What the platform stores
- Operator accounts: name, email, role, status, last sign-in, and security events (successful and failed sign-ins, lockouts, token reuse).
- Network equipment: router names, addresses, model and firmware, and health samples (reachability, CPU, memory, connected users).
- Hotspot users: the credential or voucher used to sign in, the device MAC and IP address of the session, bytes in and out, and session start/stop times.
- Money: package prices, voucher sales, payments and wallet movements, with references from the payment provider.
- Audit log: who performed which action, on which record, and when.
How it is protected
- Passwords are stored as Argon2id hashes, never in readable form.
- Router credentials, payment keys and two-factor secrets are encrypted with AES-256-GCM; they are never returned by the API or written to logs.
- Voucher codes and password-reset tokens are stored as hashes.
- Every tenant only ever sees its own data; that isolation is enforced on the server.
Retention and requests
Session and accounting records are kept for the period the operator configures, because they are the record of what was sold and delivered. To ask about, correct or delete data, contact the operator whose network you used — they control it — or your platform administrator.
Draft wording, pending legal review.