Master Functional Specification
BoRo's controlling product specification, v9.0. Every canon claim on this site defers to this document — which is the whole reason it is here rather than one repository away.
Title: BoRo Master Functional Specification Eyebrow: Product Specification Version: v9.0 Status: Controlling — confirmed current 2026-08-20 Updated: 2026-07-30 Owner: Jaydan Hoang Nguyen, Chief Executive Officer Audience: Internal
The controlling product specification. Transaction, authorization, exchange, evidence, settlement and listing-restriction architecture.
[critical] This markdown is a conversion, and the executed
.docxis the source of record. Converted fromBoRo_Master_FSD_07_30_V9.docxon 2026-08-20 so that the specification lives where the Search-First precedence rule can reach it — it previously existed in no repository, which is why the Stage 2 canvas drifted from it on the money model and on listing restrictions. Headings, tables and locked callouts are carried across structurally; section numbering is preserved verbatim so every existing citation of the formFSD §6.1still resolves. Where this file and the.docxdisagree, the.docxgoverns and this file is the defect. Re-convert rather than hand-edit.
[positive] This document governs
boro-sharedas well as the product — confirmed by CJ on 2026-08-20. The question was live at conversion becauseconstants.tscites a numbered module family — “FSD 07”, “FSD 10”, “FSD 01” — that this Master does not reference. It is now settled: where a numbered module and this Master disagree, this Master governs. Four constants therefore stand as defects rather than as a difference of scheme.
| Constant | Code | This document |
|---|---|---|
MAX_TOTAL_RENTAL_DAYS |
12 | §13.1 — 30 days, both lanes. MAX_RENTAL_DAYS = 6 is correct as the Lane B segment ceiling; the total and the extension ceiling are not |
MILEAGE_RATE_CENTS |
50 | §8.3, §10.6 — 75 |
BORROWER_FEE_PCT |
0.06 | §6.3 — 0.07; 7% borrower + 3% lender = 10% blended |
STRIPE_AUTH_WINDOW_HOURS |
155, hardcoded | §7.6 — the constant should not exist. Read Stripe’s capture_before on each charge and schedule downstream jobs against that value |
And §6.2’s two-lane model is not represented in code at all — ShieldTierEnum is damage severity (none/minor/moderate/severe), not lane. Lane is derived from declared value, so it wants a boundary constant and a resolver, never a stored field that can drift from the value it was derived from.
ASTON VENTURES INC. a Delaware corporation, d/b/a BoRo USA MASTER FUNCTIONAL SPECIFICATION Version 9.0 — Consolidated Master Peer-to-Peer Rental Marketplace · Transaction, Authorization, Exchange, Evidence, Settlement & Listing-Restriction Architecture
| Field | Value |
|---|---|
| Version | 9.0 — Consolidated Master |
| Supersedes | V8.6 (Consolidated Master), V8.5, V8.4, and V8.3, in full |
| Effective | Locked upon execution by Jaydan Hoang Nguyen, Chief Executive Officer |
| Prepared by | Office of the CEO — Aston Ventures Inc., d/b/a BoRo USA |
| For | Brad Larson (CTO); Zachary De Jesus (Lead Engineer); Robert Fiege (Security & Platform Architecture); Christopher Oltman (VP Product Design, Growth & Brand); Product, Finance & Operations |
| Entity | Aston Ventures Inc., a Delaware corporation (File No. 10279912), d/b/a BoRo USA · 8 The Green, Ste #23301, Dover, DE 19901 |
| Payments | Stripe Connect · MCC 7394 (Equipment, Tool, Furniture and Appliance Rental and Leasing) |
| Status | LOCKED — Production Specification |
| Launch Market | Charlotte, North Carolina (MVP) — testable app mid-August 2026; user testing Aug–Oct 2026; pilot November 2026 |
| Companion Document | BoRo USA Terms of Service v2.4 (Section 8 — Listing Restrictions; Section 15 — Risk Allocation) |
§ 0 Version 9.0 Change Log
Version 9.0 is a consolidated master restatement superseding Version 8.6 in full. It resolves all twelve open items carried in V8.6 § 16, introduces the two-lane BoRo Shield model, extends the maximum rental term to thirty (30) days, corrects four numerical defects in prior versions, and adds two sections that did not previously exist: § 14 Listing Restrictions and § 15 Risk Allocation and Legal Architecture. Where a prior provision is superseded, the change is identified below and controls over any conflicting language in any prior version.
| Section | Change in V9.0 |
|---|---|
| § 2.5 | RESOLVED. Card/identity name mismatch permitted with no restriction, no lane cap and no gate. |
| § 4.4 | AMENDED. Pending-hold timeout is now the lesser of 24 hours and one half of the time remaining to the requested rental start. |
| § 6.1 | AMENDED. Commitment Hold is 20% of the total rental transaction; the lender matches the borrower’s dollar amount exactly. |
| § 6.2 | REPLACED. Two-lane BoRo Shield: Lane A (≤ $100) carries no Shield; Lane B ($101–$1,000) carries a Shield. |
| § 6.3 | CORRECTED. Gross-up formula operator order fixed; rounding rule set to round up to the nearest cent. |
| § 6.5 | NEW. Saved payment method (SetupIntent) established as the second protective layer platform-wide. |
| § 7.5 | RESOLVED. Three-strike non-confirmation regime on a rolling 90-day window plus a public completion rate. |
| § 8 | REPLACED. Travel priced on productive beyond-midpoint miles, one way per leg, at $0.75 per mile. |
| § 10.6 | AMENDED. Dispatch obligations split into two clocks; concurrent dispatch capped; service area bounded. |
| § 11.3 | AMENDED. Rental Fee recognized ratably across the rental term rather than at a point in time. |
| § 11.7 | NEW. Chargeback liability assigned. BoRo absorbs where the lender is blameless. |
| § 12.6 | RESOLVED. Storage fee set at $5.00 per day, capped at the declared item value. |
| § 13 | REPLACED. Extensions run to a 30-day maximum on a committed-duration model and earn the full platform fee. |
| § 14 | NEW. Listing Restrictions — Categories A–I, Tier 2 conditional permissions, and enforcement architecture. |
| § 15 | NEW. Risk Allocation and Legal Architecture — the controlling protective provisions. |
Supersession This document supersedes Versions 8.3, 8.4, 8.5 and 8.6 in full. Any provision of a prior version not expressly carried forward herein is retired. Sections carried forward from V8.6 without substantive change are identified as such.
§ 1 Scope, Roles & Defined Terms
§ 1.1 Scope
This specification governs the end-to-end rental transaction lifecycle of the BoRo peer-to-peer rental marketplace: request, acceptance, authorization, confirmation, item exchange, functional test, active rental, extension, return, evidence capture, and final settlement, together with the financial instruments, listing restrictions, risk-allocation architecture and edge-case state machines supporting each phase. It is the controlling engineering and product specification for the Charlotte MVP build.
§ 1.2 Roles
| Role | Definition |
|---|---|
| Lender | The party listing and owning the physical item offered for rent. |
| Borrower | The party requesting and taking temporary possession of the item. |
| BoRo / Platform | Aston Ventures Inc., d/b/a BoRo USA, operating the marketplace and, through Stripe Connect, the payment rails. Merchant of record for platform fees. Not the owner, lessor or bailee of any listed item (see § 15.1). |
| BoRo Ops | BoRo operational personnel executing dispatch, recovery, custody and evidence adjudication. |
§ 1.3 Defined Terms
| Term | Meaning |
|---|---|
| Commitment Hold (CH) | An authorization hold equal to 20% of the total rental transaction, minimum $10.00, placed on each party’s card to guarantee attendance at the exchange. The lender posts the identical dollar amount as the borrower. Card only; wallet prohibited. Released at QR pairing. Never platform revenue. |
| BoRo Shield | An authorization hold on the borrower’s card equal to the lender’s declared resale value, applicable to Lane B items only ($101–$1,000). Captured only per § 11 or § 12. Always credited to the Lender Wallet, never a Stripe payout, never platform revenue. |
| Lane A / Lane B | Lane A: declared item value $0.01–$100.00. No Shield; protection is the Saved Payment Method. Lane B: declared item value $101.00–$1,000.00. Shield applies. |
| Saved Payment Method | The borrower’s card vaulted by SetupIntent at Stage 2 verification, chargeable off-session for damages, loss or late fees. The sole protective instrument in Lane A and the second protective layer in Lane B. |
| Rental Fee | The only true capture in the standard lifecycle. Computed by the gross-up formula in § 6.3 so the borrower absorbs all Stripe processing cost and BoRo absorbs none. |
| QR Pairing | The mutual in-app QR scan at the exchange proving co-presence, activating the transaction, releasing both Commitment Holds, authorizing the BoRo Shield in Lane B, and starting the 45-minute session. |
| Session (45-minute) | The single 45-minute window opened at each of the two phases (check-in and return). It is the functional-test window and the claim window; on expiry the claim right for that phase is extinguished. |
| Condition Record | Timestamped photo and video evidence captured at each handoff, constituting the adjudication and chargeback-defense record. |
| Confirm Tap | The cardholder-present action, approximately 26 hours before the meetup, by which each party places their Commitment Hold and confirms attendance. |
| Refresh Tap | The cardholder-present action on every sixth day of a committed extension term by which the borrower authorizes a fresh Shield before the prior Shield is released (§ 13). |
| Tier 2 Item | An item prohibited at MVP launch whose conditions for permission are stated in advance (§ 14.4). |
§ 2 Accounts, Eligibility & Verification
Account creation is two-stage. A lightweight browse account requires only name and email; a fully verified account, required before any booking, requires government-ID and biometric verification and a card on file. Carried forward from V8.6 without substantive change except as to § 2.5.
