Acceptable Use Policy
GuestPass Cloud, a Simple Technologies product. Version 1.0 — last updated 2026-09-22.
Draft pending legal review. These documents were written in-house and have not been reviewed by an attorney; Simple Technologies should have counsel review them before signing a paying customer.
This policy forms part of the Terms of Service and applies to everyone who uses GuestPass Cloud: account holders, their staff, and anyone they invite.
1. The network access you grant is yours
This is the most important clause in this policy, so it goes first.
GuestPass issues credentials and authorizes devices on your network. We do not operate your network, choose who may use it, see the traffic on it, or filter it. When you let somebody onto a network through GuestPass, you are the one letting them on.
You are responsible for:
- having the legal right to provide internet access at that property, and for meeting any licensing, telecoms or lawful-intercept obligations that apply to you where you operate;
- what you require of guests before you let them on, and for enforcing it;
- the consequences of the access you grant, including anything a guest does with it;
- any filtering, content control, logging or data retention your own obligations require. If you need Cisco Umbrella or an equivalent, that is your procurement decision, not ours.
2. The captive portal is your notice to your guests
If you run a guest portal, everything on it — the welcome text, your terms, the privacy notice, and every question you ask — is your content and your responsibility. We render what you configure. We do not review it.
So:
- Show guests real terms. If you require guests to accept terms of use, make sure the terms you show are yours, are accurate, and say what you actually do with what you collect.
- Ask for the least you need. The portal lets you write up to twelve free-text questions and to ask for name, email address and mobile number. Every field you add is personal data you have decided to collect and must justify.
- Do not use a WiFi sign-in sheet to collect sensitive information. Health information, government identifiers, financial account details, precise location, biometric data and data about children's characteristics do not belong in a captive portal question. The product is not designed for them.
- Get consent where the law requires it, including for marketing. A guest typing an email address to get online has not agreed to a newsletter unless you asked and they said yes.
- Honour what you promised. If your portal says you delete records after a period, you must actually have them deleted — GuestPass does not delete them automatically today. Ask us and we will.
3. Prohibited use
You may not use GuestPass Cloud, or let anyone else use it, to:
- break the law, or help anyone else to;
- connect or manage equipment you are not authorized to manage, or use credentials you were not given;
- gain unauthorized access to any system, account, network or data, including ours, another tenant's, or a guest's;
- probe, scan, load-test or attempt to circumvent the security or the tenant isolation of the platform, except under a written test agreement with us;
- send unsolicited bulk or commercial messages, or use addresses or phone numbers collected through a portal for anything the guest was not told about;
- collect data covertly — running a portal that does not disclose what it captures, or capturing guest information under a false pretext;
- misrepresent who is operating the network, or impersonate any person or organization;
- distribute malware, or host content on a portal or block page that is unlawful, that infringes someone's rights, or that sexually exploits children;
- resell, sublicense or provide the service to a third party except as a managed service provider administering companies in your own organization under the Terms;
- interfere with the service for other customers, including by automated traffic that is disproportionate to normal use, by abusing the API beyond its published rate limits, or by using a third-party API through us in a way that risks our access to it;
- use the platform Stripe integration to route money that is not a GuestPass subscription, or use guest self-pay to take payments for anything other than network access at that property.
4. Fair use of the API and the bridge
The API has documented rate limits and idempotency rules. Respect them. Do not attempt to extract another tenant's data through any endpoint. Keep bridge tokens and API keys secret, rotate them when someone with access to them leaves, and revoke them at once if they leak.
5. Security research
We welcome it, and we would rather hear from you than read about it. Report what you find as described on the Security page. Test against your own tenant and your own data. Do not access another customer's data, degrade the service, or disclose an issue publicly before we have had a reasonable chance to fix it. We will not pursue good-faith research that follows those rules.
6. Enforcement
If we believe this policy is being breached we may investigate, ask you to fix it, restrict a feature, suspend an account, company or site, or terminate under the Terms. We act proportionately and we tell you what we have done and why, unless the law stops us. Serious threats to the platform or to another customer may be stopped first and explained after.
7. Reporting abuse
Email support@simple-technologies.com with what you saw, where, and when.
Questions: support@simple-technologies.com