Saltar para o conteúdo principal
80,000+
venues running Purple
440M
sign-ins processed last year
350M
unique visitors captured
99.9%
platform uptime SLA

TL;DR / Key Takeaways

  • Guest WiFi is the visitor-facing wireless surface of a venue. Distinct from staff WiFi (managed devices, strong authentication) and multi-tenant WiFi (long-term residents with device discovery).
  • Four delivery models: software overlay on existing access points, fully managed, MSP-bundled, ISP-bundled. The software-overlay model is the most common in mid-market and enterprise.
  • The captive portal is the join surface, the marketing capture, and the analytics anchor. The five companion pillar guides cover each layer in depth.
  • Compliance posture is part of the platform, not an afterthought. GDPR consent, PCI DSS network segmentation, lawful-intercept logging, and WCAG 2.2 accessibility all ship as defaults.
  • Choosing a provider is six tests: hardware compatibility, CRM integration, analytics depth, compliance posture, support SLA, transparent pricing. The 80,000-venue platform is a different question to the single-venue one.

Guest WiFi sits at an awkward crossroads. IT owns the connectivity, marketing owns the capture, operations owns the experience, finance owns the procurement, and the visitor just wants to get online - the same simple goal behind World WiFi Day, the global celebration of connectivity for everyone. Most platforms in the category were designed to address one of those buyers and tolerated the rest. The result is a procurement conversation that often misfires.

This guide is the master reference. The five sibling pillar guides cover the layers in depth - captive portal mechanics, marketing programme design, analytics methodology, enterprise security, and multi-tenant residential. This page is the connecting tissue, the one a buying committee can read together to agree what they are actually procuring.

The structure: what guest WiFi is (and is not), the four delivery models, how it relates to the rest of the platform, the compliance shape that actually works, the choice criteria, and an honest set of FAQs for the procurement conversation.

What guest WiFi is - and what it is not

Three things in the same building, all called WiFi, all doing different jobs.

DimensionGuest WiFiStaff WiFiMulti-tenant WiFi
AudienceTransient visitorsKnown employees and contractorsLong-term residents
AuthenticationCaptive portal (email, social, SMS, click-through)802.1X, EAP-TLS, iPSK against IdPiPSK per resident, ongoing
Session lengthMinutes to hoursPersistent on managed devicesYears
Device discoveryIsolated by defaultPer-role segmentationPer-resident WiFi-bubble
Internal accessNeverYes, scoped by roleNo (private to resident)
Marketing capturePrimary purposeNot applicableNot applicable

Most venues need at least two of these in parallel. A typical retail estate runs guest WiFi for shoppers and staff WiFi for the back-of-house team on the same access points, segmented by SSID and VLAN. A residential building adds multi-tenant for residents and runs guest WiFi for delivery drivers and contractors. The architectural rule is one platform, multiple SSIDs, each with its own authentication model.

The four delivery models

How guest WiFi is bought, paid for, and operated. The right model depends on the existing AP estate, the in-house IT capability, and the marketing ambition.

Software overlay (BYO hardware)

Purple software runs on the access points you already own. The most common model in mid-market and enterprise. Per-site or per-AP subscription.

Best for: Existing AP estate. Multi-site brands. Predictable opex.

Fully managed

Purple-supplied access points plus software plus support, billed per site per month. Operational simplicity at the price of a longer commitment.

Best for: New builds. Single-site operators without IT.

MSP-bundled

Your IT services partner resells Purple inside a broader managed-IT contract. Day-to-day operations and support sit with the MSP.

Best for: Organisations already on a managed-IT contract.

ISP-bundled

A basic captive portal included with a broadband contract. Limited analytics, limited marketing, limited integrations. Usually the lowest cost and the lowest ceiling.

Best for: Single-site, low-traffic, no marketing programme.

Pricing models and ROI framing

Guest WiFi pricing splits into three honest models. Per-site subscription (Purple, most predictable), per-AP subscription (some competitors, scales with venue size), and per-sign-up or per-MAC pricing (legacy and usually punitive). The marketing programme that runs on top is a separate cost line, and a separate ROI conversation.

The honest ROI conversation is in the WiFi marketing pillar, where the three measurable numbers are cost per captured opted-in record (median £0.28 / $0.35 across Purple deployments), return-visit lift on segmented audiences (12-18% in retail and hospitality), and basket-size delta on triggered journeys. Avoid the trap of attributing every subsequent visit to the WiFi capture; run a hold-out test for the marginal effect.

The paid-WiFi calculator models the revenue case for venues running paid premium tiers alongside free capture - common in airports, ferries, and conference centres.

