Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains what Barista WiFi (Vodola Ventures LLC) collects, how we use it, and the choices you have. We built this company on a simple promise: we never sell your data, and we never sell the data of the guests who connect to your Wi-Fi.
What we collect
- From shop owners (the businesses that use Barista WiFi): your name, email address, phone number, business name and address, and billing details. Card payments are processed by Stripe — we never see or store full card numbers.
- From guestswho connect to a shop's Wi-Fi through our captive portal: the information the shop asks for on its sign-in page — typically name and email, and optionally phone number — along with the device's hardware (MAC) address, connection timestamps, and whether the guest chose to receive marketing.
- What we don't collect: we do not log the websites guests visit, the contents of their traffic, or their passwords. We have no interest in browsing history.
What we do with it
We use this information only to:
- provide and operate the Wi-Fi service;
- recognize returning guests so they don't have to sign in every visit;
- send the marketing emails and texts a guest has chosen to receive from the shop;
- bill shop owners and provide customer support;
- prevent abuse, keep the network secure, and comply with the law.
We never sell personal data — not to advertisers, not to data brokers, not to anyone.
Google sign-in
If a guest chooses to sign in with Google, we receive only their name and email address from Google, and only to identify them for Wi-Fi access. We do not request or access any other Google account data. Barista WiFi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Third parties
We share data only with the service providers that help us run Barista WiFi, and only as needed to provide the service:
- Stripe — payment processing and billing.
- SendGrid— delivering email on a shop's behalf.
- Twilio — sending SMS verification codes and texts.
- Supabase — secure database and authentication hosting.
- Google — guest sign-in, when a guest chooses it.
- Ubiquiti (UniFi) — the Wi-Fi hardware and network platform.
Each provider is contractually bound to use the data only to perform its service for us. We do not authorize any of them to use it for their own purposes.
Retention & deletion
We keep guest data for as long as the shop's account is active and the guest hasn't asked to be removed. Guests can unsubscribe from marketing at any time using the link in any email, which stops further marketing immediately. A shop owner can delete individual guests or close their whole account; when an account is closed, we delete its data within 30 days, except limited records we must keep for legal, tax, or fraud-prevention purposes. Routine backups may persist for a short period before they cycle out.
Controller vs. processor
For guest data collected through a shop's captive portal, the shop is the data controller and Barista WiFi acts as its processor— we handle that data on the shop's instructions. For a shop owner's own account information, Barista WiFi is the controller. Shop owners are responsible for having a lawful basis to collect from and market to their guests.
Your rights
Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to access, correct, or delete your personal data, to opt out of marketing, and to opt out of any “sale” of personal data — though we don't sell it in the first place. Guests should direct requests to the shop they connected at; shop owners and anyone else can contact us directly. We will never discriminate against you for exercising these rights.
Privacy contact
For any privacy question or request, email hello@baristawifi.com. We may update this policy from time to time; material changes will be reflected by the “last updated” date above.