Sub-processors
GuestPass Cloud, a Simple Technologies product. Version 1.0 — last updated 2026-09-22.
Draft pending legal review. These documents were written in-house and have not been reviewed by an attorney; Simple Technologies should have counsel review them before signing a paying customer.
These are the third parties that may process personal data on our behalf in order to run GuestPass Cloud. Each entry says what it actually receives. Several are optional: they receive nothing unless the feature is turned on.
This list is a separate document so it can be kept current without reopening the Terms, the Privacy Policy or the Data Processing Addendum, each of which refers to it.
Always in use
| Sub-processor | What it does | What it receives |
|---|---|---|
| Cloudflare, Inc. (United States) | Hosting and the whole platform: Workers compute, D1 database, R2 object storage for uploaded logos and brand assets, DNS, TLS termination and CDN | Everything stored or processed by the service, and the IP address of every request |
| Cloudflare Web Analytics (part of Cloudflare) | Page analytics on our own console and marketing pages. Cookieless; no fingerprinting. Not present on the guest portal or block pages | Page views from our own pages |
Used for specific features
| Sub-processor | When it applies | What it receives |
|---|---|---|
| Stripe, Inc. (United States) — platform billing | When you subscribe to a paid GuestPass plan | Your billing contact details and payment method, handled by Stripe. We store the Stripe customer and subscription identifiers, not card data |
| Stripe, Inc. — guest self-pay | When a property enables guests to buy WiFi by card | The guest's card details, entered on Stripe's hosted checkout page, plus the amount and a description. This runs on the property's own Stripe account, not ours. The money and the customer relationship are theirs; we never take custody of the funds and never see the card number |
| Resend, Inc. (United States) | Transactional email: sign-in links, invitations, verification, password resets, voucher and receipt delivery, notifications. Inactive until the sending key is configured | The recipient's email address and the content of the message |
| Google LLC (United States) — sign-in | When a user chooses "Sign in with Google" | Google authenticates the user and returns their name, email address and profile picture to us. We request only the openid, email and profile scopes |
| Google LLC — Workspace directory | Simple Technologies' own staff domain only, so that a suspended or deleted ST account loses GuestPass access automatically. Read-only on user status | ST staff email addresses. No customer directory is read |
| Google LLC — Google Fonts | The signed-in console and the public marketing pages load one display font. The guest portal and block pages do not load it, deliberately | The IP address and user-agent of a browser loading those pages |
| Ubiquiti Inc. (United States) — UniFi cloud API | Only when a site is connected over Ubiquiti's cloud service (api.ui.com) instead of an on-site bridge | Voucher and authorization instructions relayed to your own console, including guest device MAC addresses. Sites connected through the on-site bridge do not use this path |
| Cisco Systems, Inc. — Duo | When an organization enables Duo MFA or Duo single sign-on | The signing-in user's username or email address, and the authentication result |
| Cisco Systems, Inc. — Umbrella | When a customer points an Umbrella block policy at our block pages. Uses the customer's own Umbrella organization and API credentials | The public IP address of the blocked visitor, to look up what was blocked |
| Your own identity provider, if you configure OIDC single sign-on instead of Duo | When SSO is enabled for your organization or company | Authentication requests; it returns identity claims to us. This is a provider you choose and contract with |
Not sub-processors
Listed here because they appear in the product and it would be reasonable to wonder.
- The on-site bridge is our software running on your hardware, on your premises, under your control. It is not a third party.
- Your UniFi controller is your equipment. Guest device data sent to it is going to you.
- Public DNS resolvers (Cloudflare and Google DNS-over-HTTPS) are queried to verify domain ownership records. Only the domain name being verified is sent — no personal data.
- Odoo appears only as an outbound link to a demo-booking page. Clicking it takes you to Odoo's own site under Odoo's own terms; we send them nothing.
Changes to this list
We give at least 30 days' notice before adding or replacing a sub-processor that handles customer personal data, by email to account owners. The version and date at the top of this page record when it last changed. Objections and questions: support@simple-technologies.com.
Questions: support@simple-technologies.com