KeyZup Background Screening Consent Framework
| Field | Value |
|---|---|
| Version | 1.0.0 |
| Effective date | August 8, 2026 |
| Audience | Internal (product/legal/trust & safety); informs provider-facing consent flows |
| Acceptance method | Disclosures and authorizations are presented to providers through KeyZup's screening flow, hosted by our screening service provider |
| Change notice | Reviewed on material vendor or legal change; versioned |
| Governing law | the laws of the state in which KeyZup is organized, without regard to its conflict-of-laws principles |
1. Scope
This document describes the components of KeyZup's background-screening consent process for KeyZup providers. Vendor- and law-dependent elements are handled by our screening service providers. Background verification is point-in-time.
KeyZup operates as a marketplace/intermediary. KeyZup's specific role for screening purposes, and any resulting obligations, is determined by the laws applicable to your jurisdiction.
2. Standalone disclosure requirements
A clear and conspicuous disclosure that a background check may be obtained is presented on its own — a standalone document, separate from any other agreement (not buried in terms of service, the provider agreement, or an application). The disclosure includes:
- A plain-language statement that a consumer report / background check may be procured for eligibility purposes.
- No extraneous content, waivers, or liability releases mixed into the disclosure.
- Presentation before authorization is requested.
- Exact wording, format, and any state-specific inserts as provided by our screening service providers. US FCRA and state-law considerations apply.
3. Authorization requirements (kept separate)
- Obtain the provider's written authorization to procure the check.
- Keep the authorization separate from other agreements and from the disclosure where required.
- Capture and version the authorization record (who, what, when, which text).
- The scope of authorization (one-time vs. ongoing/recheck) and any state-specific authorization rules are handled through our screening service providers.
4. Privacy notice within the flow
The screening flow links to KeyZup's Privacy Policy and clearly states:
- What data is used to initiate the check and who performs it (the screening provider — a service provider).
- That KeyZup stores only the check status/reference and does not store the background report itself.
- How the provider can access or dispute results (Section 7).
- Retention of status/reference data per the Data Retention & Deletion Policy.
5. Provider-hosted flow
KeyZup uses a screening-provider-hosted flow so that disclosures, authorizations, and any report contents are collected and handled by the vendor's compliant infrastructure, with KeyZup receiving only a status/reference callback. This approach:
- Reduces KeyZup's handling of sensitive report data (supports minimization).
- Leverages vendor-maintained, jurisdiction-aware disclosure/authorization content.
- Keeps report contents off KeyZup systems entirely.
How responsibilities are allocated between KeyZup and the vendor is governed by the applicable service-provider agreement and the laws applicable to your jurisdiction.
6. Pre-adverse-action and adverse-action procedures
Where a background result may lead to denial or removal and applicable law requires it, KeyZup follows a pre-adverse-action and adverse-action process:
- Pre-adverse action: provide notice, a copy of the report through the screening service provider, and any required summary of rights; allow a reasonable period to respond or dispute.
- Adverse action: after the waiting period, provide the final notice and required disclosures.
- Timing, content, required summaries of rights, and state-specific variations are handled through our screening service providers as required by the laws applicable to your jurisdiction. Because KeyZup stores only status/reference data, the report copy is furnished through the vendor, not from KeyZup storage.
7. Report and dispute access
- Providers can obtain a copy of their report and dispute inaccuracies through the screening provider (a service provider), which holds the report.
- KeyZup directs providers to the vendor's access/dispute process and does not adjudicate report contents it does not hold.
- Access and dispute mechanics are handled through our screening service providers.
8. Recheck consent
- Because verification is point-in-time, KeyZup may run periodic or event-based rechecks.
- Rechecks may require renewed or ongoing authorization, as provided by the laws applicable to your jurisdiction and our screening service providers' requirements.
- Where ongoing authorization is used, KeyZup discloses the scope and cadence clearly and records consent.
9. Company-attestation alternative
KeyZup offers an attestation alternative for locksmith companies that screen their own technicians rather than routing each technician through KeyZup's flow. Under this alternative:
- The company attests to the scope, recency, and standards of the screening it performs, and KeyZup retains the attestation record and any reference provided.
- The company remains responsible for the correct handling of consumer-report disclosures and authorizations as to its own Personnel, as provided by the laws applicable to your jurisdiction.
- Where KeyZup instead runs technician-level checks, the technician completes KeyZup's standalone disclosure and authorization flow.
10. KeyZup data-minimization policy (screening)
- KeyZup stores background-check status / reference data only.
- KeyZup never stores the background report or its contents.
- Report contents (if retained at all) reside with the screening provider under its own terms.
- Status/reference retention follows the Data Retention & Deletion Policy.
- Access to screening status within KeyZup is limited to authorized admin roles.
