Privacy Policy
Last updated on August 14, 2026
Your privacy is critically important to us. This Privacy Policy ("Policy") applies to services provided by Veranet, Inc. ("we", "us", or "Veranet") and our website (the "Site"), captive portal engine, firmware cloud integrations, RADIUS authentication management, mobile applications, APIs, or other digital products that link to or reference this Policy (collectively, the "Services") and explains what information we collect from users of our Services (a "user", "you", or "your"), including information that may be used to personally identify you ("Personal Information") and how we process and safeguard it.
We encourage you to read the comprehensive details below. This Policy applies to any visitor to or registered operator of our Services. Any capitalized terms used herein but not defined shall have the meaning set forth in our Terms of Service.
We reserve the right to modify or update this Policy at any time. We will notify you of any material changes by posting the updated Policy on this page with a revised "Last updated" date and/or by sending an email notice to the primary email address registered to your account. You acknowledge that your continued use of our Services after such notices are published constitutes your acceptance of the updated terms.
Scope and Applicability
This Policy governs Personal Information collected through our websites, cloud dashboards, APIs, and connected edge devices. It applies to:
- B2B Platform Operators: Businesses, ISPs, and hotspot managers who register an account with Veranet to deploy and manage captive portals, voucher billing, and network access points.
- Website Visitors: Individuals who browse our public-facing web pages, request technical demonstrations, or submit inquiries.
- End-Users of Captive Portals: Individuals who connect to Wi-Fi access points operated by our B2B customers powered by Veranet software.
Data Processor Status: Under applicable data protection frameworks (including the EU/UK General Data Protection Regulation and Nigeria Data Protection Act), when processing personal data of end-users in connection with the provision of Services to our B2B Customers, Veranet acts as a Data Processor, while our B2B Customer acts as the Data Controller. Where we are deemed a Data Processor, end-users should direct their data subject requests primarily to the respective network operator. We will reasonably cooperate with our Customers to support and comply with all valid data subject requests.
What Information Do We Collect?
We collect information in three primary ways: information you provide directly, telemetry collected automatically through device interaction, and information provided by third-party integrations.
A. Information You Provide Directly
- Account Registration: Full name, organizational business name, work email address, phone number, and encrypted password credentials.
- Billing Information: Billing address, tax identification numbers, and payment details processed directly through our secure PCI-DSS Level 1 compliant payment gateways (e.g. Stripe, M-Pesa, Paystack). Veranet does not store full credit card numbers or security CVV codes on its servers.
- Communications & Support: Inquiries, technical tickets, and diagnostic logs submitted via our contact forms, email, or customer portal.
B. Information Collected Automatically via Telemetry
- Router & Gateway Telemetry: Router MAC address, hardware vendor model (e.g. MikroTik RouterOS, OpenWrt), local IP configuration, uptime, connection heartbeat, and firmware version.
- Session & Usage Metrics: Aggregate bandwidth throughput, connected active client counts, voucher generation counts, and packet failure diagnostics necessary to maintain uptime.
- Log & Device Data: Public IP addresses, browser user-agent strings, operating system, referral URLs, and standard web server access logs.
C. Captive Portal End-User Data (Processed on Behalf of Operators)
- Voucher Session Identifiers: Voucher access codes, client device MAC addresses, assigned local IP addresses, connection start/end timestamps, and consumed data quotas used strictly to authorize network access.
How Do We Use The Information We Collect?
We use the collected information for specific, lawful operational purposes:
- Delivering Core Services: Provisioning cloud-managed captive portals, authenticating users against RADIUS protocols, validating prepaid vouchers, and executing fair-share bandwidth throttling.
- Infrastructure Reliability & Security: Maintaining high-availability offline caching, mitigating Distributed Denial of Service (DDoS) attacks, detecting unauthorized voucher tampering, and preventing fraudulent gateway abuse.
- Billing & Invoicing: Calculating recurring subscription fees, processing automated payouts for hotspot voucher sales, and maintaining regulatory financial audit records.
- Service Improvement: Aggregating non-identifying telemetry to optimize platform latency, resolve software bugs, and improve edge firmware compatibility.
- Transactional Notifications: Transmitting essential account alerts, critical security patches, payment confirmations, and system status updates.
How Do We Use Tracking Technologies?
We use essential cookies, local storage tokens, and web session identifiers to ensure our platform operates correctly:
- Strictly Necessary Cookies: Essential for user authentication, maintaining secure administrator login sessions, and preventing Cross-Site Request Forgery (CSRF) attacks.
