How do I

How Do I Screen Guests Booking Direct?

Short answer

Screen direct-booking guests with the least intrusive checks that manage the actual risk: confirm working contact details, guest numbers, stay dates, payment status and acceptance of your house rules. Use a secure payment provider's fraud tools and apply the same objective criteria to every booking. Request identity documents only when necessary and proportionate, explain why you need them, collect them securely, restrict access and delete them when they are no longer required.

Start with the booking details, not an identity document

A useful first screen is a complete, internally consistent booking. Ask for the lead guest's name, email address, phone number, number of adults and children, arrival and departure dates, and any information needed to meet clearly stated occupancy, pet or accessibility rules. Send a confirmation link or message so you know the contact details work. This is usually enough to resolve ordinary mistakes without collecting sensitive evidence.

Ask neutral questions that relate directly to operating the property. You can confirm the number of guests, whether a pet is coming, whether the booking includes an event, and the expected arrival window. Avoid asking for personal characteristics or an open-ended explanation of why a person is travelling unless that information is genuinely needed. A family visit, work trip or holiday should not be treated as a risk category by itself.

New Zealand Privacy Principle 1 says an organisation should collect personal information only for a lawful purpose connected with its functions and only when the collection is necessary. That makes 'collect everything just in case' a poor default. Define the problem each field solves, remove fields that do not solve one, and state what you collect in a plain-language privacy notice beside the form.

Use secure payment and fraud controls

Take payment through a reputable payment provider rather than asking guests to send card details by email, message or phone. Use the provider's built-in controls, such as address checks, card authentication and risk signals, and follow its documented response when a payment is declined or flagged. A successful authorisation reduces risk, but it does not guarantee that a payment cannot later be disputed or refunded.

Set a written process for unusual payments. For example, pause a booking when the cardholder name and lead-guest name differ, then ask for a simple explanation or have the cardholder complete the provider's normal authentication step. Do not guess that a booking is fraudulent solely because the guest is overseas, uses a foreign-issued card, travels through another country or has limited public information online. Those signals can have ordinary explanations.

Confirm that required deposits or scheduled payments have reached the status your payment provider treats as complete before releasing door codes. Keep check-in instructions in your booking system and send them at a consistent time. If a charge is reversed or disputed, use the provider's evidence process and your signed booking terms. Do not store full card numbers, security codes or screenshots of payment credentials yourself.

Request ID only when it is necessary and proportionate

Some properties have a genuine reason to verify identity, such as an insurer's documented condition, a high-value booking with a specific fraud flag, or a legal requirement that applies to the operation. Before asking, record the purpose and why less intrusive checks are insufficient. Tell the guest what document or verification result is needed, how it will be used, who can access it and when it will be deleted.

Where possible, use a vetted identity-verification provider that returns a verification result without sending the host a reusable copy of the document. Do not ask guests to email passport scans, driver-licence images or selfies to a general inbox. Do not routinely copy dates of birth or identity-document numbers into a booking record. Those details can cause serious harm if an account, device or mailbox is compromised.

Privacy Principle 5 requires reasonable safeguards against loss, misuse and unauthorised disclosure. Limit staff access, use multi-factor authentication, keep records in the booking system rather than personal devices, set a short retention period and delete information securely when the purpose has ended. Check that any overseas verification provider gives you suitable privacy and data-location information before adopting it.

Apply objective rules consistently

Write a short decision checklist and use it for every guest. Suitable criteria include payment completion, maximum occupancy, age requirements that are lawful and genuinely necessary, acceptance of no-party and noise rules, and provision of working emergency contact details. Record the criterion that was not met instead of vague impressions about whether a guest seemed trustworthy.

Do not search a guest's social profiles as a routine substitute for a fair process. A small online footprint is not evidence of risk, and social information can expose protected or irrelevant personal characteristics that should not influence a booking decision. Do not rely on nationality, ethnicity, disability, family status, accent, age or other personal traits as proxies for payment or property risk. Get legal advice before introducing a rule that may exclude a group.

Give guests a simple way to correct an error or explain a mismatch. If a legitimate payment is flagged, allow another secure payment method or a manual review. If you decline a booking, keep the explanation factual and tied to the written booking requirement. A consistent appeal path reduces avoidable cancellations and helps you identify when an automated fraud rule is rejecting good guests.

Make the stay rules part of confirmation

Show the cancellation policy, occupancy limit, pet policy, quiet hours, no-party rule, bond or damage process and check-in requirements before payment. Ask the lead guest to actively accept those terms and email a copy with the confirmation. Clear terms manage more real-world risk than collecting extra identity data after a vague booking flow.

Keep the process proportionate to the property and reservation. A one-night local booking for a large house may justify different operational checks from a week-long family stay, but the differences should come from documented risk factors, not instinct. Review declines, chargebacks, rule breaches and guest complaints periodically. Remove checks that add friction without reducing a measured problem.

Your privacy notice should identify the business collecting the information, the purposes of collection, likely recipients, access and correction rights, retention approach and a contact for questions. Update it when you add a new payment, booking or verification provider. Screening is strongest when it combines clear rules, secure systems and restrained data collection, rather than trying to build a permanent dossier on every guest.

Want to see what a finished direct-booking site actually looks like? Luc 22 is a complete example, built the same way we would build yours.

See Luc 22 Ask about my property
Not legal or tax advice

This page explains the general position at the time it was written. Rules differ by council, by property, and by your own structure, and they change. Confirm your specific situation with your local council, your accountant, or a lawyer before you rely on it.

Sources checked

Last reviewed: