FAQ
Fourteen questions, answered without spin.
The honest answers are the product. If a question you have isn’t here, ask — we answer the awkward ones too.
What exactly do your sensors capture?
Phones looking for WiFi broadcast short probe frames. Our sensors — passive, listen-only hardware, equivalent to a WiFi access point that never transmits — receive those frames and record signal strength and timing. The device identifier in the frame is hashed on the sensor itself, with a random salt, in 1–3 seconds; the raw identifier is never stored on the sensor, in transit, or on our servers.
Are your counts people counts?
No, and we will not pretend otherwise. Counts are unique devices, not people. Phones with WiFi switched off are not seen; some visitors carry two devices; modern phones randomise their identifiers, which our statistical model accounts for. We do not apply a hidden multiplier to turn devices into “visitors” — you get the device numbers and the definitions, and the comparison that matters is like-for-like across your own zones, days and editions.
Can you identify or track an individual person?
The passive pipeline is built so that we do not. Each device is assigned a pseudonymous identity, irreversibly de-linked at campaign end: the salt that links a device to its hash is destroyed when your event closes (or at campaign end by agreement), and destruction irreversibly eliminates linkability in production systems. No report cell ever represents fewer than 12 devices — in production since 2019 — and outputs are aggregate statistics only: no profiles are created, stored, or delivered, and no re-marketing use.
Where do you stand on GDPR?
We will not answer that with a compliance slogan. The system is designed to meet GDPR, with documented safeguards: during the live processing window we treat hashed identifiers as pseudonymised personal data and apply GDPR in full, on a legitimate-interests basis (Art 6(1)(f)). Our GDPR Support Statement — the pipeline, the salt lifecycle, retention, and a customer Q&A — is available to your compliance team, and we offer a walkthrough call.
Who is responsible for telling visitors?
Venue signage and privacy notices are the venue operator’s responsibility as controller of the deployment context — it is your venue, your event, your relationship with visitors. We supply template wording so you are not drafting from scratch.
What does “engaged” mean in your reports?
Zone visits resolve into three shapes from two measurements — signal strength and time: faraway, passer-by, and engaged. Engaged means at least 30 seconds of dwell in the vicinity of a zone, a platform-defined threshold we state rather than hide. Engagement rates are venue-type-dependent: a trade-show booth and an open festival produce very different baselines, so we never benchmark across venue types without saying so.
How accurate is it?
We publish one calibration point rather than a blanket percentage: at a major international Grand Prix, our weekend figure of 289,661 unique devices compared with a box office of 301,837 tickets — within about 4%, with the caveats stated in full in our case studies (devices are not people; tickets include no-shows; agreement is venue-dependent). Any accuracy figure without its method and bounds is marketing, not measurement.
What about phones that randomise their identifiers?
Modern iOS and Android devices randomise the identifier they broadcast, which limits re-identification — a privacy property we welcome — and complicates naive counting. Our statistical model factors randomisation into unique-device estimates, and our definitions are stable across an event, so trends and comparisons within your deployment remain sound.
Can I see repeat visitors across my events?
Within one event by default, or across a contracted campaign by agreement — repeat-visitor metrics exist only within one event or contracted campaign, because the salt that makes them possible is destroyed at the end of that scope. Year-over-year, you compare aggregate patterns, never recognised devices.
Do I get the raw data?
Yes, as standard. The anonymised, consolidated data behind your reports is exportable — it is your deployment. Anonymous aggregates and delivered reports are retained for 12 months.
What does the sensor need from my venue?
A 220V outlet — that is the list. Sensors have internal batteries for gaps, 4G connectivity (local network optional), and encrypted local storage for offline operation. They mount on existing structural or equipment elements at 1.5–2.0 m, and once placed they must not move: triangulation accuracy depends on positional consistency.
Is the HITmap tracking people’s positions?
No. HITmap — hotspots, interest, traffic — is perimeter detection, not positioning. Sensors define perimeters; the map shows density of visits inside them: interest around single sensors, traffic between pairs, hotspots where three or more sensors see the same visits. Positions on it are density functions, not located individuals.
Has anyone independently reviewed this?
Our privacy architecture is screened at onboarding and renewal by public-sector and enterprise clients, and client-commissioned audits are supported under NDA. No standalone independent penetration test has been commissioned to date — we say so rather than imply otherwise.
How is the captive portal different?
It is the consent product. Captive-portal users are identified with consent (double opt-in) — they scan a QR code and register by phone or email — unlike the anonymous passive pipeline, which never identifies anyone. The two are separate by design, and reports keep them separate.