Compliance and legal posture

Guest WiFi sits at the intersection of four regulatory regimes. None of them prohibit guest WiFi. All of them shape how it is operated.

Free tool

Not sure about the guest network regulations in your region? Use our free Guest WiFi Compliance Check to generate localized legal checklists and customizable terms of service templates.

UK GDPR

Lawful basis at the captive portal: consent for marketing capture under PECR and UK GDPR, legitimate interest with DPIA for analytics presence. Unticked checkboxes and granular consent.

Reference ›

PCI DSS 4.0

Guest WiFi must be segmented from any cardholder data environment. Authenticated wireless access to the CDE prohibited via shared passwords; guest SSIDs always separate.

Reference ›

Lawful intercept (UK IPA, US ECPA)

Venues providing public WiFi have logging obligations, with a retention window for your jurisdiction - 12 months under the UK Investigatory Powers Act. A modern platform produces the required log retention and export format without the venue having to engineer it.

Reference ›

Accessibility (WCAG 2.2 / EAA)

The captive portal is a publicly accessible service, so it falls under the Equality Act 2010 and WCAG 2.2. WCAG 2.2 AA conformance is required in the UK and EU; the EAA has made it enforceable across the EU since June 2025.

Reference ›

How to choose a guest WiFi provider

Six tests, applied in order. The honest comparison is total cost including the marketing programme the platform enables - not the platform line on the invoice.

Free tool

Planning a guest network deployment? Use our free Access Point Calculator (from our free WiFi tools library) or download our free native Netforge desktop app for one-click network health checks, path analysis, and speed testing.

✓Hardware compatibility

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. Confirm the platform supports the access points you own and the ones on your refresh roadmap.

✓Data capture and CRM integration

Native connectors into HubSpot, Salesforce, Mailchimp, Klaviyo, Bloomreach, Marketo, Iterable, and Twilio - not webhook-only. Identity resolution across visits.

✓Analytics depth

Both presence (anonymous, MAC-randomisation-corrected) and engagement (identified, consented). Live dashboards and BI export to S3, BigQuery, Snowflake.

✓Compliance posture

GDPR, PECR, CCPA, TCPA, PCI DSS 4.0. A platform that ships DPIA templates and venue signage, not one that hands you the law and a manual.

✓Support and SLA

A support model matched to your venue type. Hospitality and stadiums need different escalation than retail. 99.9%+ platform uptime is table stakes.

✓Transparent pricing

Per-site or per-AP pricing that scales predictably. Per-MAC or per-sign-up pricing distorts the marketing programme and penalises success.

Direct head-to-head comparisons against the main category alternatives: Cloud4Wi, IronWiFi, Stampede, Spotipo, Cloudi-Fi, SecureW2, Portnox, JumpCloud, RADIUSaaS, and Aislelabs. The captive portal software comparison aggregates the lot.

Guest WiFi by industry

The platform is the same; the deployment profile changes by venue type.

Each industry page covers the sector-specific WiFi challenge, the deployment pattern, named same-industry customers - Pizza Express, AGS Airports, and the University of Sheffield among them - and the relevant compliance frame.

Frequently asked questions

What is guest WiFi?

+

Guest WiFi is the wireless network a venue offers to visitors, separate from the staff network. It is identified at sign-in (anonymously or with consent), session-bounded, isolated from the venue's internal systems, and typically branded to the host. It is not the same as multi-tenant WiFi (which serves long-term residents) or staff WiFi (which authenticates managed devices).

Do I need guest WiFi?

+

For any customer-facing venue with dwell time over a few minutes, the answer is almost always yes. For QSR, retail, and hospitality, guest WiFi is now a baseline expectation - venues without it lose foot-traffic share and forgo the marketing capture. The exception is venues where the dwell is too short for the sign-in to be worth it (queue-only retail, drive-throughs).

How is guest WiFi delivered?

+

Four models: bring-your-own hardware with a software overlay (Purple, most common), fully managed (Purple + access points provided), MSP-bundled (an IT services partner), or ISP-bundled (the broadband provider includes a basic captive portal). The software-overlay model is the most flexible and the most common in mid-market and enterprise.

What does guest WiFi cost?

+

It varies by model and venue size. The software-overlay subscription typically sits in the £25-£150 per site per month range depending on feature tier (analytics, marketing automation, hardware integrations). Hardware, where new, adds £200-£800 per access point. ISP-bundled is usually 'free' but with no analytics or marketing layer. The honest comparison is the total cost including the marketing programme it enables.

How is guest WiFi different from multi-tenant WiFi?

