Meta custom audiences from guest WiFi data: a checklist for venues
You will be able to decide whether your guest WiFi data is ready to feed Meta custom audiences, and run the routine yourself.
You turn guest WiFi sign-ups into Meta custom audiences by exporting opted-in profiles from Purple's WiFi Visitors data. Keep only guests who gave a specific advertising consent. Then upload their email, cell phone and name fields to Meta Ads Manager. Facebook login and registration-form profiles carry the most match keys. Build lapsed-guest, loyal-guest and suppression audiences first.
What do Meta custom audiences from guest WiFi data do for your venue?
A Meta custom audience lets you show Facebook and Instagram ads to people you already know. You upload a list and Meta matches it against its accounts. You then target, exclude or model new audiences from the matched group. For a venue, that list is the guests who connected to your WiFi and agreed to hear from you.
Facebook custom audiences for venues work the same way they do for online retailers, with one difference. Your list comes from people who walked through your door. The outcomes worth chasing are concrete:
- More repeat visits from lapsed guests who stopped opening email but still scroll Instagram.
- Lower wasted spend, because you stop paying to reach guests who visited last week.
- Better new-guest targeting, using lookalike audiences seeded from your regulars.
- Higher lifetime value, because paid social reaches guests between emails rather than replacing them.
The mechanism is what separates this from a standard email platform. Mailchimp, Klaviyo and HubSpot send campaigns to a list you already have. They do not build that list. Purple does. Every guest who connects to your Guest WiFi creates a WiFi Visitors record, captured as consented, first-party data. Across Purple's network, that adds up to 440 million logins in 2024 at 80,000+ live venues (Purple's own data).
Each record holds more than an email address. Purple's WiFi Visitors documentation lists what it stores. That includes which venues a guest visited, how many times, and the date of their last visit. It also includes how they connected, the devices they used and the campaigns you have sent them. That visit history turns a flat upload into audiences built on behavior. It also lets you check afterward whether the ads brought anyone back.
What do you need before you build a Meta custom audience?
A Purple license that includes WiFi Visitors
WiFi Visitors needs a Capture or Engage license. Purple Engage adds the CRM and email side. The same consented list then feeds both your email sends and your Meta audiences.
Login methods that collect match keys
Meta matches on identifiers such as email, cell phone number, name, date of birth and zip code. The fields you hold depend on how guests log in. Purple's Social Media Authentication article lists what each method collects, where the guest chooses to share it.
| Login method | Cell phone number | First and last name | Date of birth | Zip code | Value for Meta upload | |
|---|---|---|---|---|---|---|
| Registration form | Yes | Yes | Yes | Yes | Yes | High - five match keys |
| Yes | No | Yes | Yes | No | High - account email plus date of birth | |
| Yes | No | Yes | No | No | Medium - not offered on iOS devices | |
| Yes | No | Yes | No | No | Medium - email may be a work address | |
| X | No | No | Yes | No | No | Low - names only |
| Apple | No | No | Yes | No | No | Low - names only |
SMS authentication also collects a cell phone number, which Meta can match. It needs a Twilio connector.
Three practical points follow from the table.
- X and Apple logins give you names but no email. Meta's guidance is to pair names with an email or cell phone number. Purple's Follow On Form lets you ask for missing details after login.
- Google login does not appear on iOS devices. Google does not support the iOS WiFi login window. If your guests skew toward iPhone, a Google-first splash page leaves gaps.
- Social login needs one IT task. Your IT team or WiFi partner adds Purple's listed domains to the walled garden. That is the list of sites a device can reach before it is fully online.
A specific advertising consent
This is the step most often missed. Accepting WiFi terms and conditions to get online is not consent to social advertising. Under CCPA/CPRA, consent must be specific, informed, unambiguous and freely given. It cannot be bundled into terms a guest must accept to receive a service. The FTC and state attorneys general treat list-based targeting on social platforms as direct marketing.
So add a conscious-choice opt-in to your splash page. Keep it unselected, separate from your email opt-in and plain about the purpose. "Show me offers from [venue] on social media such as Facebook and Instagram" does the job. Applicable privacy regulations require you to tell guests who receives their data, so name Meta in your privacy notice. Your Purple account manager can confirm the best way to add the field for your login methods.
