Upload the logo
Select an image file in the signup form. The browser sends it to the backend and stores it with the tenant.
Use this page when a client needs the checklist for logo upload, DNS, router configuration, and portal publishing — or when a real question needs a real answer. Looking for the full field-by-field reference instead of a quick answer? See our Documentation.
Privacy requests: guests can now download everything your WiFi holds about them, or ask for it to be deleted, right from their own My Account panel, as South Africa's POPIA requires. Downloads are instant. Deletion requests appear under Security → Privacy requests with a 30-day due date for you to action, and one click removes the guest's identity while keeping the connection records RICA says you must hold for 5 years. Proof of play: every campaign in the Captive Dashboard now has a Proof of play button that produces a PDF or CSV showing how often the ad played, where, when, and to how many different people. It's ready to hand to an advertiser's client. See Privacy requests and Proof-of-play reports on the Docs page.
Four additions for running this like a real ISP: Subscriber accounts (recurring monthly/weekly plans with automatic card billing, retries, and self-service cancellation — see the FAQ below), an optional static IP reservation for a subscriber's device on plans that support it, bandwidth congestion alerts when a router crosses 90% of its real capacity, and an outage-alert SMS option alongside the existing router-offline email, with a full outage-history log. See Subscribers and Bandwidth congestion alerts on the Docs page for the full field-by-field reference.
The dashboard a captive's own owner/admin/team logs into — separate from this reseller console — got a full visual and workflow redesign: a colored sidebar matching that captive's own brand, tabs that load their own data automatically instead of waiting for a manual refresh, a rebuilt phone layout, and one consistent look across every table and pop-up. Nothing about how any feature works changed, only how it looks and how it loads. See the full breakdown in that dashboard's own Help Centre.
Per-stop journey pricing (see the entry below) now reaches Generate vouchers and Voucher presets as well, not just Data plans/External voucher bundles — print a batch of codes for one specific leg or every leg at once, or let your own booking system reference a per-stop preset ID directly through the API. Router restriction on a voucher or preset is now real enforcement rather than just a display choice: a code can only be redeemed while connected to the router(s) you've ticked, inherited automatically from a mapped route's own restriction in Journey-based mode. Separately, every "restrict to specific routers" checklist across the platform now has a search box and a sane cap on how many render at once, for a fleet too large for a flat list. And Fleet map fixed a real bug (it could show only a corner of itself until the page was refreshed) while gaining two new things: your own location on the map, and a "Get directions" button per router for a real driving distance/route where you've connected a GraphHopper key, or a straight-line distance and compass direction otherwise. See Generate vouchers, Voucher presets, and Fleet map on the Docs page for the full breakdown.
Journey presets (Vouchers → Journey presets) now go further than one flat trip duration: per-leg pricing lets an operator charge a real, admin-set fare for each stop-to-stop leg of a mapped route (plus an optional full-route discount for riding the whole way), and Data plans' "Journey-based pricing" turns that into one real, buyable bundle per stop automatically. A router-restricted, distance-priced route also now closes a fare-evasion gap — buying the cheap short leg then boarding a pricier bus in the same fleet no longer carries that cheap access over, while ordinary WiFi portability (a shop, hotel, office) is completely unaffected. Three passenger-side fixes round it out: a passenger who buys before a set departure time gets their access extended to cover the wait instead of losing it while boarding; a bus that breaks down can have its replacement router "stand in" for it for 24 hours so already-paid passengers keep working; and a terminal with routers for several different routes can now be restricted, per bundle, to only show the routes that actually depart from it, with the stops of one route shown grouped together on the guest's own screen instead of as a flat list. See Journey presets and Data plans on the Docs page for the full field-by-field breakdown.
Select an image file in the signup form. The browser sends it to the backend and stores it with the tenant.
Add the required DNS records, then confirm the custom domain is resolving to the portal host.
Apply the captive portal address, DHCP, and WiFi settings, then re-run the status check.
The questions our own support team hears most, answered straight — no "contact us to find out." Organized by topic: your account, the portal & branding, vouchers & data plans, multi-device access, fair usage policy, routers & domains, messaging & billing, team & API, partners (revenue-share), and what your guests see.
Your dashboard's sidebar has a "My profile" entry under the Account group. It's your own email/password — the login you use across every captive you run — kept separate from any single captive's "Owner name" contact field, which lives in that captive's own Branding & colors form instead.
A checklist right at the top of your Dashboard home for exactly this: add your first router, upload your logo, turn on at least one way to earn (ads, vouchers, or data plans), and publish. Each step ticks itself off the moment you actually do it elsewhere in the dashboard — nothing to check by hand — and the whole panel disappears once all four are done. It's rechecked live every time the page loads rather than remembered permanently, so it also reappears if something that was done becomes undone later (e.g. your only router gets removed).
Use "Switch captive" in the dashboard sidebar, or the account menu in the header — both list every captive tied to your login and switch you into a fresh session for whichever one you pick. Same login, no re-entering a password. "Add another captive" from either place starts a brand-new one without leaving your current session.
Every branded location you run — name, domain, publish status, and router count — all reachable from one login. It's built for agencies and resellers operating WiFi for more than one business or site; each client is its own fully isolated captive with its own branding, routers, and vouchers.
Yes — it's the same platform at any scale, not a separate enterprise tier. My clients gives one login a franchise-style rollup across every site you run, each one fully isolated (its own branding, routers, vouchers, guest data). Plan & pricing includes unlimited routers and locations at no extra cost — you're billed on peak concurrent users, never on fleet size. Hardware breadth covers a mixed real-world fleet (MikroTik, Teltonika, GL.iNet, generic OpenWRT, Cisco Meraki, and TP-Link Omada fully automated; Cisco WLC/ISE, Cambium, Ruckus, and others guided), Network topology gives visibility across switches and access points at hotel/mall/campus scale, and RADIUS authentication plugs a router straight into a RADIUS server or Active Directory/Cisco ISE setup you already run. Team members lets a large staff work with exactly the access their role needs, enforced on the server rather than just hidden in a menu, and the Partner API issues vouchers or grants access programmatically at volume, safely retryable by design.
Use "Forgot password" on the login page — a reset link is emailed to your account's address. If you already know your current password and just want to change it, use "My profile" in the dashboard instead.
Yes. Every owner login already gets a mandatory second step — a 6-digit code emailed after your password. "My profile" → "Two-factor authentication" lets you turn on an alternative: a code from an authenticator app (Google Authenticator, Authy, or any standard TOTP app) instead. Scan the QR code, confirm with the 6-digit code the app shows, and you're also given 8 one-time backup codes — save them somewhere safe, since each works once if you ever lose the phone. From then on, signing in asks for the authenticator code (with a "use a backup code instead" option) rather than an emailed one. This currently applies to the account owner only, not team members, and can be turned off again at any time with your password.
