跳至主要內容
29B
data points captured on Purple
±3-7%
corrected accuracy vs camera
80,000+
venues running Purple
< 60s
dashboard freshness

TL;DR / Key Takeaways

  • WiFi analytics has two modes: presence (anonymous, sensor-based) and engagement (identified, captive-portal-based). Most venues need both, with each answering a different question.
  • MAC randomisation changed the discipline. Platforms that adapted use statistical correction and consented identification to maintain ±3-7% accuracy versus camera ground truth. Platforms that ignored the change have lost accuracy.
  • The headline metrics are footfall, dwell time, return-visit rate, zone transitions, new-vs-returning split, and capture rate. The honest reading is the corrected figure with the confidence interval, not the raw probe count.
  • GDPR-compliant analytics is achievable with hashed MAC and rotation for presence, explicit consent at the portal for engagement, a DPIA, and clear venue signage. the ICO and the EU's CNIL have both issued positive guidance on the model.
  • The strongest sector applications are retail, shopping malls, airports, stadiums, museums, and corporate offices. Each uses the same data model with a different framing layer on top.

Most venues are sitting on a sensor network they have already paid for: the access points they put in for guest WiFi. The same hardware, the same RF events, the same association logs, used differently, produce a usable account of who walked in, how long they stayed, where they went, and whether they came back.

That is WiFi analytics. It is not a perfect substitute for a turnstile counter at the door or a computer-vision camera on the till. It is a much cheaper substitute that covers the whole venue rather than one chokepoint, and that surfaces movement and dwell data the cameras cannot produce.

This guide is the operating reference for venue and marketing teams considering or running WiFi analytics. It covers the two modes (presence and engagement), the metrics that matter, what MAC randomisation broke and how the discipline adapted, the comparison against alternative people-counting technologies, the UK GDPR shape, and the sector applications that work.

The two modes: presence and engagement

Almost every confused conversation about WiFi analytics is the result of mixing these two up. They use different data, answer different questions, and run under different legal bases.

Presence analytics

Anonymous, sensor-based, derived from probe requests and association logs. Counts unique devices in a zone over a time window. Hashed MAC with rotation as the technical privacy control.

Answers: how many people came in, how long they stayed, how they moved between zones, and whether overall volume is up or down.

Lawful basis: legitimate interest with DPIA, signage, opt-out.

Engagement analytics

Identified, captive-portal-based, derived from sign-ins and ongoing sessions. Ties visits to a contact record. The substrate for segmentation, journeys, and lifecycle marketing.

Answers: who came in, how often they come, what time of day, which sites of a multi-site brand, and the marketing-actionable cohort behaviour.

Lawful basis: explicit consent at the portal sign-in.

Most venues need both. Presence gives the headline footfall and dwell numbers, comparable like-for-like across sites. Engagement gives the identified cohort that marketing can actually run journeys against. The two are joined at the captive portal: a visitor who signs in moves from the presence dataset to the engagement dataset for that visit.

MAC randomisation and why it changed the discipline

For most of the 2010s, WiFi analytics rested on a quietly false assumption: that a device’s MAC address was stable across visits. iOS 14 (2020) broke that for iPhones. Android 10 broke it for Android. Windows 11 and macOS Sonoma extended the change to laptops. By 2026, the great majority of consumer devices present a randomised, rotating MAC during probe requests before association.

Naive counting that treated each unique MAC as a unique device started over-counting. Return-visit rates collapsed; new-visitor share rocketed; cohort retention curves stopped making sense.

The discipline adapted in two ways. First, statistical correction: probabilistic models that account for the expected randomisation rate and rotation cadence per device class, calibrated against camera ground truth at known sites. Second, identification through the captive portal: visitors who sign in present a stable identity that survives randomisation entirely.

The combined accuracy of a corrected presence stream plus an opted-in engagement layer in 2026 is comparable to where 2018 footfall analytics sat, with a stronger privacy story. The vendors that did the correction work have maintained accuracy; the vendors that did not have lost it. Worth checking explicitly during evaluation.

Free tool

Want to see how MAC rotation affects your metrics? Use our free MAC Randomization Simulator (from our free WiFi tools library) to model raw device counts, ground truth visitor counts, and the reconciled counts.

The randomisation timeline

  • 2014: iOS 8 introduces randomised probes (off by default in practice).
  • 2020: iOS 14 randomises per-SSID by default.
  • 2020: Android 10+ randomises per-SSID by default.
  • 2022: Windows 11 expands to all WLAN probes.
  • 2023: macOS Sonoma matches iOS behaviour on laptops.
  • 2026: randomisation is the dominant assumption; static MAC is the edge case.

