In 2026, host groups and vendor blogs are pushing a simple-looking trick: put a splash in front of the property Wi-Fi. The guest types their name, email, and phone. Then the internet comes on. The pitch is that you capture every device in the house — not only the person who booked — and build a list for later.
That is not the same as asking how to reach them about this stay. Airbnb and Booking.com already limit how you get a real inbox. Privacy and spam law in New Zealand, the EU, the UK, Australia, and US states (they are not one rule) can treat a forced email gate as something else entirely: marketing collection.
The guidebook already has the Wi-Fi password. Copy it. Do not trade the network for an email.
The guest joins the Wi-Fi. Instead of a normal password, a page blocks the connection until they hand over personal details. Vendors sell this as “every guest, not just the booker.” Smart TVs, consoles, and watches often cannot complete that page. Reviews suffer. You now hold a file of emails you took in exchange for an amenity they already paid for.
This is not only cheap router software. Paid kits that look premium do it too. Ten One Design (makers of Wifi Porter) also sell Porter Hospitality and PHN: a splash that can request or require email for promotions. A tap or QR that only hands over the password is fine. Requiring an email before the network comes on is the same marketing-list job — you are still the one collecting.
We do not say they are breaking the law. Tap-to-share password stays fine.
The Privacy Act 2020 says you collect personal information only when it is necessary for a lawful purpose, by fair means, and you do not later use it for a different purpose without a proper basis. A password is enough to run Wi-Fi. Taking an email so you can market later is a different job.
From 1 May 2026, Information Privacy Principle 3A is in force. If you get someone’s details from someone else — a portal vendor, a CRM, a marketing tool — you must take reasonable steps to tell that person, unless an exception applies.
If you then send commercial email or texts without proper consent, the Unsolicited Electronic Messages Act 2007 applies. The Department of Internal Affairs says failure to comply can mean a fine of up to NZ$500,000 for an organisation.
Those figures are statutory ceilings. They are not a quote for your bach. This is not legal advice.
Official:
Privacy Commissioner — IPP 3A: https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/
Privacy principles: https://www.privacy.org.nz/privacy-principles/
DIA — how New Zealand regulates spam: https://www.dia.govt.nz/Spam-How-New-Zealand-Regulates-Spam
DIA — spam law for businesses: https://www.dia.govt.nz/Spam-NZ-Spam-Law-for-Businesses
Under the GDPR, consent must be freely given. You cannot make a service the guest already paid for — including advertised Wi-Fi — depend on consent to marketing if that data is not needed to run the network. The European Data Protection Board’s guidelines on consent cover this kind of tying.
If you later email an EU resident at home offering a return stay, the GDPR’s targeting rules can still apply even if the splash happened in New Zealand or Australia.
Administrative fines can reach up to €20 million or 4% of worldwide annual turnover — the law’s ceiling, not a bill in every inbox. This is not legal advice.
Official:
EDPB Guidelines 05/2020 on consent: https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en
GDPR (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2016/679/oj
The UK has its own UK GDPR and the Data Protection Act 2018, enforced by the ICO. The higher maximum fine is £17.5 million or 4% of worldwide annual turnover — again a ceiling. Electronic marketing also sits under PECR. Do not copy the EU block and change the flag. Read the ICO pages for your situation. This is not legal advice.
Official:
ICO — maximum fine under UK GDPR: https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/
ICO home: https://ico.org.uk/
The Privacy Act 1988 and the Australian Privacy Principles apply to many APP entities. The OAIC can seek court penalties for serious or repeated interference with privacy — for a body corporate, the Act’s maximum can reach AU$50 million (or other turnover / benefit tests in the statute). Small operators may sit outside some rules. Check the OAIC, not a Facebook summary. This is not legal advice.
Official:
OAIC: https://www.oaic.gov.au/
Privacy Act s 13G (AustLII): https://www.austlii.edu.au/cgi-bin/viewdoc/au/legis/cth/consol_act/pa1988108/s13g.html
There is no single US privacy statute like the GDPR. Federal CAN-SPAM (FTC) covers commercial email: it is mostly an opt-out regime, not an EU-style opt-in. If you send marketing email, that guide still applies. It does not bless a Wi-Fi gate.
