacy settings this can include your name, email address, profile picture, gender, age range or date of birth. We do not get your social media password, and we do not post anything as you unless you take that action yourself on the welcome page.
  • Facebook like, share or check-in — if the venue requires this before granting access, the action happens on Facebook and is governed by Facebook’s own terms. You should be given an alternative login route; if you are not, please tell us.
  • Voucher, or username and password — the code or credentials issued to you by the venue, and their usage.

We do not require identity documents to use guest WiFi.

4.5 Hotel PMS integration

Where a hotel or guest house has connected its property management system, guests may log in with a room number and surname, or a booking reference. We check that against the PMS to authorise access. We hold the minimum needed for that check and for the duration of the stay, plus the retention period in section 12.

4.6 Splash content, advertising and surveys

  • Ads on the splash and welcome pages: these are the venue’s own video or image content, served by us from the venue’s account. We record impressions, completions and clicks so the venue can measure the campaign. Where a venue targets a campaign by age, gender or interest, that targeting uses data you provided at login for that venue. We do not run third-party ad networks on splash pages, and no advertising or tracking cookies are set.
  • Surveys: your answers, and whether you completed the survey. Do not enter health information, ID numbers or financial details into a WiFi survey; venues are told not to ask for them.
  • Review prompts (TripAdvisor and similar): we record that a prompt was shown and whether you clicked it. Anything you then write is submitted on the review platform under that platform’s own privacy policy, not ours.

4.7 Network security and content filtering

Where a venue enables web filtering, our system checks the domain names requested by devices on the network against category lists in order to block categories the venue has chosen to block — typically illegal, malware or adult content. We also log blocked attempts, authentication failures and other security events.

We do not decrypt your HTTPS traffic, and we do not read, store or sell your browsing history, the content of your messages, or the content of anything you send over the network. Filtering decisions are made in the moment; filtering logs are short-lived and are used to keep the network safe and to troubleshoot, not to profile you.

4.8 Location

We know which venue and which access point you connected through, so we know roughly where you were at that time. For in-vehicle deployments (buses, taxis and other mobile installations) the router may report the vehicle’s position, so a session may be associated with a route or a position rather than a fixed address. We use this for network operation, coverage and fleet reporting to the operator. We do not use it to track individuals between venues on behalf of anyone, and we do not sell location data.

4.9 Support and communications

Emails, calls and messages you send us, our replies, and delivery events for the one-time codes and account emails we send. Server and application logs containing account identifiers and technical context, for security and debugging.

5. Things we do not do

Because guest WiFi has a reputation to live down, it is worth being explicit:

  • We do not sell personal information, and we do not share it with third parties for their own marketing.
  • We do not send marketing. Venue campaigns are sent by the venue, from the venue’s own email system — see section 7.
  • We do not charge guests for access, and we hold no payment card details.
  • We do not decrypt or inspect the content of your traffic.
  • We do not build a cross-venue advertising profile of you, or sell foot-traffic data to data brokers.
  • We do not run third-party advertising networks, analytics trackers or advertising cookies on our splash pages.
  • We do not collect special personal information (health, religion, race, political or trade-union affiliation, biometrics, criminal history) and venues are contractually prohibited from configuring splash pages to ask for it.
  • We do not use guest WiFi data to make automated decisions that have legal consequences for you.

6. Why we process, and our lawful basis

Under section 11 of POPIA we rely on the following:

Purpose Lawful basis
Providing WiFi access, applying your internet plan or access limit, keeping the session running Performance of a contract / legitimate interest
Verifying an email address by one-time code Necessary to provide access that you requested
Authorising a hotel guest against the PMS Performance of a contract
Network operation, capacity planning, fault diagnosis and roaming Legitimate interest
Security, abuse and fraud prevention, rate limiting, content filtering Legitimate interest / legal obligation
Aggregated and pseudonymised venue analytics and footfall reporting Legitimate interest
Collecting guest details into a venue’s own guest database Consent (given to the venue at login)
Holding a guest’s marketing opt-in or opt-out so the venue can honour it Consent — see section 7
Social login, and Facebook like/share/check-in Consent (you choose that route)
Ad targeting on splash and welcome pages by age, gender or interest Consent
Surveys Consent
Venue account administration, invoicing and support Performance of a contract
Our own communications with business customers and enquirers Legitimate interest, with opt-out in every message
Retaining records for tax, accounting and legal defence Legal obligation / legitimate interest
Responding to lawful requests from law enforcement or a court Legal obligation

Where we rely on legitimate interest we have weighed that interest against your rights, and you may object — see section 14.

7. Marketing: who actually sends it

Section 69 of POPIA restricts unsolicited electronic marketing. How that works here depends on a fact that is easy to miss, so we state it plainly.

Wigglewifi does not send marketing messages to guests. We have no marketing mail system. The only email we send from wigglewifi.com is a one-time login code, plus account and support email to our venue customers.