The six metrics worth reporting

WiFi analytics platforms can produce a hundred derived metrics. Six of them carry almost all the decision weight.

Footfall

Unique visitors entering a defined zone in a time window. The headline KPI for retail and venue operators.

Reported daily, weekly, monthly. Comparable like-for-like.

Dwell time

Median, p25/p75, p95 time-in-zone per visit. Distinguishes browsers from buyers.

Median by sector; trend is what matters most.

Return-visit rate

Share of visitors in a window who also visited in the previous N days. Loyalty signal.

18-32% in retail; 45-60% in transit and corporate.

Zone transitions

Origin-destination flows between defined zones. The basis for journey analytics and layout testing.

Used in malls, airports, museums, large retail.

New vs returning

Acquisition vs retention split. Useful for marketing attribution and for honest reporting of footfall lift.

70/30 to 50/50 typical, depending on category.

Capture rate

Share of detected presence converting to a captive-portal sign-in. Bridge between presence and engagement.

15-40% depending on portal design and incentive.

WiFi vs cameras vs door sensors

WiFi analytics is not the only people-counting technology. The right answer for most venues uses two of them together: a high-accuracy chokepoint counter at the front door and WiFi across the whole venue for dwell and journey.

MethodAccuracyCoverageCostPrivacyJourneys
WiFi presence±3-7%Whole venueUses existing APsHashed MAC, opt-out, signageNative
Computer vision±1-3% at doorwayField of view onlyPer-camera + computeStrongest concern in EULimited
Door sensor (IR / 3D)±2-4%Doorway onlyPer-doorLowNone

Compliance: UK GDPR, CNIL, CCPA, ISO 27001

WiFi analytics that respects privacy is a solved problem. The model below is what the CNIL has explicitly approved and what the ICO has consistently allowed. Pizza Express, AGS Airports, and the University of Sheffield all run venue analytics on Purple.

UK GDPR

Presence analytics: legitimate interest with DPIA. Engagement analytics: explicit consent at the portal. Hashed MAC with rotation is the accepted technical control for presence.

Reference ›

CNIL guidance

The French regulator has issued specific guidance on WiFi analytics. The model that satisfies the CNIL is the one the rest of the EU follows.

Reference ›

CCPA / CPRA

California requires a privacy notice and opt-out mechanism. WiFi analytics that aggregates and anonymises sits within the existing privacy-policy framework.

Reference ›

ISO 27001

Annex A.5.34 (privacy and protection of PII) and A.5.12 (classification of information) apply. The platform should produce a DPIA template and a retention-schedule export.

Reference ›

The four operational requirements: a completed DPIA, hashed MAC with rotation for the presence stream, explicit consent at the captive portal for the engagement stream, and visible venue signage explaining what is being measured and how to opt out. Purple ships templates and venue-signage assets for each. The compliance posture is part of the product, not an afterthought.

How to evaluate a WiFi analytics platform

An eight-item checklist for procurement, operations, and the data team.

✓Statistical correction for MAC randomisation

A platform that does not correct for randomised MACs is not measuring footfall in 2026. Ask for the methodology and the validation against camera ground truth.

✓Both presence and engagement modes

You need the anonymous, whole-venue mode and the consented, identified mode. Platforms that only do one of them aren't enough.

✓Zone configuration without recabling

Zone definitions should be edited in the dashboard, not by re-pulling cable. Coverage areas, anchor stores, departments.

✓Like-for-like comparable framing

Multi-site operators need normalised KPIs across sites of different size and traffic profile. Raw numbers do not work.

✓Live BI export

Hourly batch to S3 / BigQuery / Snowflake. Native Looker / Tableau connectors. The data should land where your analysts already work.

✓DPIA template and signage assets

The platform should hand you the privacy paperwork and the venue signage you need. Building it from scratch slows deployment by weeks.

✓Hardware independence

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. The analytics layer should outlive the AP refresh.

✓Auditable retention controls

Configurable retention by data class. Identifiable data on the shortest defensible schedule. Aggregate data on whatever your reporting needs.

Frequently asked questions

What is WiFi analytics?

+

WiFi analytics is the practice of using a venue's existing wireless network as a sensor for footfall, dwell time, and customer movement. Two modes: presence analytics (anonymous, sensor-based, MAC-randomisation-affected) and engagement analytics (identified, captive-portal-based, opted-in). Most operators run both, with each answering a different question.