- Functional Preferences: Storing your interface preferences such as dark mode rendering, regional currency selections, and billing display preferences.
- Performance Telemetry: Aggregated, anonymized performance metrics to measure server latency and interface responsiveness.
You can configure your web browser to reject cookies or notify you when cookies are being set; however, disabling strictly necessary cookies may impair portal functionality and prevent you from accessing authenticated areas.
How Do We Secure Your Personal Information?
We implement multi-layered industry-standard technical, organizational, and physical security measures to safeguard all stored and transmitted data:
- End-to-End Transport Encryption: All data transmitted between your browser, client routers, and Veranet cloud clusters is encrypted using TLS 1.3 cryptographic protocols with modern cipher suites.
- Encryption at Rest: Core databases, voucher archives, and configuration snapshots are encrypted at rest using AES-256 bit encryption keys managed via dedicated Hardware Security Modules (HSM).
- Hashed Authentication Secrets: All passwords and API secret tokens are irreversibly hashed using salted Argon2id / bcrypt hashing algorithms.
- Least-Privilege RBAC: Internal access to server clusters is strictly partitioned through Role-Based Access Controls (RBAC), multi-factor authentication (MFA), and comprehensive audit trail logging.
- Offline Resiliency Tokens: Offline cached tokens stored on edge access points are cryptographically signed and ephemeral, preventing local key extraction.
Data Retention
We retain Personal Information only for as long as necessary to fulfill the operational purposes outlined in this Policy, satisfy legal, tax, or accounting requirements, or enforce our agreements:
- Operator Account Data: Retained for the duration of your active subscription and up to 180 days following account closure, after which it is permanently purged or anonymized.
- Transient End-User Captive Portal Logs: Session connection logs and voucher redemption records are automatically purged on rolling retention cycles (typically 30 to 90 days, as customized by the network operator).
- Financial & Transactional Records: Retained for statutory compliance periods (typically 5 to 7 years) as required by international tax and commercial laws.
Managing Your Privacy & Data Rights
Depending on your geographic location, you possess statutory rights regarding your Personal Information:
- Right of Access & Portability: Request a complete copy of the Personal Information we maintain about you in a structured, machine-readable format.
- Right to Rectification: Request correction of inaccurate or incomplete personal details in your account profile.
- Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your Personal Information, subject to statutory retention obligations.
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests or request restrictions on certain processing workflows.
- Right to Withdraw Consent: Withdraw previously granted consent at any time with future effect.
To exercise any of these rights, please submit a verified request to privacy@veranet.online. We will respond to all valid requests within thirty (30) business days.
How We Respond to Do Not Track (DNT) Signals
Some web browsers incorporate a "Do Not Track" (DNT) or Global Privacy Control (GPC) signal. Because there is currently no universal industry standard for interpreting DNT signals, our systems do not alter data collection practices based solely on generic DNT headers; however, we strictly honor universal Global Privacy Control (GPC) opt-out signals and adhere to the strict no-selling policy described throughout this document.
Children Under 16
Our Services are exclusively intended for commercial B2B operations and are not directed to or designed for children under the age of 16. We do not knowingly collect or solicit Personal Information from individuals under 16. If we discover that we have inadvertently collected Personal Information from a minor under 16 without verified parental consent, we will promptly delete such records from our servers.
Region-Specific Disclosures
A. European Economic Area (EEA) & United Kingdom (GDPR)
We process Personal Information under the following legal bases recognized by GDPR Article 6: (1) Contractual necessity to provide Services; (2) Legitimate business interests in platform security and performance; (3) Compliance with legal obligations; and (4) Your affirmative consent. Data transfers outside the EEA are governed by European Commission Standard Contractual Clauses (SCCs).
B. California Privacy Disclosures (CCPA / CPRA)
California residents have specific rights under the CCPA/CPRA, including the right to know the categories of Personal Information collected, the right to delete, and the right to non-discrimination for exercising privacy rights. Veranet does not sell or share Personal Information as defined under California law.
C. African Continental & NDPA Disclosures
In compliance with the Nigeria Data Protection Act (NDPA) and applicable regional data protection frameworks, Veranet implements localized safeguards, data sovereignty measures, and lawful processing guarantees for all African B2B operator deployments.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, our data protection practices, or our Services, please contact our designated Data Protection Officer (DPO) at: