Compliance

Built for responsible host operations.

Bonsori supports short-term rental hosts with guest messaging, stay verification, ID document review and AI concierge access. This page explains the controls Bonsori provides and the responsibilities that still sit with each host.

Last updated: 20 July 2026

What Bonsori helps you control

Bonsori gives hosts a structured way to keep property information, StayLink guest verification, ID document review, guest messages, AI testing, calendar blocks and host notifications in one workspace.

The product is designed so guests verify their stay before concierge access opens. Where ID is required, guests upload documents for host review and the concierge remains locked until the host approves access.

Host responsibility

Hosts decide what information to collect, whether ID is required, which guests are approved, what property instructions are shown and whether any guest request should be accepted.

Hosts should only request ID or sensitive guest information where they have a lawful, booking, building, insurance or local compliance reason to do so. Bonsori is the tool used to collect and present that information; it does not decide whether the host is legally entitled to request it.

Guest ID and StayLink controls

StayLink is designed to collect guest name, email, stay dates, optional booking details and required ID documents before the AI concierge opens.

Approved stays receive a temporary 4-digit stay PIN that is valid for the stay window. The PIN helps guests regain access from a new browser or the app without exposing the concierge to anyone with only a public QR code.

After checkout, guest access is designed to end. Hosts can review previous stays and permanently delete records where appropriate.

AI concierge boundaries

Bonsori answers from host-approved property information, guest stay context and configured product services. Questions that cannot be answered safely should be escalated to the host.

Bonsori is not an emergency service, booking platform, legal adviser, travel agent, locksmith, payment provider or insurance provider. Guests should contact emergency services first if there is immediate danger.

Security controls

The host dashboard uses account-based access. StayLink guest actions use signed access tokens and stay status checks. ID documents are stored in private storage and are reviewed inside the host workspace.

Bonsori uses rate limiting, cross-origin request checks, private storage buckets, row-level security, signed guest access and provider-managed infrastructure to reduce exposure.

Privacy and data protection

Bonsori collects and processes host, property, guest, message, stay and document information only as needed to run the product, support the stay, notify the host, improve answers and meet legal or operational obligations.

Hosts should avoid adding unnecessary sensitive data to property guides. Guests should only upload ID where the host has asked for it for that stay and the purpose has been explained.

ISO 27001 readiness

Bonsori is not claiming ISO 27001 certification unless and until an accredited certification audit has been completed.

The product is being organised around ISO-style controls: access control, data minimisation, retention, supplier awareness, incident reporting, secure development, audit logs and risk review. Formal certification would also require company policies, evidence, audit scope, management review and ongoing control monitoring.

What hosts should do before launch

Review every property guide before sharing it with guests, confirm entry instructions and PINs are current, use lawful reasons for any ID request, keep host notification details up to date and remove guest records when they are no longer needed.

If you operate under local licensing, hotel-registration, building, insurance or platform rules, you should make sure your Bonsori setup matches those obligations.

Report a compliance concern

Email operations@bonsori.com with the affected property, guest flow or dashboard area. Please avoid sending unnecessary ID images or sensitive guest details by email unless requested through a secure support process.

Bonsori Compliance | Bonsori