In this article
Every owner can quote their rent to the euro, their card-processing fee to the basis point and their energy bill to the kWh. Ask what the guest Wi-Fi is actually doing for the business and the answer is usually a shrug — "it's just the password on the wall." That shrug is exactly why nobody has ever priced it either way.
Guest Wi-Fi is the one piece of restaurant technology that almost never gets a decision. The POS system was chosen, the payment provider was compared, the delivery platform's commission was negotiated line by line — and then someone plugged in a router, wrote the password on a chalkboard, and that was the whole strategy. It has stayed that way for years, in most venues, without anyone asking what it's actually doing to covers, to marketing, or to the two compliance rules that quietly come attached to it.
That would be fine if guest Wi-Fi were neutral — a nice-to-have that costs a router and nothing else. It isn't. The same open network that turns a single-coffee visitor into someone who orders a second round and stays for lunch is the network that turns a two-top into a three-hour laptop desk on a Tuesday afternoon when you needed that table twice. And the same login screen that can hand you a guest's e-mail address for almost nothing is, the moment it asks for that e-mail address, a data-collection form — which is precisely the point at which GDPR starts caring what you do with it.
This guide walks through the seven numbers that actually decide whether your guest Wi-Fi is quietly making you money or quietly costing you tables: what guests now expect walking in, what a good login screen does to how long they stay, what two European rules require of the network itself, and what the open rate on a Wi-Fi-captured e-mail looks like against an ordinary newsletter. At the bottom, you put your own numbers into a calculator that nets the upside against the downside for your own room — because for a fast-turn lunch spot and a destination café, the honest answer points in opposite directions.
Everything runs in your own browser: nothing is sent anywhere and nothing is stored. The figures in this guide are planning reference points drawn from published surveys, case data and the relevant EU/PCI rules — your own room, your own guests and your own router are the final word.
Why Wi-Fi is the only technology line nobody prices either way
Every other piece of restaurant technology gets evaluated because it has an obvious, single cost attached to it: the POS system has a monthly fee, the payment provider has a per-transaction rate, the delivery platform takes a visible commission. Guest Wi-Fi has neither an obvious cost nor an obvious benefit on a normal invoice — the router was a one-off purchase years ago and the internet line was already being paid for regardless, so there is nothing on a bill that ever prompts the question.
That absence of a bill is exactly why it never gets managed the way rent or energy do. Nobody schedules a quarterly review of the guest network, because nobody schedules a review of something with no line item. Meanwhile the network is quietly doing two things at once, in opposite directions: it is a small marketing channel every time someone logs in with an e-mail address, and it is a small operational risk every time that same login turns a table into a workspace nobody is paying rent on.
And unlike a fire-safety certificate or a pest-control contract, getting this one wrong rarely produces a single, visible event that forces a decision. There is no inspector who flags an unsegmented guest network the way one flags an expired extinguisher — the cost, in both directions, only shows up if someone actually sits down and works it out. This guide is that sitting-down.
The ultimate guide Restaurant Technology: The Complete Guide From POS to Wi-Fi to cybersecurity: everything your restaurant's tech stack can do for you, in one guide. Open the guideThe 7 numbers, and what each one tells you
They run in the order a Wi-Fi decision actually gets made: what guests already expect, what it does to their visit, what the law requires of the network, and finally what it's actually worth to you — both ways.
1. 92% — the expectation you already set, whether you meant to or not
A 2025 Hotel Internet Services survey found that 92% of guests now expect free Wi-Fi as a standard amenity, not a bonus worth mentioning — a figure consistent with older TripAdvisor and Red Roof Inn surveys that put the same expectation between 88% and 96%. That expectation was formed in hotels and cafés long before it ever reached a restaurant dining room, and guests carry it with them: nobody notices a Wi-Fi network that works, and a growing share notice — and mention, in a review — one that doesn't.