Yes — as of this update. That's a completely separate login system from the one on this site (its own password, its own session), so it has its own matching two-factor setup: an emailed code by default, plus the same authenticator-app option under its own Settings page, independent of anything you've set up here. Its code emails come from your own configured sender if you've set one up under Email settings; otherwise from the default ISN Free WiFi sender.
If it's one of your own accounts on business-dashboard.html, an admin can turn their 2FA off directly from Business Accounts — no need to contact ISN. If it's your own login (the account owner) that's locked out, email info@isnfreewifi.co.za and ISN support will verify it's you and disable it for you.
Nothing you rely on it for silently stops arriving. If your configured mailbox (Email settings) stops working for any reason — the password changed on your provider's side, the mailbox got suspended, anything that makes sending through it fail — every email that would have gone through it, including a two-factor sign-in code, automatically falls back to the default ISN Free WiFi sender instead, still shown under your own brand name. You won't be locked out of your own dashboard by a mailbox problem you haven't had a chance to notice or fix yet.
That's a maintenance or incident notice, color-coded so you don't have to go check the status page to know something's up. Amber (with a pulsing border) means a maintenance window is planned — a heads-up for something coming, not happening yet. Orange means it's active right now. Click "Read more" to jump straight to the details on the status page. The same color cue shows in your ISN Dashboard header and on your own captive's guest home page, and it disappears on its own the moment the window ends or the incident is resolved — nothing for you to dismiss or reset manually.
No — never. If you ask us for hands-on help (e.g. configuring a router), our staff access your dashboard through an internal support tool tied to their own ISN Free WiFi account, not yours. Your password is never shared, entered, or seen by anyone at ISN Free WiFi, and every such access is logged separately from ordinary logins to your account (see our Terms & Conditions, Section 9). If anyone ever asks you for your password directly — by phone, email, or otherwise — that is not really us, and you should refuse and let us know.
Brand name, logo, primary/accent/background/text colors, tagline and summary copy, login page description and "how it works" steps, support email/WhatsApp, social links, and your own terms of service text — all from Branding & colors. Changes apply immediately; there's a live preview so you can see exactly what guests will see before you commit to anything.
No — on phones, the interactive phone-mockup preview is replaced with a "Preview" button that opens the real portal in a new tab instead (a live side-by-side mockup doesn't fit usefully on a phone screen). Tablets and desktop still get the full interactive preview with Login/Home/Business tabs.
Your captive portal is reachable as soon as your router points at it — publishing doesn't gate guest access. It's your own confirmation that setup is complete, and it's what flips your dashboard's "Portal state" from "Setup in progress" to "Portal live."
From Vouchers in the sidebar: generate a batch of codes with a data bundle and duration, or set up a reusable preset with your own pricing. Duration can be typed in hours or days — whichever's easier, the days field just converts for you. Data plans (Vouchers → Data plans) let guests pay directly by card, no code needed, once you've connected a payment gateway under Billing & plan.
Yes, all new. Yoco is a third card option alongside Paystack/PayFast under Billing & plan → Payment gateways (exactly one card gateway is active at a time) — paste your Secret key and a Webhook secret, and a guest paying for a data plan is sent to Yoco's own hosted checkout. SnapScan and Zapper are different: QR-code payments, not card, and both can run alongside a card gateway and each other. A guest sees a real QR code right on the captive portal and scans it with their own SnapScan or Zapper app to pay directly, no card details touching this portal at all. All three are newly built and not yet verified against a real account of any of them.
Yes — turn on "Allow adding extra devices" when generating the voucher/preset/data plan, and set how many devices can share it. A guest who redeems (or buys) then sees an "Add a device" option in their menu to bring a second phone, tablet, or Smart TV onto the same data pool instead of starting a fresh purchase.
Yes — "Print voucher sheet (PDF)" on All vouchers generates a printable grid of tear-off slips (code, data, duration, price, expiry) from your currently unused vouchers, up to 100 per sheet. Built for a front desk selling vouchers in person instead of reading a code off a screen.
Yes — the low-data nudge, on by default. A small banner with a "Top up now" button appears on a guest's screen the moment their active bundle drops below a percentage you set (default 20%), instead of finding out only once they're cut off. That banner only works while the guest still has the portal tab open, though — it can't reach someone who's closed it or moved on to browsing another site. Turn on "Also text the guest" (off by default, uses your SMS credits) right next to it to close that gap — a text reaches their phone at the same threshold no matter what they're browsing, at most once every 6 hours per guest. Change the threshold, or turn either one off, from the toggles above Data plans.
Yes — a bundle priced R0 automatically turns on promo abuse-protection (the one thing forced on for a free bundle, since otherwise it's open to unlimited repeat claims); a paid bundle can turn the same protection on voluntarily, e.g. a heavily-discounted launch promo you still want rate-limited. Set how often the SAME device or account can claim it — once ever (the strict default), hourly, daily, weekly, monthly, or yearly — plus an optional start/end window for a time-limited promo. It's enforced by device fingerprint AND by the guest's phone/email, whichever is more restrictive, so signing up under a new account on the same phone (or moving an already-used account to a different phone) doesn't get around it. An ineligible guest sees the bundle already greyed out on the connect screen, not a failed tap after trying.
Whichever combination you switch on. Turn on any one, two, or all three of ad-supported bundles, voucher redemption, and direct card payment, and guests see exactly those options on the connect screen — with no dead-end button for anything you've switched off.
An "internal" voucher is one you create yourself under Generate vouchers — you set the price and hand it out however suits your venue (cash, front desk, your own booking system); the platform only tracks issuance and redemption, so you keep whatever you actually charged for it. An "external" voucher is the reverse: a real prepaid 1Voucher or OTT Voucher PIN a guest already bought elsewhere — a spaza shop, a supermarket till, their own banking app — with no connection to you until they redeem it on your portal. You still profit from these: you set the bundle/price menu the redeemed balance buys (External voucher bundles), and the money settles into your own connected Flash merchant account. Together with ad revenue (businesses paying to reach your guests) and data plan revenue (guests paying by card), that's three separate income streams you can run at once — see How you profit on the Docs page for the full breakdown.
