Most hosts collect passport scans and IDs by email or chat, then leave them sitting in an inbox forever. This guide explains why that is a real privacy risk, surveys the standard ways to handle guest data safely, and shows what good looks like: collect less, verify IDs through a system that never dumps the document in your inbox, set a deletion clock, and tell guests what you do with their data.

Sign up free. Nowistay runs guest identity verification through Stripe Identity, so the ID document stays with the verification provider and never lands in your inbox, while you get the result and a fuzzy match against the booking name. Free to try, then $12 per property per month after the trial.
Start free trialOpen your email and search for the word "passport." If you have been hosting for a year or two, you will probably find a dozen attachments: scanned ID pages, photos of driving licenses, the occasional full credit card front. Most of them arrived because you asked a guest to "send a copy of your ID" before check-in, and most of them have been sitting in your inbox ever since, fully indexed, fully searchable, backed up to whatever cloud your mail provider uses, and readable by anyone who ever gets into your account.
That pile is the quiet privacy problem almost every short-term rental host carries. You did not set out to build a database of government IDs. You were trying to follow the law (many countries legally require you to register guests and record their identity documents) or just trying to screen for fraud. But the way most hosts collect that data, over email or a messaging app, with no plan for deleting it, is exactly the kind of handling that data protection rules like the EU's GDPR were written to discourage. The fines are real, the breach risk is real, and the fix is mostly about changing how the data flows, not buying more software.
Personal data has a cost even when nothing goes wrong, and a much bigger cost when something does. Under the GDPR, a passport scan is not ordinary information. It identifies a person, it can be used for identity theft, and in many readings it counts as a sensitive category that demands extra care. The regulation expects you to collect only what you actually need, keep it only as long as you need it, protect it properly, and be able to explain, on request, what you hold and why.
An inbox full of IDs fails most of those expectations at once. There is no retention limit, so you are holding a license you took three summers ago for a guest you will never host again. There is no real access control beyond your password. There is no record of consent or a clear reason for keeping it. And email is one of the most common places data leaks from: a reused password, a phishing link, a forwarded thread, and suddenly someone has a folder of strangers' identity documents.
The numbers are not trivial. GDPR penalties can in theory reach into the millions or a percentage of turnover for serious cases, and while a single host is unlikely to face the headline figure, smaller fines and formal complaints are well within reach, especially if a guest reports you. Property managers handling dozens of units carry proportionally more exposure. Beyond regulators, there is the trust cost: a guest who learns their passport has been floating around your email for years is not booking with you again, and may say so publicly. Treating identity data carelessly is a liability that compounds quietly with every booking.
The full text and plain-language guides live at GDPR.eu; France's regulator explains the essentials in the CNIL's GDPR overview.

There is no single tool that makes guest data handling compliant, but a handful of approaches show up again and again. Most hosts end up combining two or three.
Strip away the jargon and a privacy-respecting operation passes a few simple tests. These are vendor-neutral; any combination of tools that satisfies them is fine.
Identity verification is the part of guest data where hosts get into the most trouble, because it is where the most sensitive document, a government ID, changes hands. Nowistay's approach is built so that document never lands with you.
Guest identity verification runs through Stripe Identity. When you ask a guest to verify, they complete the check on Stripe's secure flow, and the ID document is handled by the verification provider, not by Nowistay and not by you. What comes back to your dashboard is the result: whether the guest passed, plus a fuzzy match of the verified name against the name on the booking, so a near-match (a middle name added, an accent dropped) still lines up while a genuinely different person stands out. You get the confidence that the person checking in is who they claimed to be, without becoming the custodian of a passport scan. That is data minimization in practice, and it is exactly the kind of handling data protection rules reward: the riskiest piece of information never enters your inbox, your phone, or your message threads in the first place. You can turn it on per property in a couple of clicks; the steps are in how to enable guest identity verification.
Keeping documents out of your inbox also makes the rest of compliance easier. Because the verification result lives in your dashboard rather than in scattered email threads, answering a guest's question about what you hold is a matter of looking in one place, not searching three years of mail. If you run on more than a handful of properties and want to query your own records in plain language, the connector lets you link ChatGPT, Claude, or Gemini to your live Nowistay data and ask things like which bookings have a completed verification, which is described in how to connect ChatGPT, Claude, or Gemini to Nowistay. To be clear about scope: Nowistay handles the verification flow and keeps the raw document away from you, but it does not provide legal advice, and you remain responsible for your own privacy notice, retention rules, and any local registration obligations. Whether you verify guests through Nowistay or through a separate identity vendor bolted onto a full PMS, the criteria above (collect less, keep documents out of general tools, set an expiry, be transparent) are the test.

The single most common error: asking guests to email a photo of their ID, then never deleting it. Even if you read it once and move on, the file lives on in your sent and received folders and every backup behind them. If you must receive a document at all, get it out of email immediately and delete the original.
"Send a full copy of your passport" is rarely the right ask. For most stays you need to confirm identity and capture the specific fields a local law requires, not warehouse the whole document. Over-collecting turns a minor obligation into a major liability.
Hosts will set up a tidy storage system and still keep everything indefinitely because no one defined when files should go. Decide the retention period up front (often tied to how long a registration law requires records), write it down, and make deletion a routine, not an afterthought.
Many hosts collect personal data with no notice at all. Guests are entitled to know what you take and why before they share it. A short, honest notice is quick to write and closes a real gap.
Assuming that because a guest booked, you can add them to a marketing list is a frequent slip. The reason you hold someone's email to coordinate a stay is not the same reason you would need it to send promotions. Keep those purposes separate and do not assume consent you were never given.
You do not need a compliance project to make real progress. A few focused hours covers most of the risk.
Guest expectations around privacy are rising, and so is enforcement. The hosts who will sleep easy are the ones who stopped treating identity data as something to hoard and started treating it as something to verify, use briefly, and let go. The direction of travel is clear: less raw data in your hands, more of the sensitive work done by systems built to hold it safely, and a guest experience where handing over an ID feels secure rather than risky. Get the flow right now (collect less, keep documents off your own devices, set a deletion clock, and say what you do) and the next round of rules, whatever shape it takes, will be a small adjustment rather than a scramble.
Sign up free. Beyond identity verification, Nowistay's autonomous AI co-host answers guests in seconds, 24/7, in 15+ languages on Airbnb, Booking.com, WhatsApp, and email, and syncs your rates and availability across Airbnb, Booking.com, VRBO, Expedia, and Agoda. Onboard a property in minutes and keep guest data handling tidy from day one.
Try Nowistay free


































































































