Hi Dawid,
I'm not sure on Ruckus WAPs itself, but a standard security practice in hospitality is to isolate L2 on your switches. That means that you do not allow your switch ports that have WAPs to talk to each other, only allowing it to talk to uplinks or Gateway.
This concept of port isolation is also known as Private VLAN. Most major switch manufacturers (HP/Aruba, Cisco, Brocade I know do for sure) support this functionality on managed switches.
Best,
Alex