Skip to content
HaloWiFi
  • Features
  • Products
  • Pricing
  • Case studies
  • About
Halo CloudBook a demo
  • Features
  • Products
  • Pricing
  • Case studies
  • About
Book a 20-min demo
Legal/Privacy Policy

Privacy Policy

MassvHalo Pvt. Ltd. (“HaloWiFi”, “we”, “us”). Version 1.4, effective 16 September 2026. Last updated 16 September 2026.

The one-line summaries under each heading are there for convenience. The full text is what applies.

Contents

  1. 1. Who we are and how to reach us
  2. 2. Who this policy covers
  3. 3. What we collect, and from whom
  4. 4. Why we use it, and the legal basis
  5. 5. Storage on your device, and your analytics choice
  6. 6. Who we share it with
  7. 7. Where it is stored and how it moves
  8. 8. How we protect it
  9. 9. How long we keep it
  10. 10. Your rights
  11. 11. Children
  12. 12. Marketing messages
  13. 13. Changes to this policy
  14. 14. Grievances and complaints
  15. Version history

1. Who we are and how to reach us

In short: MassvHalo Pvt. Ltd., Bengaluru. Privacy questions go to [email protected].

MassvHalo Pvt. Ltd., CIN U61900KA2024PTC196331, registered office 126, RNS Plaza, Electronic City Phase II, Bangalore, Karnataka 560100, India, is responsible for the personal data described in this policy, except where section 2 says a venue is responsible.

Privacy requests and questions: [email protected].
Grievance Officer (Digital Personal Data Protection Act, 2023): Amit K, Grievance Officer, [email protected], 126, RNS Plaza, Electronic City Phase II, Bangalore, Karnataka 560100, India. We acknowledge grievances within two working days and respond within thirty working days.

2. Who this policy covers

In short: website visitors, our customers, and guests at venues. Guests: your venue is responsible for your data; we process it for them.

This policy covers three groups of people, and it is different for each:

Website visitors. Anyone using halowifi.com or docs.halowifi.com. We are responsible for your data.

Customers. Venue operators, their staff and their partners who hold a Halo Cloud account, buy HaloWiFi hardware, or contact us about doing so. We are responsible for your account, billing and support data. The Service Agreement adds detail.

Guests. People who connect to WiFi at a venue that runs HaloWiFi. The venue decides what its captive portal asks you for, what it does with your data, and how long it keeps it. In the language of the Digital Personal Data Protection Act, 2023, the venue is the Data Fiduciary and we are its Data Processor; under the GDPR and similar laws, the venue is the controller and we are the processor. We process guest data only on the venue’s instructions, set out in the Service Agreement. If you have a question or request about your data as a guest, the venue is the right first contact, and its details are shown on the portal. If you cannot reach the venue, write to [email protected] and we will pass your request to them and help them respond.

3. What we collect, and from whom

In short: what you give us, what your browser sends, and, for venues, what the portal and the router record.

Website visitors

  • Enquiries and demo bookings: name, work email, phone (optional), company, and details about your venue (type, size, number of properties), and anything you write in a message.
  • Calculator inputs, if you ask us to send you a breakdown.
  • Newsletter sign-ups: email address.
  • Usage analytics: pages visited, referrer, browser and device type, and your IP address, from which PostHog works out an approximate location — country, and sometimes region or city. The IP address is stored on the event. Collected by PostHog; see section 5 for the cookie it sets and how to turn it off.
  • Session recordings: where analytics is running, PostHog also records a replay of your visit to this website — the pages you open, how far you scroll, and where you click or tap. Everything you type is masked in your browser before anything is sent, so the demo form, the contact form and the calculator fields are recorded as blocked-out shapes and never as text. We do not record Halo Cloud, and we never record a venue’s guest portal.
  • Server logs: IP address, request time and path, kept for security and debugging by our hosting provider, Cloudflare.

Customers

  • Account: name, work email, phone, role, organisation, and the venues you manage.
  • Billing: billing address, tax identifiers, and payment records. Card details are handled by Stripe and Razorpay and never stored by us.
  • Support: what you send us when you ask for help, including screenshots and diagnostic exports you choose to share.
  • Device telemetry from HaloWiFi hardware: device identifiers, firmware version, uptime, throughput, connected-client counts, and error reports. Telemetry is about devices; it becomes personal data only where it can be linked to an individual staff member’s account.

