ENCS

See a guest's history before it repeats.

When a booking arrives, and again when the guest checks in, your team sees whether that guest already has a record. It never blocks the booking. It just means no one is caught off guard.

Redflag is an optional add-on for CheckinGuest. It cannot work without it, since the confirmed match depends on the passport scan at check-in. CheckinGuest runs perfectly well without Redflag, and Redflag is not sold on its own.

Book a demo
Property 1
Arriving now
Sofia Marek
14–17 Sep · Dorm 6B
 
Prior incident
Reported by another property
Property damage · High severity

A record that grows as operators join.

When a property logs an incident, that record surfaces at any other Redflag property the guest turns up at. Not as a list they can browse, only at the moment that guest books or checks in with them.

Redflag is new, so today the record spans the properties you operate. Every operator who joins widens it for everyone already in.

Joining does not hand anyone a searchable directory of guests. A property sees a record only when that guest is actually arriving. No browsing, and no lookups on people who have never stayed with you.

Two checkpoints, two levels of confidence.

The system only speaks at the two moments it changes what your team does.

At booking: a soft flag

A booking gives us a name and no document yet. We do not store a guest's email or phone, so the name, hashed, is all there is to match on. That makes it a weak signal: a prompt to pay attention and verify at check-in, never a verdict. Your team might ask for a deposit, assign a different room, or do nothing at all.

At check-in: a confirmed flag

The passport is scanned, so the document number is known. An exact match on that is a confirmed record, and everything downstream treats it differently from a booking-time guess. Now the decision is made with certainty, not a hunch.

What a record holds.

Staff log an incident after it happens, in a few seconds, on one form.

01
A category
Noise, damage, unauthorised guests, smoking, theft, non-payment, chargeback, no-show, abusive behaviour, or other. Nothing outside that list.
02
A severity
Info, minor or serious. A serious record has to carry evidence: a police reference, a photo, or a written complaint. No evidence, no serious flag.
03
When, and a factual note
The date it happened and a short note of what happened. Facts, not opinion, and no labels attached to the person.
04
Evidence files
Photos and PDFs attach to an incident. They are stored privately, served only to staff who can already see that incident, and deleted when the incident expires.

Open a flag, see the whole record.

A flag is never the last word. Behind it is the record it came from, and the rights of the guest it names.

In the record
  • Which property logged it, and when it happened
  • The category and the severity
  • The factual note
  • The evidence, if any is attached
  • Whether the record is contested
The guest's rights
  • A listed guest can ask what is held about them
  • They can contest any record
  • A contested record still shows, marked as contested
  • The property that logged a record can correct or withdraw it

Kept to what is needed, and no further.

Records exist to inform a decision, then they expire. There is exactly one way to reach one outside the access rule, and it is accountable.

Retention
12
months
Info / minor
36
months
Serious

Deleted on expiry, not archived, on its own clock that is independent of Foreign Police filing.

The one exception

When a guest asks what is held about them, an administrator can look the record up to answer that request. It is the only way to reach a record outside the access rule above, and every use of it is audited, so it is always accountable.

What it will never do.

It never blocks a booking. The decision is always yours to make.
It never uses nationality, country of origin, or any protected attribute as a signal.
It never scores or ranks guests. Records only, nothing derived from them.

Put it in front of your front desk.

Book a demo