跳至主要內容
29B
data points captured on Purple
±3-7%
corrected accuracy vs camera
80,000+
venues running Purple
< 60s
dashboard freshness

TL;DR / Key Takeaways

  • WiFi analytics has two modes: presence (anonymous, sensor-based) and engagement (identified, captive-portal-based). Most venues need both, with each answering a different question.
  • MAC randomisation changed the discipline. Platforms that adapted use statistical correction and consented identification to maintain ±3-7% accuracy versus camera ground truth. Platforms that ignored the change have lost accuracy.
  • The headline metrics are footfall, dwell time, return-visit rate, zone transitions, new-vs-returning split, and capture rate. The honest reading is the corrected figure with the confidence interval, not the raw probe count.
  • GDPR-compliant analytics is achievable with hashed MAC and rotation for presence, explicit consent at the portal for engagement, a DPIA, and clear venue signage. the ICO and the EU's CNIL have both issued positive guidance on the model.
  • The strongest sector applications are retail, shopping malls, airports, stadiums, museums, and corporate offices. Each uses the same data model with a different framing layer on top.

Most venues are sitting on a sensor network they have already paid for: the access points they put in for guest WiFi. The same hardware, the same RF events, the same association logs, used differently, produce a usable account of who walked in, how long they stayed, where they went, and whether they came back.

That is WiFi analytics. It is not a perfect substitute for a turnstile counter at the door or a computer-vision camera on the till. It is a much cheaper substitute that covers the whole venue rather than one chokepoint, and that surfaces movement and dwell data the cameras cannot produce.

This guide is the operating reference for venue and marketing teams considering or running WiFi analytics. It covers the two modes (presence and engagement), the metrics that matter, what MAC randomisation broke and how the discipline adapted, the comparison against alternative people-counting technologies, the UK GDPR shape, and the sector applications that work.

The two modes: presence and engagement

Almost every confused conversation about WiFi analytics is the result of mixing these two up. They use different data, answer different questions, and run under different legal bases.

Presence analytics

Anonymous, sensor-based, derived from probe requests and association logs. Counts unique devices in a zone over a time window. Hashed MAC with rotation as the technical privacy control.

Answers: how many people came in, how long they stayed, how they moved between zones, and whether overall volume is up or down.

Lawful basis: legitimate interest with DPIA, signage, opt-out.

Engagement analytics

Identified, captive-portal-based, derived from sign-ins and ongoing sessions. Ties visits to a contact record. The substrate for segmentation, journeys, and lifecycle marketing.

Answers: who came in, how often they come, what time of day, which sites of a multi-site brand, and the marketing-actionable cohort behaviour.

Lawful basis: explicit consent at the portal sign-in.

Most venues need both. Presence gives the headline footfall and dwell numbers, comparable like-for-like across sites. Engagement gives the identified cohort that marketing can actually run journeys against. The two are joined at the captive portal: a visitor who signs in moves from the presence dataset to the engagement dataset for that visit.

MAC randomisation and why it changed the discipline

For most of the 2010s, WiFi analytics rested on a quietly false assumption: that a device’s MAC address was stable across visits. iOS 14 (2020) broke that for iPhones. Android 10 broke it for Android. Windows 11 and macOS Sonoma extended the change to laptops. By 2026, the great majority of consumer devices present a randomised, rotating MAC during probe requests before association.

Naive counting that treated each unique MAC as a unique device started over-counting. Return-visit rates collapsed; new-visitor share rocketed; cohort retention curves stopped making sense.

The discipline adapted in two ways. First, statistical correction: probabilistic models that account for the expected randomisation rate and rotation cadence per device class, calibrated against camera ground truth at known sites. Second, identification through the captive portal: visitors who sign in present a stable identity that survives randomisation entirely.

The combined accuracy of a corrected presence stream plus an opted-in engagement layer in 2026 is comparable to where 2018 footfall analytics sat, with a stronger privacy story. The vendors that did the correction work have maintained accuracy; the vendors that did not have lost it. Worth checking explicitly during evaluation.

