If your business runs guest WiFi on UniFi, a captive portal can do more than unlock internet access: it can help you build a permissioned audience for useful updates, offers or return-visit campaigns. The important part is separating WiFi access from marketing consent.
This guide explains the practical setup pattern for collecting an email address on a UniFi guest portal while keeping the network secure and the marketing choice clear.
Short answer
Use a dedicated guest SSID or Hotspot network, isolate guest traffic, make the portal reachable before authentication, collect only the data you need, and use a separate unticked marketing opt-in. Do not make marketing consent the same thing as acceptance of WiFi terms.
UniFi supports Hotspot Portals for an SSID or VLAN and supports external portal servers for advanced integrations. Its external portal workflow can pass client and SSID information to the portal, which can then authorize the client after the required steps are complete. Source: Ubiquiti Hotspots; Source: Ubiquiti External Hotspot API
This is practical implementation guidance, not legal advice. Confirm the correct privacy and electronic-marketing rules for your jurisdiction and business model.
1. Build the network boundary first
Before collecting any contact information:
- Create a dedicated guest network or VLAN.
- Enable network isolation so guest devices cannot reach internal networks.
- Assign the guest SSID to the intended access points.
- Enable the UniFi Hotspot Portal or captive portal.
- Confirm DNS, portal and required pre-authentication destinations are reachable.
Ubiquiti recommends isolating public guest networks from other VLANs and optionally using a Hotspot Portal for authentication.
A working form is not enough. Test the full journey on a real phone: join the SSID, confirm the portal appears, submit with and without marketing consent, and verify the intended authorization and internet-access behavior.
2. Separate WiFi access from marketing consent
Use separate controls for WiFi terms, the privacy notice and optional marketing consent.
Example:
☐ I would like to receive occasional marketing emails from [Business] about offers, events and updates. I can unsubscribe at any time.
Keep the box unticked by default. Do not hide consent inside terms or treat silence as agreement. ICO guidance describes valid consent as freely given, specific, informed and based on clear affirmative action, with records of who consented, when and how.
If WiFi access depends on marketing consent, the choice may not be freely given. Consider whether an equivalent non-marketing access route is needed.
3. Collect the minimum useful data
Start with the smallest form that supports the intended follow-up: email address, optional first name, and consent status, wording/version, timestamp and source.
Avoid collecting extra personal data without a defined purpose. Keep access required for WiFi separate from service communications and optional marketing consent.
4. Make the external portal reachable
For an external portal, guests must be able to reach the portal before authorization. Check UniFi pre-authentication or authorization-access settings for the portal hostname, assets, APIs and consent endpoints.
Common symptoms include blank pages from blocked assets, failed submissions from endpoint or TLS problems, device-specific captive-assistant behavior, and internet access before the intended authorization step. Record the first failed layer rather than only saying the portal is broken.
5. Use clear privacy and unsubscribe language
Link to a readable privacy notice before submission. Explain the responsible organisation, data collected, purpose, marketing channel, providers, retention, withdrawal and contact routes.
Marketing emails should identify the sender and provide a working opt-out route. Individual email marketing generally requires specific consent unless a defined soft-opt-in applies.
6. Configure the data flow before launch
Document: Guest device → UniFi portal redirect → external portal → consent decision → contact store → UniFi authorization → marketing system.
For every step, identify data received, purpose, storage, access, deletion propagation and failure behavior. If the marketing integration fails, do not turn a missing consent record into marketing permission.
7. Pre-launch test checklist
- Guest SSID is isolated.
- Portal appears on iOS, Android and laptop.
- HTTPS certificate is valid.
- Privacy notice is reachable.
- Marketing checkbox is optional and unticked.
- WiFi terms and marketing consent are separate.
- Consent wording and timestamp are stored.
- Unsubscribe works.
- Deletion/suppression handling is documented.
- Portal assets and APIs are allowed before authentication.
- Real-device testing confirms presentation, authentication and internet access.
Turn UniFi guest WiFi into a measurable marketing channel
LiquidEdge helps businesses connect a hosted, publicly reachable UniFi controller and turn guest WiFi into a measurable visitor and contact-capture experience. Create a permanent free LiquidEdge account for one site and one access point, with limited contact collection and no payment card required. Eligibility requires a hosted, publicly reachable UniFi controller.
