Privacy Policy
The one-line summaries under each heading are there for convenience. The full text is what applies.
1. Who we are and how to reach us
In short: MassvHalo Pvt. Ltd., Bengaluru. Privacy questions go to [email protected].
MassvHalo Pvt. Ltd., CIN U61900KA2024PTC196331, registered office 126, RNS Plaza, Electronic City Phase II, Bangalore, Karnataka 560100, India, is responsible for the personal data described in this policy, except where section 2 says a venue is responsible.
Privacy requests and questions: [email protected].
Grievance Officer (Digital Personal Data Protection Act, 2023): Amit K, Grievance Officer, [email protected], 126, RNS Plaza, Electronic City Phase II, Bangalore, Karnataka 560100, India. We acknowledge grievances within two working days and respond within thirty working days.
2. Who this policy covers
In short: website visitors, our customers, and guests at venues. Guests: your venue is responsible for your data; we process it for them.
This policy covers three groups of people, and it is different for each:
Website visitors. Anyone using halowifi.com. We are responsible for your data.
Customers. Venue operators, their staff and their partners who hold a Halo Cloud account, buy HaloWiFi hardware, or contact us about doing so. We are responsible for your account, billing and support data. The Service Agreement adds detail.
Guests. People who connect to WiFi at a venue that runs HaloWiFi. The venue decides what its captive portal asks you for, what it does with your data, and how long it keeps it. In the language of the Digital Personal Data Protection Act, 2023, the venue is the Data Fiduciary and we are its Data Processor; under the GDPR and similar laws, the venue is the controller and we are the processor. We process guest data only on the venue’s instructions, set out in the Service Agreement. If you have a question or request about your data as a guest, the venue is the right first contact, and its details are shown on the portal. If you cannot reach the venue, write to [email protected] and we will pass your request to them and help them respond.
3. What we collect, and from whom
In short: what you give us, what your browser sends, and, for venues, what the portal and the router record.
Website visitors
- Enquiries and demo bookings: name, work email, phone (optional), company, and details about your venue (type, size, number of properties), and anything you write in a message.
- Calculator inputs, if you ask us to send you a breakdown.
- Newsletter sign-ups: email address.
- Usage analytics: pages visited, referrer, approximate location by country, browser and device type, collected by PostHog. This analytics is cookieless; see section 5.
- Server logs: IP address, request time and path, kept for security and debugging by our hosting provider, Cloudflare.
Customers
- Account: name, work email, phone, role, organisation, and the venues you manage.
- Billing: billing address, tax identifiers, and payment records. Card details are handled by Stripe and Razorpay and never stored by us.
- Support: what you send us when you ask for help, including screenshots and diagnostic exports you choose to share.
- Device telemetry from HaloWiFi hardware: device identifiers, firmware version, uptime, throughput, connected-client counts, and error reports. Telemetry is about devices; it becomes personal data only where it can be linked to an individual staff member’s account.
Guests (processed on the venue’s behalf)
What is collected depends on how the venue has configured its portal. It may include:
- What you enter at the portal: name, email address, mobile number (for OTP verification), date of birth, room or booking number, or a social login token, and any consent you give for marketing.
- What the network records to run your session: your device’s MAC address, the time you connected and disconnected, the amount of data used, the access point you connected through (which gives an approximate location inside the venue), and the device type.
- Your visit history at that venue, so a returning device can be recognised and, if the venue has enabled it, reconnected without the portal.
- Browsing content is not inspected or recorded. We do not perform deep packet inspection of guest traffic. DNS queries are not logged or stored; the router caches resolved records locally for a short period, as any resolver does, and that cache is not retained.
