Legal
Privacy policy
Last updated 28 Sept 2026
This policy explains how Wispot ("Wispot", "we", "us") handles personal data when you visit wispot.net, use the Wispot dashboard, or connect to a Wi-Fi network run by a business that uses Wispot. We follow the Nigeria Data Protection Act 2023 (NDPA) and the guidance of the Nigeria Data Protection Commission (NDPC).
Who is responsible for your data
- Businesses using Wispot ("operators"). For operators and their staff, we are the data controller for account, billing and security data.
- Customers of those businesses. When you buy Wi-Fi at a café, hotel or other venue that uses Wispot, that business is the data controller for your data, and we process it on its behalf as a data processor, following its instructions and this policy. Questions about how a venue uses your data should go to that venue first; we will help it respond.
What we collect
From operators and their staff
- Name, email address, phone number, business name, business type and state.
- Password (stored only as a salted hash), two-factor settings, sign-in times and approximate IP address (for security and fraud prevention).
- Payment provider settings. Secret keys are encrypted and never shown back in full.
- Records of actions in the dashboard (the audit log), support conversations and billing records.
From Wi-Fi customers (on behalf of operators)
- Phone number, and optionally name and email address.
- Device identifiers the router shares (MAC address), plan purchases, data used, session times and the location used.
- Payment references and amounts. We never receive or store card numbers or bank passwords: payments are handled on the payment provider's secure page.
- Wallet balances, referral codes and points, and messages sent to you (such as receipts or announcements) if the operator uses those features.
From website visitors
- Information you send through our forms (name, business, phone, email, message).
- Basic technical logs (IP address, browser, pages requested) kept for security and troubleshooting.
Why we use it, and our lawful basis
| Purpose | Lawful basis (NDPA s.25) |
|---|---|
| Providing the service: accounts, Wi-Fi access, payments, receipts | Performance of a contract |
| Verifying identity, preventing fraud and abuse, keeping systems secure | Legitimate interests; legal obligation |
| Billing operators and keeping financial records | Contract; legal obligation |
| Replying to enquiries and setup requests | Steps before a contract; legitimate interests |
| Product emails about new features to operators | Legitimate interests (you can opt out any time) |
| Marketing messages to Wi-Fi customers | The operator's lawful basis, usually consent |
We do not sell personal data, and we do not use it for advertising profiles.
Who we share it with
Only with service providers that help us run Wispot, under written agreements that require them to protect it:
- Payment providers chosen by each operator (Paystack, and where enabled Flutterwave or Monnify), to process payments.
- Messaging providers: our email provider, Termii for SMS, and Meta (WhatsApp Cloud API) where an operator enables WhatsApp.
- Cloudinary, to store and deliver images operators upload (such as Wi-Fi page ads).
- Hosting and infrastructure providers for our servers, databases and backups.
We may also disclose data where the law requires it, or to protect the rights, safety and property of our users, the public or us.
Transfers outside Nigeria
Some providers (for example Cloudinary, Meta and certain email services) may process data outside Nigeria. Where they do, we rely on the transfer mechanisms in Part VIII of the NDPA, including adequacy or appropriate contractual safeguards, and we transfer only what is needed for the service.
How long we keep it
- Operator accounts: for as long as the account is active, then up to 12 months after closure, except records we must keep longer by law.
- Financial and billing records: 6 years, as required for tax and accounting.
- Wi-Fi customer data: for as long as the operator uses Wispot, or until the operator deletes it, and in any case no longer than needed for the purposes above. Usage and session records are summarised or deleted after 24 months.
- Security logs: up to 12 months.
- Website enquiries: up to 24 months after our last contact.
How we protect it
Encryption in transit (HTTPS/TLS) and at rest for secrets, hashed passwords, two-factor sign-in for owners, account verification, least-privilege access for our staff, an append-only audit log, and regular backups. No system is perfectly secure; if a personal data breach is likely to put your rights at risk, we will notify the NDPC and affected people as the NDPA requires.
Your rights
Under the NDPA you can ask to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent where we rely on it. Wi-Fi customers should contact the venue first; we will help it respond.
To exercise a right, email [email protected]. We respond within 30 days. If you are not satisfied, you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng).
Cookies and similar technologies
We use only what the service needs: a session cookie to keep you signed in, and your browser's local storage to remember choices such as light or dark mode and, on Wi-Fi pages, your plan login on your own device. We do not use advertising or cross-site tracking cookies.
Children
Wispot is not directed at children under 13. Operators who sell Wi-Fi to minors (for example on a school campus) are responsible for doing so lawfully.
Changes
We will post changes here and update the date above. For significant changes affecting operators, we will also email account owners.
Contact
Wispot, . Privacy questions: [email protected]. General support: [email protected].