KeyZup Privacy Policy
| Field | Value |
|---|---|
| Version | 1.0.0 |
| Effective date | August 8, 2026 |
| Audience | Customers and service providers (independent technicians and locksmith companies) using KeyZup apps and website |
| Acceptance method | Presented at account registration and on material updates; continued use after notice constitutes acknowledgement |
| Change notice | In-app notice and/or email; effective date updated on posting; material changes highlighted |
| Governing law | the laws of the state in which KeyZup is organized, without regard to its conflict-of-laws principles |
1. Who we are and what KeyZup does
KeyZup operates a technology marketplace/intermediary platform. KeyZup connects customers who need locksmith-type services with independent service providers — independent technicians and locksmith companies. KeyZup does not perform locksmith services itself. The independent technicians and locksmith companies that provide services are not KeyZup employees.
Customers pay providers directly for services. KeyZup does not process customer payments for services and does not make payouts to providers. KeyZup charges providers platform fees and charges companies subscriptions through a provider wallet (billed via our payment processor).
This Privacy Policy explains what personal information we collect, why, how we share it, and the choices and rights that may be available to you. Because our platform serves different roles (customers, independent technicians, companies), some sections apply only to certain users, as noted.
2. Scope
This Policy covers personal information processed through the KeyZup mobile applications, our website, and related services. It does not govern the independent providers' own privacy practices for information they collect or retain outside the platform, nor the practices of third parties whose services we integrate (see the vendor list in Section 12).
3. Data inventory
The table below summarizes the categories of personal information we process. Legal bases and retention periods reflect how we process each category; retention is also governed by the Data Retention & Deletion Policy.
| Data category | Purpose | Legal basis | Source | Sharing | Retention | Notes |
|---|---|---|---|---|---|---|
| Account & profile data (name, role, credentials) | Create/manage accounts, authenticate, operate platform | Contract performance / legitimate interests / consent | User | Firebase/Google (auth) | As long as necessary for the stated purpose and as required by law | Firebase Authentication used for identity |
| Contact information (email, phone) | Communications, notifications, support, account recovery | Contract / legitimate interests | User | Firebase/Google; providers/customers as needed for a job | As long as necessary for the stated purpose and as required by law | — |
| Precise location | Match nearby jobs, routing, on-site service coordination | Consent (device permission) | Device (with permission) | Provider/customer as needed for the job | As long as necessary for the stated purpose and as required by law | Collected only with OS-level permission; revocable in device settings |
| Approximate location | Service-area matching, coarse discovery | Consent / legitimate interests | Device / derived | Provider/customer as needed | As long as necessary for the stated purpose and as required by law | — |
| Job/service details (request type, notes, status) | Facilitate and record service requests | Contract / legitimate interests | Customer/provider | The matched provider/customer | As long as necessary for the stated purpose and as required by law | — |
| Customer addresses / access information | Enable providers to locate and access the service site | Contract / legitimate interests | Customer | The matched provider only | As long as necessary for the stated purpose and as required by law | Sensitive; access-limited |
| Technician identity documents | Verify provider identity for trust & safety | Consent / legal obligation / legitimate interests | Provider | Stored in Firebase Storage (owner/admin access only) | As long as necessary for the stated purpose and as required by law | Admin access via short-lived signed URLs; no public access |
| Licences | Verify qualification/eligibility | Legitimate interests / legal obligation | Provider | Firebase Storage (owner/admin only) | As long as necessary for the stated purpose and as required by law | — |
| Insurance documents | Verify coverage for trust & safety | Legitimate interests | Provider | Firebase Storage (owner/admin only) | As long as necessary for the stated purpose and as required by law | — |
| Business documents (company) | Verify company legitimacy, onboarding | Legitimate interests / legal obligation | Company | Firebase Storage (owner/admin only) | As long as necessary for the stated purpose and as required by law | — |
| Background-screening status / reference data | Trust & safety eligibility signal | Consent / legitimate interests | Screening provider (future) via status callback | Not shared externally except as required | As long as necessary for the stated purpose and as required by law | We store status/reference only — we do NOT store background report contents. Point-in-time |
| Payment tokens / card summary | Bill provider platform fees and company subscriptions | Contract / legal obligation | Provider (entered into Stripe) | Stripe | As long as necessary for the stated purpose and as required by law | Cards are tokenized by Stripe; we do NOT store full card numbers — only a card summary / Stripe token reference |
| Wallet / ledger / subscription data | Operate provider wallet, fees, subscriptions, accounting | Contract / legal obligation | Platform | Stripe; accounting/tax processors | As long as necessary for the stated purpose and as required by law | Financial records may have extended statutory retention |