§ 2.1 Eligibility
18+ hard age gate to hold a transacting account. Ages 13–17: permitted only under a parent or guardian. The account is legally the parent’s; the minor is a permitted user. See § 2.4. Under 13: not permitted.
§ 2.2 Stage 1 — Browse Account
Any eligible user provides name and email to create a browse-only account. A Stage 1 account may search, browse and view listings. It may not request or book a rental; attempting to book triggers Stage 2.
§ 2.3 Stage 2 — Verified Account
| Check | Requirement |
|---|---|
| Government ID | Valid government-issued ID, scanned. Confirmed authentic; name captured. |
| Selfie / liveness | Biometric match confirming the person holding the device is the person on the ID. |
| Agreements | All platform agreements signed — Terms of Service v2.4, rental terms, evidence-and-settlement consent, and the assumption-of-risk acknowledgment required by § 15.3. |
| Card on file | A valid card must be added to complete verification. |
| Saved Payment Method | A SetupIntent is executed at verification, vaulting the card for off-session charge. This is mandatory and is the protective instrument in Lane A. See § 6.5. |
§ 2.4 Minor Accounts — Parent/Guardian Model
A user aged 13–17 completes Stage 2 by handing the device to a parent or guardian, who completes the full verification in person: the parent supplies their own name and address, passes ID and liveness verification against their own identity, and signs all agreements authorizing the minor to operate the account.
Locked — Parent Owns the Account The verified account is legally the parent’s or guardian’s. The parent is the responsible account holder; the card on file, the Commitment Hold, the BoRo Shield and the Saved Payment Method all run against the parent. The minor is a permitted user. A Shield capture on a rental the minor booked is charged to the parent’s card. The in-person device hand-off is a deliberate low-friction alternative to an email-and-download parental-consent flow, and is stronger evidence of consent than a clicked link.
§ 2.5 Card on File — Identity Mismatch (Resolved)
A live card is mandatory to complete verification. The platform does not gate on a match between the cardholder name and the verified identity name.
Resolved — No Restriction on Name Mismatch V8.6 § 2.5 flagged the card/identity mismatch as an open item requiring a soft downstream control. It is resolved: household and shared-card use is permitted with no lane restriction, no first-transaction gate and no monitoring requirement. A verified identity may fund transactions with a card in another name. The residual exposure is accepted knowingly: a verified identity funding a transaction with another party’s card is a fraud vector for which no downstream control now exists. Chargeback consequences are governed by § 11.7 and the representations in § 15.4.
§ 3 Listing Creation (Lender)
A verified user may list an item. The listing flow is ordered so that the item’s value — which drives the lane assignment, the BoRo Shield and the platform’s exposure — is captured first, and so that listing restrictions are enforced before any other field is collected.
§ 3.1 Listing Fields
| Field | Notes |
|---|---|
| Category & restriction screen | Captured first. Runs the § 14 listing-restriction gate before any other field. A prohibited category cannot proceed. |
| Item value | Drives lane assignment (§ 6.2), the BoRo Shield amount, and the Lane A recovery ceiling (§ 6.4). MVP cap $1,000. |
| Suggested rates | From the value, the system generates a suggested daily and weekly rate. The lender may adjust both freely — suggestions are not caps. |
| Title & description | Free text. Indexed for keyword search and screened by prohibited-term matching (§ 14.5). |
| Photos | Item imagery. |
| Take-home-test consent | Lender toggle: whether the borrower may take the item away from the meetup to test it (§ 10.4). |
| Availability | Managed on the lender calendar (§ 4.3). |
| Lender Safety Certification | Required attestation under § 14.6 for any Tier 2 item, and the general certification for all items. |
§ 3.2 Declared Value — Lane Assignment and Recovery Ceiling
Locked — Declared Value Is the Recovery Ceiling The lender’s declared value determines which lane the item falls into and is the maximum amount BoRo will ever recover or credit for that item, in either lane. A lender who declares a lower value to reach the frictionless Lane A experience accepts that lower figure as the ceiling of their own recovery. This must be disclosed on screen at the moment of declaration, in plain language, before the lender commits. A ceiling the lender was not shown is not a ceiling.
§ 3.3 Optional For-Sale Listing
A lender may additionally offer an item for sale. A sale is a lightweight feature outside the rental protection flow: the two users coordinate through chat and meet to exchange the item themselves. BoRo provides no logistics, no Shield and no evidence capture for a sale.
Locked — Sales Are Not Protected A for-sale transaction carries none of the rental trust layer — no Commitment Hold, no Shield, no condition evidence, no settlement adjudication. The sale listing must carry a visible notice that sales are not BoRo-protected, consistent with § 5.3. Section 14 listing restrictions apply to sale listings identically.
§ 4 Discovery, Booking & Availability
§ 4.1 Search & Browse
Keyword search matches against listing title and description. Category browse for structured discovery. Reach: no hard distance cap. Results sort nearest-first, so distant items still appear but rank lower. A map-first interface was declined for MVP because thin early inventory renders poorly on a map.
§ 4.2 Booking Request
From a listing, the borrower requests specific dates. The request enters the pending state and is subject to the lender’s acceptance and the authorization flow of § 7. The $0 card validation of § 7.1 runs at request.
§ 4.3 Lender Calendar & Availability States
| State | Colour | Meaning |
|---|---|---|
| Open | — | Available to request. |
| Pending confirmation | Yellow | Requested, awaiting lender acceptance. Visually blocked but not yet committed. |
| Rented | Red / black | Committed rental, including any committed extension term. Hard-blocked. |
§ 4.4 Pending-Hold Collision Rule (Amended)
A yellow (pending) date is locked to the first requester — no second borrower may request it while yellow. First-come, first-served.
Amended — Dynamic Timeout The yellow-hold expiry is the LESSER of (a) twenty-four (24) hours from the request, and (b) one half of the time remaining between the request and the requested rental start. Expressed as: expiry = min(24h, 0.5 × time-to-start). A request for a rental beginning in eight hours expires in four. Rationale: a flat 24-hour hold is correct for distant bookings but kills near-term dates, because a non-responsive requester can freeze tomorrow’s slot for a full day and it reopens only after the opportunity has passed. Implementation remains a single expiry timestamp on the request record.
§ 5 Chat — Transaction & Support Hub
Chat is the central surface of the application, not merely messaging. Both parties may chat freely before booking, and the transaction is driven from within the chat through embedded action buttons — scheduling, booking, requesting an extension, reporting a problem and contacting a BoRo team member all occur in the chat.
§ 5.1 Chat-Driven Actions
Embedded controls surface the correct action for the transaction state — request-to-book, propose or adjust a meetup, request an extension (§ 13), report a problem (§ 10.6), or escalate to BoRo Ops. Users are not routed out to separate screens for routine actions.
§ 5.2 Chat Privacy
For user safety, the chat never reveals a party’s phone number, last name or exact address. The meetup venue is a named public location (§ 8.1); precise personal addresses are not exposed.
§ 5.3 Off-Platform Activity
Locked — Off-Platform Is Unprotected If users elect to transact outside BoRo, that is their choice. The Terms of Service provide that any activity conducted outside the platform carries none of BoRo’s protections — no Shield, no evidence, no settlement, and none of the risk-allocation provisions of § 15. BoRo does not otherwise police off-platform behavior.
§ 6 Financial Instruments
Four instruments operate across the lifecycle. Two are authorization holds, one is a vaulted off-session charging capability, and one is a capture. Correct classification of each is a controlling requirement of this specification. Only the Rental Fee and the fees enumerated in § 12.5 and § 12.6 are ever platform revenue.
§ 6.1 Commitment Hold (Amended)
Amount: 20% of the total rental transaction, minimum $10.00. Symmetry: the lender posts the identical dollar amount as the borrower. Both parties post one Commitment Hold each. Instrument: card authorization only. BoRo Wallet balances are prohibited as the funding source. Placement: at the Confirm Tap (§ 7.4), approximately 26 hours before the scheduled meetup. Release: both holds release at QR pairing. Their sole function is attendance assurance. Forfeiture: on borrower cancellation 12–24 hours before the meetup, 50% is captured; under 12 hours or no-show, 100%. Forfeited funds pass through 100% to the non-violating party’s BoRo Wallet and are never BoRo revenue.
Locked — Symmetric Amounts Worked example: a $100.00 total rental transaction produces a $20.00 Commitment Hold on the borrower and a matching $20.00 Commitment Hold on the lender. Symmetry is deliberate. Forfeiture passes 100% to the non-violating party, so unequal holds would mean the same offence costs a lender and a borrower different amounts. The Commitment Hold is calculated once, on the initial booking, and releases at pairing — extensions never recalculate it.
§ 6.2 BoRo Shield — Two-Lane Model (Replaced)
The single-Shield model of V8.6 is replaced. Shield application is determined by the lender’s declared item value.
| Lane A | Lane B | |
|---|---|---|
| Declared value | $0.01 – $100.00 | $101.00 – $1,000.00 |
| BoRo Shield | None | Authorization hold equal to declared value |
| Protective instrument | Saved Payment Method (§ 6.5) | Shield, with Saved Payment Method as second layer |
| Commitment Hold | Applies — unchanged | Applies — unchanged |
| Base rental term | Up to 30 days, no refresh required | 6 days, extendable to 30 (§ 13) |
| Recovery ceiling | Declared value | Declared value |
| Authorization point | n/a | QR pairing (§ 9) |
Locked — Why Lane A Carries No Shield A $30 rental earns approximately $3.00 in platform fee. Placing a Shield on it would carry up to five authorization events, five decline opportunities and five support-ticket opportunities over a 30-day term, and one support conversation costs more than the rental earns. Holds on low-value casual items also deter precisely the high-frequency volume the Charlotte pilot requires. Maximum Lane A exposure is capped at $100 per item and is partially recovered through the Saved Payment Method. BoRo has no empirical damage rate; this is a data-gathering posture, not a conviction.
Locked — Universal Shield Config Flag Engineering shall implement the Shield authorization path such that it can be enabled for Lane A by configuration flag, without a rewrite. Lane A loss data — damage claim rate, Saved Payment Method recovery rate, and actual dollars lost — shall be instrumented from day one of the pilot. If Lane A losses exceed Lane A fee revenue over the pilot period, the flag is enabled and Lane A carries a Shield. This is a switch, not a decision to be re-argued.
§ 6.3 Rental Fee & Gross-Up Formula (Corrected)
The Rental Fee is captured from the borrower and is the only true capture in the standard lifecycle. It is grossed up so the borrower bears all Stripe processing cost. Borrower Charge = ( Rental × 1.07 + $0.30 ) ÷ 0.971
Corrected — Operator Order and Rounding V8.6 § 6.3 expressed the formula as ( Rental × 1.07 ) ÷ ( 1 − 0.029 ) + $0.30, placing the $0.30 fixed component OUTSIDE the divisor. That form leaves the fixed fee ungrossed and under-collects approximately $0.009 per transaction, contradicting the locked rule that the borrower absorbs all Stripe processing cost and BoRo absorbs $0.00. The $0.30 must sit inside the numerator. The corrected formula above is controlling. ROUNDING: the final borrower charge is rounded UP to the nearest whole cent. Rationale: rounding to nearest would leave BoRo fractionally short on roughly half of all transactions, which contradicts the same locked rule. No borrower disputes a penny.
Worked example — $18.00/day × 3 days ($54.00 rental): borrower charge $59.82; Stripe fee $2.03; BoRo clears $57.79; lender receives $52.38 (rental less 3%); BoRo nets $5.40 (7% borrower + 3% lender = 10% blended). Borrower absorbs the Stripe fee in full; BoRo absorbs $0.00.
§ 6.4 Lane A Recovery Ceiling
In Lane A, the maximum amount chargeable against the Saved Payment Method for damage, loss or theft is the lender’s declared item value. The ceiling is disclosed at listing per § 3.2 and at booking to the borrower.
§ 6.5 Saved Payment Method — Second Protective Layer (New)
At Stage 2 verification a SetupIntent vaults the borrower’s card for off-session charge. This instrument is mandatory platform-wide and performs three distinct functions. Lane A: it is the sole protective instrument. Damage, loss or theft is charged against it, capped at declared value. Lane B: it is the second layer, reached where damage exceeds the Shield amount, where a card brand grants no extended authorization window, or where a Refresh Tap is missed and the Shield lapses mid-term (§ 13.5). Both lanes: it covers late fees, storage fees and recovery fees where the Shield is unavailable or exhausted.
Locked — A Saved Card Is Not a Hold A hold guarantees the funds are present. A saved card does not: an off-session charge weeks later can decline, and the cardholder can dispute it with a materially higher success rate than a disputed capture against a live authorization. Lane A recovery is therefore expected to be materially below 100%. Finance shall model Lane A recovery conservatively and shall not treat declared value as recoverable value.
§ 6.6 Payment Architecture Constraint
Locked — Extended Authorizations Are Not Available Stripe confirmed on 29 July 2026 that extended card authorizations are available only to accounts on Interchange-Plus (IC+) pricing, and that BoRo does not qualify. The stated threshold for a pricing review is at least $100,000 USD per month in processed volume, consistently, over two to three months. The standard authorization window therefore governs. The six-day Lane B base term and the Refresh Tap chain of § 13 are the architecture, not a workaround, and shall not be built against a thirty-day authorization window that does not exist. Engineering shall never hardcode an authorization-window length. Read Stripe’s capture_before on each charge and schedule all downstream jobs against that value. Monthly processed volume is the trigger metric for revisiting IC+.
§ 7 Authorization & Confirmation
Design Rationale — One Path, Built to the Strictest Window Card networks grant different authorization-hold lifespans. For card-not-present merchant-initiated transactions Visa provides only 4 days 18 hours, while Mastercard, American Express and Discover provide 7 days. A hold placed on the cardholder’s own action receives the full 7 days on every network. BoRo therefore builds a single authorization path sized to the strictest window and relies on cardholder-present action to obtain the full window uniformly. No branching on card brand: two clocks means two defect surfaces and a silent failure the day a network changes its terms.
§ 7.1 Booking — $0 Validation, No Hold
At request the borrower selects the exchange lane (§ 8) and the system performs a $0.00 card validation confirming the card exists, is live and can carry the Commitment Hold. No hold is placed at booking. A booking is not binding until mutual confirmation under § 7.4. Validation failure means the request is not confirmed.
§ 7.2 Acceptance — Vault
On lender acceptance both cards are vaulted for later authorized action. No hold and no Shield are placed at acceptance.
§ 7.3 T−26h Confirmation Reminder
Twenty-six hours before the scheduled meetup the system prompts both parties to confirm and agree. This is the controlling gate on whether the appointment proceeds.
§ 7.4 Mutual Confirm Tap — Commitment Hold Placement
| Confirmation Outcome | System Action |
|---|---|
| Both parties confirm | Appointment scheduled and confirmed. Both Commitment Holds live with a full 7-day window. |
| Only one confirms | Transaction auto-cancels. Any hold placed is released. Non-confirming party receives a strike under § 7.5. |
| Neither confirms | Transaction auto-cancels. Booking dissolves with no holds outstanding. Both parties receive a strike. |
Locked — No Background Hold Mutual confirmation is the gate. There is no server-initiated fallback hold on a non-confirming party. This eliminates any dependency on a Terms-of-Service off-session-authorization clause for hold placement. The accepted consequence — a non-confirming borrower can cost the lender the reservation without a hold to penalize — is addressed by § 7.5.
§ 7.5 Non-Confirmation Consequences (Resolved)
V8.6 § 7.5 left the reputation consequence undefined. It is resolved as a three-strike regime on a rolling 90-day window, applied identically to lenders and borrowers.
| Occurrence (rolling 90 days) | Consequence |
|---|---|
| First | Warning notification. No restriction. |
| Second | Seven (7) day booking suspension. |
| Third | Thirty (30) day booking suspension. |
| Fourth | Permanent removal from the platform. |
Locked — Public Completion Rate Every user profile displays a completion rate: confirmed-and-completed transactions as a percentage of accepted bookings. It is visible to any counterparty before booking. This does more work than the suspensions. No money lever exists against a non-confirmation because the Commitment Hold is not placed until confirmation, so access and reputation are the only available enforcement. A lender looking at a borrower with a 60% completion rate will simply decline.
§ 7.6 Engineering Requirements — Authorization
| Requirement | Specification |
|---|---|
| Card-brand agnosticism | Single authorization path. No conditional logic on card network. Path sized to the Visa merchant-initiated window as the floor. |
| Window source of truth | Never hardcode an authorization-window length. Read Stripe’s capture_before on each charge and schedule all downstream jobs against that value. |
| Cardholder-present classification | The Confirm Tap and every Refresh Tap must execute as cardholder-present (on-session) PaymentIntents to obtain customer-initiated classification and the full window. |
| Mutual gate | Booking state advances to CONFIRMED only on both parties’ taps within the window. Single or nil confirmation triggers auto-cancellation with counterparty notice and strike. |
| Statement descriptors | Account descriptor BORO USA; shortened descriptor BORO. Per-charge suffixes are mandatory: DEPOSIT for Shield authorizations, RENTAL for Rental Fee captures, RECOVERY for § 12.5 fees. An unrecognized descriptor on a long-held authorization is a primary dispute driver. |
§ 8 Item Exchange Methods & Travel
The borrower selects one of three exchange lanes at booking. The three are not separate systems; they are one signed travel adjustment. BoRo earns $0.00 on peer travel in either direction — travel between users is a pure transfer, never platform revenue.
