Privacy Policy
Covers the ISP Manager web platform at
https://wi-fi-pro.com and the Hotspot Pro Android app
(com.wifipro.hotspotpro).
Last updated 10 August 2026.
Who this is for
This service is a management tool for internet service providers. There are two different kinds of people in it, and they are treated differently.
- Operators — the ISP staff who hold an account, sign in to the dashboard, and use the Hotspot Pro app. We are the controller of their account data.
- Subscribers — the operator's own internet customers, whose records the operator creates and manages here. For that data we act only as a processor, on the operator's instructions. If you are a subscriber and want your records changed or removed, ask your internet provider; they control it, not us.
What we collect
Operator accounts
Username, email address, and a password we store only as a salted hash — we never hold the password itself. We record sign-in times and failed attempts, because we lock an account after repeated failures to stop someone guessing their way in.
Subscriber records, entered by the operator
Name, phone number, username and access password, chosen plan and expiry date. From the router we also receive device MAC addresses, session start and stop times, and bytes transferred, which is what produces the usage figures and the online/offline state.
Payments
Payments are handled by our payment providers. We receive the amount, the status, a reference, and the mobile-money number used. We never receive or store card numbers, PINs or banking credentials; those are entered on the provider's own page, not ours.
The Hotspot Pro app specifically
The app requests one Android permission, INTERNET. It does not
ask for contacts, location, camera, storage, or the phone's identifiers, and
it contains no advertising or analytics SDK.
Signing in stores an access token in Android's encrypted storage on the device. That token is what identifies the app to our servers; it expires after 90 days and can be revoked at any time from Devices in the web dashboard, which is what to do if a phone is lost. Everything else the app shows is fetched over HTTPS when you open a screen and is not kept on the phone.
Why we collect it
To run the service you asked for: authenticate operators, create and manage subscriber accounts on your routers, meter usage, take payment, and show you what your network is doing. We do not sell personal data, and we do not use subscriber data to advertise to anyone.
Who else sees it
Only the providers we need to deliver the service:
- Flutterwave and Fapshi — payment processing.
- DeepSeek — powers the optional in-app assistant. It only applies if an operator has enabled the assistant and supplied a key; the text of those conversations is sent to DeepSeek to generate a reply. If the assistant is off, nothing goes there.
- Google Fonts and jsDelivr — serve fonts and stylesheets to your browser. Some pages of the public website carry Google AdSense; the signed-in dashboard and the app do not.
- Our hosting and network providers, who store the data at rest.
Beyond that, we disclose data only where the law requires it. We do not share one operator's data with another: every account is scoped to its own tenant, and that boundary is enforced on the server for both the website and the app.
How it is protected
- All traffic, web and app alike, travels over HTTPS.
- Passwords are stored hashed. App tokens are stored only as a SHA-256 hash, so a copy of our database does not yield a working token.
- Access is limited by role, so staff see only what their role permits.
- Router credentials are held encrypted and are never shown in the app.
No system is perfectly secure, and we will not claim otherwise. If we ever discover a breach affecting your data, we will tell you.
How long we keep it
Account and subscriber records are kept while the account is active and for a period afterwards where we need them for billing, tax or dispute records. Session and usage logs are pruned automatically on a rolling schedule. Deleting an operator account removes its data, subject to those obligations.
Your choices
- See and correct your account details from the dashboard.
- Revoke any signed-in device from Devices, immediately.
- Turn the AI assistant off, which stops anything going to DeepSeek.
- Ask us for a copy of your data, or for it to be deleted, using the address below.
Subscribers should direct these requests to their own internet provider. We cannot act on an operator's data without that operator's instruction.
Children
This is a business tool for network operators. It is not directed at children, and we do not knowingly collect data from anyone under 13.
Changes
If this policy changes we will update the date at the top of this page. If a change materially affects how your data is used, we will say so rather than leaving you to notice.
Contact
Use the contact details on our website.