This is the number that makes "should I even bother" the wrong first question. The expectation is already set by the market you compete in, whether or not you ever turned the router on. The real questions are the ones the rest of this guide is built to answer: what kind of network, what it should ask a guest for, and what it's actually doing to your room while it's switched on.
It also explains why almost nobody thinks of guest Wi-Fi as a decision at all — it reads as table stakes, like clean cutlery, rather than as a lever with real upside and real downside. The next six numbers are what that lever actually moves.
2. +40% — what a good login screen does to how long someone stays
A café that shipped a branded, secure guest-Wi-Fi login reported a 40% increase in average dwell time within two months, with single-coffee visits turning into a second drink, an added pastry, and a table treated as a workspace — and afternoon revenue nearly doubling in the process (case data widely reported by hospitality Wi-Fi vendors; treat it as a plausible upper bound, not a guarantee). Remote workers and students genuinely filter where they sit by connectivity, and a venue with no reliable network loses that segment before it ever orders.
The graphic below puts a number on where that extra time actually goes. Take a venue with a 62-minute average visit before Wi-Fi: at +40% that becomes roughly 87 minutes — 62 minutes of the meal itself, plus 25 minutes that is, in a genuinely destination-style café, mostly the laptop staying open after the plate is cleared.
That 25 extra minutes is the whole tension this guide is built around. In a café or a brunch spot built for people to linger and order again, it is close to pure upside. On a lunch-rush two-top that would otherwise turn twice in that window, it is the seventh number below — and the two readings of the same 40% cannot both be right for your own room.
A 62-minute visit without guest Wi-Fi, against the same visit at the reported +40% dwell-time lift — the same 25 minutes reads as pure upside in a destination café and as the seventh number in a lunch-rush bistro.
Both bars are drawn to the same 87-minute scale, so the "without Wi-Fi" bar visibly stops short — the 25-minute gap is exactly the number the camping-hour calculation further down is built to price.
3. PCI DSS Requirement 1.3.3 — two networks, never one password
The PCI Security Standards Council's current DSS requires that any wireless network — including your own staff or guest Wi-Fi — sits with security controls between it and the Cardholder Data Environment, the network your card terminal, POS till and payment gateway live on, with wireless traffic into that environment denied by default (Requirement 1.3.3). A second password on the same router does not satisfy this: what the standard asks for is a genuinely separate network segment, in practice a separate VLAN with firewall rules that block any path between the two, not two Wi-Fi names sharing one piece of hardware.
This is worth naming plainly because it is one of the most common restaurant network mistakes, and it is invisible until something goes wrong: a guest device on the same flat network as a card terminal is, from a security standpoint, one compromised phone away from being on the same network as the till. Most modern business-grade routers can create this second, isolated network for the cost of ten minutes' configuration — the failure is almost never technical difficulty, it is that nobody ever asked the question.
The graphic further down puts this as two lanes on one router: a small, always-on payment lane that a handful of devices need reserved bandwidth on, and a much larger, variable guest lane that scales with how busy the room is — and the two are not meant to share a lane, technically or legally.
A small, always-on payment lane against a much larger, variable guest lane — PCI DSS requires the two to sit on genuinely separate network segments, never two passwords on one router.
The payment lane barely moves — a handful of devices need a small, steady, always-available connection. The guest lane is the one that has to scale with how busy the room is, and it is exactly the one PCI DSS requires to have no routable path back to the till.
4. GDPR Article 6/7 — a login screen is a data form the moment it asks for a name
The instant a captive-portal login screen asks a guest for a name, an e-mail address or a phone number, it stops being a convenience feature and becomes a data-collection form, and GDPR's Article 6 (lawful basis) and Article 7 (conditions for consent) both apply to it. Consent has to be freely given, specific, informed and unambiguous — a pre-ticked box, or marketing consent buried inside the terms a guest has to accept to get online at all, does not meet that bar.