Yes — Journey presets, under Vouchers. Create a preset like "Cape Town to Johannesburg overnight" with a trip duration and a separate grace period (extra minutes on top, for a big terminal city where the vehicle is still navigating to the actual stop after arriving — e.g. a bus that's reached Bloemfontein's city limits isn't at its terminal yet). It works across every unlock type — ads, surveys, data plans, vouchers, and external voucher bundles — not just one. Without a booking-system integration, your guest offers it as a "which route are you on?" choice before the normal ad/survey/voucher/data-plan step. With the API, your booking system already knows the trip, so it passes the journey preset automatically at ticket purchase — no passenger input needed at all. Optionally restrict a preset to specific routers if different vehicles run different fixed routes. Not sure of the real trip duration? "Pick the route on a map instead" has a search box so you can jump straight to a place by name instead of panning/zooming, then lets you click every real stop along the route in order (not just the two endpoints — up to 12 stops, matching how buses/taxis actually pick up and drop off along the way), each with its own optional "wait here" minutes for a real dwell like a water break or rest stop. It pre-fills an estimated driving time, leg by leg plus any wait minutes summed into a total, with the actual road route drawn on the map — admin-only, one-time setup, and it never reads or tracks any guest's actual location. Both the search box and the map estimate need your own free GraphHopper API key saved at the top of the Journey presets page (sign up at graphhopper.com) — it's your own key, not a shared platform one, so you control its usage/cost. If a router is GPS-capable and reporting a live position, and your key is saved, a running trip that's genuinely delayed on the road (traffic, a breakdown) can also auto-extend just that passenger's access to cover the real remaining drive time, capped so it can never more than double the originally planned duration. Whether a given router supports GPS at all shows automatically in that router's Manage panel. Charging different fares for different stops along the route, covering a passenger who arrives early, handling a breakdown/relief-bus swap, and keeping a terminal's guest screen limited to routes that actually depart from it are all covered in the What's new entry above.
Yes — Subscribers, a separate section from vouchers/data plans, for a fixed account that renews automatically rather than a one-off purchase. Create a plan (price, billing interval, data allowance, optional speed caps and its own fair-usage override) under Subscription plans, and a guest can subscribe themselves from "Buy Internet Access" on your portal — the checkout also securely tokenizes their card so every later cycle charges automatically, with an SMS receipt each time. Already collected payment yourself (cash, EFT)? Search for that guest under Subscriber accounts and assign the plan directly to their real, already-recognized account — no fabricated login, no password. A failed automatic charge gets a 3-day grace period with retries before access actually pauses, and a subscriber can cancel their own future renewals any time from My Usage without losing access already paid for. Plans can optionally reserve a static IP for a subscriber's device too — see the Docs page for the full field-by-field breakdown.
A fourth way guests can earn data alongside ads, vouchers, and card payment: answer a short survey you curate (or, at a venue like a mall, one a specific business at the venue curates) and unlock a data bundle. Turn it on from Surveys in this dashboard, where you also set the rate you're paid per answer — question writing, budgets, age targeting, and unlock tiers all live on your Captive Dashboard's Surveys tab. Every question is AI-reviewed for age-appropriate content before it can go live, and every response is anonymous — no guest name, phone number, email, or ID number is ever stored against an answer, only aggregate results and, where a question was assigned to a business, that business's own results.
Lets a guest with an internal account at a PARTNER institution log in at YOUR captive using their own home credentials — the same idea as mobile carrier roaming or eduroam. Instead of just their username, a visiting guest types username@theirschool.ac.za; the part after the @ tells your captive which partner to check the password against. Set up your own realm and connect with a partner from Roaming Partners in your dashboard — nobody can connect to you without a one-time code you generated and shared yourself, and both sides must explicitly accept before any login trust exists. A guest's plain username with no @ only ever checks your own accounts, exactly as before. A visitor whose home institution uses Single Sign-On (below) is redirected through their own home sign-in automatically — no password prompt at your captive either way.
Yes — turn on Single Sign-On under Free access and connect your own identity provider (Google Workspace, Microsoft/Entra ID, Okta, or any other OIDC or SAML provider). An account is created automatically the first time someone signs in, using auto-provisioning defaults you set once (data cap, duration, device limit, speed caps) — you never add these accounts by hand, and no password for them is ever stored on this platform. Revoking someone's access in your own identity provider locks them out here automatically too.
Yes — Guest satisfaction (NPS), off by default under Free access. When it's on, tapping "Log out" opens a quick, optional prompt with three faces (🙁 😐 🙂) and a one-line comment box before the guest actually logs out — either tapping a face or "Skip" completes the real logout either way, so nobody is ever blocked from disconnecting. It's free and anonymous on both sides: unlike Survey-supported access, nothing is bought, sold, or rewarded, and no guest identity is ever stored against a response. Results (average score, response count, happy/not-great split, and recent comments) show right on the same settings panel.
Yes — Google review bonus, off by default under Free access. Paste your Google review link and set a bonus (data + duration); a guest sees an option to leave a review and earn it, which opens your review link in a new tab and reveals a "claim my bonus" button. The reward is for leaving a review, never for a positive one (Google's own policies don't allow incentivizing by sentiment). There's no realistic way to confirm a specific anonymous Google review came from a specific guest, so this runs on trust, granted once per guest ever — the same honor-system approach most guest-WiFi review tools use.
On your captive's own dashboard, a separate page from this one — at your live captive's own address (your subdomain or custom domain, whichever you're using) with /dashboard added to the end, e.g. https://yourbrand.isnfreewifi.co.za/dashboard. Log in there with the exact same email and password you use here. From your dashboard's sidebar (Overview → "Post ads & more"), this opens that page for you directly in a new tab, already pointed at your own captive, so you don't need to remember or type the URL yourself.
Yes — both the ad-campaign builder and the survey-question builder on your Captive Dashboard have a "Locations" picker listing every router you've registered, all checked by default. Uncheck the ones you don't want a specific campaign or question showing at — e.g. a promo for one branch only — and leave everything else running everywhere as normal. Leaving every location checked (or not touching the picker at all) behaves exactly as before this existed: it runs at every router you own, including any you add later.
Yes — "Frequency Cap" on the ad-campaign builder, off by default (a guest can see a campaign as often as it's otherwise eligible to show). Turn it on and set a limit — e.g. 3 views per day, per week, or per month — and once a guest hits it, that one campaign simply stops being offered to them until the period resets; every other campaign keeps showing to them as normal, and it doesn't affect the campaign's budget or end date. Worth knowing before you turn it on: it only caps that campaign's own reach, not a competitor's, so a low cap can mean its budget or goal-views target takes longer to spend, or never fully spends. It's best used for a genuine reason to avoid repeating the same guest too often (e.g. a one-time event promo) rather than switched on as a default — most advertisers get more views, and more of their budget spent, leaving it off.
If ads are your only way for guests to get online (no vouchers, data plans, or surveys turned on), the platform handles it automatically — "Connect" falls back to "My Usage" instead of sending the guest into an empty ad player with nothing left to show them, the same fallback a brand-new captive with zero ads uploaded already gets. It switches back to "Connect" by itself the moment that guest's cap period resets, you upload another campaign, or you turn on another access mode — nothing for you to do, and no dead end for the guest.
Yes — "Brand takeover day" on the same ad-campaign builder, a premium placement you price and invoice however you like. Check "Make this the ONLY ad guests see, for one full day" and pick a date; on that day, this campaign replaces every other active campaign for every guest it would otherwise have been eligible to show to (still respecting its own Locations restriction and any age-gating). Only one takeover can be booked per calendar day per captive — the date picker warns you immediately if a date's already spoken for, so two advertisers can never both believe they bought the same day.
