If you run a restaurant, hotel, bar, or any hospitality venue with guest WiFi, you have almost certainly encountered a captive portal — even if you didn't know it by that name. It's the screen that appears when a guest connects to your WiFi and asks them to log in, agree to terms, or register before they can get online.
Done well, a captive portal is one of the highest-value touchpoints in hospitality. Done poorly, it's an annoying pop-up that guests dismiss in two seconds and forget. This guide explains what a captive portal is, how it works technically, and how to use one to build real guest relationships.
The basic definition
A captive portal is a web page that intercepts a device's internet access and redirects it to a login or registration page. The guest's device is "captured" on a local network — able to reach the portal but not the open internet — until the login conditions are met.
You encounter captive portals in airports, hotels, coffee shops, stadiums, and public transport. The mechanism is the same in each case: the network router redirects all HTTP traffic to the portal page until the guest authenticates.
Key point: A captive portal is not just a nuisance gate. For hospitality operators, it is a first-party data capture point that sits between a guest and your WiFi — the single moment when you can legitimately collect their name, email and marketing consent before they've even ordered.
How a captive portal works technically
The process has three stages:
- Connection: The guest's device joins your WiFi network via the router or access point. The router assigns an IP address but blocks all traffic except DNS and access to the portal server.
- Redirect: When the guest opens a browser (or when their device auto-detects a captive portal), they are redirected to the portal login page. This redirect is handled by the router via a DHCP lease or HTTP redirect rule.
- Authentication: The guest completes the login — typically by entering their name and email, or by logging in via a social account. The router then whitelists their device's MAC address and grants full internet access.
Modern captive portal platforms, including CaptiveWiFi, handle the portal page and authentication server separately from the router. This allows the portal to be fully branded, GDPR-compliant, and integrated with your CRM — regardless of which access point hardware you use.
What guest data can a captive portal collect?
At the point of WiFi login, a captive portal can collect:
- First name and surname
- Email address (verified, not a booking-platform alias)
- Date of birth (for age verification or birthday rewards)
- Marketing consent and opt-in timestamp
- Visit timestamp and frequency
- Device type
This data is first-party — provided directly by the guest to you, not inferred or purchased. First-party data is the most valuable kind for building a CRM, personalising communications, and measuring loyalty.
Captive portals and GDPR
In the UK and EU, collecting personal data through a WiFi login is legal — but you must have a lawful basis. For marketing, that basis is explicit consent. The captive portal must:
- Clearly explain what data is being collected and why
- Provide a specific, unticked opt-in checkbox for marketing
- Link to your Privacy Policy
- Record the consent timestamp and wording shown to the guest
Pre-ticked boxes, bundled consent, and vague "by connecting you agree to everything" clauses are not compliant. PECR (the UK's electronic privacy regulation) adds an additional requirement: you cannot send marketing emails to someone who has connected to your WiFi unless they have actively opted in to receive them.
CaptiveWiFi's captive portal includes a built-in GDPR consent framework that captures and stores consent records automatically. Operators cannot modify the consent flow in a way that removes required disclosures.
Social login vs. email login
Most captive portal platforms offer two login methods:
- Email login: The guest enters their name and email address. You get first-party data directly. This is the recommended method for building a clean CRM.
- Social login (Facebook, Google): The guest authenticates via a social account. Faster for the guest, but data quality depends on what the platform shares — and social platform policy changes can affect what you can access.
For hospitality operators focused on loyalty and repeat visits, email login consistently produces higher-quality data. CaptiveWiFi venues using email login see a +90% opt-in rate on average — significantly higher than email capture rates through booking platforms.
What to do with captive portal data
The value of a captive portal is not in the data itself — it's in what you do with it. The most effective hospitality operators use their guest WiFi data to:
- Sync new guest records to their CRM (SevenRooms, Klaviyo, Airship, OpenTable) automatically
- Enrol guests in loyalty programmes in the same session
- Send a post-visit follow-up email within 24 hours
- Identify repeat visitors and personalise their next experience
- Track footfall patterns by day, time, and location
Guests who receive a personalised follow-up within 24 hours of a visit are more likely to return than those who receive nothing, based on hospitality industry benchmarks.
Choosing a captive portal platform
When evaluating captive portal software for your venue, look for:
- GDPR compliance: The platform must handle consent capture, storage and withdrawal. Ask to see sample consent records.
- CRM integrations: Look for native connections to the platforms you already use, not just Zapier webhooks.
- Branding control: Your portal should look like you, not like a generic login screen. Brand recognition at login improves opt-in rates.
- Hardware compatibility: Check that the platform works with your existing access points (Cisco Meraki, Ubiquiti, Ruckus, TP-Link Omada, etc.).
- Analytics: Real-time footfall, repeat visit rates, and campaign attribution matter more than raw connection counts.
CaptiveWiFi is built exclusively for hospitality operators in the UK and Europe. If you'd like to see how it works at a live venue, book a 15-minute demo. For the compliance side of running a captive portal, read our guide to GDPR-compliant WiFi data capture.