§ 8.1 The Midpoint Principle (Replaced)
Locked — Only Productive Miles Are Billable Travel is priced on productive miles only, measured from the MIDPOINT between the two parties, counted ONE WAY per leg, at $0.75 per mile. Neither party is paid for reaching the midpoint: the midpoint is the neutral baseline both parties accept, which is why a halfway meetup nets to zero. Neither party is paid for the empty return trip — the deadhead. A rideshare does not charge the rider for the driver’s trip to reach the pickup point, and BoRo does not charge for it either. Each leg is priced independently. The handover leg and the return leg are separate transactions.
Worked example — lender and borrower 20 miles apart, midpoint at 10 miles. Lender delivery: the drop-off leg is 10 billable miles and the collection leg is 10 billable miles; 20 billable miles × $0.75 = $15.00 to the lender, being $7.50 per leg. A halfway meetup on both legs is $0.00 to both parties.
§ 8.2 Exchange Lanes
| Lane | Lender travels | Borrower travels | Adjustment |
|---|---|---|---|
| Meet halfway (default) | To midpoint | To midpoint | $0.00 — nets out |
| Lender delivery | Beyond midpoint | None | Borrower pays lender the beyond-midpoint miles |
| Borrower self-pickup | None | Beyond midpoint | Lender credits borrower the beyond-midpoint miles |
§ 8.3 Rate — Single Platform-Wide Figure
Locked — $0.75 Per Mile, Every Mile, Every Party The mileage rate is $0.75 per mile and applies to every billable mile driven by a user (lender or borrower) or by a BoRo team member. One number governs peer travel, Recovery dispatch (§ 12.5) and lender-fails-to-collect dispatch (§ 12.6). This supersedes the $0.50 peer rate in all prior versions. Every travel figure in any prior version, flow map or financial model is superseded and must be recomputed on this basis. The rate is a fixed number reviewed annually. It shall NOT be pegged to the IRS standard mileage rate. The IRS raised that rate mid-year in 2026, from 72.5 cents to 76 cents effective 1 July 2026; a pegged rate would reprice the marketplace without notice to either party.
§ 8.4 Basis for BoRo Dispatch
Locked — Agreed Distance, Not Actual Route Where a BoRo team member dispatches, the mileage charge is computed on the SAME agreed user-to-user distance established at booking, at $0.75 per mile, PLUS the applicable flat dispatch fee. BoRo does not bill its team member’s actual route. Two reasons. The at-fault party sees a predictable, pre-known figure rather than a bill that varies with wherever a team member happened to be. And BoRo requires no GPS route tracking to compute it. Where BoRo’s actual route exceeds the agreed distance, BoRo absorbs the excess; the flat dispatch base covers it.
§ 8.5 Meetup Venue
The lender enters their address and the borrower enters theirs; the system computes the midpoint and offers a selection of safe public venues with restroom access near that midpoint. A named venue — not a map pin — is required, because the venue supplies the address and ZIP that the tax-sourcing and geofence rules depend upon.
§ 8.6 Self-Pickup Gate
Locked — Lender Net Must Remain Positive Fees compute on the gross rental, before any travel adjustment, so the self-pickup credit never reaches BoRo’s slice. If the credit would drive the lender’s net payout below zero, the self-pickup option is not offered for that listing — it is withheld WITH AN EXPLANATION, not silently greyed out, and the booking itself is never blocked; the default halfway lane remains available and free. This matters more in the delivery case: a lender who has already been paid for a delivery leg and then sees the borrower elect self-pickup for the return is paying twice. The screen must explain why the option is unavailable. Any positive net payout, down to $0.01, is permitted and is the lender’s decision. The exact net figure is displayed to the lender at acceptance, before the lender commits.
§ 8.7 Travel — Accounting Treatment
Locked — Travel Is Not Revenue Peer travel amounts shall not be recognized as revenue. BoRo earns $0.00 on travel between users; a travel amount is a pass-through liability settling to the counterparty, in the same manner as a Commitment Hold forfeiture. Any Chart-of-Accounts line or revenue projection carrying peer travel as BoRo revenue is to be corrected. The borrower self-pickup credit is a deduction from the lender’s payout — not an operating expense of BoRo and not a reduction of Deferred Revenue. Dispatch fees under § 12.5 and § 12.6 ARE BoRo operational revenue and are accounted separately.
§ 9 BoRo Shield — Authorization Point
In Lane B the BoRo Shield authorizes at QR pairing (§ 10.1), at the moment the item changes hands — not at lender acceptance. Carried forward from V8.6 as controlling.
§ 9.1 Rationale
Authorizing the Shield at lender acceptance consumes the authorization window while the item still sits with the lender. On a six-day rental accepted two days early, exposure is 48 + 144 + 9 = 201 hours against a 168-hour hold, and the Shield expires roughly 33 hours before the return deadline — on every card brand. Authorized at pairing, exposure is 153 of 168 hours, leaving a 15-hour margin uniformly.
§ 9.2 Card Validation at Acceptance
To preserve the lender’s protection against meeting an unfundable borrower, the borrower’s card is validated by a $0.00 SetupIntent at acceptance. The Shield authorization itself is not placed until pairing. In Lane A no Shield is placed at any point; the SetupIntent vault of § 6.5 is the protection.
§ 10 Exchange, Functional Test & Condition Evidence
§ 10.1 QR Pairing — Activation
At the meetup the parties complete QR pairing. BoRo generates one QR code tied to the booking; the code identifies which booking, and the geofence proves both people are actually present. The code is displayable only within the 100-foot geofence and validates only when both devices are inside the zone at scan time — defeating any attempt to screenshot the code and pair remotely. Pairing proves co-presence, activates the transaction, releases both Commitment Holds, authorizes the BoRo Shield in Lane B, and opens the single 45-minute session. The same mechanic runs at both check-in and return.
§ 10.2 Session Timer — One 45-Minute Window Per Phase
Each of the two phases has exactly one 45-minute session timer. There is no separate 15-minute timer. The check-in session is the borrower’s functional-test window; the return session is the lender’s. Upon expiry no claim may be filed by either party for that phase: the window closes the claim right.
§ 10.3 Check-In Evidence — Lender Capture
Before the item changes hands the lender captures the condition record: up to five (5) photographs and one (1) video, timestamped, establishing condition at handover. This evidence is displayed on the borrower’s device, and the borrower confirms it matches the listing description and that the item is functional before taking possession.
§ 10.4 Borrower Controls — State-Based
| Control | Effect |
|---|---|
| Accept | The borrower accepts the rental. The Rental Fee captures per § 6.3 and the rental becomes ACTIVE. |
| Decline | The borrower declines at no charge. Available only BEFORE the item is taken to test. All holds release. |
| Report a problem | The borrower reports a non-functional (mechanical) fault only. Cosmetic condition may not be reported; the borrower inspected cosmetics at handoff. See § 10.6. |
Locked — Decline Disables on Take-to-Test The moment the borrower takes the item to test or use it, the Decline control is disabled, leaving only Accept and Report a problem. The trigger is the ACT of taking the item to test, not the passage of time. This prevents a borrower from deriving use — operating a console for forty minutes, for instance — and then declining at no charge. Where the 45-minute window expires with the parties OUTSIDE the geofence and no action taken, the system auto-accepts. Where it expires with both parties INSIDE the geofence and no action taken, the dual-confirmation handback of § 10.5 applies.
§ 10.5 Geofence Handback
Borrower return confirmation requires a photograph of the returned item, timestamped and geofenced, saved to the record as proof of return. Where the borrower confirms return with the required photograph, the borrower is cleared; a subsequent lender assertion of non-return is defeated by the timestamped evidence. Where the borrower does not confirm return, the borrower is presumed to retain the item and is subject to penalty, preventing a false lender claim from operating in reverse.
Locked — Photo Failure Handling Where the borrower taps to confirm return but photo capture or upload fails, the return still confirms, but the confirmation is flagged for BoRo review rather than auto-cleared. A subsequent non-return claim is adjudicated on other evidence rather than dismissed automatically. A present photograph auto-clears the borrower; a missing photograph routes to manual review.
§ 10.6 Report-a-Problem — Fault by Inspection
A problem report freezes the transaction: the Rental Fee does not capture, the auto-accept timer halts, and the BoRo Shield remains live. The lender is notified to retrieve the item. Fault follows the inspection, not the accusation.
| Inspection Finding | Fault & Fee |
|---|---|
| Fault is genuine (item non-functional) | Lender at fault. The $25.00 dispatch fee plus $0.75/mile on the agreed distance is borne by the lender, deducted from the lender’s proceeds. Borrower released. |
| Fault is not genuine (false report) | Borrower at fault. The dispatch fee flips to the borrower and captures against the live Shield, or against the Saved Payment Method in Lane A. A false report is never free. |
Locked — Two Dispatch Clocks (Resolved) V8.6 § 10.6 flagged dispatch feasibility as an open item and conflated two different clocks. They are separate and both are controlling. CLOCK 1 — Lender grace: two (2) hours, running from the moment the borrower reports. The transaction freezes; lender and BoRo Ops are notified. CLOCK 2 — BoRo dispatch commitment: SAME DAY BY 9:00 PM, and this clock starts when the lender’s two hours expire, not when the borrower first reported. Carve-out: where the lender’s grace expires after 7:00 PM, BoRo dispatches the NEXT DAY BY NOON. The borrower does NOT wait at the meetup venue. The borrower takes the item home and BoRo collects from the borrower’s address.
