Privacy Policy

GuestPass Cloud, a Simple Technologies product. Version 1.0 — last updated 2026-09-22.

Draft pending legal review. These documents were written in-house and have not been reviewed by an attorney; Simple Technologies should have counsel review them before signing a paying customer.

Two very different groups of people

This policy covers two groups, and the difference matters because our role is different for each.

Staff of our customers — the people who sign in to the GuestPass console to issue vouchers, configure sites and run reports. For their account data we are the controller: we decide what to collect in order to run the service, and this policy is our notice to them.

Guests on our customers' networks — the people who join WiFi at a property and see a captive portal, buy access, or are handed a voucher code. For their data we are a processor. The property (or the managed service provider acting for it) decides what to ask a guest and why. We store and process it on their instruction. A guest's first port of call for access or deletion is the property whose WiFi they used; we will help that property respond.

Simple Technologies, Bastrop, Texas, United States. Contact: support@simple-technologies.com.

What we collect about tenant staff

DataWhyHow long
Name and email addressTo identify the account, address you, and send service emailFor the life of the account, then 30 days after termination
Password hash and salt (PBKDF2-SHA256; the password itself is never stored or recoverable)To sign you inLife of the account
Passkey records: credential id, public key, signature counter, device labelPasswordless sign-inUntil you remove the passkey
Authenticator (TOTP) secret, if you enable app-based 2FASecond factor at sign-inUntil you turn 2FA off
Emailed sign-in links — stored as a hash of the token, plus the requesting IP addressSingle-use sign-in; the hash means a leak of this table cannot be turned back into working linksUntil used or expired
Session records: session id, user, expiry, and which method signed you inTo keep you signed inUntil expiry, which the organization sets (default 30 days)
Email verification and password-reset tokensAccount recoveryUntil used or expired
Audit log: who did what, when, to which organization, company or site, and from which IP addressSecurity, support and your own accountability to your customersCurrently kept indefinitely — see "How long we keep things"
Support reports you submit in-app: your email, your message, the page you were on, and your browser's user-agent stringTo reproduce and fix what you reportedUntil resolved and reviewed
Error log: route, method, error message and stack traceTo find and fix faultsCurrently kept indefinitely
Billing records: plan, subscription status, Stripe customer id and billing eventsTo bill youAs long as tax and accounting law requires

If you sign in with Google, Google tells us your name, email address and profile picture. Nothing else. If your organization signs in through its own identity provider, we receive the claims that provider sends.

Separately, Simple Technologies connects its own Google Workspace domain to the service so that when an ST staff account is suspended or deleted, that person's GuestPass access and network credentials are withdrawn automatically. That connection reads ST staff account status only. It does not read customer directories.

What we collect about network guests

What a guest is asked depends entirely on what the property configured. Everything below is optional except the technical fields the network itself supplies.

DataWhyHow long
Device MAC address, access-point MAC address, network name (SSID)To authorize that specific device onto that network. The MAC is what the controller needs; without it nobody gets onlineWith the sign-in record
Sign-in method, package, duration granted, and whether the attempt succeeded or failedThe property's record of who was on the network and how, and the basis for support and reportingWith the sign-in record
Guest name, if the property asks for itThe property's own record-keepingWith the sign-in record
A reference the property chooses — lot, site, room, unit, slip, table or booking numberTo match a guest to a bookingWith the sign-in record
Answers to custom questions the property writes — up to twelve free-text questions, plus optional name, email address and mobile numberWhatever the property decided. We do not see or vet these questionsWith the sign-in record
Guest IP address and browser user-agent stringTroubleshooting and abuse investigationWith the sign-in record
Voucher records: code, and any guest name, location and note entered by staff when the voucher was createdTo issue and redeem accessWith the voucher
Guest payment records: amount, currency, status, the Stripe session and payment-intent identifiers, device MAC, network name and IP addressTo take the payment, get the guest online, and recover the case where a guest pays and the tab closes before they are authorizedWith the payment record

Card details never reach GuestPass. Guests pay on a Stripe-hosted checkout page. We store the identifiers Stripe gives back, not card numbers.

A property can ask a free-text question, and a free-text question can collect anything. If you run a portal, ask for the least you need. If you ask for something sensitive, that is your decision and your legal exposure — see the Acceptable Use Policy.

Block pages

If a customer points a Cisco Umbrella policy at our block page, we show the visitor a page and ask that customer's own Umbrella organization what that public IP address was just blocked for. The visitor's public IP address is sent to Cisco for that lookup. Behind NAT this identifies a site, not a person. We record block-page hits and any access requests submitted on them.

What we do not do

  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We do not use guest data or customer data to build advertising profiles.
  • We do not use customer or guest data to train machine-learning models.
  • We do not run third-party advertising or analytics trackers on the guest portal or the block pages. Those pages load no external fonts, scripts or beacons.

Cookies and similar technology

The console sets one session cookie, HttpOnly, Secure, SameSite=Lax, so that you stay signed in. Short-lived cookies are used during sign-in and identity-provider flows. There are no advertising cookies.

The signed-in console and the public marketing pages load a display font from Google Fonts, which means Google sees the IP address of a browser loading those pages. The guest portal and the block pages deliberately do not.

Cloudflare Web Analytics is enabled on our own pages. It is cookieless and does not fingerprint visitors.

Who we share data with

Our sub-processors are listed, with what each one receives and why, on the sub-processor page. That list is maintained separately so it can be kept current.

We also disclose data where the law requires it, to enforce our Terms, or to a successor in a merger or sale — in which case this policy continues to apply until it is replaced and you are told.

Where data is processed

Data is stored in Cloudflare's D1 and R2 in Cloudflare's network and processed in Cloudflare Workers, which execute at the edge location nearest the request. We are a United States company. Our sub-processors operate internationally. See the Data Processing Addendum for the transfer mechanisms.

How long we keep things

Be aware of this: GuestPass does not currently delete operational records automatically. There is no scheduled purge of portal sign-in records, voucher history, guest payment records, audit logs or error logs. They are kept until the tenant deletes them, or until the account is deleted, at which point they go with it.

We are saying this plainly rather than publishing a retention schedule we do not enforce. If your own retention policy requires guest records to be removed on a schedule, tell us and we will delete them for you on request, and say so in writing when it is done. Automatic, configurable retention is on the roadmap and is not built.

Account data is deleted within 30 days of account termination. Backups are covered below.

Backups

We rely on Cloudflare D1's point-in-time restore ("Time Travel"), which allows the database to be restored to any moment within the preceding 30 days. A deletion therefore persists in a restorable snapshot for up to 30 days before it is gone everywhere. We do not currently keep a separate backup outside Cloudflare.

Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy in a portable format, and to complain to a supervisory authority. Residents of some United States states have similar rights, including the right not to be discriminated against for exercising them.

  • Tenant staff: write to support@simple-technologies.com from the address on the account.
  • Guests: contact the property whose WiFi you used. They control that data. If you write to us we will route the request to them and help them answer it, but we will not disclose or delete a property's records on the say-so of someone we cannot verify.

We will respond within the time the applicable law allows.

Children

GuestPass is sold to businesses and is not directed at children. A guest portal at a family property may well be used by a child's device; a property that knowingly collects information from children is responsible for handling that lawfully. Configure your questions accordingly.

Security

How the platform is built and protected is described on the Security page.

Changes

We will update the version and date at the top of this page when this policy changes, and notify account owners by email of material changes.

Contact

Simple Technologies, Bastrop, Texas, United States. support@simple-technologies.com.

Version 1.0 · Last updated 2026-09-22
Questions: support@simple-technologies.com