How accurate is WiFi footfall counting?

+

Modern WiFi analytics with statistical correction for MAC randomisation runs at ±3-7% versus camera-based ground truth in retail environments. The accuracy is good enough for like-for-like comparison, trend tracking, and benchmarking; it is not good enough for cash-register reconciliation. The number you report should be the corrected figure with the confidence interval, not the raw probe count.

Has MAC randomisation broken WiFi analytics?

+

It changed it. iOS 14+, Android 10+, Windows 11, and macOS Sonoma randomise the MAC address presented in probe requests before association. Naive counting that treated each unique MAC as a unique device is now wrong. Statistical correction models, plus opted-in captive-portal identification for engagement analytics, are how modern platforms maintain accuracy. The platforms that ignored the change have lost accuracy; the ones that adapted have not.

What is the difference between presence and engagement analytics?

+

Presence analytics counts devices that are physically present but not authenticated; it measures footfall and dwell anonymously and is GDPR-defensible under legitimate interest with a DPIA. Engagement analytics measures behaviour for visitors who signed in to the captive portal and gave consent; it ties visits to identity, supports segmentation, and runs under explicit consent. Most venues need both.

Is WiFi analytics GDPR-compliant?

+

Yes, with proper design. For presence analytics, hash the MAC client-side with rotation, document a legitimate-interest assessment, complete a DPIA, and post visible signage. For engagement analytics, run on explicit consent at the captive portal. the ICO and the EU's CNIL have both issued positive guidance on WiFi analytics where these conditions are met. We have a full compliance playbook linked from this pillar.

Is WiFi or camera better for people counting?

+

Different jobs. Cameras with computer vision are more accurate at single-doorway counting (95%+ vs ground truth) but cost more, see only their field of view, and raise stronger privacy concerns. WiFi covers the whole venue cheaply, supports dwell and zone-to-zone analysis natively, and identifies returning visitors statistically. Most large-format retail and venue operators run both: cameras at the door for accuracy, WiFi inside for coverage.

What sort of dwell time should I expect?

+

Median dwell across Purple's dataset: 9-14 minutes in QSR, 35-55 minutes in casual dining, 18-32 minutes in apparel retail, 55-95 minutes in shopping malls, 75-130 minutes in airports air-side. Useful as benchmarks; the more useful measure is your own dwell trend month-on-month against same-store comparable.

Can WiFi analytics track customer journeys?

+

Within a venue, yes. Zone-to-zone transitions, time-in-zone, common paths, and drop-off points are all measurable. Across venues of the same brand, it depends on whether the visitor authenticated (engagement) or not (presence); presence-only journeys across sites are very weak signal once MAC randomisation is accounted for.

Does WiFi analytics work for office occupancy?

+

Yes. The same infrastructure that authenticates staff devices reports utilisation by floor, by day-of-week, and by hour-of-day. Integration with workplace booking systems (Robin, Envoy, Microsoft Places) is a common pattern. Office occupancy is one of the higher-confidence use cases because the population is largely authenticated and the device count is more stable than retail footfall.

How does this integrate with my existing BI stack?

+

Direct API access, hourly batch export to S3 / BigQuery / Snowflake, native Looker and Tableau connectors, and webhook event streaming. The data model is documented and stable. Most large operators land WiFi data into the same warehouse as POS and loyalty, then build reporting in their own tool of choice.

Speak to an expert

Tell us what you want to measure and we'll show you the dashboards on your own venue data.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of measuring footfall, dwell, and visitor behaviour from WiFi. All 31 guides in this pillar are listed below.

WiFi 客流分析:如何測量與運用訪客數據

本指南為 IT 經理、網路架構師和場館營運總監提供了在餐旅、零售、活動和公共部門環境中部署 WiFi 客流分析的務實技術參考。內容涵蓋完整的資料管線 - 從 802.11 探測請求擷取和基於 RSSI 的定位,到符合 GDPR 規範的資料處理和可據以行動的商業智慧儀表板。讀者將獲得一個清晰的部署框架、真實案例研究,以及在本季度選擇、部署和最佳化 WiFi 分析平台所需的決策標準。