No — 100% of what guests and advertisers pay is yours. Your only cost is the flat monthly subscription under Billing & plan; everything else never routes through an ISN-controlled account at all. Card payments for data plans, and 1Voucher/OTT redemptions, settle straight into your own connected Paystack, PayFast, or Flash Group merchant account — we only confirm a payment happened, we never touch the money. Vouchers you generate are sold however you choose (cash, front desk, your own booking system), and the platform just tracks issuance and redemption. Ad campaign spend from a business isn't even processed through a payment gateway on this platform at all — it's tracked (views delivered × your price, capped at their budget) purely so you know what to invoice or collect, on whatever terms you and that business agree.
Yes — My revenue (or Billing & Revenue on the /dashboard admin panel) has a Revenue by Router table alongside the combined total: ad views, voucher redemptions, and data plans sold at each router, plus revenue from each. A router earning under half your per-router average for the selected date range is flagged Underselling; one earning more than 1.5× the average is flagged Overselling. Each router also shows live online/offline status right next to its numbers, since a router that's simply been offline explains low revenue on its own, not necessarily a sales problem. Survey revenue isn't broken out per router yet, only ads, vouchers, and data plans.
Yes — a Revenue by Department table sits right under Revenue by Router on both My revenue and the Captive Dashboard's own Billing & Revenue tab. It's the same ad/voucher/data-plan/total numbers, just grouped by router group instead of listed per router — one row per group (a city's Parks routers vs its Libraries routers, a franchise's branches), plus an "Ungrouped" row for any router you haven't assigned to a group yet. Create and assign groups under Network → Your routers → Router groups; the report picks up any change immediately, nothing extra to configure.
It turns foot traffic you already have into income you don't have to chase yourself. On your Captive Dashboard (business-dashboard.html), an Admin or IT team member clicks "Add Business" and creates a real login for a local advertiser — just a business name and login email needed, no card required to create the account. That business gets its own invite email, logs into the same dashboard from then on, and builds and funds its own ad campaigns (and sees its own assigned survey results, if you've set any up) — entirely separate from your own data and any other advertiser's. You set the ad price once under Free access → Ad pricing; the business does the rest, and your revenue updates as their campaign delivers, with none of it shared with ISN (see the question above).
Four features combine to fix this without you policing it manually. First, stop issuing one shared password at all — give every tenant their own internal account instead, each with its own data cap, device limit, and duration; there's no single password left to leak. Second, let real guests connect anyway with "Guest vouchers from residents" — a tenant generates a voucher from their own usage panel for an actual visitor, with its own device limit, daily issue limit, visitor speed cap, and optional curfew hours; a random signup with no connection to a resident still gets nothing. Third, the Fair Usage Policy closes the loophole a resident-level check alone would miss: it tracks the visiting device, not the identity it signed up with, so a visitor can't dodge their limit by logging out, signing up again, or trying a different resident's voucher — soft mode throttles live, hard mode blocks new vouchers and blocks that device from redeeming any voucher until next month. Fourth, WiFi signal / coverage control attacks it from the radio layer: lower a router's broadcast power on 2.4GHz and/or 5GHz so it barely reaches past your own property line, so a neighbour or someone on the street stops seeing a usable signal at all, rather than seeing one and being turned away at login.
Once — every device added to a plan draws from the same shared data pool, and usage from any of them counts against that one balance. It's designed for real households and small teams sharing one plan across several devices, not a way to multiply free data. This applies to fair usage policy too: two devices sharing one plan (60GB and 40GB used, say, against a 100GB fair-usage threshold) are judged together as one combined 100GB, not as two separate 100GB allowances that neither device alone reaches.
Yes, if that plan allows extra devices. The device being added opens "Get Added to Another Plan" from its own menu (useful when it's already online under its own separate account), gets a short code, and gives that code to whoever owns the target plan — they enter it under their own "Add a device." Usage from the newly added device then counts against the plan it just joined, not any account it used before.
From the TV's browser, open the login page directly and choose "Adding a device you already have a plan on?" — it shows a short code on screen. Enter that code on an already-connected device's "Add a device" screen to approve it; the TV connects automatically once approved, no typing a voucher code on a remote required.
Yes — "Deactivate" in a guest's device list cuts that device's internet immediately but keeps its spot on the plan, so it can be turned back on later without re-pairing. "Remove" frees the spot entirely for a different device.
Logging out actually revokes that device's network access right away — it doesn't just clear the screen while quietly staying connected. Other devices sharing the same plan are unaffected.
It shouldn't stay that way for long. A device only counts against an internal account's or a roaming visitor's device limit while it's actually still connected, not for the rest of its whole access window — it's automatically freed after roughly 10 minutes of no sign of it, whether that's on the captive portal itself or, where your router reports connected devices, the router's own hardware confirmation. A device that's genuinely still online keeps its slot even if it never revisits the captive page again.
There are two separate fair-usage policies, and you can use either, both, or neither. The older one is scoped specifically to guest vouchers issued by your own residents/internal accounts, resets monthly, and has a soft (throttle) or hard (block new vouchers) mode. The broader one — off by default, turned on from Free access → Owner & guest access → Fair usage policy — covers everything else a guest can buy or earn: data plans, external voucher bundles, your own generated vouchers, voucher presets, ad-supported access, and survey-supported access. Set a data threshold in GB and a throttled download/upload speed; once a guest's usage crosses it, their speed drops immediately, live, with no reconnect needed. Every item above can optionally set its own threshold and speed, overriding your tenant-wide default just for that item — a cheap top-up voucher can throttle much sooner than a 30-day plan, for example.
No. Usage counts for a rolling 24 hours from when it was granted, even after the bundle it came from has expired — so an already-throttled guest who lets their voucher run out and immediately buys a fresh one stays throttled, because the old usage is still inside that 24-hour window. The same protection stops a guest from chaining several small vouchers to individually stay under one threshold; everything granted in the last 24 hours adds up together. Usage only genuinely resets once the old bundle's usage ages fully out of that rolling window, not just past its own duration.
Yes. Enforcement checks a guest's usage the moment their own connection reports it — effectively real-time — rather than only on a periodic timer, so a threshold crossed a few minutes into a short voucher gets caught immediately instead of waiting for a longer cycle to come around. A background safety-net check also runs every 5 minutes to catch anything the real-time path missed (a guest who was briefly offline, for instance), so short and long bundles are both covered.
All of them, each with its own place to set an override. An internal account holder's own direct login is covered automatically, with an optional threshold/speed set right on that account (separate from the older monthly policy that covers a voucher the account issues to someone else). A roaming visitor from a partner institution is covered automatically at the venue they're actually visiting, with an optional roaming-specific override sitting alongside your other outsider access rules on the Roaming Partners page. Single Sign-On has its own fair-usage default too, on the SSO settings page — baked onto every account SSO auto-provisions from then on, the same way its other defaults (data cap, duration, speed caps) already work.
