TL;DR: A hotel can see which sites you connect to, when, for how long and how much data you moved. It cannot see the pages you read, the messages you send, the searches you run or the passwords you type, because HTTPS encrypts all of that. The metadata still tells a story, though, and the login form you filled in at the start is stored separately from any of it. Use a VPN or your mobile data if the destination itself is the sensitive part.
You connect to the hotel WiFi, tick a box, type your email, and you're online. Somewhere in a back office there's a router that just made a note of it.
The question most people have at that moment is a fair one. How much of this is the hotel watching?
The honest answer is more than you'd like and less than you fear. Let's go through exactly what a network operator can see, what modern encryption keeps from them, what the login page itself keeps, and what you can do about any of it.
Hotels see where you go, not what you do there
Here's the short version, and it holds for hotels, cafés, airports, gyms and every other guest network you'll ever join.
The network carries your traffic, so it sees the envelopes. Which server you contacted, at what time, for how long, and how big the exchange was.
It does not see the letters. The content inside those connections is encrypted between your device and the site you're visiting, and the network in the middle has no key.
That distinction is the whole answer. Everything below is detail on where the line sits and how much the envelopes give away.
.png)
What hotel WiFi can actually see
Domain names are the big one. Even with HTTPS, your device usually announces which site it wants before the encrypted tunnel is built, and your DNS lookups may pass through the network's resolver. So the network can log that you reached a given domain, even though the content stays sealed.
Timing and volume matter more than people expect. A short burst to a messaging service looks different from two hours of steady high-volume traffic to a video platform. Nobody needs to see your screen to work out which was which.
Device names leak. Phones and laptops broadcast a hostname when they join a network, and plenty of them are still called things like "Sarah's iPhone". If your login form asked for a name too, those two records sit side by side.
MAC addresses are less identifying than they used to be. Modern iPhones and Android devices generate a private MAC address per network by default, so the address the hotel sees usually isn't the one your device shows anywhere else. It stays consistent for that one network, which is how a portal recognises you when you come back.
.png)
HTTPS hides the content, and almost every site uses it now
The reason this question has a reassuring answer in 2026 is that the encrypted web won. The overwhelming majority of traffic on a guest network is HTTPS, and there is no practical way for a hotel router to read inside it.
Encrypted means encrypted. The hotel cannot see the article you opened, the flight you searched, the item you added to a basket, the message you sent or the password you entered. Not partially. Not with effort.
The exceptions are narrow and worth knowing.
Plain HTTP sites are readable in full. Almost nothing serious runs on plain HTTP anymore, but if you land on one, everything on that page travels in the open.
Certificate warnings are not to be clicked through. On a network you don't control, a browser warning about an untrusted certificate is the one signal that something may be intercepting traffic. Close the tab instead.
Corporate-style TLS inspection exists but is rare here. Some managed networks install their own root certificate on company devices so they can decrypt and inspect traffic. That requires access to your device, which a hotel does not have. Nobody can decrypt your traffic just by handing you a WiFi password.
.png)
The newest layer closed the last gap. Encrypted Client Hello, standardised as RFC 9849 in March 2026, hides even the domain name from the network during the handshake. Support is still uneven, because it needs encrypted DNS on your side and support from the site's CDN on theirs. Where it works, the network sees a connection to a content network and nothing more specific.
What the captive portal login page records is a separate thing entirely
This is the part people conflate, and it's worth separating.
The login screen you filled in is a captive portal. It's the system that holds you at a page until you complete some condition, then tells the router to let your device through. If you want the mechanics, our plain English guide to captive portals walks through the whole redirect chain.
What a portal like Spotipo stores: the details you typed, your device identifier, when you logged in, how long the session lasted, how much data you used, and which login method you chose.
What it does not store: your browsing. The portal handles authentication at the front door. It is not sitting in the traffic path afterwards reading what goes past.
That's a genuine architectural distinction, not a policy promise. Deep packet inspection is a different category of product that most hotels have never bought and would not know how to operate.
Where your email goes is the question worth asking. It usually syncs to a marketing platform so the venue can send you something later, which is exactly what the guide to guest WiFi email capture describes from the operator's side. If the splash page said it would email you, believe it.
Metadata still tells a story, so treat destinations as sensitive
Everything above is reassuring right up until you think about what a list of domain names actually reveals.
The content of a visit to a health service, a legal advice line, a dating platform, a job board or a support group is private. The fact of the visit often is not, and the fact is frequently the sensitive part.
