Privacy Policy

Hudson House LLC Last Updated: August 26, 2026

1. Introduction

Hudson House LLC ("Hudson House," "we," "us," or "our") is a California limited liability company that configures existing Wi-Fi infrastructure at business, institutional, and commercial locations to enable mobile carrier data offload.

This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to:

  • hudsonhouse.io and any subdomain or page we operate (the "Site");
  • our communications with prospective and current venue partners, hosts, and channel partners; and
  • the data we receive in connection with operating carrier offload services at partner locations (the "Services").

This Policy does not cover the privacy practices of: (a) the venue or property owner whose Wi-Fi network you connect to; (b) your mobile carrier; or (c) any third-party website or service linked from the Site. Each of those parties maintains its own privacy practices, and we encourage you to review them.


2. Who This Policy Applies To

We interact with three distinct groups, and the information involved is very different for each. This Policy is organized accordingly.

Group What this means Section
Business contacts Owners, operators, IT staff, and channel partners who inquire about or contract for our Services §3
Site visitors Anyone browsing hudsonhouse.io §4
Mobile subscribers People whose mobile devices connect through a partner location's network §5

3. Information We Collect From Business Contacts

When you submit our onboarding form, request a network audit, email us, or call us, we collect:

Contact and business information

  • Name, email address, telephone number, and job title or role
  • Business or organization name
  • Location name and street address of the site or sites you are inquiring about
  • Site type (restaurant, campus, medical facility, retail, etc.)

Network and infrastructure information

  • Wi-Fi controller make, model, and management platform
  • Controller NAS-ID or hardware (MAC) address
  • Access point count, manufacturer, model, and indoor/outdoor placement
  • Internet service provider and circuit information you choose to share
  • Additional technical configuration details exchanged during qualification, onboarding, and support

Commercial and relationship information

  • Correspondence, proposals, qualification results, and support requests
  • Contract, payment remittance, and tax information (including a W-9 and payment instructions) once a partnership is executed

We collect this information directly from you. We may also receive information about you from a channel partner or referral source who introduced us, or from publicly available business sources.

Why we ask for network details. Controller identifiers and access point inventories are required to determine whether a location technically qualifies, to register the location with our carrier and roaming partners, and to attribute settlement revenue to the correct site. We treat this information as confidential business information belonging to you.


4. Information We Collect From Site Visitors

Information you provide. Anything you type into a form on the Site, including the fields listed in Section 3.

Information collected automatically. When you visit the Site, our hosting provider and any analytics tools we use may automatically record:

  • IP address and general geographic region derived from it
  • Browser type, device type, operating system, and screen size
  • Pages viewed, time on page, referring URL, and exit pages
  • Date and time of access

Cookies and similar technologies. The Site uses cookies and similar technologies for essential functions (page delivery, caching, security, form handling) and, where enabled, for analytics and marketing measurement.

[ACTION REQUIRED - confirm before publishing] List the specific tools you actually run here. For example: Google Analytics 4, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Hotjar, HubSpot, reCAPTCHA. If you run any advertising or social pixel, see Section 10 - that likely constitutes "sharing" under California law and requires an opt-out link in your footer.

You can set your browser to refuse cookies or alert you when cookies are being sent. Some parts of the Site may not function properly if you disable them.

Do Not Track. The Site does not currently respond to browser Do Not Track signals, because no common standard for them has been adopted.


5. Carrier Offload Data - What We Do and Do Not Receive

This section describes what happens when a mobile device connects through a Hudson House partner location. It is the section most likely to be reviewed by a security, privacy, or procurement team, and it reflects how the service is actually built.

How the connection works. Participating carrier subscribers connect automatically over a Passpoint (Hotspot 2.0) network. Authentication is performed between the device and the subscriber's own mobile carrier using encrypted industry-standard protocols. Hudson House does not hold, issue, or have access to subscriber credentials, and we cannot decrypt the authentication exchange.