By default, no — an internal/SSO account is usually added for months or years and reuses the same data allowance the whole time, unlike a voucher or data plan that naturally gets a fresh bundle. Turn on an automatic reset from Free access → Owner & guest access (the same control also appears on SSO Settings and on the internal-accounts Add-account form — all three save to the one tenant-wide setting): Rolling restores normal speed a set number of days after the account was last over threshold, or Calendar month restores it on the 1st. Only the fair-usage throttle resets — the account's real usage total and expiry date are never touched, so this doesn't add data or extend the account.
No. This is the same device-sharing protection as the plain log-out-and-register-again dodge, just with real credentials for a different account instead of a fresh sign-up. Fair usage is checked against every identifier that has shared a device, not just the one signed in right now, so a housemate's still-healthy internal, SSO, or roaming-partner login inherits the throttle the moment it's used on an already-throttled device, rather than needing to separately rack up its own usage first.
No. Every number this policy depends on lives in your account's database, never only in temporary router or server memory, so a reboot or a brief restart doesn't reset anyone's usage count. The background safety-net check also runs again the moment things come back online — not just on its usual clock — so enforcement catches back up within moments either way.
Once a router is paired to your tenant, its captive portal address, DHCP, and WiFi settings are pushed from your dashboard — there's no manual firmware editing. Re-run the status check any time to confirm a router picked up the latest configuration.
Yes — every plan includes unlimited routers and locations with no per-router charge. Add as many as you run from the same dashboard, and manage them all with the same branding, monetization, and access rules, or vary settings per location if you need to.
Yes — Zero-touch enrollment, above your router list. Generate a batch of QR codes ahead of time (pick MikroTik or OpenWRT-family, how many you need), print the sheet, and hand one code to whoever's actually installing each router — a driver, an on-site installer. They open it on their own phone, no ISN login at all, optionally name the router, and get that exact install command with step-by-step instructions. It's not fully hands-free — a real browser limit means someone still has to paste one command into the router's own terminal — but it does mean you don't have to be the one there, or on a call walking them through it, for every single unit. Each code works once; a used or cancelled one can't be reused.
Yes — Router groups, under Routers. Create a group (e.g. "Ground floor", "Branch A"), assign routers to it, then apply a speed cap to the whole group in one action, or scope the "Rotate WiFi password for all routers" action to just that group instead of your entire fleet. A router not in any group works exactly as it always has, and deleting a group only ungroups its routers — it never removes or changes them.
No, not by themselves — verifying updates what the dashboard shows and hands to any NEW router you add, but a router you already configured keeps using whatever login address was pasted into its own Hotspot settings at the time. Once your domain is verified, an "Update your routers to the new address" button appears on the Custom domain page — one password-confirmed click re-pushes the new address to every OpenWRT, Teltonika, or GL.iNet router you own, no need to log into each one. A MikroTik or other-vendor router has no automated push for this specific setting and needs its Hotspot URL changed by hand, or via Remote CLI. Either way, there's no rush: your old free address never stops working, even after your custom domain is verified, so nothing breaks for a router you haven't gotten to yet.
Direct command access to a paired router for diagnostics and restarts, without needing physical or SSH access to the hardware yourself. Every command run is logged against your account, since it's the kind of tool that can take a whole site's WiFi offline if used carelessly.
Not with Fair Pause, which is on by default. If a specific router loses power and a guest was mid-session on it with paid time-based access still remaining, that access clock freezes for exactly as long as the router is down, then resumes right where it left off once it is back — a guest with 4 hours left when the power cuts still has 4 hours left once it returns, no matter how long the outage runs. This only affects the one router that actually went down; guests on your other routers, even at the same site, are unaffected. It covers ad-watch unlocks, vouchers, data plans, POS sales, and API grants; resident/internal-account-issued vouchers are excluded. If an affected guest connects to a different one of your routers during the outage and keeps browsing there, they will not also get time credited back on the original router once it returns — no double-crediting. Turn it off under Network in your dashboard if you would rather access simply expire on schedule regardless of outages.
Two separate alerts, both under Network → Fair Pause. An outage alert emails you the moment any router stops reporting in, and again the moment it's back — checked every 5 minutes, sent once per outage, with an opt-in SMS version if email alone isn't reliable enough for you (uses your own SMS credits). Every outage is logged in an "Outage history" table: which router, when it went down, when it came back, how long, and how many guests had their access time restored. Separately, a bandwidth congestion alert fires when a router that's still online crosses 90% of its real capacity (compared against its own ISP-line speedtest, or its configured speed cap) — a different problem from an outage: guests are online but the pipe is saturated. Both are switched off/on individually under Notifications.
Yes — Content filtering lets you type in exactly the domains you want blocked (e.g. example.com), or turn on a one-click category (adult content, gambling, malware & phishing — a starter list of roughly 150 known domains each, from a maintained open-source blocklist, combined with anything you type). Nothing is blocked until you turn something on yourself. Re-enter your password to unlock changes, same as Remote CLI. The optional VPN mitigation toggle blocks common VPN ports and known public DNS-over-HTTPS providers to discourage casual VPN use — it's a real deterrent, not a guarantee; a determined, technical user can still find a way around any network-level filter, which is true of every vendor's product, not just ours. Automated push currently works for supported router models (Teltonika, GL.iNet, generic OpenWRT, and MikroTik in beta); other models get manual setup guidance in the same section.
Yes — in the same Content filtering section, "Protect minors from adult content" is a separate toggle from the category checkboxes above it. Turn it on and set an age (default 18), and any guest under that age gets redirected to a family-safe DNS resolver, while an adult guest on the exact same router keeps browsing normally — it targets who's connected, not just what's blocked router-wide like the other options here. It uses each guest's date of birth already on file from signup; a guest with none on file is treated as under the age until they provide one. Off by default. Works for MikroTik and OpenWRT-family routers (Teltonika, GL.iNet, generic OpenWRT); not yet verified against real hardware for either.
Yes — also in the Content filtering section, below the blocking controls, an "Allow extra domains before login (walled garden)" box lets you add domains your own setup needs reachable before a guest signs in, like a custom ad network or an embedded booking widget. It's additive only: a fixed baseline (payment gateways, known ad CDNs, and the domains phones/laptops check to pop up the "sign in to this network" prompt) is always allowed automatically and can't be removed here, so this can never accidentally lock your own guests out of paying or unlocking. One per line, wildcards like *.example.com allowed. Saves and pushes to your routers the same way the rest of the panel does — no separate step. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — on that router's own management page (opened from Routers), a "WiFi signal / coverage control" section lets you lower its broadcast power for 2.4GHz and 5GHz independently. Useful in dense buildings with shared walls or neighbouring shops, or to stop people outside on the street from connecting to your network. This only ever reduces power: values are hard-capped at South Africa's ICASA license-exempt ceilings (20 dBm / 100 mW on 2.4GHz, 30 dBm / 1 W on 5GHz), so you can never push a router above what it's legally allowed to broadcast without a license — staying under those caps is exactly what keeps it license-free. Leave a field blank to keep that radio at full hardware power. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — on by default, nothing to set up. Every 30 minutes, each of your routers briefly scans nearby WiFi networks and checks whether a different device is broadcasting the exact same network name yours uses — the standard "evil twin" attack, where someone sets up a fake copy of your hotspot (sometimes with a cloned login page too) to trick guests into connecting to them instead. If one's heard, you get an automatic email the moment it's detected, same as a router-offline or firewall-tamper alert.
