LPP Development Studio ("LPP", "we", "our", or "us") is the creator of Captive Portal Generator — a professional tool that enables network administrators, MSPs, and enterprises to design, deploy, and manage custom captive portal interfaces for Wi-Fi authentication, terms acceptance, and data consent collection. This Privacy Policy describes how we handle information when you (the administrator or licensee) use our software, website, associated services, or API integrations.
Because Captive Portal Generator is a privacy-first infrastructure tool, we distinguish between two data flows: (1) Data that LPP directly collects from our customers and their accounts; and (2) Data collected by network administrators via the generated captive portals from end-users. Under no circumstances does LPP access, host, or store end-user personal data that passes through portals you create — that data is owned and controlled solely by you, the administrator.
This Policy is intended to be exhaustive, detailed, and legally robust — reflecting LPP's commitment to transparency, data minimization, and security by design.
LPP collects only the data necessary to provide, maintain, secure, and improve the Captive Portal Generator platform. Data categories include:
Core architectural commitment: Captive Portal Generator acts as a code generation and configuration tool. When you deploy a generated portal (HTML, PHP, Node.js or API routes), the authentication flows and data submitted by your Wi-Fi guests (e.g., email, social login, room numbers) are transmitted directly to your designated backend or third‑party authentication service (RADIUS, ADFS, Firebase, etc.). LPP does not host, proxy, store, or inspect any personal data entered by your end-users. You remain the data controller for all guest information.
LPP uses collected information for the following legitimate purposes:
Aggregate statistical insights — such as "average number of portal designs per customer" — may be shared in anonymized form for case studies or marketing, without any identifiable information.
LPP implements state‑of‑the‑art measures to protect information in our possession: encryption at rest (AES-256) and in transit (TLS 1.3), access controls, regular security audits, and penetration testing. Our license validation servers are isolated from production environments.
Retention periods: Account data is retained as long as your license is active or for up to 24 months after inactivity, unless earlier deletion is requested. Support tickets are archived for 3 years. Crash logs are anonymized after 90 days. You may request deletion of your personal data at any time (see Rights section).
Depending on your jurisdiction, you may have the following rights regarding your personal data processed by LPP:
To exercise any right, contact [email protected] or use our Data Subject Request portal (available in-app). We will respond within 30 days. For EU residents, you have the right to lodge a complaint with your local supervisory authority.
Lawful basis (EEA/UK): We process data based on contract performance (license fulfillment), legitimate interest (software security improvements), and legal compliance.
Captive Portal Generator is not directed at individuals under the age of 16, and LPP does not knowingly collect personal information from minors. If you are a network administrator and your captive portal collects data from users under the age of consent, you are solely responsible for obtaining verifiable parental consent in compliance with COPPA, GDPR‑K, or other local laws.
LPP operates from the European Union and the United States. Your personal data may be transferred to and processed in countries other than your own. For transfers from the EEA, Switzerland, or UK to third countries, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented with additional safeguards where required. Our hosting partners are certified under EU-US Data Privacy Framework where applicable.
If you are located in a jurisdiction with restrictive data export laws, you acknowledge and accept such transfers as necessary for the performance of our software license agreement.
We may revise this Privacy Policy from time to time to reflect legal updates, feature modifications, or regulatory guidance. Changes are effective upon posting on this page with an updated "Last updated" date. For material changes, we will notify you via email or in‑app notification at least 30 days in advance. Your continued use of Captive Portal Generator after changes constitutes acceptance of the revised policy.
When you use Captive Portal Generator to design authentication workflows, the metadata (template configurations, redirect URLs, RADIUS secrets) is stored locally on your machine or your private cloud. LPP never processes that metadata remotely unless you use optional cloud backup (encrypted end‑to‑end). In such cases, metadata is encrypted using your master key.
Data Protection Impact Assessment (DPIA): LPP has conducted a DPIA regarding the use of telemetry and license validation, concluding that risks are minimal and mitigated by anonymization. For administrators using Captive Portal Generator, you are encouraged to conduct your own DPIA for end‑user processing.
To assist our enterprise customers, Captive Portal Generator includes pre‑built legal notice templates (GDPR Article 13 statements, CPNI notices, etc.). However, you must customize these notices to reflect your actual data collection practices. LPP disclaims any liability for incomplete or incorrect legal notices generated via templates.
For further transparency we also publish a transparency report biannually, detailing government requests for data (if any). As of the latest update, LPP has received zero requests for user data.
If you have questions, concerns, or requests about this Privacy Policy or our data handling practices, please reach out to our Data Protection Officer (DPO):
Our DPO is available in English and French, and responds within 5 business days. For urgent data protection matters please include "[DPO REQUEST]" in the subject line.
For network administrators using Captive Portal Generator: In case you receive a data subject request from your Wi-Fi guests (e.g., right to access, erasure), please handle it directly because LPP does not host their data. We can provide technical documentation to assist you in fulfilling such requests from your authentication systems.