§ 10.7 Dispatch Capacity & Service Area
Locked — Single-Operator Reality Dispatch at pilot is executed by Jaydan Hoang Nguyen. Jeffrey Wolf (Regional Partnerships, Charlotte Metro) is the named backup dispatcher and shall be operationally onboarded before pilot launch. A same-day public commitment with a single unbacked operator is one flat tire from a public failure. CONCURRENT DISPATCH CAP: one (1). Where a second dispatch event arises while one is active, the second item remains with the borrower on a live Shield and is collected the following morning. The borrower is notified of the revised collection time at the moment of the report, not afterwards. SERVICE AREA: Mecklenburg County, North Carolina only. Dispatch requests outside the county are declined and any dispatch fee charged is refunded in full.
§ 11 Return & Final Settlement
Supersedes the V8.4 24-Hour Claim Window The 45-minute return session is the single, final settlement point. There is no post-return holding period during which new claims may be raised.
§ 11.1 Return Scheduling
The return meetup mirrors the check-in day and time. In Lane B the return is hard-capped at the six-day boundary of the current authorization term; where an extension has been committed under § 13, the cap moves to the committed return date and each six-day segment requires a Refresh Tap. In Lane A the return is capped at thirty (30) days from check-in. Users may propose and adjust meetup times through chat, but the system auto-caps any return at the applicable boundary.
§ 11.2 Blind Double-Submission
At the return meetup the parties scan and the return session opens. The borrower photographs the item at handback; the images are shown to the lender. The lender tests the item within the session and photographs any observed condition. Neither party sees the other’s submission. Both condition tickets are transmitted to BoRo, blind, so that neither party can tailor evidence to rebut the other.
§ 11.3 Single Final Decision & Revenue Recognition (Amended)
| Outcome | Settlement |
|---|---|
| Clean return | Shield released (Lane B) or Saved Payment Method released from claim (Lane A); lender paid; BoRo fee booked. |
| Damage on the evidence | Shield captured by tier (§ 11.5) to the Lender Wallet, remainder released; or Saved Payment Method charged in Lane A, capped at declared value. |
Amended — Ratable Revenue Recognition The Rental Fee is recognized RATABLY across the days of the rental term under ASC 606, not at a point in time on return confirmation. V8.6 recognized at return. That was defensible when the maximum term was six days. With terms now running to thirty days, a rental beginning 25 November and ending 25 December would recognize entirely in December although BoRo carried the platform obligation and the risk for five days in November. A rental is a service delivered over time. Ratable recognition is the more defensible treatment, produces monthly figures that reflect actual activity, and matters for the processed-volume trigger in § 6.6. This is a CEO-level accounting policy decision and is locked.
§ 11.4 Latent Risk Allocation
A defect that the in-person 45-minute test could not reveal, discovered after the window closes, is borne by the lender. This allocation is the deliberate consequence of a fast, single-pass settlement and is reflected in Terms of Service § 15.
§ 11.5 Shield Damage Tiers
| Tier | Capture | Illustration ($120 Shield) |
|---|---|---|
| Minor | 25% of Shield | $30.00 |
| Moderate | 50% of Shield | $60.00 |
| Total loss / theft | 100% of Shield | $120.00 |
Captured Shield amounts credit the Lender Wallet only, never a Stripe payout, and are never platform revenue. The identical tier structure applies to Lane A charges against the Saved Payment Method, capped at declared value.
§ 11.6 Payout & Processing Queue
The settlement decision is locked when the 45-minute window closes. Stripe then transfers the lender’s proceeds (rental less 3%); the lender may elect instant payout at 1.5%, minimum $0.50, borne by the lender. BoRo absorbs no payout cost.
Locked — 24-Hour Processing Window Is Not a Claim Window Cases are worked through a processing queue within an operational window of roughly 24 hours, triaged by time-to-Shield-expiry: a case whose Shield runs out in hours is processed before one with days remaining. This window governs only WHEN BoRo executes an already-final decision — it is never a second window in which the outcome can change.
§ 11.7 Chargeback Liability (Resolved)
V8.6 § 16 item 5 left dispute liability unassigned. Stripe assigns dispute liability to the platform by default, and a network chargeback lands months after the internal settlement window has closed.
Locked — BoRo Absorbs Where the Lender Is Blameless Where the lender has done nothing wrong, BoRo absorbs the disputed amount AND the Stripe dispute fee in full. This includes rental-fee disputes where the lender has already been paid out. There is NO clawback from a blameless lender’s Wallet or future payouts. This is the cost of operating this business. It is recorded as an operating expense on a dedicated line — Chargeback and Dispute Losses — not netted silently against revenue, with a reserve accrual as volume grows. Reaching into a good lender’s account is not fair and is not the customer experience BoRo is building. CARVE-OUT — LENDER FAULT: clawback applies where the lender is demonstrably at fault. A fraudulent or phantom listing, an item never handed over, an item materially not as described, or lender conduct that caused the dispute. Without this carve-out a bad actor could list a phantom item, collect, hand over nothing and keep the funds while BoRo absorbs every dispute, repeatably. DISPUTE RATIO IS A SEPARATE RISK: absorbing disputes addresses the money, not the ratio. Card networks place merchants into monitoring programs above published dispute-rate thresholds, with fines and eventual account termination. BoRo shall contest every disputable chargeback with auto-assembled evidence regardless of the decision to absorb the loss. Absorbing is not conceding.
§ 12 Late Return Flow & BoRo Recovery Service
Carried forward from V8.4 and V8.6 and reconciled to the § 11 settlement model, with § 12.6 resolved. The 9-hour grace window, the two borrower resolution paths, the Shield capture trigger and the locked Recovery fee structure are retained.
§ 12.1 The 9-Hour Grace Window
Trigger: at the scheduled return time, if the item is not confirmed returned, the rental transitions to OVERDUE. Grace window: the borrower has 9 hours to exercise one of two resolution paths. Expiry: if neither path is exercised within 9 hours, the system automatically captures 100% of the Shield in Lane B, or charges the Saved Payment Method to the declared value ceiling in Lane A. No manual team action is required. In-app enforcement: at OVERDUE the app surfaces a non-dismissable Late Return screen showing both options and the hard deadline countdown.
§ 12.2 Late Return State Machine
| State | Trigger | System Action |
|---|---|---|
| ACTIVE | Rental in progress | Normal lifecycle |
| OVERDUE | Scheduled return passed | Late Return screen surfaced; 9-hour countdown; both options presented |
| PENDING_SELF_RETURN | Borrower selects Option 1 | Lender in-app contact unlocked; system monitors for return confirmation |
| RECOVERY_REQUESTED | Borrower selects Option 2 and pays | Recovery fee charged; Ops notified; team member dispatched |
| SHIELD_CAPTURED | 9-hour window expires, no action | 100% Shield captured (Lane B) or Saved Payment Method charged to ceiling (Lane A); funds released to lender; rental force-closed |
| CLOSED_RETURNED | Item confirmed returned | Shield released; rental closed |
§ 12.3 Option 1 — Self Return to Lender
Fee to borrower: $0.00. Shield preserved if returned within the 9-hour window. BoRo team involvement: none. BoRo does not facilitate, monitor or confirm the physical handoff for Option 1. Return confirmation is lender-triggered in-app. The 9-hour deadline is hard; a partial window does not extend it.
§ 12.4 Option 2 — BoRo Recovery Service
Base fee: $25.00 minimum, regardless of distance. Mileage: $0.75 per mile on the agreed user-to-user distance (§ 8.4). Total shown in-app before the borrower confirms. Full fee charged synchronously at request confirmation; failed payment rejects the request. Shield preserved if recovery is requested within the 9-hour window; delivery may extend beyond the window without Shield penalty. Non-refundable once dispatched. BoRo Ops sends status updates to both parties at dispatch, pickup and delivery.
§ 12.5 Recovery Fee Structure (Locked)
| Component | Amount | Basis | When Charged |
|---|---|---|---|
| Base fee (minimum) | $25.00 | Flat, all recoveries | At request confirmation |
| Mileage fee | $0.75/mile | Agreed user-to-user distance | At request confirmation |
| Example: 10 mi | $32.50 | $25 + (10 × $0.75) | Pre-authorized before dispatch |
| Example: 20 mi | $40.00 | $25 + (20 × $0.75) | Pre-authorized before dispatch |
Recovery fees are collected by BoRo, are separate from the 10% platform fee, are not split with the lender, and constitute BoRo operational revenue offsetting dispatch cost. Any modification requires CEO approval and an FSD version increment.
§ 12.6 Storage Fee — Lender Fails to Collect (Resolved)
Locked — $5.00 Per Day, Capped at Declared Value Where BoRo takes possession of an item and the lender fails to collect it, a storage fee of $5.00 per day accrues against the lender, beginning twenty-four (24) hours after BoRo takes possession. A lender who collects promptly pays nothing. The accrued fee is CAPPED AT THE ITEM’S DECLARED VALUE. Without the cap, a $50 item held thirty days would accrue $150 in fees — indefensible and unenforceable. The fee is deducted from the lender’s Wallet or future payouts.
