← All legal documents

KeyZup Privacy Policy

FieldValue
Version1.0.0
Effective dateAugust 8, 2026
AudienceCustomers and service providers (independent technicians and locksmith companies) using KeyZup apps and website
Acceptance methodPresented at account registration and on material updates; continued use after notice constitutes acknowledgement
Change noticeIn-app notice and/or email; effective date updated on posting; material changes highlighted
Governing lawthe laws of the state in which KeyZup is organized, without regard to its conflict-of-laws principles

1. Who we are and what KeyZup does

KeyZup operates a technology marketplace/intermediary platform. KeyZup connects customers who need locksmith-type services with independent service providers — independent technicians and locksmith companies. KeyZup does not perform locksmith services itself. The independent technicians and locksmith companies that provide services are not KeyZup employees.

Customers pay providers directly for services. KeyZup does not process customer payments for services and does not make payouts to providers. KeyZup charges providers platform fees and charges companies subscriptions through a provider wallet (billed via our payment processor).

This Privacy Policy explains what personal information we collect, why, how we share it, and the choices and rights that may be available to you. Because our platform serves different roles (customers, independent technicians, companies), some sections apply only to certain users, as noted.

2. Scope

This Policy covers personal information processed through the KeyZup mobile applications, our website, and related services. It does not govern the independent providers' own privacy practices for information they collect or retain outside the platform, nor the practices of third parties whose services we integrate (see the vendor list in Section 12).

3. Data inventory

The table below summarizes the categories of personal information we process. Legal bases and retention periods reflect how we process each category; retention is also governed by the Data Retention & Deletion Policy.

Data categoryPurposeLegal basisSourceSharingRetentionNotes
Account & profile data (name, role, credentials)Create/manage accounts, authenticate, operate platformContract performance / legitimate interests / consentUserFirebase/Google (auth)As long as necessary for the stated purpose and as required by lawFirebase Authentication used for identity
Contact information (email, phone)Communications, notifications, support, account recoveryContract / legitimate interestsUserFirebase/Google; providers/customers as needed for a jobAs long as necessary for the stated purpose and as required by law
Precise locationMatch nearby jobs, routing, on-site service coordinationConsent (device permission)Device (with permission)Provider/customer as needed for the jobAs long as necessary for the stated purpose and as required by lawCollected only with OS-level permission; revocable in device settings
Approximate locationService-area matching, coarse discoveryConsent / legitimate interestsDevice / derivedProvider/customer as neededAs long as necessary for the stated purpose and as required by law
Job/service details (request type, notes, status)Facilitate and record service requestsContract / legitimate interestsCustomer/providerThe matched provider/customerAs long as necessary for the stated purpose and as required by law
Customer addresses / access informationEnable providers to locate and access the service siteContract / legitimate interestsCustomerThe matched provider onlyAs long as necessary for the stated purpose and as required by lawSensitive; access-limited
Technician identity documentsVerify provider identity for trust & safetyConsent / legal obligation / legitimate interestsProviderStored in Firebase Storage (owner/admin access only)As long as necessary for the stated purpose and as required by lawAdmin access via short-lived signed URLs; no public access
LicencesVerify qualification/eligibilityLegitimate interests / legal obligationProviderFirebase Storage (owner/admin only)As long as necessary for the stated purpose and as required by law
Insurance documentsVerify coverage for trust & safetyLegitimate interestsProviderFirebase Storage (owner/admin only)As long as necessary for the stated purpose and as required by law
Business documents (company)Verify company legitimacy, onboardingLegitimate interests / legal obligationCompanyFirebase Storage (owner/admin only)As long as necessary for the stated purpose and as required by law
Background-screening status / reference dataTrust & safety eligibility signalConsent / legitimate interestsScreening provider (future) via status callbackNot shared externally except as requiredAs long as necessary for the stated purpose and as required by lawWe store status/reference only — we do NOT store background report contents. Point-in-time
Payment tokens / card summaryBill provider platform fees and company subscriptionsContract / legal obligationProvider (entered into Stripe)StripeAs long as necessary for the stated purpose and as required by lawCards are tokenized by Stripe; we do NOT store full card numbers — only a card summary / Stripe token reference
Wallet / ledger / subscription dataOperate provider wallet, fees, subscriptions, accountingContract / legal obligationPlatformStripe; accounting/tax processorsAs long as necessary for the stated purpose and as required by lawFinancial records may have extended statutory retention
MessagesIn-app communication between usersContract / legitimate interestsUsersThe other party to the conversationAs long as necessary for the stated purpose and as required by law
Message imagesShare job-relevant photos in chatContract / legitimate interestsUsersThe other party; Firebase StorageAs long as necessary for the stated purpose and as required by law
Portfolio imagesProvider showcases work publicly on profileConsent (publication)ProviderPublicly visible on provider profileAs long as necessary for the stated purpose and as required by lawIntentionally public when published
ReviewsCommunity trust, service quality signalLegitimate interests / consentCustomersPublicly visibleAs long as necessary for the stated purpose and as required by law
Push tokens / device dataDeliver push notifications; app functionality/securityConsent (push) / legitimate interestsDeviceFirebase/Google (FCM), Apple/Google push infraAs long as necessary for the stated purpose and as required by lawRevocable via device settings
Analytics / logsReliability, security, abuse prevention, product improvementLegitimate interests / consentPlatform/deviceFirebase/Google; analytics vendorsAs long as necessary for the stated purpose and as required by law
Support / incident reportsHandle support requests, investigate incidentsLegitimate interests / legal obligationUsers/staffInternal; support toolingAs long as necessary for the stated purpose and as required by law
Admin audit logsSecurity, accountability, complianceLegal obligation / legitimate interestsPlatformInternal onlyAs long as necessary for the stated purpose and as required by law
Cookies / web analyticsWebsite functionality and measurementConsent / legitimate interestsWebsite/browserweb analytics vendorsAs long as necessary for the stated purpose and as required by lawSee Section 11

4. How we use personal information

We use personal information to: operate and secure the marketplace; verify provider identity, licences, insurance and eligibility on a point-in-time basis; match customers with providers; enable communication; bill providers for platform fees and company subscriptions; prevent fraud and abuse; provide support; comply with legal obligations; and improve the service. We do not sell personal information for money; whether any activity constitutes a "sale" or "sharing" under specific US state laws is governed by the laws applicable to your jurisdiction (see Section 8).

5. Security

We apply administrative, technical, and organizational safeguards designed to protect personal information, including:

  • Payment data minimization: payment cards are tokenized by Stripe; KeyZup does not store full card numbers, only a card summary / Stripe token reference.
  • Background data minimization: KeyZup stores background-check status/reference data only; it does not store background report contents.
  • Document access controls: verification documents (identity, licences, insurance, business documents) are stored in Firebase Storage with owner/admin access only; administrators access them through short-lived signed URLs; there is no public access.
  • Authentication managed through Firebase Authentication.
  • Access controls, audit logging of administrative actions, and least-privilege practices.

No method of transmission or storage is completely secure; we cannot guarantee absolute security.

6. International data transfers

KeyZup launches initially in the United States (multi-state) and the app also supports Canada. Personal information may be processed in the United States and in locations where our infrastructure vendors operate. Cross-border transfer mechanisms and any required safeguards (for example, between Canada/Quebec and the United States) are applied as required by the laws applicable to your jurisdiction.

7. Your rights and choices

Depending on your jurisdiction, you may have rights to access, correct, delete, and port your personal information, and to opt out of certain processing. These rights are region-dependent and their scope, exceptions, and verification requirements vary by law, including:

  • California (CCPA/CPRA)
  • Other US state privacy laws
  • General US
  • Canada PIPEDA and Quebec Law 25

To exercise available rights, contact us as described in Section 13. We will verify requests before acting and respond within the timeframe required by applicable law.

8. "Sale"/"sharing" and opt-out (region-dependent)

Whether any data practice constitutes a "sale" or "sharing" of personal information, or "targeted advertising"/"profiling" under US state laws, and the corresponding opt-out and disclosure obligations, are governed by the laws applicable to your jurisdiction.

9. Deletion and its limitations

When you request deletion, we will delete or de-identify personal information where required and feasible. However, we may retain certain information where permitted or required, including for:

  • Legal and regulatory obligations (e.g., financial/tax recordkeeping)
  • Accounting for provider fees and company subscriptions (wallet/ledger/Stripe references)
  • Fraud prevention and platform integrity
  • Safety, trust, and dispute resolution
  • Legal holds / litigation (see the Data Retention & Deletion Policy)

Retained data is limited to what is necessary for the stated purpose and is deleted or de-identified when the basis for retention expires. Deletion of data held by independent providers outside the platform is governed by those providers' own practices.

10. Children

KeyZup is not directed to children and is intended for adults (and, for providers, eligible working professionals). We do not knowingly collect personal information from children. Age thresholds and any parental-consent obligations apply as provided by the laws applicable to your jurisdiction. If we learn we have collected information from a child in violation of applicable law, we will take steps to delete it.

11. Cookies and web analytics

Our website may use cookies and similar technologies for functionality and measurement. The specific cookies, vendors, consent-banner requirements, and opt-out mechanisms apply as provided by the laws applicable to your jurisdiction. Where required, we will present a consent mechanism before setting non-essential cookies.

12. Vendors and service providers

We rely on the following infrastructure vendors to operate the platform:

  • Firebase / Google — authentication, Firestore database, Firebase Storage, and Firebase Cloud Messaging (push).
  • Stripe — payment card tokenization and billing of provider platform fees and company subscriptions.
  • Apple App Store / Google Play — app distribution and related platform services.

Additional processors (e.g., a background-screening provider, analytics, support tooling) may be engaged; those relationships and disclosures are governed by this Policy and applicable law. We bind processors to appropriate confidentiality and data-protection terms.

13. Contact and requests

Privacy questions and rights requests: privacy@keyzup.com. We will acknowledge and handle requests in accordance with applicable law. Intake channels, verification steps, and response timelines follow applicable law.

14. Changes to this Policy

We may update this Policy. We will update the effective date and, for material changes, provide additional notice through the app and/or email. Continued use after the effective date constitutes acknowledgement, subject to any consent requirements under applicable law.