Important to be clear about the limit here: this detects and alerts, it doesn't shut the rogue device down — no WiFi platform, ours included, can reach out and silence someone else's radio. What it solves is guests and you actually finding out an attack is happening at all, which is normally the real failure point. Once alerted, walking the venue for an unfamiliar device is the next step. Expect a possible few-second disconnect blip during each scan, since the radio briefly has to leave its own channel to listen — that's also why this runs every 30 minutes rather than every 5. A repeat sighting of the same device only alerts once, not on every scan it's still there. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — under Network → Routers, an Advanced section (collapsed by default, since most tenants never need it) lets you enter your own RADIUS server's address, ports, and shared secret. This points your router's captive-portal login at a RADIUS server you already run (often tied to Active Directory) — it's not a RADIUS server we host for you. The shared secret is encrypted and never shown back to you once saved. Pushed automatically to both OpenWRT-based routers and MikroTik routers (MikroTik support is beta — hasn't been verified against real hardware yet); any other router vendor needs this set directly on the router. If your RADIUS server is actually Cisco ISE, this is the integration you want — ISE already acts as a RADIUS server, so there's nothing Cisco-specific to configure beyond this panel.
Yes, in beta. Meraki APs are cloud-managed with no local access to script against, so instead of a command to run on the device, the Auto-config wizard asks for your Meraki Dashboard API key plus your network ID and SSID number, then configures that SSID's splash page to send guests straight to your Captive Login — done the moment you submit those, no separate verify/connect step. Content filtering and RADIUS aren't automated for Meraki yet, since Meraki's own settings for those work differently from every other router here and need their own design pass. For a Cisco WLC/ISE setup instead, pick that option in the wizard for manual web-auth guidance, and see the RADIUS question above if ISE is your RADIUS server.
Yes, in beta, and it works differently from every other router here. Omada has no config-push API for setting up the guest portal itself, so the Auto-config wizard instead asks for your Controller URL and a hotspot-operator account (create one under Settings → User Accounts if you don't have one) — once those verify, ISN tells your Controller a guest is authorized the moment they're actually granted access on our side, working for every ISN guest flow (ads, vouchers, SSO — not just accounts with a username and password). The one thing you still set by hand in Omada's own UI is this SSID's Portal Type ("External Portal Server") and its External Portal URL, both shown to you right after your credentials verify. Content filtering and RADIUS aren't covered here yet.
Yes, new and in beta, under Network topology → "Connect a controller." For UniFi, paste a Site Manager API key (generate one at unifi.ui.com → Settings → API Keys) — this uses Ubiquiti's own cloud API, so it works even without a port-forward to your console. For Omada, this is a separate, more privileged credential from the guest-login connection above: your Controller's Open API Client ID, Client Secret, and Omada ID (Settings → Platform Integration → Open API in the Controller). For Ruckus, paste your SmartZone controller's own URL (including the port and API path your model/firmware uses) plus an admin username and password. Either way, pick which of your routers the discovered devices should nest under, save, and every switch/access point the controller reports gets added and kept in sync automatically every 5 minutes — no SNMP community string needed for these (Ruckus covers access points only for now, not switches). "Sync now" checks immediately instead of waiting for the next cycle. Newly built and not yet verified against a real controller of any of the three, so a wrong credential fails as one clear error on the page rather than silently.
Add your domain in the dashboard, then create the DNS records it gives you. We check those records against live DNS — not a self-tick box — so the domain only goes active once it's actually resolving correctly. Guests never see the underlying subdomain once your domain is verified.
Under Network → Routers, each router shows its currently-reported firmware version. Rather than maintaining our own list of what's "current" per vendor (which goes stale and risks giving you wrong security advice), it's a fleet-relative comparison: if you run two or more routers of the same vendor and one is running an older version than its siblings, it's flagged as outdated so you know to update it — with a direct link to that vendor's own official changelog/advisory page for the details. A single router, or a lone vendor in your fleet, has nothing to compare against so nothing gets flagged. OpenWRT-family routers self-report on their regular check-in; MikroTik is checked once a day via Remote CLI.
Under Insights → Abuse & IP complaints, log the reported IP and when it happened, then run "Look up." Every router's own public IP is tracked over time (not just the current one — a complaint often arrives days after the fact, by which point a dynamic IP may have changed), so the tool can tell you which of your routers had that IP at that moment, and cross-reference it against guest sessions active on that router at the time. This is an operational lookup tool, not legal advice — it doesn't generate abuse notices or cite specific laws, since accuracy there varies by jurisdiction and getting it wrong could do more harm than good. What to do with the result (block the guest, report further, ignore) is your call.
Yes — Security → Banned devices. Enter the device's MAC address (found via the abuse lookup above, or your router's own connected-devices list) and it's blocked at the router itself, not just inside this dashboard — the device genuinely can't get online, on any of the different ways a guest normally would (voucher, ad, card payment, SSO). An already-connected device is kicked off immediately too. Ban it on just one router, or tick "Ban across all my routers" to block it everywhere at once — a router you add afterward doesn't automatically inherit existing bans yet, so re-ban from this page if you want it applied there too. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — Scheduled reboot, on that router's own management page (or apply the same schedule to a whole Router group at once, under Network → Routers → Router groups). Pick an hour and, optionally, specific days — leave every day unchecked for a daily reboot, or tick just one day for weekly. This is a deliberate, routine restart on your own schedule, separate from the outage alerting this platform already does — that only emails you when a router goes down unexpectedly, it doesn't restart anything itself. It fires sometime within the hour you chose, not necessarily on the exact minute, which is fine for routine maintenance. Works for every router vendor this platform supports.
Yes — Network → Fleet map, colored by whether each router is online right now, with its own search box to jump to a place instead of panning/zooming by hand. Worth knowing exactly how the location is worked out: by default it comes from each router's own reported public IP, run through a free IP-geolocation lookup — genuinely accurate to city/area level for a router at a fixed site (a shop, an office), shown as a plain dot. For a router on a mobile/cellular connection, like an LTE dongle on a bus or taxi, IP-based location only shows roughly where that connection is registered on the mobile network, not the vehicle's exact position. Where the router's agent actually supports GPS and is reporting a fresh fix, its real live position is shown instead (a blue-ringed marker), moving as the vehicle actually travels — whether a given router supports this is auto-detected and shown in its Manage panel. A router that hasn't reported a public IP yet has nowhere to plot and is listed below the map instead, until it checks in for the first time. Many routers close together group into a single number badge (like a ride-hailing app) — click it to zoom in and split them apart, and marker size scales with zoom so a large fleet doesn't look cluttered zoomed out.