§ 12.7 Uncollected Items and Abandonment (Resolved)
Where a lender does not collect an item in BoRo’s custody, BoRo holds another party’s property with no title, no disposal right and no means of recovering accrued charges. Terms of Service v2.4 § 16 closes this. The product requirements follow.
| Stage | Trigger | System Action |
|---|---|---|
| CUSTODY | BoRo takes possession | Lender notified item is available for collection. Photographic record captured at intake. Storage accrual begins at T+24h. |
| COLLECTION_WINDOW | Day 1–30 | $5.00/day accrues against the lender, capped at declared value. Reminder at day 7, day 20 and day 28. |
| FINAL_NOTICE | Day 31 | Automated final notice by email and in-app, stating charges accrued, the abandonment date, and the right to collect before it. Delivery logged. |
| CURE_PERIOD | Day 31–45 | Fifteen (15) days to collect. Non-dismissable in-app banner on the lender’s account. |
| ABANDONED | Day 46 | Item deemed abandoned. Lender relinquishes all right, title and interest. Disposal permitted. |
| DISPOSED | On disposal | Declared value ≤ $100: donate or discard. Declared value > $100: commercially reasonable sale. Photographic record at disposal. |
| SETTLED | After disposal | Proceeds applied to sale costs, storage, dispatch/recovery cost, then other sums due. Surplus credited to Lender Wallet and held 12 months, then treated per unclaimed property law. Shortfall recoverable from Wallet, future payouts or card on file. |
Locked — Surplus Must Be Held, Not Retained Where a sale produces more than the sums owed, the surplus is credited to the lender’s Wallet and held for twelve months, with notice to the lender. This is not optional and must not be simplified away in build. Retaining the surplus rather than holding it for the owner converts a defensible disposal into a conversion of the owner’s property and destroys the enforceability of the entire abandonment provision. The provision works because the lender agreed to it at listing and because BoRo takes only what it is owed. Evidence retention is equally load-bearing: photographs at intake and at disposal, and a delivery log for every notice, retained not less than three years. Without the notice log the abandonment cannot be proven and the disposal is indefensible.
§ 13 Extensions (Replaced)
The Lane B base rental ceiling is six (6) days: 144 hours of rental plus the 9-hour late window is 153 hours of exposure against a 168-hour authorization, a 15-hour margin on every card brand. A term longer than six days cannot be covered by a single authorization and is executed as a chain of handoffs, never as a background re-authorization.
§ 13.1 Maximum Term
Locked — Thirty Days, Both Lanes The maximum rental term is thirty (30) days in both lanes. Lane A reaches thirty days with no Shield and no refresh. Lane B reaches thirty days as five six-day segments, each requiring a Refresh Tap. Both lanes share the same headline number deliberately: “rent anything up to 30 days” is one rule to market, one rule to build and one rule to support.
§ 13.2 Request, Commitment and Calendar
During the current term the borrower is offered an extension. The commitment model is as follows. Borrower declines, or borrower requests and lender declines: the calendar reopens immediately for the next borrower. No dates are held speculatively. Borrower requests and lender accepts: the system requires the borrower to COMMIT to a total additional duration up front, selected from +6, +12, +18 or +24 days, to a 30-day total maximum. The calendar blocks ONLY for the committed window — never for the theoretical thirty-day maximum. Blocking a lender’s calendar for thirty days against an extension that may never be requested would cost lenders bookings they would otherwise take. The lender sees the total resulting duration before accepting, and is not re-asked thereafter. The Refresh Tap is mechanical, not a renegotiation.
Locked — Menu Aligns to the Authorization Cycle The extension menu is expressed in six-day increments (+6 / +12 / +18 / +24) because the Shield refreshes every sixth day. Offering 5, 10 or 15-day options would create partial segments and additional code paths for no product benefit.
§ 13.3 Extension Economics (Replaced)
Locked — Extensions Earn the Full Platform Fee The 10% blended platform fee (7% borrower / 3% lender) applies to the ENTIRE rental transaction including every extension day. A $1,000.00 total rental transaction earns BoRo $100.00. This REPLACES V8.6 § 13.3, under which extensions billed at the daily rate and carried no platform fee. That position was a defensible rounding error when extensions were rare and the maximum term was twelve days. It is not defensible when up to twenty-four of thirty rental days can be extension days, with BoRo carrying the Shield risk, the dispatch obligation and the settlement load across all thirty. The full committed extension fee is captured in ONE charge at the moment of commitment, not per segment. This backs the calendar block with real money and avoids repeated $0.30 fixed fees; a borrower who commits and abandons at day six would otherwise cost the lender the balance of the blocked calendar for nothing.
§ 13.4 Refresh Tap — Bridge, Never Gap
On every sixth day of a committed term the borrower is prompted to tap. The tap, cardholder-present, authorizes a fresh Shield with a full window. The prior Shield is released only AFTER the new Shield succeeds. There is no interval in which the item is unsecured. Ordering is the controlling safety property. New authorization declines: the borrower has two hours to correct payment. Failing that, § 13.5 governs.
Locked — No Background Re-Authorization A server-initiated mid-rental hold is merchant-initiated and receives a materially shorter window on Visa, which cannot cover a six-day segment. Re-authorization shall occur only on the borrower’s tap. Authorize the new Shield, confirm success, then release the prior Shield — never the reverse.
§ 13.5 Missed Refresh Tap (Resolved)
Locked — The Rental Does Not Cancel Where a borrower misses a Refresh Tap mid-commitment, the Shield lapses BUT THE RENTAL IS NOT CANCELLED. The borrower has already paid the committed fee and the lender’s calendar is already blocked. The Saved Payment Method (§ 6.5) becomes the protective instrument for the remainder of the term. The borrower is flagged, the app surfaces a non-dismissable prompt, and the system pushes for return. Cancelling a paid rental over a missed tap punishes a borrower for a notification they may never have seen. Cover the exposure and pursue the return.
§ 13.6 Double-Hold Disclosure (New)
Locked — Mandatory Disclosure at the Refresh Tap Authorization releases are not instantaneous at every issuing bank. Both the prior Shield and the new Shield may therefore appear on the borrower’s card simultaneously for several days. The Refresh Tap screen MUST disclose this in plain language before the tap: on a $500 item the borrower may briefly see $1,000 held. This is not optional. A borrower who sees an unexplained double hold contacts their issuing bank, and that is a dispute BoRo created — which under § 11.7 BoRo absorbs, and which counts against the dispute ratio regardless.
§ 14 Listing Restrictions (New)
V8.6 contained no listing-restriction section and made no reference to the prohibited-items provisions of the Terms of Service. The Terms carried the rule and nothing in the product enforced it. This section closes that gap and is the controlling product specification for listing eligibility.
§ 14.1 Structure
| Tier | Nature | Lift Path |
|---|---|---|
| Categories A–G | Permanent prohibitions — weapons, controlled substances, hazardous materials, licensed vehicles, adult items, stolen or encumbered property, counterfeits. | None. Never lifted. |
| Category H | MVP pilot prohibitions — items whose risk is not manageable within BoRo’s current operational and insurance infrastructure. | Lifted by ToS amendment as infrastructure matures. |
| Category I | Life-Safety Equipment — permanent prohibitions. Equipment whose sole function is preventing death and whose failure is not visually detectable. | None. Never lifted. |
| Tier 2 | Conditionally permitted — prohibited at MVP launch with the conditions for permission stated in advance. | Lifted on satisfaction of § 14.4. |
§ 14.2 Category I — Life-Safety Equipment (New Permanent Tier)
Category I is created in Terms of Service v2.4 and is permanent. Its members share one characteristic: the product’s only function is preventing death, and the event that destroys that function leaves no visible trace. Car seats, booster seats and infant carriers. A seat that absorbed crash energy is microfractured and looks identical to a new one. Helmets of every type. The liner crushes once and does not spring back; the shell looks unmarked afterwards. Life jackets and personal flotation devices of every type, inherently buoyant and inflatable alike. Fall-protection harnesses, ropes and climbing hardware. Retirement is driven by a fall history no peer lender documents. Medical devices — CPAP, nebulizers, mobility scooters, blood pressure monitors. Prescription status makes this a licensing question, not a risk-tolerance one.
Locked — Why a Separate Permanent Category These items cannot sit in Category H, because Category H is by design the list that gets lifted as insurance and operations mature. No insurance outcome should ever unlock a used car seat of unknown provenance. The distinction that governs Category I is verifiability, not squeamishness. A fleet operator renting car seats owns the seat from purchase, holds records, retires on schedule and carries commercial coverage written for it. A peer-to-peer lender may honestly not know whether the seat was in a collision. No photograph, longer checklist or lender attestation reaches that gap — and an unverifiable attestation is worse than either allowing or prohibiting, because it manufactures false assurance.
§ 14.3 Category H — MVP Prohibitions
The full item-level schedule is set out in Terms of Service v2.4 § 8. Three stated principles govern the schedule and shall be reproduced in the Terms as the rationale, because they answer “why this and not that” far better than a list does. Machines that throw objects, or that are towed, are prohibited. Thrown-object risk reaches bystanders as a normal operating condition rather than as an incident, and towing adds hitch and highway liability outside anything BoRo can evidence. Stored pressurized fuel, indoor combustion and delayed ignition are prohibited. A contained fire the user is watching is not the same risk as a fuel system, a carbon monoxide source in a sleeping household, or a spark that smolders in insulation for hours after everyone has gone home. Anything the borrower must ASSEMBLE is prohibited. A ladder is a finished product; scaffolding is a kit. The lender hands over components and what gets built is beyond anyone’s inspection — and a five-photograph condition record cannot count fasteners or verify a complete set went out and came back.
