Privacy Policy

Last updated: July 6, 2026

This policy covers two kinds of people: account holders (tenants who run portals) and guests (people who connect through a portal).

Account holders

We store your email address, a hash of your password, your sites' configuration, and encrypted credentials for the UniFi consoles you connect. Controller passwords are encrypted at rest (AES-256-GCM) and used only to configure your gateway and authorize your guests. Payments are processed by Stripe; we never see your card number. We send transactional email (verification, password resets, service notices) — no marketing without your consent.

Guests

When a guest submits the portal, we record on behalf of the account holder: the email address entered, the device and access-point MAC addresses, the network name (SSID), and a timestamp. The account holder owns this data and is its controller; we process it solely to provide the service — storing it, showing it in their dashboard, and delivering it to them via export, API, or webhooks they configure.

Guests who want their data corrected or deleted should contact the venue or host whose WiFi they used. Account holders can delete individual signups from their dashboard.

Where data lives

Data is stored in a hosted Postgres database and served from cloud infrastructure in the United States. Webhook deliveries go wherever the account holder points them.

Retention

Captured signups are kept until the account holder deletes them or their account. Webhook delivery logs are pruned after 30 days. Deleting your account removes your sites, credentials, and captured signups.

Changes

Material changes will be announced by email to account holders.

Questions: matt@soldo.org