Yes — Multi-WAN failover, on that router's own management page, if you already have a second internet connection physically wired in (an LTE dongle or a second line into a spare port — this pushes configuration, it doesn't provide or install the second connection itself). Enter the backup connection's details and it's monitored continuously; if the primary drops, guests are automatically routed over the backup within moments, then switched back once the primary recovers. Every switch is logged so you can see how often it's happened and for how long. Turning it off does not remove the routes/config already pushed to the router — it just stops us managing them — since undoing it automatically could risk cutting a guest off mid-failover. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — Smart Queue Management, on that router's own management page. This is the real fix for "bufferbloat": the delay that builds up when a connection is fully loaded (someone downloading a large file, for example) and everything else — a video call, a game, just browsing — grinds to a crawl even though there's technically still bandwidth free. It works by actively managing the router's own send queue (a well-established technique called CAKE) so that no single device or download can starve everything else, without needing to identify or prioritize specific apps or websites, which isn't something we do — traffic type is easy to get wrong and we'd rather not guess. Enter your real download/upload line speed (a slightly conservative number, around 90-95% of what a speed test shows, works best) and the interface it applies to. Works for MikroTik (RouterOS 7 or newer) and OpenWRT-family routers; not yet verified against real hardware for either.
Yes — Config backups, on that router's own management page. A snapshot of the router's config is taken automatically right before any of those four changes is pushed, so there's always a "before" version to fall back to; a "Back up now" button is also there for taking one any other time. Restoring re-enters your dashboard password first, since it's a real, destructive action that replaces the router's current config with the saved snapshot. WiFi password and RADIUS shared secret are never included in a backup, so restoring can never blank those out. Works for MikroTik and OpenWRT-family routers; not yet verified against real hardware for either.
SMS is built into the platform for guest and account signup verification plus account notifications — there's no separate provider or API key to configure. A short message (an OTP code, most notifications) uses one credit; buy more from Messaging → Buy credits (type either a Rand amount or a credit count, the other side calculates itself), and review balance, purchase history, and every message sent from the other Messaging tabs.
Length. A plain-text message fits 160 characters in a single credit — go over that and it splits into real, separate SMS parts of 153 characters each, billed as one credit per part (so a 250-character message is 2 credits, a 400-character one is 3), matching exactly what our own SMS provider bills us for it. Using emoji, accented characters, or a non-Latin script drops those limits to 70/67 characters, since that forces a different, less space-efficient encoding — the same reason a single emoji can suddenly "use up" far more of a text's character count than you'd expect, on any phone or platform. Sent messages (just below) shows a Credits column so you can see exactly what any specific message was charged and why. There's also a hard ceiling of 3 parts (459 plain-text characters, or 201 with emoji/accents/non-Latin script) — a message longer than that is rejected outright before anything sends or any credit is charged, rather than being allowed through at a higher cost.
Both SMS and the default ISN email sender have a fair-use daily ceiling per tenant (200/day for SMS, 50/day for email) since every tenant shares one provider account for each — this stops one tenant's send volume from degrading delivery for everyone else. It never affects sign-in codes, password resets, account verification, team invites, or your own invoices/receipts — those always go through. Only routine notification sends (marketing texts, ad/survey milestone emails, router/capacity alerts) count against it. Connecting your own SMTP or Resend account under Email settings removes the email limit entirely, since you'd be sending through your own account at that point. Need a higher SMS limit specifically? Email ISN Free WiFi to request one.
Yes — Messaging → Email settings lets you connect a Resend API key as well as, or instead of, SMTP. You can connect both: a send tries Resend first, then your SMTP sender, then falls back to the default ISN address only if both are unavailable, so pairing them gives you a real backup rather than one point of failure. Saving a Resend key sends a real test email to your own account address to confirm it actually works before it's used for anything else. For security, create a Resend key scoped to "Sending access only" rather than full access — this platform only ever needs to send, never to read your domains or account settings.
Your account enters a 5-day grace period. During that window your dashboard flags the account as past due, but your captive portal keeps serving guests normally. If the balance isn't settled within 5 days, portal-facing features (splash page, voucher issuance, ads) are suspended until payment goes through. Nothing is deleted — your configuration and history stay intact. Full detail in our Service Level Agreement.
Billing & plan → Invoices lists every charge with date and status. Plan & pricing on the same page shows your current subscription, next billing date, and card on file.
Starting a trial, paying immediately, or updating your saved card all run a one-time R5 charge to confirm the card is genuine. Our payment processor doesn't support automatically refunding this charge, so instead of a cash refund you're credited 10 free SMS credits (worth R5, at the standard R0.50/credit rate) the moment verification completes — real value back, just not a literal refund.
Unpublish takes your guest-facing URL offline without touching your subscription at all — republish any time before your next billing date at no extra cost, since unpublishing never forfeits time you've already paid for. But that free window closes once your next billing date passes while you're still unpublished: republishing after that charges the current monthly rate immediately, right before you go back live, since the billing system never charges an unpublished tenant on its own. Cancel is different again — it clears your billing date and trial, takes the portal offline immediately, and stops every future charge for good until you actively resubscribe. Your saved card stays on file either way, so coming back later never needs a fresh R5 verification charge.
Two, if your account has never completed a real subscription payment on any of them — an anti-abuse limit on spinning up unlimited unpaid drafts, not a feature you're missing. It lifts permanently the moment your first real payment goes through (a trial converting to paid, or an immediate charge, both count), no matter which of your captives paid — every captive you create after that is unlimited.
Yes — Free access → Owner & guest access lets you configure open/free access rules and internal accounts (staff, management) that bypass the normal ad/voucher/payment flow entirely.
Yes — internal accounts have an optional "Unit / room / ward" label (e.g. "Ward 4A", "Room 212") you set when adding or editing one, and a filter box above the accounts list to see everyone in one unit at a glance. It's a free-text label you set yourself, not automatic physical-location detection — there's no way for the platform to know which room a device is actually in, only whatever you type when you create the account.
Analytics & reports gives you the aggregate picture — traffic trends, peak concurrent devices, voucher/ad performance over time. Guest activity is the individual event log (logins, redemptions, ad views) for when you need to trace one specific guest or incident. Notifications surfaces anything that needs your attention (payment issues, router problems) in one place.
Automatic anomaly detection for internal-account and roaming logins: impossible travel (one account authenticating from two places too far apart to be the same person in that short a window), excessive device cycling (one login moving through an unusual number of distinct devices in a day, the pattern a shared or leaked login produces), and a general credential-sharing signal. These are review signals, not an automatic block — a legitimate case like a phone and a laptop can still occasionally brush the same thresholds, so nothing is auto-logged-out; you review a fired alert and decide what to do.