§ 14.4 Tier 2 — Conditional Permission
Tier 2 items are prohibited at MVP launch. Permission is granted item-by-item on satisfaction of all three conditions below, by Terms of Service amendment rather than by a rewrite of § 8.
| Condition | Requirement |
|---|---|
| Carrier confirmation | Written confirmation from BoRo’s general liability carrier that the item category is within coverage and not excluded. |
| Lender safety certification | An item-specific attestation the lender can truthfully make and BoRo can meaningfully act on — not a generic checkbox. Examples: nail guns certified as set to sequential-trip mode; propane grills certified as to hose and regulator condition. |
| Borrower acknowledgment | A booking-time acknowledgment specific to the item category, distinct from the general terms acceptance. |
Locked — Insurance Sets the Floor The Category H schedule shall be reconciled against the exclusions schedules of BoRo’s general liability carrier. Where a carrier excludes a category, that category is not permitted regardless of BoRo’s own risk assessment. Permitting an item the policy excludes is a different and worse problem than accepting a risk that has been priced. STANDING ACTION: obtain written exclusions schedules from all carriers under consideration and reconcile before pilot launch.
§ 14.5 Enforcement Architecture
A self-attested Lender Safety Certification is not enforcement. A lender taps “I certify” and lists the item regardless. The following controls are required for MVP.
| Control | Specification |
|---|---|
| Category gate | The restriction screen runs FIRST in the listing flow, before any other field. Selecting a prohibited category ends the flow with a plain-language explanation and a link to § 8 of the Terms. |
| Prohibited-term matching | Title and description are screened against a maintained term list at submission and on every edit. A match blocks publication and routes to review — it does not merely warn. |
| Threshold capture | Where a category is permitted only below a numeric threshold, that figure is a required structured field, not free text. Applies to e-scooters and e-bikes (mph and class) and drones (grams). |
| Review queue | Blocked and flagged listings route to a human review queue with a defined SLA. A blocked listing is never silently deleted. |
| Re-screening on edit | Every listing edit re-runs the full gate. A lender must not be able to publish a permitted item and then edit it into a prohibited one. |
| Audit log | Every gate decision is logged with timestamp, rule version and outcome. This is chargeback and litigation evidence. |
§ 14.6 Consequences of Prohibited Listing
Locked — Consequence Falls on the Breaching Party Terms of Service § 8.1 currently provides for “forfeiture of any BoRo Shield associated with any affected Transaction.” The Shield is the BORROWER’S money. Where the LENDER listed the prohibited item, that clause as drafted reads as capturing the borrower’s funds for the lender’s breach. The intended meaning is forfeiture of Shield COVERAGE — the lender’s right to claim against it. Terms of Service v2.4 shall be redrafted to say so expressly. A consequence must fall on the party who breached. Consequences for a lender listing a prohibited item: immediate delisting; forfeiture of the right to claim against the Shield or the Saved Payment Method for that transaction; liability for any dispatch or recovery cost; and account suspension or termination for repeat breach.
§ 15 Risk Allocation & Legal Architecture (New)
This section states the risk-allocation architecture the platform depends upon and specifies the Terms of Service provisions required to support it. It is written to protect Aston Ventures Inc. and its shareholders, and to protect the lenders and borrowers on whom the marketplace depends. Counsel shall settle final language; the allocations below are the CEO-locked commercial positions.
§ 15.1 Platform Role — What BoRo Is and Is Not
Locked — BoRo Is Not the Lessor BoRo is a technology platform connecting independent lenders and borrowers, and the merchant of record for its own platform fees. BoRo is NOT the owner, lessor, bailee, distributor, manufacturer, retailer or inspector of any listed item. BoRo takes possession of an item only in the limited dispatch, recovery and custody circumstances specified in § 10.6, § 12 and § 12.6, and does so as a custodian for the lender. This characterization must be stated expressly in the Terms of Service and must be consistent with actual operation. It is a live risk that a plaintiff will argue BoRo is the lessor rather than a venue, because BoRo takes a fee, controls the transaction flow, holds the funds and adjudicates damage. Operational practice shall not undercut the drafted position — BoRo shall not inspect items for fitness, shall not certify item quality, and shall not represent that any item is safe or suitable for any purpose.
§ 15.2 No Warranty as to Items
Required Terms of Service provisions: BoRo makes no representation or warranty, express or implied, as to the condition, safety, legality, fitness for a particular purpose, merchantability, maintenance history, provenance, recall status or age of any item listed on the platform. The condition record captured under § 10.3 and § 11.2 is evidence of visible condition at a moment in time for the purpose of settlement adjudication. It is not an inspection, a certification, or a representation that an item is safe or functional. Every item is made available by an independent lender. The lender, not BoRo, is the source of every representation about the item.
§ 15.3 Assumption of Risk — Borrower
The borrower expressly assumes the risk of using a rented item, including risk of property damage, personal injury and death, and acknowledges that BoRo has not inspected, tested, serviced or certified the item. This acknowledgment shall be obtained at Stage 2 verification and re-presented at booking for any Tier 2 item.
Critical — A Waiver Binds Only the Signer An assumption-of-risk provision is a necessary layer and an insufficient one. It binds the borrower who signed it. It does NOT bind: an injured bystander or neighbour; a member of the borrower’s household, including a child; the borrower’s health insurer exercising subrogation rights; or any other third party. North Carolina enforces exculpatory provisions but construes them strictly against the drafter and will not enforce them as to gross negligence — which means a plaintiff pleads gross negligence and the provision does not dispose of the case at the pleading stage. Defending a case successfully still costs six figures. The commercial conclusion, which drives § 14: the listing-restriction schedule is the primary risk control and insurance is the second. The waiver is the third layer, not the first. BoRo shall not permit a category on the strength of the waiver alone.
§ 15.4 Lender Representations and Warranties
Required Terms of Service provisions. The lender represents and warrants on each listing and on each transaction that: The lender owns the item outright or has the unrestricted legal right to rent it, and the item is not subject to any lien, security interest or third-party claim. The item is not prohibited under § 8 of the Terms of Service, is not subject to any outstanding safety recall, and is not otherwise unlawful to distribute or rent. The item is in the condition represented, is functional for its ordinary purpose, and has been maintained in accordance with any manufacturer requirements. The lender has disclosed any known defect, damage, modification or incident affecting the item. The lender has verified whether their own insurance covers rental of personal property for compensation, and understands BoRo makes no representation that it does.
Critical — Lender Insurance Disclosure Is Mandatory Most homeowners and renters policies exclude “business pursuits,” and renting personal property for compensation is very likely a business pursuit. A lender may therefore be personally uninsured for a claim arising from an item they listed on BoRo — and will discover this only after being sued personally. This must be disclosed prominently at onboarding, not buried in the Terms. The first Charlotte lender to be personally sued and find they have no coverage is a supply-side failure that no marketing spend recovers. Trust infrastructure is the thesis; a lender who feels ambushed is the fastest way to lose it. PRODUCT REQUIREMENT: a plain-language insurance disclosure screen at lender onboarding, separately acknowledged, recommending the lender confirm coverage with their own carrier.
§ 15.5 Indemnification
The lender indemnifies BoRo against claims arising from the item, including its condition, defects, recall status, legality, and any injury or damage caused by it, and from any breach of the lender representations in § 15.4. The borrower indemnifies BoRo against claims arising from the borrower’s use, misuse, storage, transport or operation of the item, and from any injury or damage caused to any person or property during the rental term. Each indemnity survives termination of the user’s account and expiration of the rental term.
§ 15.6 Limitation of Liability
BoRo’s aggregate liability to any user arising from any transaction shall not exceed the greater of the platform fees BoRo earned on that transaction or one hundred dollars ($100.00), to the maximum extent permitted by law. BoRo shall not be liable for indirect, incidental, consequential, special, exemplary or punitive damages, or for lost profits, lost data, or loss of use. The limitation applies regardless of the theory of liability and survives any failure of essential purpose of any limited remedy. These limitations do not purport to limit liability that cannot lawfully be limited.
§ 15.7 Third-Party Harm
Locked — The Category That Cannot Be Contracted Around Harm to a person who is not a party to the transaction — a neighbour struck by a thrown object, a child in a rented product, a household member exposed to carbon monoxide, a driver hit by a towed machine — cannot be addressed by any provision in the Terms of Service, because that person never agreed to them. This is the reason Category H and Category I exist and the reason the listing-restriction gate of § 14.5 must be a hard block rather than a warning. For third-party harm the only real controls are (a) not permitting the item and (b) insurance. Everything else is documentation.
§ 15.8 Evidence, Settlement and Finality
The lender assumes all latent and after-discovered risk once the 45-minute return session closes. BoRo’s evidence-based settlement decision is final and non-appealable, and the parties waive any right to relitigate it as between themselves and BoRo. Both parties consent to photograph and video capture at each handoff and to retention of that evidence for dispute adjudication, chargeback representment and legal defense. Both parties consent to the placement, refresh and release of authorization holds as specified in this specification, and to off-session charges against the Saved Payment Method as specified in § 6.5.