Volume and timing sharpen it further. A long overnight session, a pattern of daily connections to one service, a sudden spike in upload traffic. None of that needs decryption to be meaningful.
So the practical rule is simple. If the destination itself is the sensitive thing, don't rely on HTTPS alone to protect it.
How to reduce what any guest network can see about you
Use a VPN for anything genuinely private. A VPN wraps everything, including the domain names, so the hotel sees one encrypted tunnel to one endpoint and nothing else. You're moving your trust to the VPN provider rather than eliminating it, so choose one that publishes a real audit rather than a slogan.
Turn on encrypted DNS. DNS over HTTPS stops your lookups from passing in the clear through the network's resolver. Most browsers support it in settings, and it's a one-time toggle. It's also a precondition for Encrypted Client Hello to work at all.
.png)
Use mobile data for the sensitive ten minutes. Not everything needs a technical solution. Banking, medical portals, anything you'd rather not have logged anywhere, do it on your own connection.
Rename your device. Changing "Sarah's iPhone" to something neutral costs thirty seconds and removes a name from a log you'll never see.
Keep private MAC addressing on. It's the default on current iOS and Android. Leave it alone.
Don't click through certificate warnings. Repeating it because it's the one moment where a bad decision actually matters.
What a responsible operator should be doing with all of this
If you run the network rather than use it, the guest side of this question is your design brief.
Collect less. Every field on your splash page is a record you now have to protect, justify and eventually delete. Ask for what you'll genuinely use and nothing else. Tools like email domain verification mean you can improve the quality of what you hold instead of hoarding more of it.
Say what you're doing on the page itself. Guests accept an email-for-WiFi trade readily when it's stated plainly. They resent discovering it afterwards. A GDPR consent screen shown before the login screen, and an age consent screen where relevant, makes the permission unambiguous rather than buried.
Know where the data physically sits. Spotipo hosts guest data in the EU and is built for GDPR compliance, which matters both for your legal position and for the answer you give when a guest asks. Being able to answer that question is itself a trust signal.
.png)
Have a retention position before someone asks. Storage limitation is a real obligation, not a formality, and requirements vary by jurisdiction, so check what applies where you operate. Holding guest records forever because nobody set a policy is the common failure.
Don't inspect traffic. You almost certainly have no lawful basis for it, no business need, and no appetite for what happens if it leaks. Authenticate at the door and leave the traffic alone. The wider operator view is covered in our guide to guest WiFi cybersecurity.
Frequently asked questions
Can a hotel see my browsing history on their WiFi?
Not your history in the sense of pages and searches. They can log which domains your device connected to, when, and how much data moved. The content of those connections is encrypted and unreadable to them.
Can hotel WiFi see what I search on Google?
No. Search terms travel inside an encrypted connection. The network can tell you used a search engine. It cannot see what you typed into it.
Can the WiFi owner see my messages on WhatsApp, iMessage or Signal?
No. Those apps are end to end encrypted, so the content is unreadable to the network and to the app provider's own infrastructure in transit. The network can see that the app connected, and roughly when.
Does using a VPN stop the hotel seeing anything?
Effectively yes. A VPN encrypts everything including the domain names, so the hotel sees an encrypted tunnel to a single endpoint. Your VPN provider can see what the hotel no longer can, so the choice of provider matters.
Does the captive portal login page track my browsing?
No. A captive portal authenticates your device and records the session, meaning login time, duration and data volume. It isn't in the traffic path reading what you do afterwards.
Can a hotel see what I browse if I use their WiFi on a laptop instead of a phone?
There's no difference. Visibility depends on encryption and network configuration, not on the type of device you're using.
How long does a hotel keep guest WiFi records?
It varies, and it should be governed by a written retention policy. Under GDPR, operators can only keep personal data for as long as they have a reason to, and some jurisdictions impose their own requirements on connection logs. You're entitled to ask what they hold about you.
Is public WiFi still dangerous to use?
Far less than it was, because encryption is now the default across the web. The realistic risks today are fake networks with convincing names and phishing pages, not someone passively reading your HTTPS traffic.
Running guest WiFi that guests can trust
Most people never ask what the network can see. The ones who do ask deserve a straight answer, and being able to give one is worth more than any splash page design.
That means collecting only what you need, saying so on the page, keeping the data somewhere defensible, and staying out of your guests' traffic entirely.
Spotipo handles the guest WiFi login without touching what happens after it. EU hosting, explicit consent screens, and only the data you chose to ask for. Start your free 14-day trial at spotipo.com and set up a portal you'd be comfortable explaining to the person using it.