Traffic isolation. Carrier offload traffic is carried on a network segment that is logically separated from the venue's business network and, where present, from its guest network. Hudson House does not access, monitor, inspect, or store the content of any communication carried over the network. We do not perform deep packet inspection, we do not log browsing history, and we do not read messages, calls, or files.

What we actually receive. For settlement and reporting purposes, we receive aggregate usage data by location - principally the volume of data offloaded at a given site over a given period, and which carrier it is attributable to. We use this to calculate revenue owed to the venue and to any applicable channel partner, and to report performance back to the venue.

We do not receive from our carrier and aggregator partners, and we do not ask for:

  • Subscriber names, phone numbers, email addresses, or account numbers
  • Billing or payment information belonging to subscribers
  • Individual session records tied to identified persons
  • Location tracking or movement histories of individuals
  • The content of any communication

Where our systems or our partners' systems process technical records for authentication or settlement, those records may include pseudonymous network identifiers (such as a device hardware address) and volume or duration values. We do not use such identifiers to identify any individual, and we do not combine them with other information for that purpose.

Contractual backing. Our agreements with carrier aggregators and roaming partners obligate them to provide venue-level usage data on an aggregate basis and expressly exclude personally identifiable information, device identifiers, and individual session records. Our agreements with venue hosts limit our use of usage data to operating the Services and reporting to the venue and its channel partner.

Venue responsibility. If your business also operates its own guest Wi-Fi network, captive portal, marketing analytics, or presence-detection system, that network is yours, not ours, and you are responsible for providing any notice and obtaining any consent required for it. Hudson House does not operate, control, or receive data from your guest network.


6. How We Use Information

We use the information described above to:

  • Evaluate whether a location technically and commercially qualifies for the Services
  • Prepare projections, proposals, and network audits
  • Register locations with carrier, aggregator, and roaming partners and obtain carrier approval
  • Configure, deploy, monitor, troubleshoot, and support partner networks
  • Calculate, verify, and remit revenue share payments to venues and channel partners
  • Produce performance reporting and statements
  • Communicate with you about your inquiry, your account, and the Services
  • Send you information about our services where permitted by law and subject to your right to opt out
  • Meet our tax, accounting, audit, insurance, and legal obligations
  • Detect, investigate, and prevent fraud, abuse, security incidents, and misuse of networks
  • Improve the Site and our services

We do not use automated decision-making that produces legal or similarly significant effects about individuals.


7. How We Share Information

We share information only as described below. We do not sell personal information, and we have not sold personal information in the preceding twelve months.

Carrier, aggregator, and roaming partners. To register and activate locations and to settle revenue, we share location names, addresses, network identifiers, and equipment inventories with the mobile carriers, aggregators, and roaming partners through which offload is delivered. This is business and technical information about the location, not personal information about your customers.

Channel partners. Where a channel partner introduced a venue, we share the reporting necessary to calculate and support that partner's commission.

Service providers. We use third parties to host the Site, deliver email, manage customer records, process payments and remittances, and provide accounting, bookkeeping, and IT services. They may access information only to perform services for us and are contractually restricted from using it for their own purposes.

Professional advisors. Our attorneys, accountants, auditors, and insurers, subject to duties of confidentiality.

Corporate transactions. If Hudson House is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require any successor to honor this Policy or provide notice of any material change.

Legal and safety. We may disclose information where required by law, subpoena, court order, or governmental request, or where we believe disclosure is necessary to protect our rights, enforce our agreements, or protect the safety of any person.


8. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encrypted transport for network authentication traffic, network segmentation between carrier offload traffic and venue systems, access controls limiting internal access to those with a business need, and vendor diligence on the partners we work with.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you share information with us at your own risk. If you believe your interaction with us is no longer secure, contact us immediately at the address in Section 14.


