Captive Portal Generator

by LPP Development Studio — trusted infrastructure security
Last updated: March 25, 2025 · Version 3.2.1

Introduction

LPP Development Studio ("LPP", "we", "our", or "us") is the creator of Captive Portal Generator — a professional tool that enables network administrators, MSPs, and enterprises to design, deploy, and manage custom captive portal interfaces for Wi-Fi authentication, terms acceptance, and data consent collection. This Privacy Policy describes how we handle information when you (the administrator or licensee) use our software, website, associated services, or API integrations.

Because Captive Portal Generator is a privacy-first infrastructure tool, we distinguish between two data flows: (1) Data that LPP directly collects from our customers and their accounts; and (2) Data collected by network administrators via the generated captive portals from end-users. Under no circumstances does LPP access, host, or store end-user personal data that passes through portals you create — that data is owned and controlled solely by you, the administrator.

This Policy is intended to be exhaustive, detailed, and legally robust — reflecting LPP's commitment to transparency, data minimization, and security by design.

Information We Collect

LPP collects only the data necessary to provide, maintain, secure, and improve the Captive Portal Generator platform. Data categories include:

1. Personal Information You Provide Voluntarily

  • Account & License Data: When you purchase a license or register for an account (cloud dashboard), we collect your full name, business email address, company name, VAT/tax ID, and billing information (processed via PCI-compliant payment partners).
  • Support & Communications: When you contact our support team, we retain email correspondence, chat logs, and any attachments you send for troubleshooting and service improvement.
  • Beta & Telemetry Consent: If you opt in to usage analytics, we may collect feature interaction data (e.g., template selections, portal export formats) to enhance usability.

2. Automatically Collected Technical Information

  • Device & Log Data: IP address, operating system version, Captive Portal Generator version, device identifiers (hashed), crash reports, and timestamps when errors occur.
  • License Validation Data: Periodic license checks may send anonymized machine fingerprint and subscription status to our activation servers.
  • Analytics (opt-out possible): Aggregated counts of portal instances created, theme usage, and deployment frequency — never linked to end-user data.

3. No Access to End-User Captive Portal Data

Core architectural commitment: Captive Portal Generator acts as a code generation and configuration tool. When you deploy a generated portal (HTML, PHP, Node.js or API routes), the authentication flows and data submitted by your Wi-Fi guests (e.g., email, social login, room numbers) are transmitted directly to your designated backend or third‑party authentication service (RADIUS, ADFS, Firebase, etc.). LPP does not host, proxy, store, or inspect any personal data entered by your end-users. You remain the data controller for all guest information.

How We Use Your Information

LPP uses collected information for the following legitimate purposes:

  • Service delivery & license management: Activate, authenticate, and manage your access to Captive Portal Generator features and updates.
  • Technical support & troubleshooting: Analyze crash reports, debug software issues, and enhance compatibility with networking hardware.
  • Security & fraud prevention: Detect unauthorized use, license abuse, or malicious activities targeting our infrastructure.
  • Product improvement: Understand feature adoption, optimize UI/UX, and release new portal templates or authentication modules.
  • Legal compliance: Respond to lawful requests from public authorities, enforce our Terms of Service, or protect LPP's rights.

Aggregate statistical insights — such as "average number of portal designs per customer" — may be shared in anonymized form for case studies or marketing, without any identifiable information.

Sharing & Disclosure of Information

LPP does not sell, rent, or trade your personal information. Limited data sharing occurs only in the following contexts:

  • Authorized subprocessors: We use trusted third-party services for cloud hosting (AWS/GCP), payment processing (Stripe or Paddle), error monitoring (Sentry), and email support (HelpScout). All processors are GDPR-compliant and sign data processing agreements.
  • Legal obligations: If required by law, subpoena, or governmental request, we may disclose relevant information after attempting to notify you, unless prohibited.
  • Business transfers: In the event of a merger, acquisition, or asset sale, your data would be transferred with continued protection under this Policy.
  • With your explicit consent: For any other purpose, we will obtain prior opt-in consent.

We never share any end-user data collected by your captive portals — because we do not access it.

Data Security & Retention

LPP implements state‑of‑the‑art measures to protect information in our possession: encryption at rest (AES-256) and in transit (TLS 1.3), access controls, regular security audits, and penetration testing. Our license validation servers are isolated from production environments.