+

Guest WiFi serves transient visitors who are isolated from each other by default; sessions are short and the relationship ends at logout. Multi-tenant WiFi serves long-term residents who need their own devices to recognise each other (Chromecast, smart home, gaming) while staying isolated from other residents. Different sessions, different authentication models, different operational expectations. See the multi-tenant pillar for the full distinction.

How is guest WiFi different from staff WiFi?

+

Staff WiFi authenticates known users on known devices against the organisation's identity provider, with strong authentication (EAP-TLS, 802.1X) and access to internal systems. Guest WiFi authenticates unknown visitors through a captive portal with weak authentication (email, social, click-through) and never grants access to internal systems. They run on the same access points but should always be separate SSIDs.

Is open guest WiFi legal?

+

In most jurisdictions, yes - but with obligations. Venues have logging and lawful-intercept obligations, with a connection-log retention window for your jurisdiction - 12 months under the UK Investigatory Powers Act. Family-friendly venues are expected to apply content filtering. Most venues are better served by a captive portal even on otherwise free WiFi, both for the data capture and for documentary evidence of the venue's policy on acceptable use.

How do I choose a guest WiFi provider?

+

Six tests in order: hardware compatibility with what you own; data-capture and CRM integration with what your marketing team uses; analytics depth versus what your operations team will actually use; compliance posture for your jurisdiction; support model and SLA against your venue type; and pricing transparency. We publish direct comparisons against Cloud4Wi, IronWiFi, Stampede, Spotipo, JumpCloud, Portnox, SecureW2, and RADIUSaaS for the head-to-head detail.

Does guest WiFi support compliance with GDPR, PCI, and the ICO guidance?

+

It must. The captive portal is the consent moment for visitor data capture under GDPR; the network segmentation between guest and cardholder-data environment is the PCI requirement; the data-handling and retention posture is the ICO concern. A modern guest WiFi platform ships compliance-defensible defaults and provides the DPIA, signage, and policy templates the venue needs.

How does guest WiFi connect to marketing and analytics?

+

Guest WiFi is the surface; marketing and analytics are the layers built on top. The captive portal captures consented identity for the marketing programme. The presence and engagement streams produce footfall, dwell, and journey data for the analytics programme. The two are the same dataset, framed differently, sitting on the same connectivity foundation.

Is Passpoint replacing guest WiFi?

+

Not replacing - extending. Passpoint and OpenRoaming let devices join trusted WiFi automatically without a captive portal interaction. For known returning visitors, that's the better experience; for first-time and one-off visitors, the captive portal remains the right join surface. Most large venues will run both: Passpoint for known carriers and federated identities, captive portal for everyone else.

Speak to an expert

Tell us about your venues and we'll show you guest WiFi on the access points you already own.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of planning, securing, and running guest WiFi. All 109 guides in this pillar are listed below.

Como o WiFi de Colaboradores o Ajuda a Cumprir a ISO/IEC 27001: Mapeamento de Controlos do Anexo A para a Sua Rede Sem Fios

Será capaz de decidir se o seu WiFi de colaboradores pode comprovar 12 controlos do Anexo A da ISO/IEC 27001:2022, incluindo A.5.15, A.8.5 e A.8.22. Será também capaz de substituir uma chave WPA2-PSK partilhada por IEEE 802.1X e VLANs dinâmicas. Finalmente, poderá reunir os registos RADIUS, testes de segregação e registos de fornecedores que um auditor aceita na fase 2.

Read guide →

Eventos de radar DFS em Cisco Meraki, HPE Aruba e Ruckus: um checklist de diagnóstico para alterações de canal

Descubra se um evento de radar DFS causou a sua quebra de ligação de 5GHz em Cisco Meraki, HPE Aruba ou Ruckus. Distinga radares reais de falsos positivos e de alterações do planeador. Em seguida, decida quais os canais a excluir, em quais APs, sem abdicar da capacidade de que o seu espaço necessita.

Read guide →

Planeamento de uma atualização de pontos de acesso WiFi 6 para WiFi 7 quando o Cisco Meraki WiFi 6 atingir o fim de comercialização

Esta referência técnica oferece aos operadores multilocais uma estrutura de decisão para uma atualização de Cisco Meraki WiFi 6 para WiFi 7 antes da data limite para encomendas de 31 de dezembro de 2026. Alinha o planeamento de infraestrutura e backhaul com as verificações do Meraki Dashboard que garantem a continuidade da autenticação Purple e da análise de localização durante cada substituição de ponto de acesso.

