Production launch checklist
TrustStay is currently safe for local demo testing. Use this checklist before turning on real payments, payouts, and public users.
Current mode: demo/testing
Demo bookings simulate escrow and payout movement. Do not treat demo bookings as real financial transactions.
Stripe and payments
Form LLC or final business structure
Get EIN and complete Stripe business verification
Enable Stripe Connect for host payouts
Replace demo payments with production Stripe checkout
Enable Apple Pay in Stripe and verify the production domain
Configure production webhook secret
Test refund, release, dispute, and payout flows end-to-end
Public launch setup
Buy/connect production domain
Set NEXT_PUBLIC_APP_URL to the real HTTPS domain
Confirm support email and add a real phone number only when available
Add final logo, app metadata, and social preview images
Supabase and data
Review all row-level security policies
Run security-hardening-migration.sql and confirm storage buckets are private/public correctly
Back up production database
Separate test and production Supabase projects
Run launch-readiness-migration.sql in production
Confirm support tickets, notifications, and analytics tables exist
Trust and safety operations
Use admin support ticket queue daily
Review Admin → Security monitor for suspicious requests and upload attempts
Review AI high-risk photo flags
Monitor open disputes and refund rate
Complete owner verification policy before public listings
Define emergency and safety escalation process
Legal and safety
Attorney review for terms, privacy, cancellation, and refund policy
CPA/tax adviser review for sales tax, lodging/occupancy tax, owner tax responsibility, and platform fee wording
Confirm city/state/country rental rules, permit requirements, and owner compliance wording
Confirm chargeback, refund, payout reversal, and negative balance responsibility
Finalize support escalation policy
Decide insurance/liability approach
Document photo evidence and dispute decision rules
Add external alerts/monitoring for Vercel errors, Supabase errors, failed webhooks, and unusual traffic
Recommended next product step
Keep demo mode on while you polish the booking lifecycle, admin review, and owner/guest dashboards. Switch to real Stripe only after the business and legal setup are ready.
Open legal review pack