1. Data We Collect
HotspotWiFi collects the following categories of data:
- Account Data: Name, email address, organization name, and password (hashed) provided during registration.
- Gateway Data: Router/gateway configuration details including IP addresses, API credentials (encrypted at rest), and site information.
- Guest/Session Data: MAC addresses, IP addresses, session timestamps, data usage, authentication method used, and device information collected through captive portals.
- Analytics Data: Aggregated visitor counts, peak hours, dwell time, and return rates derived from session data.
- Billing Data: Subscription plan, payment history, and invoice records. Payment card details are processed by Stripe and never stored on our servers.
- Usage Logs: API access logs, audit logs, and error logs for security and debugging purposes.
2. How We Use Data
- To provide, maintain, and improve the Service.
- To authenticate users and manage captive portal sessions.
- To generate analytics, reports, and dashboards for your organization.
- To send transactional emails (OTPs, password resets, invoices) and optional marketing communications.
- To detect and prevent security threats, fraud, and unauthorized access.
- To comply with legal obligations and enforce our Terms of Service.
3. Data Sharing
We do not sell your personal data. We may share data with third-party service providers who assist in operating the Service (e.g., Stripe for payments, AWS for hosting, SendGrid/OTPless for communications). These providers are bound by contractual obligations to protect your data. We may also disclose data if required by law or to protect our legal rights.
4. Data Retention
- Account Data: Retained for the duration of your account plus 30 days after deletion.
- Session Data: Retained for 12 months, then automatically purged or anonymized.
- Audit Logs: Retained for 24 months for security and compliance purposes.
- Analytics Data: Aggregated analytics are retained indefinitely; raw data follows session retention policy.
- Billing Records: Retained for 7 years as required by Indian tax regulations.
5. Data Security
We implement industry-standard security measures including: encryption at rest and in transit (TLS 1.2+), hashed passwords (bcrypt), encrypted gateway credentials, role-based access control, and regular security audits. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your data for specific purposes.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@hotspotwifi.com.
7. Cookies
The Service uses essential cookies for authentication (access tokens, refresh tokens) and session management. We do not use third-party tracking cookies. Analytics within the platform are based on server-side session data, not browser cookies.
8. Contact
For privacy-related inquiries or concerns, please contact our Data Protection Officer at:
Email: privacy@hotspotwifi.com
NexApps Technologies
India