When a venue runs a campaign to its guests, the message is sent by the venue, through the venue’s own email system — its own mail server and SMTP credentials, or a third-party email provider the venue has chosen and contracted with directly. Wigglewifi provides the tool that assembles the campaign and the record of who has opted in; the sending, the delivery and everything that happens after the message leaves are the venue’s, and its email provider is the venue’s operator, not ours.

That makes the venue the sender and the responsible party for its own marketing, and it agrees to the following as a condition of using the service:

  • Consent to receive marketing is separate from getting online. Connecting to WiFi is not consent to be marketed to. A guest who declines marketing still gets the same internet access.
  • Consent is recorded on the platform — what was asked, when, at which venue, and the answer — so it can be evidenced.
  • Every marketing message must identify the sender and carry a working unsubscribe. Unsubscribing is free and takes effect immediately.
  • A venue may only market to guests who consented at that venue. Venues may not upload lists collected elsewhere into the platform, and may not market to guests of a different venue.

You can withdraw consent at any time by using the unsubscribe link in the message, or by emailing admin@wigglewifi.com — we will set you to opted-out on the platform so the venue cannot include you in a future campaign.

If you receive marketing you did not agree to, tell us. We will check the consent record and, if there isn’t one, suppress you and take it up with the venue. Be aware that if a venue has exported your details and is mailing you from a list held outside our platform, we can suppress you here but we cannot reach into the venue’s own systems — in that case the venue is the party to complain to, and to complain to the Information Regulator about. We will give you its contact details.

8. Children

Sections 34 and 35 of POPIA give the personal information of children (under 18) special protection: it may generally only be processed with the consent of a parent, guardian or other competent person.

Wigglewifi is designed to be used by adults, and our terms require venues to direct guest registration at adults. We know, though, that children use WiFi in schools, on school buses, in restaurants and in hotels. So:

  • Venues in the education vertical and any venue whose guests are predominantly children must configure access without collecting personal details from the guest, and must not enable marketing consent, social login or surveys on that network. Access should be by voucher, click-through or credentials issued by the school.
  • We do not knowingly hold guest lists containing children.
  • If you are a parent or guardian and believe we hold your child’s information, email admin@wigglewifi.com and we will delete it and remove them from any list.

9. Cookies

We do not run advertising cookies, analytics cookies or third-party trackers, so there is no cookie banner — there is nothing to consent to.

The only cookies we set are strictly necessary ones:

  • On the splash and captive portal pages: a session cookie that holds your login while you are connected, so you are not asked to authenticate again mid-session, together with the technical items needed to apply your language choice and the venue’s access limits.
  • On wigglewifi.com: a session cookie and a form-security token when you log into an account or submit the enquiry form.

These are necessary to deliver the service you asked for, so they do not require separate consent. They are not used to profile you or to follow you to other websites. Blocking cookies on the splash page will usually prevent you from getting online.

10. Who we share information with

We use a small number of service providers (“operators” under POPIA). Each is bound by a written agreement, processes personal information only on our instructions, and may not use it for their own purposes.

Who What they do Where
The venue whose WiFi you used Receives the guest details you provided at its splash page, and its own venue analytics. Sends its own campaigns from its own systems The venue’s location
Our platform, hosting and infrastructure providers Running, hosting and maintaining the controller, portal, splash pages and databases Microsoft Azure, multi-region across the European Union and the United States
Our email delivery provider Delivery of one-time login codes and our own account and support email only South Africa
Meta (Facebook), Google Social login, and like/share/check-in, where the venue enables it and you choose it USA
MikroTik, Teltonika Access-point and router hardware and, for mobile deployments, device management EU
Hotel PMS vendors Room-based authentication, where the venue has integrated its PMS As deployed
TripAdvisor and similar review platforms Review prompts, where the venue enables them USA
Professional advisers, auditors, accountants Where they need it to advise us South Africa

We may also disclose personal information where we are required to by law, in response to a valid court order or lawful request from law enforcement, to establish or defend a legal claim, to investigate abuse of the network, or to protect the rights and safety of our users, our venues or the public.

If our business or a part of it is sold, merged or reorganised, personal information may transfer to the acquirer, who will remain bound by this policy or one materially equivalent to it. We will notify affected customers.

11. Cross-border transfers

Wigglewifi is a South African company and this policy is governed by South African law. Our platform runs on Microsoft Azure across multiple regions in the European Union and the United States, for resilience and security, so personal information described in this policy is stored and processed outside South Africa. Some of our other operators are outside South Africa too (see section 10).

Where we transfer personal information across a border, we do so in line with section 72 of POPIA — principally on the basis that the recipient is bound by an agreement providing a level of protection substantially similar to POPIA. Microsoft’s data protection terms bind it to that standard across all Azure regions. We also rely, where applicable, on the transfer being necessary to perform our contract with you, or on your consent.

Running across more than one region means your information may be replicated between them. That is deliberate: it is what allows the service to survive the loss of a data centre, and it is the reason we do not lose your data.