Free tool

Want to see how MAC rotation affects your metrics? Use our free MAC Randomization Simulator (from our free WiFi tools library) to model raw device counts, ground truth visitor counts, and the reconciled counts.

The randomisation timeline

  • 2014: iOS 8 introduces randomised probes (off by default in practice).
  • 2020: iOS 14 randomises per-SSID by default.
  • 2020: Android 10+ randomises per-SSID by default.
  • 2022: Windows 11 expands to all WLAN probes.
  • 2023: macOS Sonoma matches iOS behaviour on laptops.
  • 2026: randomisation is the dominant assumption; static MAC is the edge case.

The six metrics worth reporting

WiFi analytics platforms can produce a hundred derived metrics. Six of them carry almost all the decision weight.

Footfall

Unique visitors entering a defined zone in a time window. The headline KPI for retail and venue operators.

Reported daily, weekly, monthly. Comparable like-for-like.

Dwell time

Median, p25/p75, p95 time-in-zone per visit. Distinguishes browsers from buyers.

Median by sector; trend is what matters most.

Return-visit rate

Share of visitors in a window who also visited in the previous N days. Loyalty signal.

18-32% in retail; 45-60% in transit and corporate.

Zone transitions

Origin-destination flows between defined zones. The basis for journey analytics and layout testing.

Used in malls, airports, museums, large retail.

New vs returning

Acquisition vs retention split. Useful for marketing attribution and for honest reporting of footfall lift.

70/30 to 50/50 typical, depending on category.

Capture rate

Share of detected presence converting to a captive-portal sign-in. Bridge between presence and engagement.

15-40% depending on portal design and incentive.

WiFi vs cameras vs door sensors

WiFi analytics is not the only people-counting technology. The right answer for most venues uses two of them together: a high-accuracy chokepoint counter at the front door and WiFi across the whole venue for dwell and journey.

MethodAccuracyCoverageCostPrivacyJourneys
WiFi presence±3-7%Whole venueUses existing APsHashed MAC, opt-out, signageNative
Computer vision±1-3% at doorwayField of view onlyPer-camera + computeStrongest concern in EULimited
Door sensor (IR / 3D)±2-4%Doorway onlyPer-doorLowNone

Compliance: UK GDPR, CNIL, CCPA, ISO 27001

WiFi analytics that respects privacy is a solved problem. The model below is what the CNIL has explicitly approved and what the ICO has consistently allowed. Pizza Express, AGS Airports, and the University of Sheffield all run venue analytics on Purple.

UK GDPR

Presence analytics: legitimate interest with DPIA. Engagement analytics: explicit consent at the portal. Hashed MAC with rotation is the accepted technical control for presence.

Reference ›

CNIL guidance

The French regulator has issued specific guidance on WiFi analytics. The model that satisfies the CNIL is the one the rest of the EU follows.

Reference ›

CCPA / CPRA

California requires a privacy notice and opt-out mechanism. WiFi analytics that aggregates and anonymises sits within the existing privacy-policy framework.

Reference ›

ISO 27001

Annex A.5.34 (privacy and protection of PII) and A.5.12 (classification of information) apply. The platform should produce a DPIA template and a retention-schedule export.

Reference ›

The four operational requirements: a completed DPIA, hashed MAC with rotation for the presence stream, explicit consent at the captive portal for the engagement stream, and visible venue signage explaining what is being measured and how to opt out. Purple ships templates and venue-signage assets for each. The compliance posture is part of the product, not an afterthought.

How to evaluate a WiFi analytics platform

An eight-item checklist for procurement, operations, and the data team.

Statistical correction for MAC randomisation

A platform that does not correct for randomised MACs is not measuring footfall in 2026. Ask for the methodology and the validation against camera ground truth.

Both presence and engagement modes

You need the anonymous, whole-venue mode and the consented, identified mode. Platforms that only do one of them aren't enough.

Zone configuration without recabling

Zone definitions should be edited in the dashboard, not by re-pulling cable. Coverage areas, anchor stores, departments.

Like-for-like comparable framing

Multi-site operators need normalised KPIs across sites of different size and traffic profile. Raw numbers do not work.

Live BI export

Hourly batch to S3 / BigQuery / Snowflake. Native Looker / Tableau connectors. The data should land where your analysts already work.

DPIA template and signage assets

The platform should hand you the privacy paperwork and the venue signage you need. Building it from scratch slows deployment by weeks.

Hardware independence

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. The analytics layer should outlive the AP refresh.

Auditable retention controls

Configurable retention by data class. Identifiable data on the shortest defensible schedule. Aggregate data on whatever your reporting needs.

Frequently asked questions

What is WiFi analytics?

+

WiFi analytics is the practice of using a venue's existing wireless network as a sensor for footfall, dwell time, and customer movement. Two modes: presence analytics (anonymous, sensor-based, MAC-randomisation-affected) and engagement analytics (identified, captive-portal-based, opted-in). Most operators run both, with each answering a different question.

How accurate is WiFi footfall counting?

+

Modern WiFi analytics with statistical correction for MAC randomisation runs at ±3-7% versus camera-based ground truth in retail environments. The accuracy is good enough for like-for-like comparison, trend tracking, and benchmarking; it is not good enough for cash-register reconciliation. The number you report should be the corrected figure with the confidence interval, not the raw probe count.

Has MAC randomisation broken WiFi analytics?

+

It changed it. iOS 14+, Android 10+, Windows 11, and macOS Sonoma randomise the MAC address presented in probe requests before association. Naive counting that treated each unique MAC as a unique device is now wrong. Statistical correction models, plus opted-in captive-portal identification for engagement analytics, are how modern platforms maintain accuracy. The platforms that ignored the change have lost accuracy; the ones that adapted have not.

What is the difference between presence and engagement analytics?

+

Presence analytics counts devices that are physically present but not authenticated; it measures footfall and dwell anonymously and is GDPR-defensible under legitimate interest with a DPIA. Engagement analytics measures behaviour for visitors who signed in to the captive portal and gave consent; it ties visits to identity, supports segmentation, and runs under explicit consent. Most venues need both.

Is WiFi analytics GDPR-compliant?

+

Yes, with proper design. For presence analytics, hash the MAC client-side with rotation, document a legitimate-interest assessment, complete a DPIA, and post visible signage. For engagement analytics, run on explicit consent at the captive portal. the ICO and the EU's CNIL have both issued positive guidance on WiFi analytics where these conditions are met. We have a full compliance playbook linked from this pillar.

Is WiFi or camera better for people counting?

+

Different jobs. Cameras with computer vision are more accurate at single-doorway counting (95%+ vs ground truth) but cost more, see only their field of view, and raise stronger privacy concerns. WiFi covers the whole venue cheaply, supports dwell and zone-to-zone analysis natively, and identifies returning visitors statistically. Most large-format retail and venue operators run both: cameras at the door for accuracy, WiFi inside for coverage.

What sort of dwell time should I expect?

+

Median dwell across Purple's dataset: 9-14 minutes in QSR, 35-55 minutes in casual dining, 18-32 minutes in apparel retail, 55-95 minutes in shopping malls, 75-130 minutes in airports air-side. Useful as benchmarks; the more useful measure is your own dwell trend month-on-month against same-store comparable.

Can WiFi analytics track customer journeys?

+

Within a venue, yes. Zone-to-zone transitions, time-in-zone, common paths, and drop-off points are all measurable. Across venues of the same brand, it depends on whether the visitor authenticated (engagement) or not (presence); presence-only journeys across sites are very weak signal once MAC randomisation is accounted for.

Does WiFi analytics work for office occupancy?