9. Data Retention

We retain information for as long as needed to fulfill the purposes described in this Policy, and thereafter as required for legal, tax, audit, and dispute-resolution purposes. In general:

  • Inquiries that do not become partnerships: retained for up to [24] months, then deleted or anonymized
  • Active partner records: retained for the term of the agreement
  • Contracts, settlement records, and tax records: retained for [7] years after the relationship ends
  • Site analytics data: retained per the retention setting of the analytics tool we use

[ACTION REQUIRED] Confirm these periods match what you actually do, and adjust the bracketed numbers.


10. Your Privacy Rights

California Residents

Under the California Consumer Privacy Act, as amended by the CPRA, California residents may have the right to:

  • Know what personal information we have collected, the sources, the purposes, and the categories of recipients
  • Access a copy of the personal information we hold about you
  • Correct inaccurate personal information
  • Delete personal information, subject to legal exceptions
  • Opt out of the sale or sharing of personal information
  • Limit the use of sensitive personal information
  • Non-discrimination for exercising any of these rights

Categories of personal information we collect (using the statutory categories):

Category Collected Examples
Identifiers Yes Name, email, phone, business address, IP address
Commercial information Yes Services inquired about or purchased
Internet or network activity Yes Site browsing and interaction data
Geolocation data Yes Business location address; approximate region from IP
Professional or employment information Yes Job title, employer
Sensitive personal information No We do not collect SSNs, precise geolocation of individuals, racial or ethnic origin, health data, biometric data, or communications content
Education information No -
Inferences No We do not build profiles about individuals

Sale and sharing. We do not sell personal information. Whether we "share" personal information for cross-context behavioral advertising depends on the marketing tools running on the Site — see the action item in Section 4.

[ACTION REQUIRED] If you run a Meta Pixel, LinkedIn Insight Tag, Google Ads remarketing tag, or any similar advertising technology, California law treats that as "sharing." You must then add a "Your Privacy Choices" or "Do Not Sell or Share My Personal Information" link in the site footer, and honor Global Privacy Control signals. If you run none of these, delete this note and state plainly that you do not share personal information for cross-context behavioral advertising.

How to exercise your rights. Email privacy@hudsonhouse.io with "Privacy Request" in the subject line, or call 323-447-9494. We will verify your identity before responding, generally by confirming information already in our records. You may use an authorized agent, who must provide written proof of authorization. We will respond within 45 days, extendable by an additional 45 days with notice.

Other U.S. States

Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as those laws take effect, may have comparable rights to access, correct, delete, and obtain a portable copy of their personal information, and to appeal a denial of a request. Use the same contact method above; we honor these requests regardless of where you live.

Canada and International

If you contact us from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. We rely on your submission of the information as your consent to that transfer. Canadian residents may have rights under PIPEDA or applicable provincial legislation; contact us and we will assist.

Marketing Communications

You can opt out of marketing email at any time using the unsubscribe link in any message, or by emailing us. We will still send you transactional and relationship communications about an active partnership.


11. Children's Privacy

The Site and the Services are directed to businesses and institutions, not to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

Note that some of our partner locations, including schools, universities, and family entertainment venues, are frequented by minors. Because carrier offload authentication is performed by the mobile carrier and we do not receive subscriber identity, we do not knowingly collect any information about any individual connecting through a partner network, regardless of age.


12. Third-Party Links and Marks

The Site may link to third-party websites. We are not responsible for their content or privacy practices. Carrier names and logos appearing on the Site are the trademarks of their respective owners and are used to identify the networks with which offload is compatible.


13. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the "Last Updated" date above. If we make a material change, we will provide additional notice, such as by email to active partners or a notice on the Site. Your continued use of the Site after an update constitutes acceptance of the revised Policy.


14. Contact Us

Questions, requests, or complaints about this Policy or our handling of your information:

Hudson House LLC 1128 Dulzura Drive Montecito, CA 93108

General: david@hudsonhouse.io Phone: 323-447-9494 Hours: Monday–Friday, 9am–5pm Pacific


This Policy is provided in English. In the event of any conflict between this version and a translation, the English version controls.