Offering Wi-Fi to customers and visitors is normal and welcome, but the way it is usually done carries a quiet risk. In many small businesses there is a single wireless network, and everything joins it: the computers, the payment system, the business's own devices - and also the customers' phones, visitors' laptops, and the staff's personal devices. When all of those share one network, they can potentially reach one another, which means a visitor's device, or an infected personal phone, is sitting on the same network as the systems that run the business and hold its data. One compromised or careless device becomes a doorway to everything else, simply because everything else is on the same side of the door.
The fix is to separate the network people visit from the network the business runs on, and most modern business routers make this straightforward through a feature usually called a guest network. A guest network provides internet access to whoever connects to it while keeping those devices walled off from the main network and from each other. Customers get their Wi-Fi; the business's computers, payment systems and files sit on a different network that the guests' devices cannot see or reach. The visitor gets exactly what they wanted - a connection - and gets nowhere near the systems that matter, because the two networks are kept deliberately apart.
The value of this separation is that it contains problems instead of letting them spread. If a device on the guest network is infected or hostile, the damage is confined to the guest side; it cannot reach across to the business's own systems, because the guest network is designed precisely to prevent that. It also keeps the business's internal traffic and devices out of sight of everyone who merely wanted to check their email while they waited, which is both a security and a privacy improvement. The same approach usefully covers staff personal phones and any casual devices too: putting anything that does not need to touch the business's core systems on the guest network keeps the trusted network small and known, which is far easier to keep safe than a network everything has been allowed to join.
Setting this up is typically a one-off task - enabling the guest network in the router's settings, giving it its own name and password, and pointing visitors and non-essential devices at it - and the router being used may well already have the capability sitting unused. It costs nothing beyond a little time, and it turns "everyone on one network" into a clean separation between the people passing through and the systems the business depends on. For a change this small, the protection is disproportionate: it removes an entire category of risk in which a single weak visitor device could reach the till, the computers and the customer records, and replaces it with a guest network where a problem stays a guest's problem and never becomes the business's.