+

Yes. The same infrastructure that authenticates staff devices reports utilisation by floor, by day-of-week, and by hour-of-day. Integration with workplace booking systems (Robin, Envoy, Microsoft Places) is a common pattern. Office occupancy is one of the higher-confidence use cases because the population is largely authenticated and the device count is more stable than retail footfall.

How does this integrate with my existing BI stack?

+

Direct API access, hourly batch export to S3 / BigQuery / Snowflake, native Looker and Tableau connectors, and webhook event streaming. The data model is documented and stable. Most large operators land WiFi data into the same warehouse as POS and loyalty, then build reporting in their own tool of choice.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of measuring footfall, dwell, and visitor behaviour from WiFi.

WiFi 7 場館部署:體育場與旅宿場所的基礎設施準備就緒指南

本操作指南可協助場館 IT 團隊在下單採購基地台之前,驗證 WiFi 7 基礎設施的準備情況。內容涵蓋 PoE、Multi-gig 交換、佈線、控制器與授權準備就緒度、分析驗證,以及適用於體育場和旅宿環境的 200 個 AP 透明規劃模型。

Read guide →

衡量訪客 WiFi 與定位分析的企業投資報酬率 (ROI)

本技術參考指南為 IT 與場域營運團隊展示如何衡量訪客 WiFi 的 ROI,建立從網路健康度、同意收集的數據,到經驗證的營運或商業成果之間具備說服力的關聯鏈。指南將可衡量的實證與假設區分開來,將 Purple Connect、Capture 和 Engage 對應至正確的衡量層級,並針對飯店、零售物業和活動場館提供規劃情境。

Read guide →

熱點圖 (Heatmapping) 與存在感應分析 (Presence Analytics):技術差異

本權威技術指南詳細介紹了 WiFi 熱點圖與存在感應分析在企業場域營運中的關鍵架構與運作差異。本指南為 IT 主管、網路架構師和營運總監提供了具體可行的部署框架、實際應用場景,以及與廠商無關的最佳實踐,旨在協助企業從現有的無線基礎設施中獲取最大的投資報酬率 (ROI)。

Read guide →

什麼是 Probe Request?深入了解裝置如何探索網路

本技術參考指南深入探討 IEEE 802.11 probe requests、主動與被動掃描,以及 MAC 隨機化對場域分析的影響。本指南為網路架構師提供具體可行的實作策略,以優化高密度部署、減緩 probe storms,並確保在使用已驗證身分層時,進行精確且符合 GDPR 規範的數據收集。

Read guide →

如何在企業無線網路上追蹤不重複裝置

本指南提供在企業無線網路上追蹤不重複裝置的完整技術概述。針對 MAC 隨機化等現代挑戰進行探討,並為場域營運商與 IT 團隊詳細說明實作策略,以維持準確的分析數據與使用者識別。

Read guide →

購物中心如何利用 WiFi 數據分析吸引並留住零售商

這份具權威性的技術參考指南解釋了購物中心 IT 團隊與物業經理如何部署 WiFi 數據分析來擷取人流量數據、衡量各區域的停留時間,並建立協商租約、留住優質零售商以及吸引新租戶所需的實證數據基礎。內容涵蓋了從 AP 部署和 MAC 層數據擷取到符合 GDPR 規範的數據分析儀表板的完整技術堆疊,並為準備在本季實施的 IT 從業人員提供具體的實際案例與決策框架。

Read guide →

動物園與主題樂園 WiFi:高人流量場域連線指南

本指南為 IT 領導者與網路架構師提供在動物園及主題樂園佈署高性能 WiFi 的全面框架。內容涵蓋戶外 RF 規劃、captive portal 佈署、家庭安全內容過濾,以及將連線轉化為具實作價值之營運分析的策略。

Read guide →

WiFi 如何改善醫院的患者體驗

本權威技術指南說明醫院如何利用企業級訪客 WiFi 基礎架構與分析,顯著提升住院患者體驗。內容涵蓋網路架構、合規性要求(HIPAA、DSPT、GDPR)、Captive Portal 設計、定位導航整合以及投資報酬率(ROI)框架,為 IT 決策者提供建立具說服力的內部商業案例並成功執行部署所需的工具。

