Wigglewifi provides guest WiFi to venues — restaurants, hotels, guest houses, retail stores, clinics, gyms, schools, buses and taxis. That means two very different groups of people give us personal information, and this policy is written for both:
This policy explains what we collect, why, who we share it with, how long we keep it, and what you can do about it. It is written to meet the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Personal information means information that identifies you or could identify you. Under POPIA that includes your name, email address, phone number, physical address, location, and online identifiers — which is important here, because a device MAC address and an IP address are personal information even when we never learn your name.
| Responsible party | Wigglewifi (Pty) Ltd |
| Registration number | 2022/436636/07 |
| Registered address | 89 Roodebloem, Woodstock, Cape Town, Western Cape, 7925 |
| Telephone | +27 (0)21 565 0888 |
| General enquiries | accounts@wigglewifi.com |
| Information Officer | Daniel Titton |
| Privacy enquiries | admin@wigglewifi.com |
Our Information Officer is registered with the Information Regulator and is accountable for our compliance with POPIA. Any request under this policy — access, correction, deletion, objection, or a complaint — should go to admin@wigglewifi.com.
This is the most important thing to understand about how guest WiFi works, so we have put it up front rather than burying it.
When you connect to WiFi at a venue, that venue is the responsible party for the guest data collected at its site. The venue decides what its splash page asks for, whether it runs a survey, and whether it sends marketing — and the venue sends that marketing itself, from its own systems (see section 7). Wigglewifi acts as the venue’s operator: we run the platform, we store the data on the venue’s behalf, and we act on the venue’s instructions under a written agreement, as required by sections 20 and 21 of POPIA.
We are the responsible party in our own right for:
Practically, this means: if you want your details removed from a particular venue’s list, the venue controls that list, and we will remove you from it on the platform. If you want to know what the network itself logged about your device, that is ours to answer. You can send either request to admin@wigglewifi.com and we will route it correctly. You are never expected to work out which of us to ask.
We collect only what the service needs. What actually gets collected at any given venue depends on how that venue has configured its splash page, so not all of the following will apply to you.
When you use the enquiry or sign-up form on wigglewifi.com we collect your name, email address, telephone number, the industry you select and any message you write. We use this to respond to you and, if you become a customer, to set up your account.
Business name, VAT number, contact name, email address, telephone number, physical or billing address, site addresses, and the login credentials of each person you authorise to administer the account (passwords are stored hashed, never in plain text). We keep the invoicing and account records we are required to keep.
We do not take card payments anywhere on the Wigglewifi platform, and we hold no card or bank card details — not from venues, and not from guests.
Whenever a device connects to a Wigglewifi network, our access points and controller record technical data. This happens automatically — it is how a network works — and it applies even if the venue asks you for nothing at all:
We treat the MAC address as personal information. Where we use this data for our own reporting and for venue analytics, we work with it in aggregated or pseudonymised form wherever the purpose allows.
Guest WiFi on a Wigglewifi network is free to the guest. We never ask you to pay for access and we never ask for payment details.
A venue can choose one or more of the following login methods. Each collects different information:
We do not require identity documents to use guest WiFi.
Where a hotel or guest house has connected its property management system, guests may log in with a room number and surname, or a booking reference. We check that against the PMS to authorise access. We hold the minimum needed for that check and for the duration of the stay, plus the retention period in section 12.
Where a venue enables web filtering, our system checks the domain names requested by devices on the network against category lists in order to block categories the venue has chosen to block — typically illegal, malware or adult content. We also log blocked attempts, authentication failures and other security events.
We do not decrypt your HTTPS traffic, and we do not read, store or sell your browsing history, the content of your messages, or the content of anything you send over the network. Filtering decisions are made in the moment; filtering logs are short-lived and are used to keep the network safe and to troubleshoot, not to profile you.
We know which venue and which access point you connected through, so we know roughly where you were at that time. For in-vehicle deployments (buses, taxis and other mobile installations) the router may report the vehicle’s position, so a session may be associated with a route or a position rather than a fixed address. We use this for network operation, coverage and fleet reporting to the operator. We do not use it to track individuals between venues on behalf of anyone, and we do not sell location data.
Emails, calls and messages you send us, our replies, and delivery events for the one-time codes and account emails we send. Server and application logs containing account identifiers and technical context, for security and debugging.