California is the worked example. The CCPA / CPRA can mean administrative fines per violation (the California Privacy Protection Agency publishes the inflation-adjusted caps — on the order of a few thousand dollars per violation, higher if intentional). Those rules often apply only if you meet California’s definition of a “business” (revenue or data-volume thresholds). A one-listing host is not automatically in. Read the CPPA, not a vendor blog.
New York is not California copied. The SHIELD Act is about reasonable security for private information. If you store guest emails from a splash, you hold private information you must safeguard. The New York Attorney General enforces data-breach and SHIELD duties. Other states have their own laws. This page is not a 50-state chart.
Official:
FTC — CAN-SPAM for business: https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business
California Privacy Protection Agency: https://cppa.ca.gov/
CPPA monetary thresholds: https://cppa.ca.gov/regulations/cpi_adjustment.html
New York Attorney General — data breach / SHIELD: https://ag.ny.gov/internet/data-breach
After a booking, Airbnb lets you confirm that the contact they already gave you is OK for this trip, or use another channel if the guest asks. Their Off-Platform policy still prohibits soliciting email through Airbnb messages after a booking, and prohibits selling, sharing, or using guest contact for marketing or signing guests up to a list.
Booking.com does not give you the guest’s private email. You see an alias. They tell partners to stay on the Extranet or Pulse. Their own FAQ: they cannot share personal information; all communication should stay on Booking.com platforms.
Stay contact is keys and Wi-Fi for this reservation. A splash that builds a marketing list is the other job. Airbnb can suspend or remove listings. That is often the fine hosts feel first.
Official:
Airbnb Off-Platform and Fee Transparency Policy: https://www.airbnb.co.nz/help/article/2799
Booking.com for Partners — contacting guests: https://partner.booking.com/en-us/help/reservations/contact-extranet/contacting-guests
Read Airbnb Direct Booking Links →
Put the Wi-Fi name and password in the digital guidebook. Guests tap to copy. No splash. No email gate.
A printed QR can unlock Wi-Fi on site (Faster Wi-Fi Join). Door codes can stay behind KoruLock.
Pio answers in the stay so they are not hunting you for the password at midnight.
On Pro, Preferred Booking Link is the next stay — your direct booking website or your Airbnb Direct Booking Link — inside the guide they already have. That is not a list scraped from the router.
KoruSignal markets the live guidebook and your listings so new guests can find you. It does not need a captive portal. It does not guarantee a Google ranking.
Optional VIP in the guide is a guest choice for deals. It is not “give us your email or you do not get Wi-Fi.”
Create a free Digital Guide →
See Next Generation Guidebook →
The guidebook that markets your direct booking website →
Ghost Guide (Wi-Fi copy in three seconds) — https://korustay.co.nz/host_resources/why-guests-ignore-guides/
The only digital guidebook that markets your direct booking website — https://korustay.co.nz/host_resources/guidebook-that-markets-your-direct-booking-website/
Airbnb Direct Booking Links — https://korustay.co.nz/solutions/airbnb-direct-booking-links/
Airbnb Off-Platform policy — https://www.airbnb.co.nz/help/article/2799
After a booking you may confirm stay contact for this trip, or use another channel if the guest asks. Airbnb still prohibits using guest contact for marketing or signing them up to a list. A Wi-Fi splash that forces email before the network comes on is that second job.
No. Booking.com does not share private email addresses. You see an alias and message through the Extranet or Pulse. Stay on their platforms for that reservation.
No. Put the Wi-Fi name and password in the guidebook. Guests tap to copy. A printed QR can unlock Wi-Fi on site. That does not require their email.
No. KoruStay is the digital guidebook. The password lives in the stay. We do not gate the network to build a marketing list.
No. Ceilings in the law are not a bill in every inbox. Exposure depends on where you and the guest are, what you collected, and what you sent. Airbnb can still remove a listing. This is not legal advice.
Guest Sign-In
Unlock the VIP Experience ✨. Sign in to access exclusive local partner deals, save your favourite spots, and let Pio remember your preferences.
By signing in, you agree to our Privacy Policy.
Your tailored responses stay active while you remain signed in.
Your data is kept safe. Review our Privacy Policy.
Magic Link
Open links on a different device? No problem. Confirm the email you used so we can finish signing you in securely.
Guest Account
You will lose your tailored responses for this stay until you sign back in.