If you wanted your Wi-Fi to be for customers only then you'd use WPA2 Enterprise with unique per-user passwords, or at least change the static password every day.
Changing the password everyday is an acceptable compromise.
Another solution would've been to implement WPA2 Enterprise, where employees could have their own, permanent credentials while visitors get temporary ones.
Now give me my million dollars!
Let’s be real. You can’t have your cake and eat it too.
Or maybe make it as easy as possible, never changing the password and thereby getting repeat trade. I am sure a firewall can be opted into with the ISP to make sure nobody is downloading ISIS kiddie porn, Trump tweets etc.