Passer au contenu principal
29B
data points captured on Purple
±3-7%
corrected accuracy vs camera
80,000+
venues running Purple
< 60s
dashboard freshness

TL;DR / Key Takeaways

  • WiFi analytics has two modes: presence (anonymous, sensor-based) and engagement (identified, captive-portal-based). Most venues need both, with each answering a different question.
  • MAC randomisation changed the discipline. Platforms that adapted use statistical correction and consented identification to maintain ±3-7% accuracy versus camera ground truth. Platforms that ignored the change have lost accuracy.
  • The headline metrics are footfall, dwell time, return-visit rate, zone transitions, new-vs-returning split, and capture rate. The honest reading is the corrected figure with the confidence interval, not the raw probe count.
  • GDPR-compliant analytics is achievable with hashed MAC and rotation for presence, explicit consent at the portal for engagement, a DPIA, and clear venue signage. the ICO and the EU's CNIL have both issued positive guidance on the model.
  • The strongest sector applications are retail, shopping malls, airports, stadiums, museums, and corporate offices. Each uses the same data model with a different framing layer on top.

Most venues are sitting on a sensor network they have already paid for: the access points they put in for guest WiFi. The same hardware, the same RF events, the same association logs, used differently, produce a usable account of who walked in, how long they stayed, where they went, and whether they came back.

That is WiFi analytics. It is not a perfect substitute for a turnstile counter at the door or a computer-vision camera on the till. It is a much cheaper substitute that covers the whole venue rather than one chokepoint, and that surfaces movement and dwell data the cameras cannot produce.

This guide is the operating reference for venue and marketing teams considering or running WiFi analytics. It covers the two modes (presence and engagement), the metrics that matter, what MAC randomisation broke and how the discipline adapted, the comparison against alternative people-counting technologies, the UK GDPR shape, and the sector applications that work.

The two modes: presence and engagement

Almost every confused conversation about WiFi analytics is the result of mixing these two up. They use different data, answer different questions, and run under different legal bases.

Presence analytics

Anonymous, sensor-based, derived from probe requests and association logs. Counts unique devices in a zone over a time window. Hashed MAC with rotation as the technical privacy control.

Answers: how many people came in, how long they stayed, how they moved between zones, and whether overall volume is up or down.

Lawful basis: legitimate interest with DPIA, signage, opt-out.

Engagement analytics

Identified, captive-portal-based, derived from sign-ins and ongoing sessions. Ties visits to a contact record. The substrate for segmentation, journeys, and lifecycle marketing.

Answers: who came in, how often they come, what time of day, which sites of a multi-site brand, and the marketing-actionable cohort behaviour.

Lawful basis: explicit consent at the portal sign-in.

Most venues need both. Presence gives the headline footfall and dwell numbers, comparable like-for-like across sites. Engagement gives the identified cohort that marketing can actually run journeys against. The two are joined at the captive portal: a visitor who signs in moves from the presence dataset to the engagement dataset for that visit.

MAC randomisation and why it changed the discipline

For most of the 2010s, WiFi analytics rested on a quietly false assumption: that a device’s MAC address was stable across visits. iOS 14 (2020) broke that for iPhones. Android 10 broke it for Android. Windows 11 and macOS Sonoma extended the change to laptops. By 2026, the great majority of consumer devices present a randomised, rotating MAC during probe requests before association.

Naive counting that treated each unique MAC as a unique device started over-counting. Return-visit rates collapsed; new-visitor share rocketed; cohort retention curves stopped making sense.

The discipline adapted in two ways. First, statistical correction: probabilistic models that account for the expected randomisation rate and rotation cadence per device class, calibrated against camera ground truth at known sites. Second, identification through the captive portal: visitors who sign in present a stable identity that survives randomisation entirely.

The combined accuracy of a corrected presence stream plus an opted-in engagement layer in 2026 is comparable to where 2018 footfall analytics sat, with a stronger privacy story. The vendors that did the correction work have maintained accuracy; the vendors that did not have lost it. Worth checking explicitly during evaluation.

Free tool

Want to see how MAC rotation affects your metrics? Use our free MAC Randomization Simulator (from our free WiFi tools library) to model raw device counts, ground truth visitor counts, and the reconciled counts.

The randomisation timeline

  • 2014: iOS 8 introduces randomised probes (off by default in practice).
  • 2020: iOS 14 randomises per-SSID by default.
  • 2020: Android 10+ randomises per-SSID by default.
  • 2022: Windows 11 expands to all WLAN probes.
  • 2023: macOS Sonoma matches iOS behaviour on laptops.
  • 2026: randomisation is the dominant assumption; static MAC is the edge case.

The six metrics worth reporting

WiFi analytics platforms can produce a hundred derived metrics. Six of them carry almost all the decision weight.

Footfall

Unique visitors entering a defined zone in a time window. The headline KPI for retail and venue operators.

Reported daily, weekly, monthly. Comparable like-for-like.

Dwell time

Median, p25/p75, p95 time-in-zone per visit. Distinguishes browsers from buyers.

Median by sector; trend is what matters most.

Return-visit rate

Share of visitors in a window who also visited in the previous N days. Loyalty signal.

18-32% in retail; 45-60% in transit and corporate.

Zone transitions

Origin-destination flows between defined zones. The basis for journey analytics and layout testing.

Used in malls, airports, museums, large retail.

New vs returning

Acquisition vs retention split. Useful for marketing attribution and for honest reporting of footfall lift.

70/30 to 50/50 typical, depending on category.

Capture rate

Share of detected presence converting to a captive-portal sign-in. Bridge between presence and engagement.

15-40% depending on portal design and incentive.

WiFi vs cameras vs door sensors

WiFi analytics is not the only people-counting technology. The right answer for most venues uses two of them together: a high-accuracy chokepoint counter at the front door and WiFi across the whole venue for dwell and journey.

MethodAccuracyCoverageCostPrivacyJourneys
WiFi presence±3-7%Whole venueUses existing APsHashed MAC, opt-out, signageNative
Computer vision±1-3% at doorwayField of view onlyPer-camera + computeStrongest concern in EULimited
Door sensor (IR / 3D)±2-4%Doorway onlyPer-doorLowNone

Compliance: UK GDPR, CNIL, CCPA, ISO 27001

WiFi analytics that respects privacy is a solved problem. The model below is what the CNIL has explicitly approved and what the ICO has consistently allowed. Pizza Express, AGS Airports, and the University of Sheffield all run venue analytics on Purple.

UK GDPR

Presence analytics: legitimate interest with DPIA. Engagement analytics: explicit consent at the portal. Hashed MAC with rotation is the accepted technical control for presence.

Reference ›

CNIL guidance

The French regulator has issued specific guidance on WiFi analytics. The model that satisfies the CNIL is the one the rest of the EU follows.

Reference ›

CCPA / CPRA

California requires a privacy notice and opt-out mechanism. WiFi analytics that aggregates and anonymises sits within the existing privacy-policy framework.

Reference ›

ISO 27001

Annex A.5.34 (privacy and protection of PII) and A.5.12 (classification of information) apply. The platform should produce a DPIA template and a retention-schedule export.

Reference ›

The four operational requirements: a completed DPIA, hashed MAC with rotation for the presence stream, explicit consent at the captive portal for the engagement stream, and visible venue signage explaining what is being measured and how to opt out. Purple ships templates and venue-signage assets for each. The compliance posture is part of the product, not an afterthought.

How to evaluate a WiFi analytics platform

An eight-item checklist for procurement, operations, and the data team.

✓Statistical correction for MAC randomisation

A platform that does not correct for randomised MACs is not measuring footfall in 2026. Ask for the methodology and the validation against camera ground truth.

✓Both presence and engagement modes

You need the anonymous, whole-venue mode and the consented, identified mode. Platforms that only do one of them aren't enough.

✓Zone configuration without recabling

Zone definitions should be edited in the dashboard, not by re-pulling cable. Coverage areas, anchor stores, departments.

✓Like-for-like comparable framing

Multi-site operators need normalised KPIs across sites of different size and traffic profile. Raw numbers do not work.

✓Live BI export

Hourly batch to S3 / BigQuery / Snowflake. Native Looker / Tableau connectors. The data should land where your analysts already work.

✓DPIA template and signage assets

The platform should hand you the privacy paperwork and the venue signage you need. Building it from scratch slows deployment by weeks.

✓Hardware independence

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. The analytics layer should outlive the AP refresh.

✓Auditable retention controls

Configurable retention by data class. Identifiable data on the shortest defensible schedule. Aggregate data on whatever your reporting needs.

Frequently asked questions

What is WiFi analytics?

+

WiFi analytics is the practice of using a venue's existing wireless network as a sensor for footfall, dwell time, and customer movement. Two modes: presence analytics (anonymous, sensor-based, MAC-randomisation-affected) and engagement analytics (identified, captive-portal-based, opted-in). Most operators run both, with each answering a different question.

How accurate is WiFi footfall counting?

+

Modern WiFi analytics with statistical correction for MAC randomisation runs at ±3-7% versus camera-based ground truth in retail environments. The accuracy is good enough for like-for-like comparison, trend tracking, and benchmarking; it is not good enough for cash-register reconciliation. The number you report should be the corrected figure with the confidence interval, not the raw probe count.

Has MAC randomisation broken WiFi analytics?

+

It changed it. iOS 14+, Android 10+, Windows 11, and macOS Sonoma randomise the MAC address presented in probe requests before association. Naive counting that treated each unique MAC as a unique device is now wrong. Statistical correction models, plus opted-in captive-portal identification for engagement analytics, are how modern platforms maintain accuracy. The platforms that ignored the change have lost accuracy; the ones that adapted have not.

What is the difference between presence and engagement analytics?

+

Presence analytics counts devices that are physically present but not authenticated; it measures footfall and dwell anonymously and is GDPR-defensible under legitimate interest with a DPIA. Engagement analytics measures behaviour for visitors who signed in to the captive portal and gave consent; it ties visits to identity, supports segmentation, and runs under explicit consent. Most venues need both.

Is WiFi analytics GDPR-compliant?

+

Yes, with proper design. For presence analytics, hash the MAC client-side with rotation, document a legitimate-interest assessment, complete a DPIA, and post visible signage. For engagement analytics, run on explicit consent at the captive portal. the ICO and the EU's CNIL have both issued positive guidance on WiFi analytics where these conditions are met. We have a full compliance playbook linked from this pillar.

Is WiFi or camera better for people counting?

+

Different jobs. Cameras with computer vision are more accurate at single-doorway counting (95%+ vs ground truth) but cost more, see only their field of view, and raise stronger privacy concerns. WiFi covers the whole venue cheaply, supports dwell and zone-to-zone analysis natively, and identifies returning visitors statistically. Most large-format retail and venue operators run both: cameras at the door for accuracy, WiFi inside for coverage.

What sort of dwell time should I expect?

+

Median dwell across Purple's dataset: 9-14 minutes in QSR, 35-55 minutes in casual dining, 18-32 minutes in apparel retail, 55-95 minutes in shopping malls, 75-130 minutes in airports air-side. Useful as benchmarks; the more useful measure is your own dwell trend month-on-month against same-store comparable.

Can WiFi analytics track customer journeys?

+

Within a venue, yes. Zone-to-zone transitions, time-in-zone, common paths, and drop-off points are all measurable. Across venues of the same brand, it depends on whether the visitor authenticated (engagement) or not (presence); presence-only journeys across sites are very weak signal once MAC randomisation is accounted for.

Does WiFi analytics work for office occupancy?

+

Yes. The same infrastructure that authenticates staff devices reports utilisation by floor, by day-of-week, and by hour-of-day. Integration with workplace booking systems (Robin, Envoy, Microsoft Places) is a common pattern. Office occupancy is one of the higher-confidence use cases because the population is largely authenticated and the device count is more stable than retail footfall.

How does this integrate with my existing BI stack?

+

Direct API access, hourly batch export to S3 / BigQuery / Snowflake, native Looker and Tableau connectors, and webhook event streaming. The data model is documented and stable. Most large operators land WiFi data into the same warehouse as POS and loyalty, then build reporting in their own tool of choice.

Speak to an expert

Tell us what you want to measure and we'll show you the dashboards on your own venue data.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of measuring footfall, dwell, and visitor behaviour from WiFi. All 33 guides in this pillar are listed below.

Comptage de personnes : WiFi contre caméra contre capteur de porte

Décidez quelle technologie de comptage de personnes répond à chacune de vos questions : des capteurs de porte pour des totaux d'entrées précis, des caméras zénithales pour des comptages en direct dans une zone spécifique, et le WiFi pour le temps de séjour et les visites répétées à l'échelle d'un site. Vous pouvez ensuite comparer la précision, les coûts et le travail sur la confidentialité, tester par rapport à un comptage manuel, et choisir une seule méthode ou une combinaison pour votre parc.

Read guide →

Analyses de présence vs analyses d'engagement

Décidez si votre parc immobilier a besoin d'analyses de présence, d'analyses d'engagement ou des deux, en fonction de la question à laquelle vous devez répondre ce trimestre. Vous découvrirez ce que chaque niveau mesure, comment la randomisation des adresses MAC limite les données de présence, quelle base légale du GDPR s'applique à chacune, et comment séquencer le déploiement sur plusieurs sites sur les points d'accès que vous possédez déjà.

Read guide →

Déploiement WiFi 7 sur site : Préparation de l'infrastructure pour les stades et l'hôtellerie

Ce guide opérationnel aide les équipes informatiques à valider l'infrastructure WiFi 7 avant de commander des points d'accès. Il couvre le PoE, les commutateurs multi-gig, le câblage, la préparation des contrôleurs et des licences, la validation des analyses ainsi qu'un modèle de planification transparent de 200 points d'accès pour les stades et l'hôtellerie.

Read guide →

Mesurer le ROI commercial du WiFi invité et de la Location Analytics

Cette référence technique montre aux équipes informatiques et de gestion de site comment mesurer le ROI du WiFi invité grâce à une chaîne de preuves justifiable, de l'état du réseau et des données consenties jusqu'aux résultats opérationnels ou commerciaux validés. Elle sépare les preuves mesurables des hypothèses, associe Purple Connect, Capture et Engage au bon niveau de mesure, et propose des scénarios de planification pour les hôtels, les parcs de commerces et les sites événementiels.

Read guide →

Privacy by Design : Anonymiser les données WiFi pour la conformité GDPR

Ce guide d'autorité détaille l'architecture technique et les stratégies de mise en œuvre pour anonymiser les données WiFi afin de garantir la conformité GDPR. Il fournit aux responsables informatiques et aux architectes réseau des cadres d'action pour concilier des analyses de fréquentation précises et des exigences strictes en matière de confidentialité des données.

Read guide →

Heatmapping vs Presence Analytics : Différences techniques

Ce guide technique de référence détaille les différences architecturales et opérationnelles critiques entre le WiFi heatmapping et le presence analytics pour les exploitants de sites d'entreprise. Il fournit aux responsables informatiques, architectes réseau et directeurs des opérations des cadres de déploiement exploitables, des scénarios d'implémentation réels et des meilleures pratiques neutres vis-à-vis des fournisseurs afin de maximiser le retour sur investissement de leur infrastructure sans fil existante.

Read guide →

Comment calculer la durée de séjour à l'aide de l'analyse de localisation WiFi

Ce guide fournit une référence technique complète pour calculer la durée de séjour WiFi à l'aide de l'analyse de localisation WiFi, couvrant l'ensemble de l'architecture, de la capture des requêtes de sonde 802.11 à l'analyse des zones géofencées, en passant par la trilatération basée sur le RSSI. Il est conçu pour les responsables informatiques, les architectes réseau et les directeurs d'exploitation de sites qui doivent déployer une intelligence de localisation précise et évolutive dans les secteurs du commerce de détail, de l'hôtellerie, de la santé et du secteur public. Les lecteurs y trouveront des conseils de mise en œuvre concrets, des études de cas réels et un cadre clair pour traduire les données spatiales brutes en résultats commerciaux mesurables.

Read guide →

Qu'est-ce qu'une Probe Request ? Comprendre comment les appareils découvrent les réseaux

Ce guide de référence technique propose une analyse approfondie des probe requests IEEE 802.11, du balayage actif par rapport au balayage passif, et de l'impact de la randomisation MAC sur les analyses de fréquentation. Il fournit des stratégies de mise en œuvre concrètes pour les architectes réseau afin d'optimiser les déploiements à haute densité, d'atténuer les tempêtes de requêtes (probe storms) et de garantir une collecte de données précise et conforme au GDPR en utilisant des couches d'identité authentifiées.

Read guide →

Comment suivre les appareils uniques sur les réseaux sans fil d'entreprise

Ce guide fournit un aperçu technique complet du suivi des appareils uniques sur les réseaux sans fil d'entreprise. Il aborde les défis modernes tels que l'activation de l'adresse MAC aléatoire et détaille les stratégies de mise en œuvre pour les exploitants de sites et les équipes informatiques afin de maintenir des analyses précises et une identification fiable des utilisateurs.

Read guide →

Comment la randomisation des adresses MAC affecte les analyses du WiFi invité

Ce guide propose une analyse technique approfondie de l'impact de la randomisation des adresses MAC sur les analyses du WiFi invité. Il offre des stratégies pratiques pour les responsables informatiques et les architectes réseau afin de restaurer la visibilité, de garantir des métriques précises et de maintenir la conformité sur les déploiements à grande échelle. Couvrant les mécanismes de la randomisation par réseau et éphémère, l'architecture de résolution d'identité et les scénarios de déploiement réels, il s'agit de la référence définitive pour toute organisation s'appuyant sur des données spatiales dérivées du WiFi.

Read guide →

Systèmes de positionnement WiFi intérieur : fonctionnement et déploiement

Ce guide complet détaille l'architecture technique, les stratégies de déploiement et la valeur commerciale des systèmes de positionnement intérieur basés sur le WiFi. Il fournit aux architectes réseau et aux directeurs informatiques des conseils pratiques sur le positionnement des AP, l'étalonnage RF et la gestion de la randomisation des adresses MAC pour obtenir des analyses spatiales précises.

Read guide →

Comment les centres commerciaux utilisent WiFi Analytics pour attirer et fidéliser les détaillants

Ce guide de référence technique et d'autorité explique comment les équipes informatiques et les gestionnaires immobiliers des centres commerciaux déploient WiFi analytics pour capturer les données de fréquentation, mesurer le temps de séjour par zone et constituer la base de preuves empiriques nécessaire pour négocier les baux, fidéliser les détaillants premium et attirer de nouveaux locataires. Il couvre l'ensemble de la pile technique, du déploiement des points d'accès et de la capture des données de la couche MAC jusqu'aux tableaux de bord d'analyse conformes au GDPR, avec des exemples concrets et des cadres de décision pour les professionnels de l'informatique prêts à une mise en œuvre dès ce trimestre.

Read guide →

Every guide in this pillar

Analytics (15)