Because guest WiFi has a reputation to live down, it is worth being explicit:
Under section 11 of POPIA we rely on the following:
| Purpose | Lawful basis |
|---|---|
| Providing WiFi access, applying your internet plan or access limit, keeping the session running | Performance of a contract / legitimate interest |
| Verifying an email address by one-time code | Necessary to provide access that you requested |
| Authorising a hotel guest against the PMS | Performance of a contract |
| Network operation, capacity planning, fault diagnosis and roaming | Legitimate interest |
| Security, abuse and fraud prevention, rate limiting, content filtering | Legitimate interest / legal obligation |
| Aggregated and pseudonymised venue analytics and footfall reporting | Legitimate interest |
| Collecting guest details into a venue’s own guest database | Consent (given to the venue at login) |
| Holding a guest’s marketing opt-in or opt-out so the venue can honour it | Consent — see section 7 |
| Social login, and Facebook like/share/check-in | Consent (you choose that route) |
| Ad targeting on splash and welcome pages by age, gender or interest | Consent |
| Surveys | Consent |
| Venue account administration, invoicing and support | Performance of a contract |
| Our own communications with business customers and enquirers | Legitimate interest, with opt-out in every message |
| Retaining records for tax, accounting and legal defence | Legal obligation / legitimate interest |
| Responding to lawful requests from law enforcement or a court | Legal obligation |
Where we rely on legitimate interest we have weighed that interest against your rights, and you may object — see section 14.
Section 69 of POPIA restricts unsolicited electronic marketing. How that works here depends on a fact that is easy to miss, so we state it plainly.
Wigglewifi does not send marketing messages to guests. We have no marketing mail system. The only email we send from wigglewifi.com is a one-time login code, plus account and support email to our venue customers.
When a venue runs a campaign to its guests, the message is sent by the venue, through the venue’s own email system — its own mail server and SMTP credentials, or a third-party email provider the venue has chosen and contracted with directly. Wigglewifi provides the tool that assembles the campaign and the record of who has opted in; the sending, the delivery and everything that happens after the message leaves are the venue’s, and its email provider is the venue’s operator, not ours.
That makes the venue the sender and the responsible party for its own marketing, and it agrees to the following as a condition of using the service:
You can withdraw consent at any time by using the unsubscribe link in the message, or by emailing admin@wigglewifi.com — we will set you to opted-out on the platform so the venue cannot include you in a future campaign.
If you receive marketing you did not agree to, tell us. We will check the consent record and, if there isn’t one, suppress you and take it up with the venue. Be aware that if a venue has exported your details and is mailing you from a list held outside our platform, we can suppress you here but we cannot reach into the venue’s own systems — in that case the venue is the party to complain to, and to complain to the Information Regulator about. We will give you its contact details.
Sections 34 and 35 of POPIA give the personal information of children (under 18) special protection: it may generally only be processed with the consent of a parent, guardian or other competent person.
Wigglewifi is designed to be used by adults, and our terms require venues to direct guest registration at adults. We know, though, that children use WiFi in schools, on school buses, in restaurants and in hotels. So:
We do not run advertising cookies, analytics cookies or third-party trackers, so there is no cookie banner — there is nothing to consent to.
The only cookies we set are strictly necessary ones:
These are necessary to deliver the service you asked for, so they do not require separate consent. They are not used to profile you or to follow you to other websites. Blocking cookies on the splash page will usually prevent you from getting online.
We use a small number of service providers (“operators” under POPIA). Each is bound by a written agreement, processes personal information only on our instructions, and may not use it for their own purposes.
| Who | What they do | Where |
|---|---|---|
| The venue whose WiFi you used | Receives the guest details you provided at its splash page, and its own venue analytics. Sends its own campaigns from its own systems | The venue’s location |
| Our platform, hosting and infrastructure providers | Running, hosting and maintaining the controller, portal, splash pages and databases | Microsoft Azure, multi-region across the European Union and the United States |
| Our email delivery provider | Delivery of one-time login codes and our own account and support email only | South Africa |
| Meta (Facebook), Google | Social login, and like/share/check-in, where the venue enables it and you choose it | USA |
| MikroTik, Teltonika | Access-point and router hardware and, for mobile deployments, device management | EU |
| Hotel PMS vendors | Room-based authentication, where the venue has integrated its PMS | As deployed |
| TripAdvisor and similar review platforms | Review prompts, where the venue enables them | USA |
| Professional advisers, auditors, accountants | Where they need it to advise us | South Africa |
We may also disclose personal information where we are required to by law, in response to a valid court order or lawful request from law enforcement, to establish or defend a legal claim, to investigate abuse of the network, or to protect the rights and safety of our users, our venues or the public.
