← All legal documents

KeyZup Background Screening Consent Framework

FieldValue
Version1.0.0
Effective dateAugust 8, 2026
AudienceInternal (product/legal/trust & safety); informs provider-facing consent flows
Acceptance methodDisclosures and authorizations are presented to providers through KeyZup's screening flow, hosted by our screening service provider
Change noticeReviewed on material vendor or legal change; versioned
Governing lawthe laws of the state in which KeyZup is organized, without regard to its conflict-of-laws principles

1. Scope

This document describes the components of KeyZup's background-screening consent process for KeyZup providers. Vendor- and law-dependent elements are handled by our screening service providers. Background verification is point-in-time.

KeyZup operates as a marketplace/intermediary. KeyZup's specific role for screening purposes, and any resulting obligations, is determined by the laws applicable to your jurisdiction.

2. Standalone disclosure requirements

A clear and conspicuous disclosure that a background check may be obtained is presented on its own — a standalone document, separate from any other agreement (not buried in terms of service, the provider agreement, or an application). The disclosure includes:

  • A plain-language statement that a consumer report / background check may be procured for eligibility purposes.
  • No extraneous content, waivers, or liability releases mixed into the disclosure.
  • Presentation before authorization is requested.
  • Exact wording, format, and any state-specific inserts as provided by our screening service providers. US FCRA and state-law considerations apply.

3. Authorization requirements (kept separate)

  • Obtain the provider's written authorization to procure the check.
  • Keep the authorization separate from other agreements and from the disclosure where required.
  • Capture and version the authorization record (who, what, when, which text).
  • The scope of authorization (one-time vs. ongoing/recheck) and any state-specific authorization rules are handled through our screening service providers.

4. Privacy notice within the flow

The screening flow links to KeyZup's Privacy Policy and clearly states:

  • What data is used to initiate the check and who performs it (the screening provider — a service provider).
  • That KeyZup stores only the check status/reference and does not store the background report itself.
  • How the provider can access or dispute results (Section 7).
  • Retention of status/reference data per the Data Retention & Deletion Policy.

5. Provider-hosted flow

KeyZup uses a screening-provider-hosted flow so that disclosures, authorizations, and any report contents are collected and handled by the vendor's compliant infrastructure, with KeyZup receiving only a status/reference callback. This approach:

  • Reduces KeyZup's handling of sensitive report data (supports minimization).
  • Leverages vendor-maintained, jurisdiction-aware disclosure/authorization content.
  • Keeps report contents off KeyZup systems entirely.

How responsibilities are allocated between KeyZup and the vendor is governed by the applicable service-provider agreement and the laws applicable to your jurisdiction.

6. Pre-adverse-action and adverse-action procedures

Where a background result may lead to denial or removal and applicable law requires it, KeyZup follows a pre-adverse-action and adverse-action process:

  • Pre-adverse action: provide notice, a copy of the report through the screening service provider, and any required summary of rights; allow a reasonable period to respond or dispute.
  • Adverse action: after the waiting period, provide the final notice and required disclosures.
  • Timing, content, required summaries of rights, and state-specific variations are handled through our screening service providers as required by the laws applicable to your jurisdiction. Because KeyZup stores only status/reference data, the report copy is furnished through the vendor, not from KeyZup storage.

7. Report and dispute access

  • Providers can obtain a copy of their report and dispute inaccuracies through the screening provider (a service provider), which holds the report.
  • KeyZup directs providers to the vendor's access/dispute process and does not adjudicate report contents it does not hold.
  • Access and dispute mechanics are handled through our screening service providers.

8. Recheck consent

  • Because verification is point-in-time, KeyZup may run periodic or event-based rechecks.
  • Rechecks may require renewed or ongoing authorization, as provided by the laws applicable to your jurisdiction and our screening service providers' requirements.
  • Where ongoing authorization is used, KeyZup discloses the scope and cadence clearly and records consent.

9. Company-attestation alternative

KeyZup offers an attestation alternative for locksmith companies that screen their own technicians rather than routing each technician through KeyZup's flow. Under this alternative:

  • The company attests to the scope, recency, and standards of the screening it performs, and KeyZup retains the attestation record and any reference provided.
  • The company remains responsible for the correct handling of consumer-report disclosures and authorizations as to its own Personnel, as provided by the laws applicable to your jurisdiction.
  • Where KeyZup instead runs technician-level checks, the technician completes KeyZup's standalone disclosure and authorization flow.

10. KeyZup data-minimization policy (screening)

  • KeyZup stores background-check status / reference data only.
  • KeyZup never stores the background report or its contents.
  • Report contents (if retained at all) reside with the screening provider under its own terms.
  • Status/reference retention follows the Data Retention & Deletion Policy.
  • Access to screening status within KeyZup is limited to authorized admin roles.