Trust & policy

Risk & mitigation policy

Stahus operates a curated short-term rental marketplace across the Caribbean and beyond. This document lists the material risks our business faces, and the specific clauses, controls, and commitments we use to mitigate each one. It complements — and does not replace — our Terms of Service and Reimbursement Policy.

Version 1.0 · Effective June 2026

Payments & financial risk

Payments & financial risk

Chargebacks & payment disputes

Risk. Guests dispute card charges after a stay, leaving Stahus or the host out-of-pocket.

Mitigation clauses

  • All payments processed through a PCI-DSS compliant gateway (WiPay / Stripe) with 3-D Secure where supported.
  • Host payouts released only after check-in plus the policy-defined hold period to allow dispute window to begin.
  • Booking ledger, messaging history, ID verification, and check-in confirmation retained for at least 18 months as chargeback evidence.
  • Stahus reserves the right to debit a host's future payouts to recover a confirmed chargeback caused by host non-performance.

Off-platform payments

Risk. Hosts or guests move payment outside Stahus to avoid the 12% service fee, voiding coverage and exposing both parties to fraud.

Mitigation clauses

  • Automated detection of phone numbers, emails, payment app handles, and bank details in messages with an in-app warning.
  • Stahus Cover, refunds, and dispute support are void for any booking transacted off-platform.
  • Repeat off-platform solicitation results in listing suspension and forfeiture of pending payouts.

FX & settlement risk

Risk. Currency fluctuation between guest charge and host payout in multi-currency Caribbean markets.

Mitigation clauses

  • Bookings priced and charged in the host's listing currency; FX shown to guest at checkout is final.
  • Stahus absorbs intra-day FX movement up to 2%; movements beyond that are reconciled at the gateway's settlement rate.
  • Daily settlement reports reconciled against gateway statements; variances investigated within 5 business days.

Fraudulent bookings (stolen cards, synthetic identity)

Risk. Bad actors book with stolen payment instruments, then no-show or commit damage.

Mitigation clauses

  • Risk-scoring at checkout (device fingerprint, velocity, BIN/country mismatch, disposable-email checks).
  • Mandatory government-ID verification for new guests and any booking over $1,500.
  • Manual review queue for high-risk bookings before host confirmation; host notified only after risk clearance.

Trust & safety

Trust & safety

Property damage by guests

Risk. Guests cause physical damage, theft, or excessive wear to a host's home.

Mitigation clauses

  • Up to $1,000,000 Host Damage Protection per stay (see Reimbursement Policy).
  • Mandatory guest ID and payment-method verification before first booking.
  • Security deposit hold available for listings flagged high-value.
  • Claim window of 14 days from checkout with photo, repair-quote, and timestamp evidence.

Guest injury or third-party liability

Risk. A guest is injured on the property or causes damage to neighbors.

Mitigation clauses

  • Up to $1,000,000 Host Liability Insurance per stay.
  • Hosts must disclose pools, hot tubs, stairs, balconies, and waterfront access in the listing.
  • Mandatory smoke detector, CO detector, and first-aid kit attestation during listing creation.
  • Annual safety re-attestation required to keep a listing active.

Discrimination & harassment

Risk. Hosts or guests discriminate against protected characteristics or harass the other party.

Mitigation clauses

  • Non-discrimination policy required at signup; violations result in permanent removal.
  • In-app messaging scanned for slurs and abusive language with real-time warnings.
  • Reports triaged by Trust & Safety within 24 hours; emergency reports within 1 hour.
  • Affected guests rebooked at Stahus's expense up to the original booking value.

Unauthorized parties & events

Risk. Guests host parties, exceed occupancy, or use the home for commercial purposes.

Mitigation clauses

  • Booking agreement caps occupancy at the number selected at checkout; overages void coverage.
  • Hosts may require guest acknowledgement of a no-party clause before key release.
  • Stahus may cancel a stay without refund on credible evidence of an unauthorized event.
  • Damage from unauthorized guests covered under Host Damage Protection.

Listing misrepresentation

Risk. Listings advertise rooms, amenities, or conditions that don't match reality.

Mitigation clauses

  • Get-What-You-Booked guarantee: full refund or comparable rebooking within 72 hours.
  • Periodic photo and amenity audits; repeated misrepresentation results in delisting.
  • Hosts attest at publishing that photos are current and accurate within the last 12 months.

Operations & service continuity

Operations & service continuity

Host cancellations close to check-in

Risk. Hosts cancel last-minute, leaving guests stranded.

Mitigation clauses

  • Cancellation penalty (10% of booking value, min $50) charged to host for cancellations within 30 days of check-in.
  • Stahus rebooks the guest at a comparable home and covers any rate difference up to 20%.
  • Repeat offenders (3+ within 12 months) face listing suspension and search-ranking penalties.

Hurricanes & extreme weather (Caribbean exposure)

Risk. Hurricanes, tropical storms, floods, or earthquakes disrupt stays.

Mitigation clauses

  • Major Disruptive Events policy: full refund to guest and waived cancellation fee to host when a Category-1+ storm or government evacuation order is issued.
  • Real-time NOAA/CDEMA monitoring during hurricane season (Jun–Nov) with proactive guest notifications.
  • 24/7 emergency rebooking line with priority hotel placement.

Third-party vendor outage

Risk. Payment gateway, hosting, email, or auth provider downtime disrupts bookings.