Read guide →

零售 WiFi:店內 WiFi 如何帶動銷售額、忠誠度與客流量

這份具權威性的技術參考指南詳細介紹了企業 IT 與營運團隊如何將零售 WiFi 部署為策略性商業資產。內容涵蓋了從基本連線到透過第一方數據收集、客流量分析以及安全、高密度網路架構轉型為創收基礎設施的過程。

Read guide →

如何使用 WiFi 分析來改善客戶體驗

本權威指南向 IT 經理、網路架構師和場館營運總監展示如何將訪客 WiFi 轉化為客戶體驗引擎,透過捕捉人流、停留時間和行為資料來實現。內容涵蓋完整的技術架構 - 從探測要求擷取和三角定位,到 Captive Portal 驗證和 CRM 整合 - 並提供實用的部署指導、GDPR 合規要求,以及可衡量的 ROI 架構。來自零售和飯店業的真實案例展示了 WiFi 分析資料如何直接轉化為佈局最佳化、動態人力配置和個人化忠誠度互動。

Read guide →

WiFi 資料收集:您的網路會擷取哪些資料以及如何運用它們

本技術參考指南詳細說明了由受管理的企業 WiFi 網路擷取的四種主要資料類別。它為 IT 主管和場地營運商提供了實用的部署架構、合規框架,以及將原始網路遙測資料轉變為可衡量的商業價值的策略。

Read guide →

WiFi 客流分析:如何測量與運用訪客數據

本指南為 IT 經理、網路架構師和場館營運總監提供了在餐旅、零售、活動和公共部門環境中部署 WiFi 客流分析的務實技術參考。內容涵蓋完整的資料管線 - 從 802.11 探測請求擷取和基於 RSSI 的定位,到符合 GDPR 規範的資料處理和可據以行動的商業智慧儀表板。讀者將獲得一個清晰的部署框架、真實案例研究,以及在本季度選擇、部署和最佳化 WiFi 分析平台所需的決策標準。

Read guide →

WiFi 分析應用案例:企業如何利用位置數據

本指南為 IT 經理、網路架構師、CTO 及場地營運總監提供關於 WiFi 分析應用案例的實用且具權威性的參考 - 涵蓋零售、醫療、餐旅和活動等產業的企業如何利用現有無線基礎設施的位置數據,以提升營運效率並實現商業投資報酬率 (ROI)。本指南深入探討支持空間智慧平台的技術架構,逐步引導實際部署情境,並提供與供應商無關的實作指南,以及合規性與風險緩釋框架。對於任何營運設有訪客 WiFi 之實體場地的組織,本指南規劃了從被動連線走向主動商業智慧的途徑。

Read guide →

什麼是 WiFi 分析?完整指南

本完整技術指南解釋了 WiFi 分析如何將標準網路基礎設施轉變為商業智慧引擎,涵蓋資料捕獲機制(人流、停留時間、裝置類型、重複造訪)、架構考量以及可衡量的 ROI。專為需要評估和部署企業級 WiFi 分析的 IT 經理、網路架構師和場域營運總監而設計。

Read guide →

預測性客流量與 AI:利用 WiFi 數據預測訪客行為模式

本權威技術參考指南詳細介紹企業 IT 團隊與場域營運商如何利用 WiFi 衍生數據和機器學習來精確預測客流量。內容涵蓋數據架構、機器學習模型選擇、隱私考量,以及將被動式儀表板轉化為預測性智慧的實際部署策略。

Read guide →

零售 WiFi:從客流分析到個人化店內體驗

本技術參考指南詳細介紹了零售環境中從傳統顧客 WiFi 到智慧邊緣平台的架構轉變。它為 IT 主管提供了實用的指導,涵蓋如何部署身分驅動的網路、將分析與 CRM 系統整合,以及透過個人化店內體驗推動可衡量的 ROI。從 RF 設計和 Captive Portal 最佳化,到導購整合與 GDPR 合規性,本指南涵蓋了完整的端到端部署生命週期。

