(I think it is a terrible idea to require this; however, chances are any scheme like the one you are proposing will be shot down in flames once the WiFi owner is dragged into court.
If you require a username and password to access, then sure, you could track who is visiting what websites (provided you don't allow guest/guest like my high school did).
You see, if the WiFi network is truly open, then client-to-access point traffic is open and can be sniffed by other clients on the network. But if the network is secured, even trivially as above, then each client's connection to the access point is individually encrypted and cannot be sniffed.
That means, if you needed any password to join the network, you needn't fear the questionable critter with the MBP in the corner (unless he's hacked the store's ISP or upstream from there).