Data Retention
This page describes how long Weird Network keeps each category of data and why. The short version: we run on a forward-only data architecture. We hold the minimum required to operate the service and we delete (or aggregate / roll off) the rest on a predictable schedule. End-user (guest) data is not retained by us at all — it is forwarded to the venue and the venue is the controller.
Effective August 18, 2026This retention page is beta-grade and has not been reviewed by outside legal counsel. We've tried to be specific and accurate rather than vague, but it is not a substitute for a lawyer-reviewed document. If you spot something unclear or wrong, please email us — we'd genuinely rather fix it than defend it. We expect to commission a formal lawyer review before opening paid customer plans to the public.
1. Provider account data
Your provider account data — the records that let you log in and get paid out — is retained for as long as your provider account is active. If you close your account, that data is deleted after a 30-day grace window, matching the export window described in our terms so you have time to grab anything you need before deletion runs.
- Email address — needed for login and important service notifications. Kept until account closure + 30 days.
- Password hash — needed to verify sign-in. Deleted when the account is deleted.
- Business name and location — displayed in your venue's captive-portal branding. Deleted with the account.
- Payout information (PayPal or bank) — needed to pay you out for revenue you have earned. Deleted after the last payout clears and the account closes.
- Email verification, password-reset, and magic-link tokens — short-lived and single-use by design; expired tokens are removed on a regular sweep.
2. Billing records
Billing records are retained on a standard SaaS finance / tax schedule: 7 years from the last relevant transaction. We keep them that long so we can satisfy tax reporting, financial audits, and chargeback-window requirements — not because we want to, but because the law (and our payment processor) expects us to.
- Stripe customer ID and subscription ID — used to reconcile which plan you're on and when it renews. Retained for 7 years from the end of the last paid period.
- Webhook event log (Stripe events) — this table already serves as the idempotency record for subscription state. It is not separately purged — it is the receipt.
- Payout history — the record of payouts we have sent to providers. Retained for 7 years from the payout date for tax-reporting purposes.
Your payment instrument (card, etc.) is held entirely by Stripe. We never see, store, or transmit your card number, so there is nothing of that kind to retain on our side.
3. Session telemetry (anonymized)
Session telemetry is rolled up into aggregate counters — connection counts, device-type aggregates, peak-hour windows, member-vs-guest ratios — which is what the network, venue, and analytics dashboards surface. End-user identifiers (guest email, name, phone, MAC beyond what the router needs to authorize the session) are not part of this retention — that's the point of the forward-only architecture.
- Aggregated counters (connection count, device-type aggregate, peak-hour window, member-vs-guest ratio) — retained indefinitely as anonymized summary data.
- Per-session rows (MAC, timestamps, byte counts, auth method, status) — rolled off after they age out of the active + recent window. We keep them long enough to support reconciliation and dispute windows, then aggregate and drop the per-session detail.
The page-view log on our marketing and provider-facing pages is also anonymized — IP is hashed with SHA-256 before storage, no cookies, no cross-site identifiers. It is retained for analytics purposes and is not linkable back to an individual.
4. Audit logs
Audit logs — the security trail of who-did-what on the provider dashboard — are configurable per provider, with a default retention of 90 days. Providers can shorten the window, and within reason can extend it (for example, for compliance reasons specific to a venue).
- Sign-in attempts (success and failure) — default 90 days.
- Payout setting changes — default 90 days.
- Alert-config changes — default 90 days.
- Voucher issuance and revocation — default 90 days.
Audit logs are kept separately from primary data so they cannot be silently edited along with the records they describe.
5. End-user PII — NOT retained by us
This is the part that is different from most guest-WiFi vendors: we do not retain guest end-user PII at the corporate layer at all. Guest entries that the captive portal collects (name, email, phone, sign-in form content) are captured on behalf of the venue and forwarded to the venue by email — the venue is the controller for that data. There is no large guest database in our infrastructure holding it.
If you (a guest) want your data changed or deleted, contact the venue directly — they hold it. We're happy to help you figure out which venue to contact if it's not obvious. To ask us to delete the WiFi session metadata we hold on our side, use our data-deletion form — it routes you to the venue (if known) for the rest.