Legal

Privacy Policy

How ISN Free WiFi collects, uses, and protects information — both for the businesses that run a Business Account, and the guests who connect through a tenant's captive portal. Last updated 6 August 2026.

1

Scope & who this applies to

This policy covers two different groups, and it matters which one applies to you:

GroupResponsible partyDetails
Business Account holders ("Tenants")ISN Free WiFi, under POPIAThe businesses, ISPs, and venues that register on ISN Free WiFi to run their own branded captive portal.
GuestsThe tenant whose captive portal they usedISN Free WiFi acts only as an operator processing this data on the tenant's behalf, consistent with Section 10 of our Terms & Conditions. Questions about how a specific captive portal uses your information should go to that venue directly, not to ISN Free WiFi.
2

Information we collect

CategoryWhat's collected
Business Account detailsBusiness/contact name, email, phone, company details, and a hashed password (never stored in plain text) when a Tenant registers.
Billing informationSubscription and SMS-credit charge history. Card details themselves are handled directly by our payment processor's own hosted checkout — ISN Free WiFi's own servers never receive or store full card numbers.
Guest account detailsEmail or phone number and a hashed password, submitted when a guest creates a login on a tenant's captive portal, plus first/last name where a portal collects it.
Device & network dataDevice identifiers (MAC address), IP address, and router/session identifiers — needed to grant and meter WiFi access and enforce a guest's data bundle.
Usage dataData consumed against a bundle, session timestamps, and ad-view/voucher-redemption/data-plan-purchase records tied to a guest's account.
CommunicationsSMS and email delivery records (verification codes, password resets, usage alerts) — the message content and delivery status, not stored beyond what's needed for support and abuse investigation.
Cookies & local storageSession identifiers used to keep a Business Account or guest logged in, and to recognize a device already granted network access. See Section 5.
3

How we use it

  • To create and operate a Business Account or guest login, and to authenticate you on return visits.
  • To grant, meter, and enforce WiFi access against a voucher, ad-supported bundle, or paid data plan.
  • To send verification codes, password resets, receipts, and — only where a tenant has explicitly turned it on — optional usage-threshold or low-balance SMS alerts.
  • To process subscription and SMS-credit payments, and to detect and prevent fraud or abuse.
  • To provide support, including the audited internal support-access mechanism described in Section 9 of our Terms & Conditions.
  • To maintain the security, availability, and integrity of the Platform.
4

Legal basis (POPIA)

Where South Africa's Protection of Personal Information Act (POPIA) applies, we process personal information on the basis of: performance of a contract (running the Business Account or captive portal a guest actively chooses to use), a legitimate interest in operating and securing the Platform, compliance with a legal obligation, or consent — for example, where a guest opts in to receive optional usage-alert SMS messages a tenant has enabled.

5

Cookies & local storage

We use session cookies and browser local storage to keep you logged in and to recognize a device that has already been granted network access, so a guest isn't forced to log in again on every page. We do not use third-party advertising or cross-site tracking cookies of our own. A tenant's own ad-supported bundles may load third-party video/ad content, which is subject to that third party's own practices, not this policy.

6

Who we share information with

We do not sell personal information. We share it only with the service providers ("sub-processors") that make the Platform work, each bound to use it only to provide their service to us:

CategoryPurpose
Database hosting providerPrimary database hosting for Business Account, guest, and portal data.
Application hosting providerApplication hosting for the Platform itself.
SMS delivery providerDelivery of verification codes, password resets, and optional usage-alert SMS messages.
Payment processorCard payment processing for subscriptions and SMS-credit purchases. Card details are handled directly by their hosted checkout, not by our own servers.
Email delivery providerDelivery of system emails (verification, password reset, receipts).

We may also disclose information where required by law, to enforce our Terms & Conditions, or to protect the rights, property, or safety of ISN Free WiFi, our tenants, or their guests.

7

International data transfers

Some of the providers listed in Section 6 host infrastructure outside South Africa. Where personal information is transferred across borders, we rely on those providers' own contractual and security safeguards, consistent with POPIA's requirements for cross-border transfers.

8

Data retention

We retain Business Account and guest data for as long as the account is active, and for a reasonable period afterward to meet legal, accounting, or dispute-resolution requirements. A tenant can request deletion of their Business Account at any time (see Section 13 of our Terms & Conditions); a guest can request deletion of their own account by contacting the tenant whose captive portal they used, or by contacting us directly if that isn't possible.

9

Security

Each tenant's data is logically isolated from every other tenant, passwords are stored hashed rather than in plain text, and actions taken through router management and remote CLI tools are recorded in an audit log — the same measures described in Section 9 of our Terms & Conditions. ISN Free WiFi staff never ask you for your dashboard password; support access to a Business Account uses a separate, audited internal mechanism tied to the staff member's own identity, never yours.

10

Your rights

Subject to POPIA, you may request access to, correction of, or deletion of your personal information, and may object to or restrict certain processing. Business Account holders can update most information directly from their dashboard. To exercise a right we can't self-serve in the dashboard, contact us using the details in Section 12.

11

Children's privacy

The Platform is intended for business use and for guests old enough to independently agree to a venue's own WiFi terms. We do not knowingly collect personal information from young children beyond what a guest voluntarily provides to connect to WiFi, and we do not knowingly target the Platform at children.

12

Contact

Questions about this policy, or requests relating to your personal information, can be sent to info@isnfreewifi.co.za.

13

Changes to this policy

We may update this policy from time to time to reflect changes to the Platform or applicable law. Material changes will be communicated to Business Account holders by email or dashboard notice ahead of taking effect. Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy.