Skip to main content
80,000+
venues running Purple
440M
sign-ins processed last year
350M
unique visitors captured
99.9%
platform uptime SLA

TL;DR / Key Takeaways

  • Guest WiFi is the visitor-facing wireless surface of a venue. Distinct from staff WiFi (managed devices, strong authentication) and multi-tenant WiFi (long-term residents with device discovery).
  • Four delivery models: software overlay on existing access points, fully managed, MSP-bundled, ISP-bundled. The software-overlay model is the most common in mid-market and enterprise.
  • The captive portal is the join surface, the marketing capture, and the analytics anchor. The five companion pillar guides cover each layer in depth.
  • Compliance posture is part of the platform, not an afterthought. GDPR consent, PCI DSS network segmentation, lawful-intercept logging, and WCAG 2.2 accessibility all ship as defaults.
  • Choosing a provider is six tests: hardware compatibility, CRM integration, analytics depth, compliance posture, support SLA, transparent pricing. The 80,000-venue platform is a different question to the single-venue one.

Guest WiFi sits at an awkward crossroads. IT owns the connectivity, marketing owns the capture, operations owns the experience, finance owns the procurement, and the visitor just wants to get online - the same simple goal behind World WiFi Day, the global celebration of connectivity for everyone. Most platforms in the category were designed to address one of those buyers and tolerated the rest. The result is a procurement conversation that often misfires.

This guide is the master reference. The five sibling pillar guides cover the layers in depth - captive portal mechanics, marketing programme design, analytics methodology, enterprise security, and multi-tenant residential. This page is the connecting tissue, the one a buying committee can read together to agree what they are actually procuring.

The structure: what guest WiFi is (and is not), the four delivery models, how it relates to the rest of the platform, the compliance shape that actually works, the choice criteria, and an honest set of FAQs for the procurement conversation.

What guest WiFi is - and what it is not

Three things in the same building, all called WiFi, all doing different jobs.

DimensionGuest WiFiStaff WiFiMulti-tenant WiFi
AudienceTransient visitorsKnown employees and contractorsLong-term residents
AuthenticationCaptive portal (email, social, SMS, click-through)802.1X, EAP-TLS, iPSK against IdPiPSK per resident, ongoing
Session lengthMinutes to hoursPersistent on managed devicesYears
Device discoveryIsolated by defaultPer-role segmentationPer-resident WiFi-bubble
Internal accessNeverYes, scoped by roleNo (private to resident)
Marketing capturePrimary purposeNot applicableNot applicable

Most venues need at least two of these in parallel. A typical retail estate runs guest WiFi for shoppers and staff WiFi for the back-of-house team on the same access points, segmented by SSID and VLAN. A residential building adds multi-tenant for residents and runs guest WiFi for delivery drivers and contractors. The architectural rule is one platform, multiple SSIDs, each with its own authentication model.

The four delivery models

How guest WiFi is bought, paid for, and operated. The right model depends on the existing AP estate, the in-house IT capability, and the marketing ambition.

Software overlay (BYO hardware)

Purple software runs on the access points you already own. The most common model in mid-market and enterprise. Per-site or per-AP subscription.

Best for: Existing AP estate. Multi-site brands. Predictable opex.

Fully managed

Purple-supplied access points plus software plus support, billed per site per month. Operational simplicity at the price of a longer commitment.

Best for: New builds. Single-site operators without IT.

MSP-bundled

Your IT services partner resells Purple inside a broader managed-IT contract. Day-to-day operations and support sit with the MSP.

Best for: Organisations already on a managed-IT contract.

ISP-bundled

A basic captive portal included with a broadband contract. Limited analytics, limited marketing, limited integrations. Usually the lowest cost and the lowest ceiling.

Best for: Single-site, low-traffic, no marketing programme.

Pricing models and ROI framing

Guest WiFi pricing splits into three honest models. Per-site subscription (Purple, most predictable), per-AP subscription (some competitors, scales with venue size), and per-sign-up or per-MAC pricing (legacy and usually punitive). The marketing programme that runs on top is a separate cost line, and a separate ROI conversation.

The honest ROI conversation is in the WiFi marketing pillar, where the three measurable numbers are cost per captured opted-in record (median £0.28 / $0.35 across Purple deployments), return-visit lift on segmented audiences (12-18% in retail and hospitality), and basket-size delta on triggered journeys. Avoid the trap of attributing every subsequent visit to the WiFi capture; run a hold-out test for the marginal effect.

The paid-WiFi calculator models the revenue case for venues running paid premium tiers alongside free capture - common in airports, ferries, and conference centres.

Compliance and legal posture

Guest WiFi sits at the intersection of four regulatory regimes. None of them prohibit guest WiFi. All of them shape how it is operated.

Free tool

Not sure about the guest network regulations in your region? Use our free Guest WiFi Compliance Check to generate localized legal checklists and customizable terms of service templates.

UK GDPR

Lawful basis at the captive portal: consent for marketing capture under PECR and UK GDPR, legitimate interest with DPIA for analytics presence. Unticked checkboxes and granular consent.

Reference ›

PCI DSS 4.0

Guest WiFi must be segmented from any cardholder data environment. Authenticated wireless access to the CDE prohibited via shared passwords; guest SSIDs always separate.

Reference ›

Lawful intercept (UK IPA, US ECPA)

Venues providing public WiFi have logging obligations, with a retention window for your jurisdiction - 12 months under the UK Investigatory Powers Act. A modern platform produces the required log retention and export format without the venue having to engineer it.

Reference ›

Accessibility (WCAG 2.2 / EAA)

The captive portal is a publicly accessible service, so it falls under the Equality Act 2010 and WCAG 2.2. WCAG 2.2 AA conformance is required in the UK and EU; the EAA has made it enforceable across the EU since June 2025.

Reference ›

How to choose a guest WiFi provider

Six tests, applied in order. The honest comparison is total cost including the marketing programme the platform enables - not the platform line on the invoice.

Free tool

Planning a guest network deployment? Use our free Access Point Calculator (from our free WiFi tools library) or download our free native Netforge desktop app for one-click network health checks, path analysis, and speed testing.

✓Hardware compatibility

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. Confirm the platform supports the access points you own and the ones on your refresh roadmap.

✓Data capture and CRM integration

Native connectors into HubSpot, Salesforce, Mailchimp, Klaviyo, Bloomreach, Marketo, Iterable, and Twilio - not webhook-only. Identity resolution across visits.

✓Analytics depth

Both presence (anonymous, MAC-randomisation-corrected) and engagement (identified, consented). Live dashboards and BI export to S3, BigQuery, Snowflake.

✓Compliance posture

GDPR, PECR, CCPA, TCPA, PCI DSS 4.0. A platform that ships DPIA templates and venue signage, not one that hands you the law and a manual.

✓Support and SLA

A support model matched to your venue type. Hospitality and stadiums need different escalation than retail. 99.9%+ platform uptime is table stakes.

✓Transparent pricing

Per-site or per-AP pricing that scales predictably. Per-MAC or per-sign-up pricing distorts the marketing programme and penalises success.

Direct head-to-head comparisons against the main category alternatives: Cloud4Wi, IronWiFi, Stampede, Spotipo, Cloudi-Fi, SecureW2, Portnox, JumpCloud, RADIUSaaS, and Aislelabs. The captive portal software comparison aggregates the lot.

Guest WiFi by industry

The platform is the same; the deployment profile changes by venue type.

Each industry page covers the sector-specific WiFi challenge, the deployment pattern, named same-industry customers - Pizza Express, AGS Airports, and the University of Sheffield among them - and the relevant compliance frame.

Frequently asked questions

What is guest WiFi?

+

Guest WiFi is the wireless network a venue offers to visitors, separate from the staff network. It is identified at sign-in (anonymously or with consent), session-bounded, isolated from the venue's internal systems, and typically branded to the host. It is not the same as multi-tenant WiFi (which serves long-term residents) or staff WiFi (which authenticates managed devices).

Do I need guest WiFi?

+

For any customer-facing venue with dwell time over a few minutes, the answer is almost always yes. For QSR, retail, and hospitality, guest WiFi is now a baseline expectation - venues without it lose foot-traffic share and forgo the marketing capture. The exception is venues where the dwell is too short for the sign-in to be worth it (queue-only retail, drive-throughs).

How is guest WiFi delivered?

+

Four models: bring-your-own hardware with a software overlay (Purple, most common), fully managed (Purple + access points provided), MSP-bundled (an IT services partner), or ISP-bundled (the broadband provider includes a basic captive portal). The software-overlay model is the most flexible and the most common in mid-market and enterprise.

What does guest WiFi cost?

+

It varies by model and venue size. The software-overlay subscription typically sits in the £25-£150 per site per month range depending on feature tier (analytics, marketing automation, hardware integrations). Hardware, where new, adds £200-£800 per access point. ISP-bundled is usually 'free' but with no analytics or marketing layer. The honest comparison is the total cost including the marketing programme it enables.

How is guest WiFi different from multi-tenant WiFi?

+

Guest WiFi serves transient visitors who are isolated from each other by default; sessions are short and the relationship ends at logout. Multi-tenant WiFi serves long-term residents who need their own devices to recognise each other (Chromecast, smart home, gaming) while staying isolated from other residents. Different sessions, different authentication models, different operational expectations. See the multi-tenant pillar for the full distinction.

How is guest WiFi different from staff WiFi?

+

Staff WiFi authenticates known users on known devices against the organisation's identity provider, with strong authentication (EAP-TLS, 802.1X) and access to internal systems. Guest WiFi authenticates unknown visitors through a captive portal with weak authentication (email, social, click-through) and never grants access to internal systems. They run on the same access points but should always be separate SSIDs.

Is open guest WiFi legal?

+

In most jurisdictions, yes - but with obligations. Venues have logging and lawful-intercept obligations, with a connection-log retention window for your jurisdiction - 12 months under the UK Investigatory Powers Act. Family-friendly venues are expected to apply content filtering. Most venues are better served by a captive portal even on otherwise free WiFi, both for the data capture and for documentary evidence of the venue's policy on acceptable use.

How do I choose a guest WiFi provider?

+

Six tests in order: hardware compatibility with what you own; data-capture and CRM integration with what your marketing team uses; analytics depth versus what your operations team will actually use; compliance posture for your jurisdiction; support model and SLA against your venue type; and pricing transparency. We publish direct comparisons against Cloud4Wi, IronWiFi, Stampede, Spotipo, JumpCloud, Portnox, SecureW2, and RADIUSaaS for the head-to-head detail.

Does guest WiFi support compliance with GDPR, PCI, and the ICO guidance?

+

It must. The captive portal is the consent moment for visitor data capture under GDPR; the network segmentation between guest and cardholder-data environment is the PCI requirement; the data-handling and retention posture is the ICO concern. A modern guest WiFi platform ships compliance-defensible defaults and provides the DPIA, signage, and policy templates the venue needs.

How does guest WiFi connect to marketing and analytics?

+

Guest WiFi is the surface; marketing and analytics are the layers built on top. The captive portal captures consented identity for the marketing programme. The presence and engagement streams produce footfall, dwell, and journey data for the analytics programme. The two are the same dataset, framed differently, sitting on the same connectivity foundation.

Is Passpoint replacing guest WiFi?

+

Not replacing - extending. Passpoint and OpenRoaming let devices join trusted WiFi automatically without a captive portal interaction. For known returning visitors, that's the better experience; for first-time and one-off visitors, the captive portal remains the right join surface. Most large venues will run both: Passpoint for known carriers and federated identities, captive portal for everyone else.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of planning, securing, and running guest WiFi.

Planning a WiFi 6 to WiFi 7 access point refresh when Cisco Meraki WiFi 6 reaches end of sale

This technical reference gives multi-site operators a decision framework for a Cisco Meraki WiFi 6 to WiFi 7 refresh before the 31 December 2026 last-order date. It pairs estate and backhaul planning with the Meraki Dashboard checks that protect Purple authentication and location-analytics continuity during every access point swap.

Read guide →

CCPA/CPRA and Guest WiFi: Compliance Guide for Venue Marketers and IT

This technical guide shows venue IT and marketing teams how to govern Guest WiFi data collection under the CCPA/CPRA, without turning a captive portal into a compliance blind spot. It separates network access, privacy information, optional marketing choices and CRM flows, then maps Purple Connect, Capture and Engage to those operational decisions.