§ 15.9 Dispute Resolution
Binding individual arbitration for disputes between a user and BoRo, with a class-action waiver and a jury-trial waiver, subject to a small-claims carve-out and a conspicuous opt-out period. Governing law: the internal affairs of the corporation are governed by Delaware law; the user agreement and the marketplace transactions are governed by North Carolina law for the Charlotte pilot. Disputes between a lender and a borrower are between those parties. BoRo’s settlement determination is final as to the movement of funds on the platform and does not purport to determine the parties’ rights against each other outside it.
§ 15.10 Severability and Survival
Each provision is severable; the invalidity or unenforceability of any provision does not affect the remainder. Sections 15.2 through 15.9 survive termination of any user account and the completion or cancellation of any transaction.
§ 15.11 Legal Review Register
No outside firm is presently engaged. The following items are drafted and in force, and are recorded here so that a single reviewing engagement — whenever one is commissioned — can be scoped efficiently rather than open-ended. None blocks the pilot.
| Item | Status | Review Value |
|---|---|---|
| § 8.1 forfeiture clause | Corrected in ToS v2.4 § 8.2. Consequence now falls on the breaching party. | Low — defect closed |
| Abandonment and disposal right | Drafted in ToS v2.4 § 16 and specified at § 12.7. Notice, cure, disposal, proceeds and records. | Medium — confirm NC notice sufficiency |
| NC exculpatory clause scope | In force at ToS v2.4 § 15.3. Known limit: unenforceable as to gross negligence. | High — highest-value single opinion |
| Platform-vs-lessor characterization | Asserted at ToS v2.4 § 15.1 and § 15.1 of this specification. | High — turns on operational practice |
| Arbitration and class waiver | In force at ToS v2.4 § 15.9. Opt-out mechanics stated. | Medium — enforceability of opt-out |
| Carrier reconciliation | Standing condition of § 14.4. No Tier 2 item is permitted before written confirmation of coverage. | N/A — broker action, not legal |
§ 16 Cross-Document Dependencies
§ 16.1 Terms of Service v2.4 — Required Changes
§ 8 Listing Restrictions: full item-level schedule for Categories H and I, the Tier 2 construct and its three conditions, and the three stated principles of § 14.3. § 8.1 forfeiture clause redrafted per § 14.6. New § 15 Risk Allocation, implementing § 15.1 through § 15.10 of this specification. Lender insurance disclosure per § 15.4. Consent to authorization refresh and off-session charge per § 15.8. New § 16 Uncollected and Abandoned Items, implementing § 12.7 of this specification — notice, cure period, deemed abandonment, disposal, application of proceeds, surplus held for the lender, and record retention.
§ 16.2 Sales Tax
Where a travel or delivery amount is charged it is taxable in North Carolina and sourced to the borrower’s delivery address. The Mecklenburg County combined rate increased to 8.25% effective 1 July 2026; Engineering shall confirm the rate engine reflects the change. Because a self-pickup credit reduces the borrower’s actual consideration, tax follows the net rental while the platform fee follows the gross — two bases in one transaction, to be documented in the tax configuration. All travel figures must be recomputed on the § 8 basis.
§ 17 Consolidated Engineering Requirements
All requirements below are locked for the MVP build. No deviation without CEO sign-off and an FSD version increment.
| Requirement | Specification |
|---|---|
| Accounts | Two-stage: browse (name + email) → verified (ID + selfie/liveness + card + SetupIntent + agreements) at first booking. 18+ gate; 13–17 under a parent-owned account. |
| Card / identity | No block on card-name ≠ ID-name. No lane cap, no gate, no monitoring requirement. |
| Listing gate | Restriction screen runs FIRST. Category gate, prohibited-term matching on title and description at submission and on every edit, structured numeric threshold fields, human review queue, full audit log. |
| Lane assignment | Declared value ≤ $100 → Lane A (no Shield). $101–$1,000 → Lane B (Shield). Declared value is the recovery ceiling in both lanes and is disclosed on screen at declaration. |
| Calendar | Three states. Pending locks to first requester with expiry = min(24h, 0.5 × time-to-start) as a single timestamp on the request row. Committed extension windows block; theoretical maximums do not. |
| Gross-up | Borrower Charge = ( Rental × 1.07 + 0.30 ) ÷ 0.971, rounded UP to the nearest cent. |
| Commitment Hold | 20% of total rental transaction, $10.00 minimum, lender matches borrower dollar-for-dollar. Card only. Placed at Confirm Tap, released at QR pairing. |
| Shield (Lane B) | Authorized at QR pairing only. Refresh Tap every sixth day of a committed term. New Shield authorized and confirmed BEFORE prior Shield released, never the reverse. |
| Saved Payment Method | SetupIntent at Stage 2, mandatory. Sole protection in Lane A; second layer in Lane B; covers missed Refresh Tap, damage above Shield, and brand fallback. |
| Universal Shield flag | Shield path implemented so Lane A can be enabled by config flag, not rewrite. Lane A loss data instrumented from day one. |
| Extensions | Menu +6 / +12 / +18 / +24 to a 30-day total. Full committed fee captured in ONE charge at commitment. 10% platform fee on the entire transaction. Double-hold disclosure mandatory at every Refresh Tap. |
| Authorization path | Single, card-brand-agnostic. Read capture_before per charge; never hardcode a window. Confirm Tap and Refresh Tap must be cardholder-present PaymentIntents. |
| Statement descriptors | BORO USA account descriptor; BORO shortened; per-charge suffixes DEPOSIT / RENTAL / RECOVERY. |
| Travel | Beyond-midpoint miles only, ONE WAY per leg, $0.75/mile, each leg priced independently. BoRo dispatch bills the agreed user-to-user distance, not actual route. Self-pickup gated at lender net ≥ $0.01 with an on-screen explanation. |
| QR pairing | One code per booking; displayable only inside the 100-foot geofence; validates only with both devices in-zone at scan. |
| Session timer | One 45-minute timer per phase. Expiry inside geofence → dual-confirmation handback; outside geofence → auto-accept. |
| Borrower controls | State-based: Accept / Decline / Report before take-to-test; Decline disables on take-to-test. Trigger is the act, not a timer. |
| Condition evidence | Check-in: lender up to 5 photos + 1 video, timestamped, borrower match-confirm required. Return: blind double-submission. Photo-capture failure → confirm-with-flag, not auto-clear. |
| Settlement | Single final adjudication on blind tickets at return; no reopening. Rental Fee recognized RATABLY across the rental term. |
| Non-confirmation | Three-strike rolling 90-day regime: warning → 7-day → 30-day → permanent. Public completion rate on every profile. |
| Chargebacks | BoRo absorbs amount and fee where the lender is blameless; clawback only on demonstrated lender fault. Contest every disputable chargeback regardless. Dedicated expense line and reserve. |
| Late return | OVERDUE auto-fires at scheduled datetime (≤60s tolerance). T+9h Shield capture or Saved Payment Method charge automated. |
| Storage | $5.00/day accruing 24h after BoRo takes possession, capped at declared value, deducted from lender proceeds. |
| Dispatch | Lender grace 2h; BoRo commitment same day by 9:00 PM from grace expiry; next day by noon where grace expires after 7:00 PM. Concurrent cap of ONE. Mecklenburg County only. |
| Mileage calculation | Server-side, shortest driving route, round up to 0.1 mile, locked at request time, computed from the midpoint. |
§ 18 Authorization
This Version 9.0 Consolidated Master Functional Specification is adopted as the controlling production specification upon execution below, and supersedes Versions 8.3, 8.4, 8.5 and 8.6 in full.
Jaydan Hoang Nguyen Chief Executive Officer & Founder Aston Ventures Inc., a Delaware corporation, d/b/a BoRo USA Date: ______________________
Conversion changelog
-
2026-08-20 — Converted from
BoRo_Master_FSD_07_30_V9.docxand landed atboro-ops/product/BoRo_MasterFSD.md. No content added, removed or reworded; structure only. Placed in the repo because the Search-First precedence chain — live repo, then synced project knowledge, then memories — had no entry for the product specification, so sessions needing a product fact read the canvas instead, and the canvas became the de facto spec. Confirmed current by CJ on 2026-08-20. Open at conversion and closed the same day: CJ confirmed this Master governsboro-shared, so the four divergent constants are defects and §6.2’s lane model is a gap in the code, not a difference of scheme. -
2026-08-24 — Promoted to
AstonVentureInc/boro-wikiatsrc/canon/BoRo_MasterFSD.md, rendered at/canon/master-fsd/, so the specification is readable by the team rather than by one person. Theboro-opscopy is now a stub. Three table cells restored in the same pass, against a fresh export of the source document provided by Jay: §6.2 Commitment Hold and Recovery ceiling had lost their Lane B value, and §8.2 Meet halfway had lost the borrower’s To midpoint. In each case the cell duplicated the one beside it and the 2026-08-20 conversion collapsed the pair, shifting every later cell one column left — so §6.2 read as though the Commitment Hold applied to Lane A alone. No wording was changed.tools/promotion/compare-source.pynow reports 104 of 104 sections identical to the export.