Yes — Automated win-back, next to Re-engage guests, off by default since it spends SMS credits on its own once enabled. Set how many days of inactivity counts as gone quiet (default 14), how many past purchases makes someone a real repeat customer (default 2), and a cooldown so the same guest isn't messaged too often (default 30 days). A daily check texts everyone who matches, using your own message. It's capped at 50 sends per day and stops itself the moment your SMS credits run out.
Yes — a "Why is my bill this amount?" panel under Plan & pricing breaks the formula down in plain numbers: your base price, how many concurrent users that includes, your real peak this month, how far over the limit that peak went, and the rate per extra user — the same numbers that already make up the total shown above it. A "Peak per month" table alongside it shows your last several months for context. It won't tell you which day or hour was busiest, though — this platform only records each month's peak number, not a timestamp for when it happened.
Yes — Data retention under Security, off until you set a window (30-day minimum, enforced either way). Once set, a daily check clears the name, date of birth, email, phone, and registration details of any guest inactive for at least that long — their past usage and revenue stay in your reporting, only who they were is cleared. Worth knowing: this clears their main record but doesn't reach every historical row elsewhere that separately logged their contact info, so treat it as a real, working purge of the primary record rather than a guarantee every trace is gone. A purge history table shows every run for your own compliance record.
Yes — Team & access → Team members lets you invite people with a specific role (for example, financial access without team management, or ads-only). Each role only sees and can act on what it's scoped to; the full Owner/IT role is the only one that can manage the team roster itself.
Yes — API & integrations lets you generate API keys to issue and reschedule vouchers programmatically from your own booking system or point-of-sale, using your own pricing presets so bundle/price/duration always stay under your control rather than whatever the calling system sends. From that same section, the Integration guide button opens full documentation — authentication, endpoint reference, idempotency, error codes, and copy-paste code samples for Node.js, Python, PHP, cURL, WordPress, and Wix (Velo) — with a clear warning never to call the API from browser/front-end code. Open the Integration Guide.
Yes — Webhooks, in the same API & integrations section (owner-only to set up). Add your own https:// URL and pick which events you want: guest.signup, voucher.redeemed, router.offline, and router.online today. The moment any of those happens, ISN sends your server a signed POST — signed with a secret shown to you once at creation, so your end can verify a delivery genuinely came from ISN before trusting it. A delivery that fails is retried a few times automatically, and a webhook that keeps failing eventually disables itself rather than getting hammered forever; a "Test" button lets you send a sample delivery on demand to check your receiver works before relying on it. Full request/header/signature details are in the Docs page.
A Partner is anyone who hosts one of your routers and earns an agreed percentage of the ad, voucher, and data-plan revenue that specific router generates — a taxi driver with a router in their vehicle, a fleet owner with many, or a venue you don't run yourself. It's on the Captive Dashboard's Partners tab (Admin/IT team roles only) — see Captive Dashboard for how to reach it from this dashboard.
Create a named group first (for example "Standard Drivers: 20%" or "Fleet Owners: 25%") with a default split, then add partners into it — or give one partner their own custom override on top of their group's rate for a one-off deal. Editing a group's percentage later applies to every partner currently in it, both going forward and for how their past revenue displays (there's no rate-history timeline) — if you want existing members to keep their old rate, leave that group alone and create a new one for future partners instead.
Adding a partner and assigning them a router starts their revenue tracking immediately — nothing waits on them logging in. They get an invite link (SMS, email, or both — your choice, in Partners → Notification settings) that opens the exact same "set your password" screen used when you add a business advertiser, branded as your own captive, not ISN. Once they set a password they land on their own small dashboard: Overview (today/week/month/lifetime earnings), My Routers (live status of what they host), Earnings (a chart plus a per-router breakdown), My Rate (their split % and where it comes from), and a bare-bones Settings (their own password and active sessions) — nothing about your other advertisers, your other partners, or your account settings.
Yes — most drivers do. Add them with just a phone number and they log in by typing that same number where the login form asks for "email," and get their sign-in code by SMS instead of email. Whatever format you or they type it in (+27..., 0..., spaced out) is treated as the same person everywhere — the Partners list, search, and login all recognize it as one identity.
Their router(s) immediately revert to "no partner," so 100% of future revenue from them comes back to you until you manually reassign the router to someone else. The partner keeps their login and can still see their own full historical earnings after being cut off — useful if the arrangement is ever disputed — and you can see a cut-off partner's history from your side at any time too.
No — same as everything else in My revenue, ISN is never a party to what you agree to pay a partner. The Partner Payouts figure on My revenue just tells you what you currently owe out across every partner for the period you pick, computed from the same router revenue you already see everywhere else — how and when you actually pay them (cash, EFT, however you already run it) is between you and them.
No — a partner (e.g. a fleet owner with several taxis) can generate a driver link for each of their own routers, right from their My Routers tab, and hand it straight to that vehicle's driver. It needs no account or password on the driver's end — just a link/QR code showing that one router's ad views and the partner's own earnings for it, nothing else. See Driver links in the full docs for details, including how to revoke one if a phone is lost.
Your own branded splash page — logo, colors, and copy exactly as set in Branding & colors — with whichever of ad-watching, voucher redemption, or card-paid data plans you've switched on. From there, a logged-in guest gets a menu with My Usage, Add a Device, Get Added to Another Plan, and Log out.
A guest signed in through an internal account, SSO, or roaming gets a My Account area right on the Home screen — their own usage, every device currently signed in, and (if roaming) where their account has connected from. It needs no separate login or password of its own: it recognizes the guest automatically for as long as they're actually logged into WiFi, and disappears the moment they log out, so a logged-out device can't be used to keep viewing that account's details. A guest can sign out one specific device remotely from this list if it was lost or left logged in somewhere.
No — video ads and any guest-facing video are automatically compressed to 720p to keep data usage and load times reasonable for everyone sharing the network, the same way major video platforms cap mobile-data playback quality.
Mbps (megabits per second) measures how fast data moves — how quickly a page loads or a video buffers — which is a different thing from the data bundle (measured in MB/GB) a guest earns or buys through your portal. A data bundle is a volume of data they can use before it runs out; it doesn't set a speed. The actual speed a guest experiences comes from your own router's internet connection (your uplink from your ISP) and how many guests are sharing it at once — ISN Free WiFi supplies the captive-portal software, not the internet connection itself, so we don't set or guarantee a specific Mbps figure (see our SLA, Section 9). If guests are consistently reporting slow speeds, the router's own uplink capacity and concurrent-user count are the first things worth checking, not your data plan configuration.
Email info@isnfreewifi.co.za with your tenant slug, domain, and router model so support can confirm what still needs attention before replying.