12. How long we keep it

Data Retention
Connection and session logs (MAC, IP, times, volumes) A maximum of 12 months, usually 3 months, then deleted or fully anonymised
Guest login details held for a venue For as long as the venue’s account is active, or until the guest asks for deletion or withdraws consent
Guest details after a venue leaves Wigglewifi Exported to the venue on request and deleted from our systems within 90 days of the account closing
One-time codes Minutes; overwritten or invalidated on use
Marketing opt-in and opt-out records A maximum of 12 months on our system. Records can be downloaded and stored by the venue directly
Web-filtering and security logs Not retained
Survey responses For as long as the venue’s account is active, or until withdrawn
Venue account and invoicing records Duration of the relationship, then as required by tax and company law (five years)
Enquiry-form submissions that do not become customers 24 months
Aggregated, anonymised statistics Indefinitely — these can no longer identify anyone

When we delete personal information from the live system it is removed immediately, but it may persist in encrypted backups until those backups rotate out, which takes up to 12 months. Backup copies are not used for any live purpose and are deleted on schedule.

13. How we protect your information

All traffic to our portals and splash pages is encrypted with HTTPS/TLS. Passwords are hashed. Administrative access to the platform is restricted to named individuals on a least-privilege basis and is logged. Management connections to access points run over an encrypted VPN with certificate-based authentication, rotated periodically. Databases are backed up, and backups are encrypted. Access attempts are rate-limited. Third parties who handle personal information for us are contractually bound to comparable standards.

We take these measures because section 19 of POPIA requires reasonable technical and organisational safeguards — but no system can be guaranteed completely secure, and we do not claim otherwise.

If a security compromise affects your personal information, section 22 of POPIA requires us to notify the Information Regulator and the affected people as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved and what you can do about it.

14. Your rights

Under POPIA you have the right to:

  • Be told whether we hold personal information about you, and to access it (section 23);
  • Correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24);
  • Object to processing we base on legitimate interest, on reasonable grounds (section 11(3));
  • Withdraw consent at any time, including for marketing — without affecting the lawfulness of what we did before you withdrew it;
  • Object to direct marketing at any time, absolutely (section 11(3)(b));
  • Not be subject to a decision based solely on automated processing that has legal or similarly significant consequences for you (section 71);
  • Complain to the Information Regulator (section 15).

To exercise any of these, email admin@wigglewifi.com. Say what you want and, if it relates to a specific venue, tell us which one and roughly when you connected — the MAC address of your device or the email address you logged in with is usually enough to find you.

We will acknowledge within 5 working days and respond within 30 days. We may need to verify your identity first, and we will only ask for what is needed to do that — we will not ask for a copy of your ID to action a simple opt-out. A formal access request under PAIA may be made on Form 2 and, where the law allows, may attract a prescribed fee; we will tell you before charging anything. We will not charge you for correcting or deleting your information or for opting out.

15. Complaints

If you are unhappy with how we have handled your personal information, please give us a chance to fix it first: admin@wigglewifi.com.

You also have the right to complain directly to the regulator:

Information Regulator (South Africa) Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Telephone: +27 10 023 5200 Complaints: POPIAComplaints@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Website: https://inforegulator.org.za

Complaints must be in writing, on the prescribed form, and may also be lodged through the Regulator’s eServices portal.

16. If you are a venue: your responsibilities

Because you are the responsible party for the guest data collected at your site, some obligations sit with you and not with us. By using Wigglewifi you agree to:

  • Tell your guests, at the point of login, who is collecting their information and why — our splash-page templates include a link for your own privacy notice, and you should populate it.
  • Keep marketing consent separate from access. Do not make consent a condition of getting online.
  • Accept that you are the sender of your own campaigns. They go out through your own mail server or an email provider you contract with directly. That provider is your operator: you are responsible for choosing it, for the contract with it, for what it does with your guest list, and for the deliverability, unsubscribe handling and complaint handling of every message you send.
  • Only market to guests who consented at your venue. Do not import lists from elsewhere, and do not share your guest data with other businesses.
  • Not configure your splash page to request special personal information, ID numbers, financial details or information from children.
  • Only export guest data to systems that give it equivalent protection, and handle any access, correction or deletion request you receive — or forward it to us within 5 working days.
  • Register an Information Officer with the Information Regulator. This is your obligation, not ours.

The full terms are in your service agreement. We will support you with all of the above, but we cannot discharge these duties for you.

17. Changes to this policy

We may update this policy. The current version is always at wigglewifi.com/privacy, with the date at the top. If a change materially affects how we use your personal information, we will notify venue customers by email and, where appropriate, give notice on the splash page before the change takes effect.

18. Contact us

Privacy and data requests: admin@wigglewifi.com General enquiries: accounts@wigglewifi.com Telephone: +27 (0)21 565 0888 Post: 89 Roodebloem, Woodstock, Cape Town, Western Cape, 7925

R250 per access point, per month · Every feature included · 12-month minimum term, rolling