4. Why we use it, and the legal basis
In short: to answer you, run the service, keep it secure, and send you what you asked for. We do not sell personal data.
| Purpose | Who | Basis under the DPDP Act | Basis under GDPR (where it applies) |
|---|---|---|---|
| Responding to enquiries and running demos | Visitors | Consent, given when you submit the form | Steps at your request before a contract |
| Providing Halo Cloud, hardware support and billing | Customers | Consent and legitimate use (performance of the contract you asked for) | Performance of a contract |
| Operating the guest network, portal login and session management | Guests | On the venue’s instructions as its processor | On the venue’s instructions as its processor |
| Security, fraud prevention and abuse detection | All | Legitimate use (security) | Legitimate interests |
| Product improvement using aggregated, de-identified data | All | Not personal data once de-identified; we do not re-identify | Not personal data |
| Newsletter and product updates | Visitors, customers | Consent, withdrawable at any time | Consent |
| Legal obligations (tax records, lawful requests) | Customers | Legitimate use (legal compliance) | Legal obligation |
We do not sell personal data. We do not use guest data for our own marketing. We do not build profiles of guests across venues.
5. Storage on your device
In short: the site keeps a few small values in your browser. None is a tracking cookie.
The website keeps four small values in your browser and nowhere else: your light or dark theme choice, the country the site resolved for pricing and contact hints (kept for the session only), the currency you chose on the revenue calculator, and, after a contact form is successfully sent, the work email you entered so the next form is pre-filled. Two session-only flags remember that you closed the demo bar and that you have seen the demo prompt. None of them is a tracking cookie, none is sent to a third party, and clearing your browser’s site data removes them.
Our analytics does not set cookies or store identifiers on your device. PostHog counts visitors with a one-way hash of your network address and browser type, computed on its servers in the EU with a secret that changes and is discarded every day, so the hash cannot be reversed or linked across days.
The Halo Cloud application stores a session token in your browser to keep you signed in. It expires after 14 days or when you sign out.
6. Who we share it with
In short: the providers we need to run the business, the venue for guest data, and the law when required. No one else.
Service providers (subprocessors). Companies that process data for us under contract, bound by confidentiality and data-protection obligations, and only for the purposes above:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Website hosting and edge security | Global edge network |
| Amazon Web Services and Hetzner | Halo Cloud hosting and databases | Mumbai, N. Virginia, N. California, Frankfurt, Cape Town, Nuremberg |
| Amazon SES | Transactional email and newsletters | Ireland (EU) and N. Virginia (USA) |
| MSG91 and Twilio | One-time codes for portal login | India (MSG91); USA and EU (Twilio) |
| PostHog (PostHog, Inc., EU cloud) | Website analytics | Germany (EU) |
| Stripe and Razorpay | Billing | USA and Ireland (Stripe); India (Razorpay) |
Support is handled by our own team; no third-party ticketing provider processes your data.
We will update this table when a provider changes. Customers receive thirty days’ notice of a new subprocessor that will handle guest data, as set out in the Service Agreement.
Venues. Guest data is the venue’s; we make it available to the venue through Halo Cloud and, where the venue has configured integrations, to the systems the venue connects (for example, its property management or CRM system). The venue chooses those integrations.
Legal and safety. We disclose personal data where the law requires it, in response to a valid legal request, or where necessary to protect the safety or rights of any person. Where the law allows, we tell the affected customer first.
Business transfers. If MassvHalo Pvt. Ltd. is involved in a merger, acquisition or sale of assets, personal data may transfer with the business, and this policy will continue to apply to it until changed with notice.
7. Where it is stored and how it moves
In short: Halo Cloud is hosted in the region closest to your venue; where data leaves a country we use recognised transfer safeguards.
Halo Cloud runs on AWS and Hetzner, in the region closest to the venue it serves: Mumbai, N. Virginia, N. California, Frankfurt, Cape Town and Nuremberg. Website data is served through Cloudflare’s global edge. Customers may request hosting in any of those regions under the Service Agreement.
Because HaloWiFi runs in venues in several countries, guest data may be processed outside the country it was collected in. Where the law of the collecting country restricts transfers, we rely on the safeguards that law recognises (for the EEA and UK, the standard contractual clauses and the UK addendum; for India, transfers to countries not restricted by the central government under the DPDP Act) and on the venue’s instructions.
8. How we protect it
In short: encryption in transit, access controls, guest isolation, and a breach process.
- All connections to the website, Halo Cloud and the API use TLS.