Guests (processed on the venue’s behalf)

What is collected depends on how the venue has configured its portal. It may include:

  • What you enter at the portal: name, email address, mobile number (for OTP verification), date of birth, room or booking number, or a social login token, and any consent you give for marketing.
  • What the network records to run your session: your device’s MAC address, the time you connected and disconnected, the amount of data used, the access point you connected through (which gives an approximate location inside the venue), and the device type.
  • Your visit history at that venue, so a returning device can be recognised and, if the venue has enabled it, reconnected without the portal.
  • Browsing content is not inspected or recorded. We do not perform deep packet inspection of guest traffic. DNS queries are not logged or stored; the router caches resolved records locally for a short period, as any resolver does, and that cache is not retained.

4. Why we use it, and the legal basis

In short: to answer you, run the service, keep it secure, and send you what you asked for. We do not sell personal data.

Purposes, who they apply to, and the legal basis under the DPDP Act and the GDPR
PurposeWhoBasis under the DPDP ActBasis under GDPR (where it applies)
Responding to enquiries and running demosVisitorsConsent, given when you submit the formSteps at your request before a contract
Providing Halo Cloud, hardware support and billingCustomersConsent and legitimate use (performance of the contract you asked for)Performance of a contract
Operating the guest network, portal login and session managementGuestsOn the venue’s instructions as its processorOn the venue’s instructions as its processor
Website analytics and session recordingsVisitorsConsent, given through the panel described in section 5 where it is shownConsent, given through that panel, which is shown throughout the EEA, the UK and Switzerland
Security, fraud prevention and abuse detectionAllLegitimate use (security)Legitimate interests
Product improvement using aggregated, de-identified dataAllNot personal data once de-identified; we do not re-identifyNot personal data
Newsletter and product updatesVisitors, customersConsent, withdrawable at any timeConsent
Legal obligations (tax records, lawful requests)CustomersLegitimate use (legal compliance)Legal obligation

We do not sell personal data. We do not use guest data for our own marketing. We do not build profiles of guests across venues.

5. Storage on your device, and your analytics choice

In short: the site’s own values are not tracking cookies. Analytics is, it sets one cookie, and you can turn it off.

The website’s own values

Separately from analytics, the website keeps five small values in your browser and nowhere else: your light or dark theme choice, the country the site resolved for pricing and contact hints (kept for the session only), the currency you chose on the revenue calculator, your answer to the analytics question below, and, after a contact form is successfully sent, the work email you entered so the next form is pre-filled. Two session-only flags remember that you closed the demo bar and that you have seen the demo prompt. None of these is a tracking cookie, none is sent to a third party, and clearing your browser’s site data removes them.

Analytics, and the cookie it sets

Until 11 September 2026 our analytics was cookieless and stored nothing on your device. It is not any more, and this section changed with it. When analytics is running, PostHog sets one first-party cookie on halowifi.com, and a matching entry in your browser’s local storage, holding a random identifier. That identifier lets PostHog recognise the same browser from page to page and visit to visit, and tie a session recording to the visit it came from. It is an analytics cookie: unlike the values above, its purpose is to recognise your browser over time. It is read by no one but PostHog and us, we do not use it for advertising, and it is not shared with any ad network. Clearing your browser’s site data removes it. Our product documentation at docs.halowifi.com runs the same analytics under the same rules and behind the same choice: the same panel asks first in the EEA, the UK and Switzerland, and its footer carries its own Cookie choices link. Each site stores your answer separately, so a choice made on one does not carry over to the other.

Analytics events also carry your IP address: PostHog uses it to work out an approximate location, and keeps it on the event. That was a deliberate change, made in the same release and for the same reason — PostHog cannot both discard the address and derive a country from it, and while it was discarding it we could not tell which countries the site was being read in at all.

Session recordings

With analytics running, PostHog also records a replay of your visit, reconstructed from the page as you saw it: the pages you open, your scrolling, and your clicks or taps. Every input is masked in your browser before anything leaves it, so what you type into the demo form, the contact form or the revenue calculator is stored as a blocked-out shape and never as text. We watch recordings to find where the site confuses people, and for no other purpose. They are stored by PostHog in the EU and deleted after 30 days (section 9).

Your choice

If you are in the EEA, the UK or Switzerland, none of this happens unless you agree to it. On your first visit a panel appears with an Accept and a Decline button, and until you choose Accept no analytics cookie is set, no recording is made, and nothing is sent to PostHog — the analytics code itself is not even downloaded. Your answer is stored in your browser for 180 days, after which we ask again. Elsewhere, analytics runs by default.

Wherever you are, the Cookie choices link in the footer of every page reopens that panel, so you can turn analytics off, or back on, at any time. Turning it off stops any further collection and any further recording. If your browser sends a Global Privacy Control signal, we treat it as a no and do not ask.

Halo Cloud

The Halo Cloud application stores a session token in your browser to keep you signed in. It expires after 14 days or when you sign out.

6. Who we share it with

In short: the providers we need to run the business, the venue for guest data, and the law when required. No one else.

Service providers (subprocessors). Companies that process data for us under contract, bound by confidentiality and data-protection obligations, and only for the purposes above:

Service providers that process data for us, their purpose and location
ProviderPurposeLocation
CloudflareWebsite hosting and edge securityGlobal edge network
Amazon Web Services and HetznerHalo Cloud hosting and databasesMumbai, N. Virginia, N. California, Frankfurt, Cape Town, Nuremberg
Amazon SESTransactional email and newslettersIreland (EU) and N. Virginia (USA)
MSG91 and TwilioOne-time codes for portal loginIndia (MSG91); USA and EU (Twilio)
PostHog (PostHog, Inc., EU cloud)Website analytics and session recordingsGermany (EU)
Stripe and RazorpayBillingUSA and Ireland (Stripe); India (Razorpay)

Support is handled by our own team; no third-party ticketing provider processes your data.

We will update this table when a provider changes. Customers receive thirty days’ notice of a new subprocessor that will handle guest data, as set out in the Service Agreement.

Venues. Guest data is the venue’s; we make it available to the venue through Halo Cloud and, where the venue has configured integrations, to the systems the venue connects (for example, its property management or CRM system). The venue chooses those integrations.

Legal and safety. We disclose personal data where the law requires it, in response to a valid legal request, or where necessary to protect the safety or rights of any person. Where the law allows, we tell the affected customer first.

Business transfers. If MassvHalo Pvt. Ltd. is involved in a merger, acquisition or sale of assets, personal data may transfer with the business, and this policy will continue to apply to it until changed with notice.

7. Where it is stored and how it moves

In short: Halo Cloud is hosted in the region closest to your venue; where data leaves a country we use recognised transfer safeguards.

Halo Cloud runs on AWS and Hetzner, in the region closest to the venue it serves: Mumbai, N. Virginia, N. California, Frankfurt, Cape Town and Nuremberg. Website data is served through Cloudflare’s global edge. Customers may request hosting in any of those regions under the Service Agreement.

Because HaloWiFi runs in venues in several countries, guest data may be processed outside the country it was collected in. Where the law of the collecting country restricts transfers, we rely on the safeguards that law recognises (for the EEA and UK, the standard contractual clauses and the UK addendum; for India, transfers to countries not restricted by the central government under the DPDP Act) and on the venue’s instructions.

8. How we protect it

In short: encryption in transit, access controls, guest isolation, and a breach process.

  • All connections to the website, Halo Cloud and the API use TLS.
  • Guest traffic on a HaloWiFi network is isolated from the venue’s staff and management networks by default.
  • Access to Halo Cloud data by our staff is role-based, logged, and limited to what support and operations need.
  • Portal credentials are verified by one-time codes; we do not store guest passwords.
  • We keep device firmware and platform dependencies updated and accept vulnerability reports at [email protected].
  • If we become aware of a personal data breach affecting customer or guest data, we will notify the affected customer without undue delay and within the periods required by the applicable law, with enough detail for them to meet their own obligations, and we will notify the Data Protection Board of India and affected individuals where the DPDP Act requires it.

No system is completely secure; these are the measures we take, not a guarantee.

9. How long we keep it

In short: as long as needed for the purpose, then deleted. Guest retention is set by the venue.

