Think about what you know about the guest arriving Friday. Their full name. Their email and phone number. Where they live. How they paid. The dates their own home will sit empty while they stay in yours. And the code that opens your front door, which you texted them this morning.
Now flip it. That is also what someone else could know, about every guest you have ever hosted, if the account holding it were compromised.
Most hosts think of themselves as running a property. Operationally, they are also running a small data business, one that collects personal information, payment details, door codes, and camera footage, stores it across a half-dozen apps and inboxes, and carries almost none of the coverage a business holding that data would be expected to have. In the audits we run, cyber coverage is the most consistently absent protection there is. Not thin. Absent.
This is about that exposure, both halves of it. The data you hold, and the devices you operate.
What a host actually holds
Run a quick inventory of where your guest information lives. The platform accounts, with years of booking history. Your email, holding confirmations, ID photos some hosts collect, and every door code you ever sent. The smart lock app, with codes and entry logs. The camera system, with footage. The dynamic pricing tool, the channel manager, the guest messaging service, the spreadsheet of past guests you keep for direct bookings.
Each one holds some slice of names, contact details, payment information, stay dates, and access credentials. Most are protected by a password you set years ago, reused from somewhere else, without two-factor authentication. That is the whole vault. For a business holding other people’s personal and financial information, it is a thin door.
Why this data is different
A retailer’s breached data exposes cards and emails. A host’s breached data does something worse. It pairs identity with location and access.
A booking record says whose house will be empty and when, because the guest is at yours. A door code paired with an address is a key. Entry logs say when the property sits vacant between stays. This is information that translates directly into physical risk, for your guests’ homes and for your property, in a way most breached data never does.
That is worth sitting with, because it changes the stakes. A compromised host account is not just a privacy problem. It is a burglary map. And if a guest’s information leaks from your systems and harm follows, the question of your responsibility for how you stored it will be asked by someone whose job is to ask it.
The device side of the same problem
The second half of this exposure is not data someone steals. It is data you collect on purpose, with devices you installed.
Cameras earn their keep on a rental. They catch the party before it starts and document the trailer that backed up to the garage. But a camera pointed the wrong way, or disclosed the wrong way, converts from protection into the claim itself. Guest privacy claims over recording devices are a real and growing category of litigation, and the platforms have moved with it. Airbnb banned indoor security cameras outright in 2024, and requires outdoor devices and noise monitors to be disclosed. The rules elsewhere vary by state, and some states treat audio recording far more strictly than video.
The pattern in the claims is rarely a hidden camera planted in bad faith. It is a doorbell camera nobody mentioned in the listing. An old indoor camera left live after the rules changed. A device that captures audio the host never realized was audio. The exposure comes from drift, devices accumulating over the years while the disclosures stand still.
And privacy claims land in an awkward spot for coverage. Liability policies are built around bodily injury and property damage. A claim for invasion of privacy, for recording someone, is neither. Whether anything covers it depends on the specific policy’s personal injury provisions, which is exactly the kind of question to ask before a demand letter arrives, not after.
What cyber coverage does, and where it lives
Cyber liability coverage exists for the first half of this problem. In its usual small-business form, it does two jobs. It pays your own costs after a breach, the forensics, the legally required notifications to affected people, credit monitoring, sometimes funds lost to fraudulent instruction scams, the fake invoice that redirects a payout. And it covers your liability to the people whose data was exposed.
The notification piece matters more than hosts expect. Breach notification laws exist across all fifty states, and they apply based on holding people’s data, not on company size. A host with eight years of guest records is holding a lot of people’s data.
Here is the gap. Homeowner’s policies do not cover this. Landlord policies do not. Most short-term rental policies, including good ones, do not include it by default either. It is its own coverage, bought as an endorsement or a standalone policy, generally inexpensive at small-business scale. Which is why the audits keep finding the same thing. The coverage is cheap and available, and almost nobody has it, because nobody told them the exposure existed.
The log that cuts both ways
One more angle, because it connects to a theme that runs through every claim we write about: documentation.
Smart lock entry logs are one of the most useful records a host has. When a property damage claim turns on who was inside and when, a timestamped entry log is evidence. When a guest disputes the timeline of an incident, the log speaks. Our piece on the first 24 hours after an incident points to access logs for exactly this reason. Kept properly, they are on your side.
The same log, mishandled, joins the exposure. It is guest data. It says when people came and went. It belongs in the inventory of what you hold, retained for a sensible period, protected like the rest, and disclosed honestly if asked. The habit is the same one we keep returning to. The records that protect you only protect you if you manage them on purpose.
What to do
Inventory what you hold and where. The accounts, the apps, the inboxes, the spreadsheet. You cannot protect a vault you have never listed.
Harden the cheap way first. Unique passwords and two-factor authentication on every account that touches guest data or door access. Rotate door codes between stays rather than reusing a house code. Delete guest data you no longer need. None of this costs money.
Walk the property for devices. Every camera, doorbell, and noise monitor. Confirm each one is outside, disclosed in the listing, compliant with your platform’s current rules, and not capturing audio you cannot lawfully capture. Then check that the listing disclosure matches what is actually installed today, not what was installed when you wrote it.
Ask two coverage questions. Does anything in my current policies respond to a data breach or a privacy claim? And what would a cyber endorsement cost me? The first answer is usually no. The second is usually smaller than you expect.
The property side of this business gets all the attention because it is visible. The data side is invisible right up until it is the whole problem. Ten minutes of inventory and two questions to your agent put you ahead of nearly every host in the market, because on this one, the bar is on the floor. The Risk Score asks the documentation and device questions, and a coverage audit reads your policies for the privacy and cyber answers.
This article is educational and describes common coverage structures and platform policies in general terms. Cyber and privacy coverage terms, recording laws, and notification requirements vary by policy, carrier, platform, and state. Confirm your own obligations and coverage with a licensed advisor.