The rule that trips up the most restaurants is the separation itself: access to the network can never be made conditional on marketing consent. A guest has to have a genuine path to "just connect" without opting into anything, and if you also want their e-mail for a newsletter or a loyalty programme, that has to be a separate, specific, un-bundled tick — not a single button that does both at once.
None of this is a reason to skip a login screen; it is a reason to build the right one. A short, honest privacy notice before the data is submitted, a clear statement of what the e-mail will and won't be used for, and connection logs kept only for the 30–90 days a security or troubleshooting need actually justifies, is the whole compliant version — and it is also, not coincidentally, the version guests trust enough to actually fill in.
5. 60–70% — the open rate on the one e-mail a newsletter never gets
A post-visit e-mail sent to an address captured at Wi-Fi login is reported to open at 60% to 70%, against roughly 21% for an ordinary restaurant marketing campaign — the same figure our own guide to e-mail marketing for restaurants uses as the industry baseline for a cold list. The gap exists because the recipient just physically sat in your room, minutes ago, which is a context no newsletter subscriber has.
This is the number that makes a compliant login screen worth building rather than skipping. A guest who opts in at the table is not a cold contact bought or scraped from somewhere else — it is someone who was there, who chose to give you the address, and who is measurably more likely to open the one message you send about tonight's event or next week's menu change.
It is not, on its own, a reason to chase every e-mail address in the room. The calculator further down treats the capture rate as one input among several, because a login screen that annoys guests into leaving negative reviews to avoid it is a worse outcome than a slightly smaller mailing list.
6. 1.5 Mbps a device — what your card terminal has to share with forty phones
A workable planning rule for a shared connection is roughly 1.5 Mbps per concurrently active device for ordinary browsing and video calls — not a guarantee, but enough to plan a line size around. A typical payment path (two card terminals plus a kitchen printer or back-office till) needs perhaps 3 devices' worth, call it 5 Mbps, reserved and always available. A guest lane scales with how busy the room is: 10 quietly connected phones need roughly 15 Mbps, 30 on a busy Friday need 45, and a packed 60-device evening needs closer to 90.
The number that matters operationally is not the total — most modern fibre or cable business lines clear these figures without difficulty — it is the word reserved. On a single shared connection with no traffic prioritisation, forty guests streaming video can genuinely starve a card terminal of the small, steady bandwidth it needs to authorise a payment, which is how "the Wi-Fi is fine" and "the card machine keeps timing out" end up being the same problem described by two different people.
This is the practical argument for the same two-lane setup PCI DSS already requires for security: a router or access point with Quality-of-Service settings can reserve the payment lane's bandwidth ahead of the guest lane, so a full dining room on a Saturday night never competes with the till for the connection it needs.
7. The camping hour — what one occupied two-top costs you when nobody orders a second round
This is where the upside in number 2 and the downside share the same 40% figure and pull in opposite directions. If a table would normally turn in 75 minutes but a laptop user occupies it for 180 minutes instead, that one seat has cost you roughly one and a half turns it would otherwise have delivered — and if that happens for even a modest number of hours a week, in a room that lives on turnover rather than on lingering, the arithmetic below in the calculator adds up faster than most owners expect.
The honest answer depends entirely on what kind of room you run. A destination café built around people staying is trading turns it was never optimising for anyway — the 40% dwell-time lift in step 2 is close to pure upside there. A lunch-rush bistro with a 45-minute average table time is trading its scarcest resource, and the same open network that helps one venue can quietly cost the other several covers a week without a single number appearing on any report.
The calculator below is built to answer this for your own room rather than in the abstract: your own camping hours, your own turn times, your own average spend, and your own e-mail capture rate, netted into one figure that can land on either side of zero — because for your specific venue, it genuinely can.
Work out your own net effect
Fill in your own numbers: how many hours a week you actually see tables occupied by laptop users, your normal turn time against a camper's real dwell time, your average spend per visit, and the e-mail capture rate at your own login screen. The fields start with the figures from this guide so you can see how it reads — overwrite them with yours.
You get the covers you lose to camping each week, what that costs across a year, what the e-mails you actually capture are worth in return visits, and the one number that matters: the net effect, which can come out positive or negative depending on the room you run.
Guest Wi-Fi Net Effect
Six numbers from your own room, netted into one answer that can land on either side of zero.
Which force is bigger, for your own room
—
The return-visit share behind the marketing figure is a conservative planning assumption (1 captured e-mail in about 7 converts to one extra visit a year), not a measurement of your own list. Everything runs in your browser; nothing is sent or stored.
Two things worth taking away. The sign of your own net effect says more about your room than about Wi-Fi itself — a destination café and a lunch-rush bistro can run the same network and land on opposite sides of zero, and neither owner is doing anything wrong. What decides it is turn time against camper dwell time, not whether Wi-Fi is "good" or "bad" in the abstract.
And the compliance numbers in steps 3 and 4 aren't optional regardless of which way your own arithmetic points. A network segmented for PCI DSS and a login screen that separates connecting from opting in cost roughly the same ten minutes of setup whether your net effect is positive or negative — get those two right first, then decide what kind of network you actually want to run.
What to do with this this week, this month and this quarter
Seven numbers at once is too many to act on together. This order works because each step makes the next one measurable.
This week — check the two that are actually compliance, not preference
- Ask whoever set up your router whether guest Wi-Fi sits on a separate VLAN from your card terminal and POS till, or just a second password on the same network — if it's the latter, this is the one item on this list that isn't optional.
- Open your own login screen as a guest would and check: can you connect without ticking anything, and is any marketing opt-in a separate, clearly labelled tick rather than bundled into "agree and connect"?
- Put your own numbers into the calculator above and read the net-effect tile — is your room closer to the destination-café story or the lunch-rush one?
- Note how many hours a week you actually see laptop "campers" at a table you'd otherwise be turning — a rough estimate from staff is enough to start.
This month — fix the network, then decide the policy
- If the network isn't segmented, ask your internet provider or a local IT contractor for a business-grade router with guest-network VLAN support — this is normally a same-visit fix, not a rebuild.
- Set Quality-of-Service so the payment lane is reserved ahead of the guest lane, so a busy Friday night never makes a card terminal wait behind forty video calls.
- If your net effect reads negative, consider a time limit on the guest network (60–90 minutes is common) rather than turning it off entirely — it keeps the upside in step 2 while capping the downside in step 7.
- Rewrite the login screen's privacy notice in one honest paragraph: what you collect, what it's used for, and how long you keep it.
This quarter — connect it to your own marketing and cost stack
- If your capture rate is genuinely being used, send the first post-visit e-mail and compare its open rate against your regular e-mail marketing baseline.
- Read the network segmentation point alongside the rest of your restaurant cybersecurity checklist — guest Wi-Fi is step one of nine there, and this guide is what step one actually involves.
- Re-check your login screen's consent flow against GDPR customer-data rules once a year, the way you would any other data collection point in the building.
- Re-run the calculator each season — a summer terrace and a winter dining room rarely see the same camping hours.
The password on the wall was never a neutral decision
Most owners who work through this find the same thing: nothing catastrophic, no villain, just a piece of technology that was switched on once and never revisited — while it kept quietly doing two different things at once the whole time. The network was never neutral; it just never got measured.
The good news is that getting the two compliance numbers right — a segmented network and a login screen that separates connecting from opting in — costs about the same twenty minutes whichever way your own net-effect number lands. That part isn't a judgement call. What kind of network to run after that, a destination café's open invitation or a lunch-rush venue's time-limited one, is the one decision in this guide that's genuinely yours to make, on your own numbers.
Put this next to your restaurant cybersecurity checklist and your e-mail marketing plan — the three belong in the same conversation, because they're the three places where the same router touches your guests, your till and your marketing list all at once.