Read guide →

GDPR e Guest WiFi: Guia de Conformidade para Marketing e TI de Espaços

Este guia técnico mostra às equipas de TI e marketing de espaços como gerir a recolha de dados de Guest WiFi ao abrigo do GDPR, sem transformar um captive portal num ponto cego de conformidade. Separa o acesso à rede, as informações de privacidade, as opções de marketing opcionais e os fluxos de CRM, mapeando depois o Purple Connect, Capture e Engage com essas decisões operacionais.

Read guide →

Cisco Catalyst WLC e guest WiFi: configuração de captive portal com a Purple

Como um controlador LAN sem fios Cisco Catalyst 9800 (IOS-XE) funciona com o guest WiFi da Purple: autenticação web externa, RADIUS e uma walled garden, com um link para o guia de configuração passo a passo da Purple para a configuração exata.

Read guide →

Como Configurar WiFi de Convidados: Um Guia de Configuração Segura para Empresas

Este guia autoritário fornece aos líderes de TI e arquitetos de rede um plano definitivo para implementar WiFi de convidados seguro em ambientes empresariais. Abrange a arquitetura essencial, a migração para WPA3, a segmentação de VLAN e a integração de captive portal para proteger os sistemas internos enquanto se recolhem dados primários em conformidade.

Read guide →

Conceber Redes WiFi Seguras para Colaboradores Separadas do Tráfego de Convidados

Um guia de referência técnica de autoridade para arquitetos de rede e líderes de TI sobre como conceber redes WiFi seguras e de alto desempenho para colaboradores. Detalha a segmentação lógica e física do tráfego operacional das redes públicas de convidados utilizando VLANs, autenticação 802.1X e WPA3-Enterprise para cumprir os requisitos de conformidade (PCI-DSS, GDPR) e eliminar os riscos de segurança de movimento lateral.

Read guide →

Utilizar Captura de Pacotes (PCAP) para Diagnosticar Desempenho Lento de WiFi

Este guia de referência técnica fornece a gestores de TI, arquitetos de rede e diretores de operações de espaços uma metodologia estruturada ao nível dos pacotes para diagnosticar e resolver problemas de desempenho lento de WiFi empresarial através da análise de Captura de Pacotes (PCAP). Ao analisar detalhadamente tramas 802.11 puras — incluindo taxas de retransmissão, utilização de tempo de antena e metadados de camada física — as equipas podem isolar com precisão os estrangulamentos da camada RF de problemas com fios ou de aplicação. Aplicável a locais de alta densidade, incluindo hotéis, cadeias de retalho, estádios e centros de conferências, este guia fornece fluxos de trabalho de diagnóstico acionáveis, estudos de caso do mundo real e etapas de remediação de configuração para recuperar capacidade de rede e proteger a experiência dos convidados.

Read guide →

Como Implementar Restrições de Tempo e de Largura de Banda em WiFi de Convidados

Um guia de referência técnica de autoridade sobre a implementação de restrições de tempo e de largura de banda em redes WiFi de convidados empresariais. Este guia fornece esquemas de arquitetura práticos, configurações neutras de fornecedor e casos de estudo reais para ajudar os líderes de TI a equilibrar o desempenho da rede, a conformidade de segurança e a experiência do visitante.

Read guide →

O que é um WLC (Wireless LAN Controller) e ainda precisa de um?

Este guia abrangente explora a evolução dos Wireless LAN Controllers (WLCs) e fornece um modelo técnico para determinar a arquitetura certa em 2026. Abrange modelos de hardware tradicionais, geridos na nuvem e sem controlador, detalhando o seu impacto na conformidade, escalabilidade e experiência de guest WiFi.

Read guide →

Redes Mesh vs Access Points: Qual é Melhor para Grandes Espaços?

Este guia técnico fornece uma comparação definitiva entre redes mesh e access points com fios tradicionais para espaços de grande escala, abrangendo a arquitetura, as compensações de desempenho e a estratégia de implementação. Capacita gestores de TI, arquitetos de rede e CTOs com estruturas de ação para conceber infraestruturas de WiFi de alto desempenho e em conformidade para os setores da hotelaria, retalho, eventos e ambientes do setor público. O guia também mapeia estas decisões de arquitetura com a plataforma de análise e de guest WiFi agnóstica de hardware da Purple, demonstrando como a escolha de infraestrutura correta impulsiona resultados de negócio mensuráveis.

Read guide →

Cisco Meraki vs. Aruba: Uma Comparação Técnica para Guest WiFi

Uma comparação técnica de referência entre a Cisco Meraki e a HPE Aruba para implementações de Guest WiFi empresariais. Este guia oferece perspetivas práticas para gestores e arquitetos de TI sobre arquitetura, autenticação, segmentação de rede e integração de analítica independente de hardware.

Read guide →

Every guide in this pillar

Network design (40)

Security (17)