Read guide →

如何利用 WiFi 定位分析計算停留時間

本指南為利用 WiFi 定位分析計算 WiFi 停留時間提供了全面的技術參考,涵蓋從 802.11 探測請求(probe request)擷取、基於 RSSI 的三邊測量,到地理圍欄區域分析的完整架構。本指南專為 IT 經理、網路架構師和場所營運總監設計,協助其在零售、餐飲旅宿、醫療保健及公共部門環境中部署精確且具擴充性的定位智慧。讀者將獲得實用的部署指南、真實案例研究,以及將原始空間數據轉化為可衡量業務成果的清晰框架。

Read guide →

場域流量熱圖分析:實用指南

本技術參考指南針對在實體場域中部署與分析基於 WiFi 的熱圖,提供了具體可行的策略。本指南說明了 IT 與營運主管如何利用現有的網路基礎架構來發掘客流模式、消除瓶頸並優化空間投資報酬率(ROI)。

Read guide →

熱點圖 (Heatmapping) 與存在感應分析 (Presence Analytics):技術差異

本權威技術指南詳細介紹了 WiFi 熱點圖與存在感應分析在企業場域營運中的關鍵架構與運作差異。本指南為 IT 主管、網路架構師和營運總監提供了具體可行的部署框架、實際應用場景,以及與廠商無關的最佳實踐,旨在協助企業從現有的無線基礎設施中獲取最大的投資報酬率 (ROI)。

Read guide →

對零售業確實重要的 WiFi 分析指標

這份權威參考指南詳細說明了與零售營收、逗留時間和顧客忠誠度直接相關的五個 WiFi 分析指標。它為 IT 經理和場館營運總監提供了一個實用的架構,用於設定網路硬體、減輕 MAC 隨機化的影響,並與行銷團隊在統一的資料儀表板上達成共識。

Read guide →

隱私源自設計:去識別化 WiFi 數據以符合 GDPR 規範

本權威指南詳細介紹了去識別化 WiFi 數據的技術架構與實作策略,以確保符合 GDPR 規範。它為 IT 主管與網路架構師提供了實用的框架,在平衡強大的場域分析與嚴格的數據隱私要求之間取得完美平衡。

Read guide →

WiFi 7 場館部署:體育場與旅宿場所的基礎設施準備就緒度

本操作指南協助場館 IT 團隊在下單採購基地台之前,驗證 WiFi 7 基礎設施。內容涵蓋 PoE、Multi-gig 交換、佈線、控制器與授權準備就緒度、分析驗證,以及適用於體育場和旅宿環境的 200 台 AP 透明規劃模型。

Read guide →

衡量訪客 WiFi 與定位分析的企業投資報酬率 (ROI)

本技術參考指南為 IT 與場域營運團隊展示如何衡量訪客 WiFi 的 ROI,建立從網路健康度、同意收集的數據,到經驗證的營運或商業成果之間具備說服力的關聯鏈。指南將可衡量的實證與假設區分開來,將 Purple Connect、Capture 和 Engage 對應至正確的衡量層級,並針對飯店、零售物業和活動場館提供規劃情境。

Read guide →

什麼是 Probe Request?深入瞭解裝置如何探索網路

本技術參考指南深入探討 IEEE 802.11 probe requests、主動與被動掃描,以及 MAC address 隨機化對場域分析的影響。它為網路架構師提供了具體的實作策略,以最佳化高密度部署、減輕 probe storms,並確保使用已驗證的身分層進行準確且符合 GDPR 規範的數據收集。

Read guide →

如何在企業無線網路上追蹤不重複裝置

本指南提供在企業無線網路上追蹤不重複裝置的完整技術概述。針對 MAC 隨機化等現代挑戰進行探討,並為場域營運商與 IT 團隊詳細說明實作策略,以維持準確的分析數據與使用者識別。

Read guide →

MAC 位址隨機化如何影響訪客 WiFi 分析

本指南深入探討 MAC 位址隨機化對訪客 WiFi 分析的技術影響。它為 IT 主管與網路架構師提供實用策略,以在大型部署中恢復可見性、確保指標準確性並維持合規性。本指南涵蓋每網路隨機化與臨時隨機化的機制、身分識別解析架構以及實際部署情境,是任何依賴 WiFi 衍生空間數據的組織之權威參考。

Read guide →

室內 WiFi 定位系統:運作原理與部署指南

本完整指南詳細介紹了基於 WiFi 的室內定位系統之技術架構、部署策略與商業價值。它為網路架構師和 IT 主管提供了關於 AP 部署、RF 校準以及克服 MAC 隨機化以提供精確空間分析的實用指導。

Read guide →

Every guide in this pillar