Read guide →

Cisco Catalyst WLC and guest WiFi: captive portal setup with Purple

How a Cisco Catalyst 9800 (IOS-XE) wireless LAN controller works with Purple guest WiFi: external web authentication, RADIUS and a walled garden, with a link to Purple's step-by-step setup guide for the exact configuration.

Read guide →

The Enterprise Guide to Setting Up Guest WiFi: Security, Segmentation, and Speed

This enterprise technical guide provides actionable instruction for IT managers and network architects on deploying secure, segmented guest WiFi. It covers VLAN architecture, WPA3 encryption, 802.1X authentication, PCI DSS and GDPR compliance, and integrating Purple's hardware-agnostic captive portal layer.

Read guide →

Staff WiFi vs. Guest WiFi: Best Practices for Corporate Network Segmentation

A comprehensive technical guide for IT leaders on segmenting staff and guest WiFi networks. It covers VLAN architecture, 802.1X authentication, firewall policies, and the business impact of secure network design.

Read guide →

How to Safely Segregate Staff and Guest WiFi Networks

This authoritative technical guide provides IT leaders with actionable strategies for safely segregating staff, guest, and IoT WiFi networks using VLANs and 802.1X. It details how to secure enterprise infrastructure, maintain PCI DSS compliance, and leverage captive portals to capture first-party data.

Read guide →

How to Set Up Guest WiFi: The Enterprise Network Segmentation Guide

This guide details the technical architecture, authentication standards, and deployment methodology required to build a secure, segmented enterprise WiFi network. You will learn how to implement the three-SSID model, deploy 802.1X for staff authentication, configure captive portals for GDPR-compliant guest access, and reduce your PCI DSS scope.

Read guide →

Hotel Guest WiFi Management: Integrating PMS, Portals, and Brand Standards

This technical guide details how to architect enterprise-grade hotel WiFi networks, focusing on VLAN segmentation, PMS integration for automated session management, and captive portal optimisation for GDPR-compliant data capture.

Read guide →

The Compliance Playbook: GDPR and Guest WiFi Data Privacy

This comprehensive guide provides IT managers and venue operators with a technical framework for architecting GDPR-compliant guest WiFi networks. It details consent mechanics, network segmentation, automated data retention, and how to transform compliance from a regulatory liability into a defensible first-party data asset.

Read guide →

How to Set Up Guest WiFi: A Secure Enterprise Configuration Guide

This authoritative guide provides IT leaders and network architects with a definitive blueprint for deploying secure enterprise guest WiFi. It covers essential architecture, WPA3 migration, VLAN segmentation, and captive portal integration to protect internal systems while capturing compliant first-party data.

Read guide →

Designing Secure Staff WiFi Networks Separated from Guest Traffic

An authoritative technical reference guide for network architects and IT leaders on designing secure, high-performance staff WiFi networks. It details the logical and physical segmentation of operational traffic from public guest networks using VLANs, 802.1X authentication, and WPA3-Enterprise to satisfy compliance mandates (PCI DSS, GDPR) and eliminate lateral movement security risks.

Read guide →

A Step-by-Step Guide to Diagnosing WiFi Roaming Issues

This comprehensive guide provides enterprise IT leaders and network architects with an authoritative, step-by-step methodology for diagnosing and resolving WiFi roaming issues. By combining technical deep-dives into IEEE 802.11k/v/r standards with real-world case studies and packet-level analysis, this reference equips teams to eliminate the 'sticky client' problem and deliver seamless mobile connectivity. It covers the full diagnostic workflow from RF site surveys and controller configuration audits through to over-the-air packet capture analysis and post-remediation validation.

Read guide →

How to Implement Time and Bandwidth Restrictions on Guest WiFi

An authoritative technical reference guide on implementing time and bandwidth restrictions on enterprise guest WiFi networks. This guide provides actionable architectural blueprints, vendor-neutral configurations, and real-world case studies to help IT leaders balance network performance, security compliance, and visitor experience.

Read guide →

Understanding RSSI and Signal Strength for Optimal Channel Planning

This guide provides a comprehensive technical deep-dive into RSSI, Signal-to-Noise Ratio (SNR), and RF propagation principles for optimal channel planning. It equips IT managers, network architects, and venue operations directors with actionable strategies to mitigate Co-Channel and Adjacent Channel Interference, optimise AP placement, and leverage analytics for measurable business impact across hospitality, retail, and public-sector environments.

Read guide →

What is a WLC (Wireless LAN Controller) and Do You Still Need One?

This comprehensive guide explores the evolution of Wireless LAN Controllers (WLCs) and provides a technical framework for determining the right architecture in 2026. It covers traditional hardware, cloud-managed, and controller-less models, detailing their impact on compliance, scalability, and guest experience.

Read guide →

Mesh Network vs Access Points: Which is Better for Large Venues?

This technical guide provides a definitive comparison between mesh networks and traditional wired access points for large-scale venues, covering architecture, performance trade-offs, and deployment strategy. It equips IT managers, network architects, and CTOs with actionable frameworks to design high-performance, compliant WiFi infrastructures for hospitality, retail, events, and public-sector environments. The guide also maps these architectural decisions to Purple's hardware-agnostic guest WiFi and analytics platform, demonstrating how the right infrastructure choice drives measurable business outcomes.

Read guide →

The Best WiFi Access Points for Enterprise and Homelabs

This technical guide evaluates the best enterprise WiFi access points for 2025-2026, covering Wi-Fi 6E and Wi-Fi 7 hardware from Cisco, HPE Aruba, Ruckus, Juniper Mist, and Ubiquiti across high-density hospitality, retail, and public venue deployments. It provides actionable architecture strategies, vendor comparisons, security frameworks, and ROI metrics for IT leaders building next-generation wireless networks. Purple's hardware-agnostic guest WiFi and analytics platform is mapped throughout as the intelligence layer that transforms network infrastructure into a first-party data asset.

Read guide →

Cisco Meraki vs. Aruba: A Technical Comparison for Guest WiFi

An authoritative technical comparison of Cisco Meraki and HPE Aruba for enterprise guest WiFi deployments. This guide provides actionable insights for IT managers and architects on architecture, authentication, network segmentation, and hardware-agnostic analytics integration.

Read guide →

Comparing Controller-Based vs. Cloud-Managed Access Points

This technical reference guide compares controller-based and cloud-managed Access Point architectures for enterprise environments. It provides IT leaders with a vendor-neutral framework for evaluating deployment models, total cost of ownership, and integration capabilities with guest intelligence platforms like Purple.

Read guide →

Access Point vs. Router: A Guide for Commercial Networking

This comprehensive guide explores the technical distinctions between access points and routers, providing actionable deployment strategies for commercial environments. It equips IT managers and venue operators with the knowledge required to architect scalable, secure, and high-performance wireless networks.

Read guide →

WiFi Repeater vs. Extender: Enterprise Use Cases

This technical reference guide provides a definitive comparison between WiFi repeaters and extenders for enterprise environments. It equips IT managers and network architects with the decision frameworks needed to deploy the right hardware for specific venue requirements, ensuring optimal performance, compliance, and ROI.

Read guide →

WiFi 6 vs WiFi 5: Does it Solve Channel Interference?

This guide provides a technical deep-dive into how WiFi 6 (802.11ax) addresses channel interference in high-density enterprise environments through OFDMA and BSS Coloring. It equips IT managers, network architects, and CTOs with actionable deployment strategies, real-world case studies from hospitality and healthcare, and a framework for evaluating the ROI of infrastructure upgrades in venues where wireless performance is business-critical.

Read guide →

How to Change Your Router's Default Channel

This authoritative technical reference guide provides IT managers and network architects with actionable strategies for configuring WiFi channels to mitigate interference, maximise throughput, and ensure a stable RF foundation for enterprise applications like Purple Guest WiFi and Analytics.

Read guide →

How to Fix Slow WiFi Without Upgrading Your Internet Plan

A comprehensive technical reference guide for IT managers and network architects on optimising enterprise WiFi performance without increasing ISP bandwidth. Covers RF tuning, client density management, QoS implementation, and how to leverage WiFi analytics to diagnose and resolve bottlenecks.

Read guide →