Trust
Security & Trust
Plain facts about how Rental Unify handles money, accounts, and guest stays. We only describe what the product actually does today.
Guest stay payments
- Guest stay payments run through Stripe Checkout to the host’s Stripe Connect account. The host is the merchant of record for the stay.
- Rental Unify does not receive, hold, or control guest booking funds (unless a future fee is clearly shown at checkout).
- Card numbers are collected by Stripe. Rental Unify does not store full card numbers.
Authorization vs charge
- When Instant Book is off, the guest’s card may be authorized (held) until the host approves. Approving charges the guest; declining releases the hold.
- Optional security deposits use a separate Stripe authorization (card hold) that the host can release or capture per listing Trust Kit settings.
Private listings
- Direct Booking pages use unguessable links and optional QR codes. There is no public browse-all marketplace.
- Hosts control Location Privacy: approximate city-level area on the listing (with full address after a confirmed booking), exact address on the private link, or the same reveal-after-confirm option by name.
Host account security
- Passwords are stored hashed. We never store OTA login passwords (iCal URLs only).
- Multi-factor authentication (MFA) is required for paid host and admin accounts, as configured in the product.
- Host and guest sign-in sessions use separate cookies.
Identity verification & evidence
- When a host enables ID checks, verification runs through Stripe Identity. Rental Unify stores verification status for the booking, not a copy of government ID images for advertising.
- Optional check-in / check-out evidence photos are stored for that booking so the host can review them.
Abuse reduction on public forms
When enabled by a Master Admin, public and guest forms may use Cloudflare Turnstile to reduce spam. That is a browser challenge, not a guarantee against all abuse.
More detail: Terms, Privacy, and the Knowledge Base.