Access to Meta Ads Manager
You need advertiser access to a Meta ad account. You must also accept Meta's Custom Audience terms before your first upload. Those terms require you to hold the rights and permissions to use the data you upload.
How do you turn guest WiFi sign-ups into a Meta custom audience?
The full filtering and download steps sit in the WiFi Visitors support article. This is the checklist around them.
Step 1: filter to consented guests
In WiFi Visitors, use visitor tags and a date range to narrow the records. Start with your advertising opt-in. Then add the behavior that defines the audience, such as visit count or last visit date.
Step 2: download the file
Choose the download option that puts a unique visitor ID in the first column. That ID lets you join this file to session or social interest downloads later without guesswork. Purple emails you when the file is ready. It also appears under My account.
Step 3: clean the file before you upload
- Delete rows without an email or cell phone number. Name-only rows inflate your count and add little to matching.
- Delete columns Meta does not need, such as devices, sessions and social interests. CCPA/CPRA's data minimization principle asks you to share only what the purpose requires.
- Format cell phone numbers with the country code, as Meta's formatting guidance recommends.
- Remove anyone who has withdrawn consent since your last export.
Step 4: upload the list to Meta
In Meta Ads Manager, create a custom audience from a list file. Map each column to the matching identifier. Meta's documentation states that the data is hashed in your browser before upload. It also states that Meta deletes the hashed data once matching completes.
Step 5: name, date and store safely
Name each audience by segment and export date, for example "Lapsed 60-180 days - March". Then delete the local CSV in line with your retention policy. Do not leave guest data sitting in a downloads folder.
What match rates should you expect from guest WiFi data?
Meta does not publish a benchmark match rate. It also shows audience size as an estimate rather than an exact count. So measure your own rate, and learn what moves it.
Work out your ceiling first
Your matchable share is the number of rows with an email or cell phone number, divided by all consented rows. Suppose 30% of your guests log in with Apple or X and skip the Follow On Form. That 30% can never match. Fix it at the splash page, not in Ads Manager.
Then read Meta's estimate
Divide Meta's estimated audience size by the rows you uploaded. For example, say you upload 10,000 rows and Meta estimates 4,000 to 4,500 people. Your effective match rate is roughly 40% to 45%. Record it for every upload so you can see the trend.
What pushes your rate up or down
- Facebook login rows. The email a guest shares through Facebook login is the address on their Facebook account. That is the same account Meta matches against.
- More identifiers per row. Meta advises uploading several identifiers, because each one adds a chance to match. Registration-form rows carry email, cell phone, name, date of birth and zip code.
- Personal over work email. LinkedIn returns whatever address the guest holds on LinkedIn. That may be a work address with no Facebook account behind it.
- Freshness. People change numbers and abandon inboxes. Recent sign-ups are more likely to still use the address they gave you.
Minimum audience sizes
Meta needs a source audience of at least 100 people from one country to build a lookalike. It recommends between 1,000 and 50,000 people. A single small cafe may need several months of sign-ups before a lookalike is worth running. A group can pool sign-ups from every site into one audience.
Which audiences should you build first, and what should you send?
Start with three: lapsed guests, loyal regulars and recent visitors. Together they cover win-back, growth and waste. Add the other two once the first three run on a routine.
| Audience | Built from in WiFi Visitors | What to do in Meta | Best for | Refresh |
|---|---|---|---|---|
| Lapsed guests | Last visit 60-180 days ago, 2+ visits | Retarget with a return offer | Restaurants, bars, hotels | Monthly |
| Loyal regulars | 5+ visits in the last 90 days | Seed a 1% lookalike for new guests | Venues or groups with 1,000+ regulars | Quarterly |
| Recent visitors | Last visit within 14 days | Exclude from win-back and acquisition ads | Every venue | Every 2 weeks |
| Multi-venue guests | 2+ venues visited | Promote a new or quieter site | Groups with 3+ sites | Quarterly |
| Mobile-only sign-ups | Cell phone number, no email | Reach guests your email cannot | Venues using SMS login or registration forms | Monthly |
Lapsed guests: give them a reason to return
Give lapsed guests one reason to come back, tied to something new. A menu change, a seasonal event or a midweek offer gives them a hook. Run the campaign for two to four weeks, then stop and measure. Send the same offer by email from Purple Engage. Guests who open email and guests who only scroll then see one consistent message.
