Skip to main content

Owner Trust

Data Protection

We studied how rental site scraping works before building this platform. Here’s exactly what we do to keep your contact information between you and your renters.

1. The Threat We Designed Against

Before writing a single line of code, we ran our own analysis of how competing rental sites expose owner data. We found four techniques used by scrapers:

  • Plain HTML scraping — crawlers read tel: and mailto: links directly from page source. No JavaScript needed.
  • Headless browsers — tools like Playwright execute JavaScript and decode client-side obfuscation (including base64-encoded contact details) in milliseconds.
  • Unauthenticated APIs — many platforms expose owner PII via public REST endpoints with no authentication, making mass collection trivial.
  • Rate limit evasion — scrapers use residential proxy pools and random delays (2–8 seconds between requests) to defeat naive IP-based rate limiting.

2. What Owner Data We Collect

  • Name — used on your listing and in communication with renters.
  • Email address — used for Owner Portal access and platform notifications. Never shown in public listing HTML.
  • Phone number — kept in the private owner profile and not displayed on public rental listings.
  • Payment information — processed exclusively by Stripe. We never store card numbers.

3. How We Protect Owner Contact Info

  • Email never appears in HTML — owner email addresses are used server-side for Owner Portal and approved platform notifications. They are never included in a public listing response, even encoded.
  • Phone stays private — owner phone numbers are not rendered on public rental pages. Listing contact actions use the controlled STV mobile-app handoff instead of a public phone link.
  • Name truncation for inactive accounts — Inactive listings show “First L.” format instead of full name, making scraped data less useful for cross-referencing.
  • Address precision control — you choose: Hidden (nothing shown), General (“The Villages, FL”), or Exact (full street address). Default is General.
  • No public owner API — there is no unauthenticated endpoint that returns owner contact data. The owner profile API requires a valid session.
  • PII scoped at query time — public listing queries omit private owner phone and email fields. The data does not reach the public render layer or listing-aware app handoff URL.

For Property Owners

As a property owner on Stay The Villages, you have direct control over what renters can see. Here’s what you can manage per-listing:

  • Address precision — choose Hidden (nothing shown), General (village name only — default), or Exact (full street address). This applies to both the map embed and Google structured data.
  • Private contact details — owner phone and email are not displayed on the public listing. The listing-aware handoff carries only the public slug to the STV app.
  • Email is always private — your email address is never shown publicly. The website does not provide a renter inquiry form; customer contact begins in the STV mobile app when messaging is released.

Manage these settings in your property editor under Policies → Privacy & Visibility.

4. How We Protect Renter Info

  • Inquiry details sent through a released STV mobile-app flow, and retained legacy inquiry records, are shared only with the owner of the specific property.
  • We never sell, trade, or share renter contact information with third parties.
  • Inquiry data is retained for up to 2 years and can be deleted on request.

5. Our Technical Safeguards

  • Server-side rate limiting — supported public mutation endpoints (platform contact, rental alerts, newsletter signup, and owner login or registration) enforce per-IP request limits in our database, independent of JavaScript. Legacy web inquiry writes fail closed.
  • Cloudflare Turnstile CAPTCHA — challenge verification on all public forms, in addition to rate limiting.
  • Honeypot fields — invisible fields on supported public contact and signup forms that automated tools fill in, triggering silent discard of the submission.
  • HTTPS everywhere — all traffic is encrypted in transit via Cloudflare.
  • bcrypt password hashing — owner passwords are hashed with bcrypt before storage. We cannot recover them.
  • JWT auth on all owner routes — owner portal and admin routes require a valid signed session token stored in an httpOnly cookie.
  • Docker-isolated deployment — the application runs in an isolated Docker container with no direct database exposure to the internet.

6. Bot Blocking Policy

We allow most crawlers — including search engines, AI assistants, and SEO tools we use for our own performance tracking (Ahrefs, Data for SEO). We block scrapers that are primarily used to harvest contact data for resale or competitor intelligence:

  • SemrushBot
  • MJ12bot
  • DotBot
  • PetalBot
  • serpstatbot
  • Bytespider

These are disallowed via robots.txt. Compliant crawlers will honor this. Combined with rate limiting and honeypots, this creates meaningful friction for non-compliant scrapers.

7. Report a Concern

If you believe your contact information has been harvested from this platform, or if you discover a security vulnerability, please email us at [email protected]. We commit to responding within 48 hours.

For our full data collection and retention policy, see our Privacy Policy.

Own a home in The Villages?

Create an owner-direct listing free through December 31, 2026. You handle renter selection, the lease, rent, and property operations.

Stay The Villages provides the public listing page and owner tools. It does not collect renter payments.

List Your Home Free