Retention periods: Account data is retained as long as your license is active or for up to 24 months after inactivity, unless earlier deletion is requested. Support tickets are archived for 3 years. Crash logs are anonymized after 90 days. You may request deletion of your personal data at any time (see Rights section).

Your Privacy Rights (GDPR / CCPA / LGPD)

Depending on your jurisdiction, you may have the following rights regarding your personal data processed by LPP:

  • Right to access: Obtain confirmation of whether we process your data and request a copy.
  • Right to rectification: Correct inaccurate or incomplete information.
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations (e.g., tax records).
  • Right to restrict processing: Limit how we use your data while disputes are resolved.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Opt out of direct marketing or analytics processing.
  • CCPA specific rights: California residents may request disclosure of categories of personal information collected, opt-out of any "sale" (we do not sell data), and non‑discrimination for exercising rights.

To exercise any right, contact [email protected] or use our Data Subject Request portal (available in-app). We will respond within 30 days. For EU residents, you have the right to lodge a complaint with your local supervisory authority.

Lawful basis (EEA/UK): We process data based on contract performance (license fulfillment), legitimate interest (software security improvements), and legal compliance.

Cookies & Similar Technologies

Our public website and cloud dashboard use essential cookies for session management, login persistence, and preference storage. Additionally, we may use first‑party analytics (Plausible or self-hosted Matomo) that do not use persistent tracking cookies. You can disable cookies via browser settings; however, some features of the Captive Portal Generator web dashboard may be impaired.

No third-party advertising cookies — we never integrate ad networks. Generated captive portals do not place any cookies by LPP; any cookies set by your portal remain under your exclusive control.

Children’s Privacy

Captive Portal Generator is not directed at individuals under the age of 16, and LPP does not knowingly collect personal information from minors. If you are a network administrator and your captive portal collects data from users under the age of consent, you are solely responsible for obtaining verifiable parental consent in compliance with COPPA, GDPR‑K, or other local laws.

International Data Transfers

LPP operates from the European Union and the United States. Your personal data may be transferred to and processed in countries other than your own. For transfers from the EEA, Switzerland, or UK to third countries, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented with additional safeguards where required. Our hosting partners are certified under EU-US Data Privacy Framework where applicable.

If you are located in a jurisdiction with restrictive data export laws, you acknowledge and accept such transfers as necessary for the performance of our software license agreement.

Changes to This Privacy Policy

We may revise this Privacy Policy from time to time to reflect legal updates, feature modifications, or regulatory guidance. Changes are effective upon posting on this page with an updated "Last updated" date. For material changes, we will notify you via email or in‑app notification at least 30 days in advance. Your continued use of Captive Portal Generator after changes constitutes acceptance of the revised policy.


Legal Basis for Processing Captive Portal Related Configurations

When you use Captive Portal Generator to design authentication workflows, the metadata (template configurations, redirect URLs, RADIUS secrets) is stored locally on your machine or your private cloud. LPP never processes that metadata remotely unless you use optional cloud backup (encrypted end‑to‑end). In such cases, metadata is encrypted using your master key.

Data Protection Impact Assessment (DPIA): LPP has conducted a DPIA regarding the use of telemetry and license validation, concluding that risks are minimal and mitigated by anonymization. For administrators using Captive Portal Generator, you are encouraged to conduct your own DPIA for end‑user processing.

Captive Portal Compliance Addendum for Network Operators

To assist our enterprise customers, Captive Portal Generator includes pre‑built legal notice templates (GDPR Article 13 statements, CPNI notices, etc.). However, you must customize these notices to reflect your actual data collection practices. LPP disclaims any liability for incomplete or incorrect legal notices generated via templates.

For further transparency we also publish a transparency report biannually, detailing government requests for data (if any). As of the latest update, LPP has received zero requests for user data.

Contact LPP Development Studio

If you have questions, concerns, or requests about this Privacy Policy or our data handling practices, please reach out to our Data Protection Officer (DPO):

  • Email: [email protected] (PGP key available upon request)
  • Postal: LPP Studio – Legal Dept., 45 Innovation Quarter, Boulevard Haussmann 75009, Paris, France
  • Support portal: https://support.lpp-studio.com/privacy

Our DPO is available in English and French, and responds within 5 business days. For urgent data protection matters please include "[DPO REQUEST]" in the subject line.

For network administrators using Captive Portal Generator: In case you receive a data subject request from your Wi-Fi guests (e.g., right to access, erasure), please handle it directly because LPP does not host their data. We can provide technical documentation to assist you in fulfilling such requests from your authentication systems.