Loyal regulars: find more people like them
Do not retarget regulars with discounts they would visit without. Use them as the seed for a lookalike audience instead. Meta builds lookalikes at 1% to 10% of a country's population, and 1% sits closest to your source. Start at 1% and point the ads at your booking page or a specific event.
Recent visitors: exclude them
This audience costs nothing to build. Add it as an exclusion to every win-back and acquisition campaign. Without it, you pay Meta to show "we miss you" ads to someone who ate with you on Tuesday.
When to run each campaign
Match the timing to the visit pattern in your own data. If your WiFi Visitors data shows weekend peaks, schedule ads from Thursday so they land while guests make plans. If midweek is your quiet spell, aim win-back offers at Monday to Wednesday visits.
Meta works best alongside your direct channels, not instead of them. For channel choices beyond paid social, see our guides on SMS vs email for pubs and bars: which channel brings guests back and WhatsApp vs SMS for restaurant marketing: cost and reach compared.
Worked scenario: a 200-room hotel wins back past guests
The figures in this scenario are illustrative, to show the method and the arithmetic.
Situation. A 200-room city hotel held 14,000 WiFi Visitors records from the past year. Of these, 6,200 guests had checked the social advertising opt-in. Direct bookings from past guests had slipped, and email open rates were flat.
What the team did. They filtered to consented guests whose last visit fell between six and 12 months ago. That left 2,400 rows. They removed 300 Apple and X rows with no email. They held back 10% of the rest, 210 guests, as a control group. They uploaded the remaining 1,890 and ran a four-week direct-booking offer on Facebook and Instagram.
Measurable outcome. The measure was return stays, read from WiFi Visitors visit dates 60 days after launch. Say 5% of the exposed group returned, against 3% of the control group. The campaign then drove two extra stays per 100 guests. Across 1,890 guests, that is about 38 incremental stays. The team sets that figure against ad spend to get a cost per incremental stay.
Worked scenario: a shopping center reaches new shoppers
These figures are also illustrative.
Situation. A regional shopping center wanted more first-time shoppers ahead of the holiday shopping period. Its WiFi data held 3,100 consented shoppers who had visited eight or more times in the past 90 days. All of them had an email address.
What the team did. They uploaded the regulars as a lookalike seed and built a 1% US lookalike. Ads ran within a set radius of the center. Recent visitors were excluded, so spend went only on people new to the center.
Measurable outcome. The measure was new WiFi sign-ups at the center, a direct count of first-time visitors who connected. Say monthly new sign-ups rose from 2,000 to 2,400 against the same month last year. On $4,000 of spend, that is $10 per additional new shopper who connected. Comparing against the same month last year keeps seasonal uplift from being credited to the ads.
How do you know your Meta custom audiences are working?
Use a holdout group every time
Meta reports reach, frequency, clicks and spend. It cannot tell you whether a guest would have come back anyway. A holdout group can. Keep 10% of each audience out of the upload. Then compare return visits between the two groups in WiFi Visitors. For a more formal read, Meta runs its own conversion lift tests through Experiments in Ads Manager.
The numbers to report
- Return rate, exposed vs holdout. The difference is your incremental effect.
- Cost per incremental visit. Ad spend divided by the extra visits.
- Match rate per upload. A falling rate means your login mix or data freshness has slipped.
- Frequency. Ads Manager shows how often each person saw your ad. A small audience reaches high frequency quickly.
- Advertising opt-in rate. The share of WiFi sign-ups who check the box. It sets the ceiling for every audience you build.
Close the loop with visit data
This is where WiFi data adds something a website pixel cannot. A pixel sees website visits. WiFi Visitors records the guest walking back in and connecting, with a date and a venue. Report on that, not on clicks alone.