Read guide →

對零售業確實重要的 WiFi 分析指標

這份權威參考指南詳細說明了與零售營收、逗留時間和顧客忠誠度直接相關的五個 WiFi 分析指標。它為 IT 經理和場館營運總監提供了一個實用的架構,用於設定網路硬體、減輕 MAC 隨機化的影響,並與行銷團隊在統一的資料儀表板上達成共識。

Read guide →

場域流量熱圖分析:實用指南

本技術參考指南針對在實體場域中部署與分析基於 WiFi 的熱圖,提供了具體可行的策略。本指南說明了 IT 與營運主管如何利用現有的網路基礎架構來發掘客流模式、消除瓶頸並優化空間投資報酬率(ROI)。

Read guide →

OFDMA 解析:WiFi 6 如何應對高密度環境

本指南針對 IEEE 802.11ax (WiFi 6) 標準的核心多使用者技術 - OFDMA(正交頻分多址)進行深入的技術剖析。內容說明了 OFDMA 與傳統 OFDM 的差異、為何其對高密度場域部署至關重要,並為網路架構師和 IT 主管提供具體可行的實作指南。飯店、零售、醫療和活動等領域的場域營運商將能從中獲得具體的部署策略、用戶端需求以及投資報酬率 (ROI) 架構,以評估並執行 WiFi 6 基礎架構的升級。

Read guide →

評估 WiFi 網路效能:IT 團隊的關鍵指標

為 IT 經理與網路架構師提供的全面技術指南,深入探討評估與基準測試企業級 WiFi 網路效能的關鍵指標。本指南提供具體可行的洞察,協助解讀效能數據,進而優化使用者體驗並達成大型場域的業務目標。

Read guide →

Estimote Beacons:設定、組態與應用場景全方位指南

本指南為 IT 經理與網路架構師提供佈署 Estimote beacon 的完整技術參考。內容涵蓋設定、組態以及室內導航、區域感應行銷和資產追蹤等進階應用場景,為企業環境中實現可衡量的投資報酬率 (ROI) 提供具體可行的指導。

Read guide →

Webhook 與 API 輪詢用於 WiFi 資料:該選擇哪一種?

本指南針對擷取 WiFi 智慧資料的 webhook 與 API 輪詢,提供了明確的技術比較。它為 IT 經理、架構師和開發人員提供了可操作的指導,協助他們選擇最佳的資料整合模式,以實現企業環境中的即時回應能力、營運效率和可擴充部署。

Read guide →

WiFi 登入的電子郵件驗證:提升數據品質

本指南為 IT 經理、網路架構師和場地營運總監提供關於 WiFi 登入電子郵件驗證的權威技術參考,說明為何訪客 WiFi 環境會產生劣質的電子郵件數據、Purple 的 Verify 功能如何實作分層驗證架構,以及營運商在部署後可預期的可衡量改善。內容涵蓋完整的驗證技術棧 - 從 RFC 5322 語法檢查到 DNS MX 記錄驗證、拋棄式電子郵件黑名單和 OTP 確認 - 並結合 GDPR 合規考量與 CRM 整合指引。遵循本指南採取行動的場地營運商可預期將無效電子郵件率從行業平均的 25-35% 降低至 2% 以下,從而實質提升行銷投資報酬率、寄件者信譽以及合規防禦能力。

Read guide →

訪客 WiFi 如何支援場地分析與人流追蹤

本指南提供了一個技術與營運框架,說明如何運用訪客 WiFi 深入洞察實體場地中的訪客行為。內容詳述了如何擷取並分析數據以進行人流追蹤和停留時間計算,使 IT 和營運領導者能夠做出數據驅動的決策,進而優化人力配置、改善場地佈局並提高業務投資報酬率。

Read guide →