How long each kind of data is kept
DataKept for
Enquiries and demo bookingsWhile we have an active conversation or relationship, then 12 months, then deleted; sooner on request
NewsletterUntil you unsubscribe
Website analytics12 months, aggregated
Session recordings30 days from the visit, then deleted by PostHog
Server logs12 months, as Indian licensing requires
Customer account and billingFor the life of the account, then as long as tax and company law require (8 years, under the Companies Act, 2013)
Support records12 months after the ticket closes
Device telemetry12 months, then aggregated
Guest portal data and session recordsAs configured by the venue in Halo Cloud, within the maximum of 12 months we allow; deleted or returned to the venue when the Service Agreement ends, within 30 days

10. Your rights

In short: ask us for access, correction, deletion or a copy; withdraw consent any time; complain to us or the regulator.

Everyone. You can ask us to access, correct, update, or delete the personal data we hold about you, to give you a copy in a usable format, and to stop sending you marketing. Where we rely on your consent, you can withdraw it at any time; this does not affect processing that already happened. Write to [email protected]. We respond within thirty days and may ask you to confirm your identity first.

Under the DPDP Act (India). In addition, you have the right to nominate another person to exercise these rights on your behalf if you are unable to, and the right to raise a grievance with our Grievance Officer (section 1). If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Under the GDPR and UK GDPR. In addition, you have the right to restrict or object to processing based on legitimate interests, the right to data portability, and the right to complain to the supervisory authority in your country. We have not appointed a representative in the EEA or UK.

Guests. For data collected at a venue, the venue decides these requests and we help it respond. Contact the venue first (its details are on the portal), or write to us and we will route your request.

11. Children

In short: the website and Halo Cloud are for adults; venues decide their own portal rules.

The website and Halo Cloud are intended for business users aged 18 and over, and we do not knowingly collect personal data from children through them. Venues decide who may use their guest WiFi and whether their portal collects any data from minors; where the venue’s portal asks for a date of birth, that is the venue’s configuration, and the venue is responsible for obtaining any consent the law requires from a parent or guardian. If you believe a child’s data has been collected through HaloWiFi in error, write to [email protected] and we will help the venue address it.

12. Marketing messages

In short: only if you asked; unsubscribe in every message.

We send newsletters and product updates only to people who signed up or who are customers. Every message has a one-click unsubscribe, and unsubscribing takes effect within 48 hours. We do not send marketing to guests, and any marketing a venue sends to its guests through HaloWiFi is the venue’s, under its own consent.

13. Changes to this policy

In short: versioned, dated, and announced when material.

We may update this policy. The version and dates at the top and the history at the bottom show what changed and when. Material changes are noted on the website for at least thirty days, and customers are emailed at the account contact.

14. Grievances and complaints

In short: our Grievance Officer first; then the Data Protection Board of India or your local authority.

If you are unhappy with how we have handled your personal data or a request about it, write to our Grievance Officer, Amit K, at [email protected] with “Grievance” in the subject line. We acknowledge within two working days and aim to resolve within thirty working days. If you remain unsatisfied, you may complain to the Data Protection Board of India, or, if you are in the EEA or UK, to your local data protection authority.

Version history

  • 1.4, 16 September 2026: named docs.halowifi.com, our product documentation site, which runs the same analytics as halowifi.com behind the same consent choice, in sections 2 and 5. No other change.
  • 1.3, 11 September 2026: our website analytics is no longer cookieless: PostHog now sets a first-party analytics cookie, records your IP address and derives an approximate location from it, and records a replay of the visit with every input masked. Added the consent panel shown in the EEA, the UK and Switzerland, the Global Privacy Control signal, a retention period for recordings, and a legal basis for analytics. Rewrote section 5 and updated the subprocessor and retention tables.
  • 1.2, 8 September 2026: named our subprocessors and their locations, set retention periods, named the Grievance Officer, and stated that DNS queries are not logged.
  • 1.1, 2 September 2026: first published version.

Terms of Service → · Guest WiFi Terms →

The guest WiFi playbook, monthly.

One email a month on making venue WiFi pay for itself. No spam, unsubscribe anytime.

Product

  • Features
  • Hardware
  • Pricing
  • Compare
  • API

Company

  • About
  • Case studies
  • Deployments
  • Blog
  • Contact

Support

  • Documentation
  • Status
  • Contact us
  • WhatsApp support

Legal

  • Privacy
  • Terms
  • Guest WiFi terms
  • Cookie choices
  • All legal
HaloWiFiHaloWiFi© 2026 MassvHalo. All rights reserved.
Book a 20-min demo