What goes wrong, and how do you avoid it?
Treating WiFi terms as advertising consent
Bundled consent fails privacy regulations. Add a separate, unchecked opt-in that names social advertising. Keep a record of when each guest gave it, because compliance standards require you to demonstrate consent.
Targeting guests who have opted out
Withdrawing consent must be as easy as giving it. You must stop direct marketing once a guest objects. List-based audiences do not update themselves. Replace the full list at each refresh rather than adding to it, so withdrawn guests drop out.
Uploading name-only rows
Apple and X logins without the Follow On Form give you names only. They inflate your upload count and depress your match rate. Remove them before upload, and fix the gap at the splash page.
Building audiences too small to use
A lookalike needs at least 100 people from one country. A small retargeting audience sees the same ad many times. Widen the date window or combine sites until the audience is large enough.
Paying to reach guests who are already coming
Without a recent-visitor exclusion, win-back budget goes on guests who visited this week. Build the exclusion first, and attach it to every campaign.
Uploading more data than the purpose needs
Social interests, likes, devices and session history help you segment inside Purple. Meta does not need them for matching. Keep them out of the file.
Discounting your regulars
Regulars who visit weekly do not need a discount to return. Use them as a lookalike seed, and save offers for lapsed guests.
Frequently asked questions
Which Purple plan do I need to build Meta custom audiences from WiFi data?
You need a Capture or Engage license, because both include WiFi Visitors. That is the record Purple creates for every guest who connects to your WiFi. Capture gives you the data and the download. Purple Engage adds CRM and email, so the same consented list drives your email sends and your Meta uploads. Your Purple account manager can confirm which plan fits your number of venues.
Does this work with the WiFi hardware we already have?
Yes. Purple is hardware-agnostic and runs as a cloud overlay on access points from Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. For social login, your IT team or WiFi partner adds Purple's listed domains to the walled garden on your access points or controller. Nothing changes on the Meta side, because the audience comes from a file you export and upload.
Is uploading guest WiFi data to Meta CCPA/CPRA compliant?
Yes, if you hold specific consent for social advertising and honor withdrawals. Accepting WiFi terms is not enough, because regulations bar bundling consent into a service. Add a separate unchecked opt-in and name Meta in your privacy notice. Upload only the match keys you need, and replace each audience when you refresh it. Meta's documentation states that list data is hashed before upload.
How is this different from building audiences in Mailchimp, Klaviyo or HubSpot?
The difference is where the list comes from. Email platforms send campaigns to the list you already have, but they do not build it. Purple builds the list from guest WiFi logins as consented, first-party data. Each record adds visit history: venues visited, visit counts and last visit date. That history is what lets you build lapsed and loyal audiences, then measure return visits afterwards.
Can we keep our current email platform and still use Purple data?
Yes. WiFi Visitors data downloads as a CSV, so you can import it into the email platform you run today. You can upload the same file to Meta in parallel. Purple also offers WiFi Visitors connectors, such as Salesforce, which show connector data inside each guest record. If you later move email into Purple Engage, the list and the sends sit in one place.
What match rate should we expect from WiFi sign-ups?
Meta does not publish a benchmark, so measure your own. Your ceiling is the share of consented rows with an email or cell phone number. Facebook login and registration-form rows carry the most identifiers. Apple and X logins carry names only unless you add the Follow On Form. Divide Meta's estimated audience size by the rows you uploaded, and record the figure every month.
How many WiFi sign-ups do we need before Meta audiences are worthwhile?
You need at least 100 people from one country to build a lookalike, and Meta recommends a source of 1,000 to 50,000. Retargeting audiences can be smaller, but watch frequency, because a small group sees the same ad many times. Single-site venues can pool several months of sign-ups. Groups can combine every venue into one audience.
How much work is it to run Meta audiences each month?
Expect one filtered export, one clean-up and one upload per audience each month. The first setup takes longer, because you add the advertising opt-in to your splash page and agree audience definitions. After that, the routine is fixed: export, remove rows without an email or cell phone number, remove withdrawn guests, replace the Meta list and compare results against your holdout group.