- Guest traffic on a HaloWiFi network is isolated from the venue’s staff and management networks by default.
- Access to Halo Cloud data by our staff is role-based, logged, and limited to what support and operations need.
- Portal credentials are verified by one-time codes; we do not store guest passwords.
- We keep device firmware and platform dependencies updated and accept vulnerability reports at [email protected].
- If we become aware of a personal data breach affecting customer or guest data, we will notify the affected customer without undue delay and within the periods required by the applicable law, with enough detail for them to meet their own obligations, and we will notify the Data Protection Board of India and affected individuals where the DPDP Act requires it.
No system is completely secure; these are the measures we take, not a guarantee.
9. How long we keep it
In short: as long as needed for the purpose, then deleted. Guest retention is set by the venue.
| Data | Kept for |
|---|---|
| Enquiries and demo bookings | While we have an active conversation or relationship, then 12 months, then deleted; sooner on request |
| Newsletter | Until you unsubscribe |
| Website analytics | 12 months, aggregated |
| Server logs | 12 months, as Indian licensing requires |
| Customer account and billing | For the life of the account, then as long as tax and company law require (8 years, under the Companies Act, 2013) |
| Support records | 12 months after the ticket closes |
| Device telemetry | 12 months, then aggregated |
| Guest portal data and session records | As configured by the venue in Halo Cloud, within the maximum of 12 months we allow; deleted or returned to the venue when the Service Agreement ends, within 30 days |
10. Your rights
In short: ask us for access, correction, deletion or a copy; withdraw consent any time; complain to us or the regulator.
Everyone. You can ask us to access, correct, update, or delete the personal data we hold about you, to give you a copy in a usable format, and to stop sending you marketing. Where we rely on your consent, you can withdraw it at any time; this does not affect processing that already happened. Write to [email protected]. We respond within thirty days and may ask you to confirm your identity first.
Under the DPDP Act (India). In addition, you have the right to nominate another person to exercise these rights on your behalf if you are unable to, and the right to raise a grievance with our Grievance Officer (section 1). If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Under the GDPR and UK GDPR. In addition, you have the right to restrict or object to processing based on legitimate interests, the right to data portability, and the right to complain to the supervisory authority in your country. We have not appointed a representative in the EEA or UK.
Guests. For data collected at a venue, the venue decides these requests and we help it respond. Contact the venue first (its details are on the portal), or write to us and we will route your request.
11. Children
In short: the website and Halo Cloud are for adults; venues decide their own portal rules.
The website and Halo Cloud are intended for business users aged 18 and over, and we do not knowingly collect personal data from children through them. Venues decide who may use their guest WiFi and whether their portal collects any data from minors; where the venue’s portal asks for a date of birth, that is the venue’s configuration, and the venue is responsible for obtaining any consent the law requires from a parent or guardian. If you believe a child’s data has been collected through HaloWiFi in error, write to [email protected] and we will help the venue address it.
12. Marketing messages
In short: only if you asked; unsubscribe in every message.
We send newsletters and product updates only to people who signed up or who are customers. Every message has a one-click unsubscribe, and unsubscribing takes effect within 48 hours. We do not send marketing to guests, and any marketing a venue sends to its guests through HaloWiFi is the venue’s, under its own consent.
13. Changes to this policy
In short: versioned, dated, and announced when material.
We may update this policy. The version and dates at the top and the history at the bottom show what changed and when. Material changes are noted on the website for at least thirty days, and customers are emailed at the account contact.
14. Grievances and complaints
In short: our Grievance Officer first; then the Data Protection Board of India or your local authority.
If you are unhappy with how we have handled your personal data or a request about it, write to our Grievance Officer, Amit K, at [email protected] with “Grievance” in the subject line. We acknowledge within two working days and aim to resolve within thirty working days. If you remain unsatisfied, you may complain to the Data Protection Board of India, or, if you are in the EEA or UK, to your local data protection authority.
Version history
- 1.2, 8 September 2026: named our subprocessors and their locations, set retention periods, named the Grievance Officer, and stated that DNS queries are not logged.
- 1.1, 2 September 2026: first published version.