If our business or a part of it is sold, merged or reorganised, personal information may transfer to the acquirer, who will remain bound by this policy or one materially equivalent to it. We will notify affected customers.
Wigglewifi is a South African company and this policy is governed by South African law. Our platform runs on Microsoft Azure across multiple regions in the European Union and the United States, for resilience and security, so personal information described in this policy is stored and processed outside South Africa. Some of our other operators are outside South Africa too (see section 10).
Where we transfer personal information across a border, we do so in line with section 72 of POPIA — principally on the basis that the recipient is bound by an agreement providing a level of protection substantially similar to POPIA. Microsoft’s data protection terms bind it to that standard across all Azure regions. We also rely, where applicable, on the transfer being necessary to perform our contract with you, or on your consent.
Running across more than one region means your information may be replicated between them. That is deliberate: it is what allows the service to survive the loss of a data centre, and it is the reason we do not lose your data.
| Data | Retention |
|---|---|
| Connection and session logs (MAC, IP, times, volumes) | A maximum of 12 months, usually 3 months, then deleted or fully anonymised |
| Guest login details held for a venue | For as long as the venue’s account is active, or until the guest asks for deletion or withdraws consent |
| Guest details after a venue leaves Wigglewifi | Exported to the venue on request and deleted from our systems within 90 days of the account closing |
| One-time codes | Minutes; overwritten or invalidated on use |
| Marketing opt-in and opt-out records | A maximum of 12 months on our system. Records can be downloaded and stored by the venue directly |
| Web-filtering and security logs | Not retained |
| Survey responses | For as long as the venue’s account is active, or until withdrawn |
| Venue account and invoicing records | Duration of the relationship, then as required by tax and company law (five years) |
| Enquiry-form submissions that do not become customers | 24 months |
| Aggregated, anonymised statistics | Indefinitely — these can no longer identify anyone |
When we delete personal information from the live system it is removed immediately, but it may persist in encrypted backups until those backups rotate out, which takes up to 12 months. Backup copies are not used for any live purpose and are deleted on schedule.
All traffic to our portals and splash pages is encrypted with HTTPS/TLS. Passwords are hashed. Administrative access to the platform is restricted to named individuals on a least-privilege basis and is logged. Management connections to access points run over an encrypted VPN with certificate-based authentication, rotated periodically. Databases are backed up, and backups are encrypted. Access attempts are rate-limited. Third parties who handle personal information for us are contractually bound to comparable standards.
We take these measures because section 19 of POPIA requires reasonable technical and organisational safeguards — but no system can be guaranteed completely secure, and we do not claim otherwise.
If a security compromise affects your personal information, section 22 of POPIA requires us to notify the Information Regulator and the affected people as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved and what you can do about it.
Under POPIA you have the right to:
To exercise any of these, email admin@wigglewifi.com. Say what you want and, if it relates to a specific venue, tell us which one and roughly when you connected — the MAC address of your device or the email address you logged in with is usually enough to find you.
We will acknowledge within 5 working days and respond within 30 days. We may need to verify your identity first, and we will only ask for what is needed to do that — we will not ask for a copy of your ID to action a simple opt-out. A formal access request under PAIA may be made on Form 2 and, where the law allows, may attract a prescribed fee; we will tell you before charging anything. We will not charge you for correcting or deleting your information or for opting out.
If you are unhappy with how we have handled your personal information, please give us a chance to fix it first: admin@wigglewifi.com.
You also have the right to complain directly to the regulator:
Information Regulator (South Africa) Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Telephone: +27 10 023 5200 Complaints: POPIAComplaints@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Website: https://inforegulator.org.za
Complaints must be in writing, on the prescribed form, and may also be lodged through the Regulator’s eServices portal.
Because you are the responsible party for the guest data collected at your site, some obligations sit with you and not with us. By using Wigglewifi you agree to:
The full terms are in your service agreement. We will support you with all of the above, but we cannot discharge these duties for you.
We may update this policy. The current version is always at wigglewifi.com/privacy, with the date at the top. If a change materially affects how we use your personal information, we will notify venue customers by email and, where appropriate, give notice on the splash page before the change takes effect.
Privacy and data requests: admin@wigglewifi.com General enquiries: accounts@wigglewifi.com Telephone: +27 (0)21 565 0888 Post: 89 Roodebloem, Woodstock, Cape Town, Western Cape, 7925