Mitigation clauses

  • Status-page monitoring with auto-failover for email (primary + secondary SMTP) and CDN.
  • Booking requests queued and retried during gateway outages; guests notified within 5 minutes.
  • RPO 1 hour / RTO 4 hours documented in the incident runbook.

Support overload during peak season

Risk. Spike in queries during high season degrades response times.

Mitigation clauses

  • Tiered SLAs: emergency 1 hour, urgent 4 hours, standard 24 hours.
  • Seasonal surge staffing contracted ahead of Dec–Mar and Jul–Aug peaks.
  • Self-service knowledge base and AI triage for tier-1 queries.

Regulatory & legal

Regulatory & legal

Short-term rental regulation

Risk. Jurisdictions ban, license, or tax short-term rentals (e.g., zoning, STR permits).

Mitigation clauses

  • Hosts warrant they have all required permits, HOA/strata consents, and landlord permission.
  • Stahus removes listings on receipt of a valid government takedown notice.
  • Country-specific compliance pages link to local STR rules; updated quarterly.

Occupancy, GCT, VAT, and income tax

Risk. Failure to collect or remit lodging taxes exposes Stahus and hosts to penalties.

Mitigation clauses

  • Configurable tax collection per jurisdiction; remittance handled by Stahus where required by law.
  • Year-end tax summary (Form 1099-K / equivalent) issued to hosts crossing reporting thresholds.
  • Hosts remain responsible for declaring income; Stahus reports payouts to relevant authorities on request.

Data protection (GDPR, UK DPA, Caribbean DPAs)

Risk. Mishandling of guest/host PII triggers regulatory fines and reputational damage.

Mitigation clauses

  • Data minimization: only fields needed for booking, payout, and safety are collected.
  • All PII encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Subject Access Requests fulfilled within 30 days via in-app data export.
  • Sub-processors listed publicly with DPAs signed.

AML / KYC for host payouts

Risk. Payouts to unverified hosts facilitate money laundering or sanctions evasion.

Mitigation clauses

  • Host KYC (government ID + proof of bank ownership) before first payout above $1,000 cumulative.
  • Sanctions screening (OFAC, UN, EU, UK) at signup and on each payout.
  • Suspicious activity reports filed via the payment processor when thresholds are met.

Intellectual property infringement

Risk. Hosts upload photos, descriptions, or trademarks they do not own.

Mitigation clauses

  • Upload terms grant Stahus a license only to content the host warrants they own.
  • DMCA-style takedown process with a designated agent; repeat infringers banned.

Information security

Information security

Account takeover

Risk. Credential stuffing or phishing leads to compromised host/guest accounts.

Mitigation clauses

  • Password breach-list checks (HIBP) at signup and password change.
  • Optional 2FA for guests; required 2FA for hosts before first payout.
  • Anomalous-login alerts (new device/country) with one-tap session revocation.
  • Bank-detail changes require email + 2FA confirmation and a 24-hour cool-off.

Data breach

Risk. Attacker exfiltrates customer data from the database or backups.

Mitigation clauses

  • Row-Level Security enforced on every public table; service-role key restricted to server functions.
  • Quarterly penetration tests and continuous dependency scanning.
  • Incident response plan with 72-hour regulator notification commitment.
  • Encrypted, geographically replicated backups with quarterly restore drills.

API abuse & scraping

Risk. Bots scrape listings or hammer endpoints, degrading service.

Mitigation clauses

  • Per-IP and per-account rate limiting on search, booking, and message endpoints.
  • Bot detection on signup and high-risk endpoints; CAPTCHA on anomalies.
  • robots.txt + Terms prohibit unauthorized scraping; legal action reserved for severe cases.

Reputational & marketplace integrity

Reputational & marketplace integrity

Fake or coerced reviews

Risk. Hosts solicit positive reviews or retaliate against negative ones, distorting trust signals.

Mitigation clauses

  • Reviews only allowed from guests with a completed, paid stay.
  • Two-way blind review window (14 days) — neither side sees the other's review until both submit or the window closes.
  • Pattern detection flags reciprocal reviews and review-bombing; offending content removed.

Negative press from a high-profile incident

Risk. A single incident (injury, scam, discrimination) spreads in media and damages brand.

Mitigation clauses

  • Crisis-comms playbook with a 2-hour first-response SLA.
  • Designated spokesperson; legal review of public statements.
  • Post-incident review published within 30 days for material events.

Business model & financial sustainability

Business model & financial sustainability

Host concentration risk

Risk. A few large hosts dominate inventory; their departure would crater supply.

Mitigation clauses

  • No single host may exceed 5% of GMV in a given market without commercial review.
  • Active supply-acquisition pipeline targeting independent and boutique operators.

Margin compression

Risk. Competitor undercutting forces the 12% take-rate down.

Mitigation clauses

  • Differentiate on curation, design quality, and Caribbean-native support rather than price.
  • Optional paid host upgrades (pro photography, featured placement) diversify revenue.

Platform / infrastructure dependency

Risk. Sole reliance on a single cloud, payment, or auth vendor creates lock-in.

Mitigation clauses

  • Abstraction layers around payment, email, and storage to enable provider swaps within 30 days.
  • Data portability: full database export available to operations team at any time.

This policy is provided for transparency and is not legal, tax, or insurance advice. Specific coverage, limits, and remedies are governed by our Terms of Service, the Reimbursement Policy presented at booking, and applicable local law. Stahus may update these clauses; material changes will be communicated to active hosts and guests at least 30 days before they take effect.

Questions? Contact Trust & Safety.