| Messages | In-app communication between users | Contract / legitimate interests | Users | The other party to the conversation | As long as necessary for the stated purpose and as required by law | — |
| Message images | Share job-relevant photos in chat | Contract / legitimate interests | Users | The other party; Firebase Storage | As long as necessary for the stated purpose and as required by law | — |
| Portfolio images | Provider showcases work publicly on profile | Consent (publication) | Provider | Publicly visible on provider profile | As long as necessary for the stated purpose and as required by law | Intentionally public when published |
| Reviews | Community trust, service quality signal | Legitimate interests / consent | Customers | Publicly visible | As long as necessary for the stated purpose and as required by law | — |
| Push tokens / device data | Deliver push notifications; app functionality/security | Consent (push) / legitimate interests | Device | Firebase/Google (FCM), Apple/Google push infra | As long as necessary for the stated purpose and as required by law | Revocable via device settings |
| Analytics / logs | Reliability, security, abuse prevention, product improvement | Legitimate interests / consent | Platform/device | Firebase/Google; analytics vendors | As long as necessary for the stated purpose and as required by law | — |
| Support / incident reports | Handle support requests, investigate incidents | Legitimate interests / legal obligation | Users/staff | Internal; support tooling | As long as necessary for the stated purpose and as required by law | — |
| Admin audit logs | Security, accountability, compliance | Legal obligation / legitimate interests | Platform | Internal only | As long as necessary for the stated purpose and as required by law | — |
| Cookies / web analytics | Website functionality and measurement | Consent / legitimate interests | Website/browser | web analytics vendors | As long as necessary for the stated purpose and as required by law | See Section 11 |
4. How we use personal information
We use personal information to: operate and secure the marketplace; verify provider identity, licences, insurance and eligibility on a point-in-time basis; match customers with providers; enable communication; bill providers for platform fees and company subscriptions; prevent fraud and abuse; provide support; comply with legal obligations; and improve the service. We do not sell personal information for money; whether any activity constitutes a "sale" or "sharing" under specific US state laws is governed by the laws applicable to your jurisdiction (see Section 8).
5. Security
We apply administrative, technical, and organizational safeguards designed to protect personal information, including:
- Payment data minimization: payment cards are tokenized by Stripe; KeyZup does not store full card numbers, only a card summary / Stripe token reference.
- Background data minimization: KeyZup stores background-check status/reference data only; it does not store background report contents.
- Document access controls: verification documents (identity, licences, insurance, business documents) are stored in Firebase Storage with owner/admin access only; administrators access them through short-lived signed URLs; there is no public access.
- Authentication managed through Firebase Authentication.
- Access controls, audit logging of administrative actions, and least-privilege practices.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
6. International data transfers
KeyZup launches initially in the United States (multi-state) and the app also supports Canada. Personal information may be processed in the United States and in locations where our infrastructure vendors operate. Cross-border transfer mechanisms and any required safeguards (for example, between Canada/Quebec and the United States) are applied as required by the laws applicable to your jurisdiction.
7. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, and port your personal information, and to opt out of certain processing. These rights are region-dependent and their scope, exceptions, and verification requirements vary by law, including:
- California (CCPA/CPRA)
- Other US state privacy laws
- General US
- Canada PIPEDA and Quebec Law 25
To exercise available rights, contact us as described in Section 13. We will verify requests before acting and respond within the timeframe required by applicable law.
8. "Sale"/"sharing" and opt-out (region-dependent)
Whether any data practice constitutes a "sale" or "sharing" of personal information, or "targeted advertising"/"profiling" under US state laws, and the corresponding opt-out and disclosure obligations, are governed by the laws applicable to your jurisdiction.
9. Deletion and its limitations
When you request deletion, we will delete or de-identify personal information where required and feasible. However, we may retain certain information where permitted or required, including for:
- Legal and regulatory obligations (e.g., financial/tax recordkeeping)
- Accounting for provider fees and company subscriptions (wallet/ledger/Stripe references)
- Fraud prevention and platform integrity
- Safety, trust, and dispute resolution
- Legal holds / litigation (see the Data Retention & Deletion Policy)
Retained data is limited to what is necessary for the stated purpose and is deleted or de-identified when the basis for retention expires. Deletion of data held by independent providers outside the platform is governed by those providers' own practices.
10. Children
KeyZup is not directed to children and is intended for adults (and, for providers, eligible working professionals). We do not knowingly collect personal information from children. Age thresholds and any parental-consent obligations apply as provided by the laws applicable to your jurisdiction. If we learn we have collected information from a child in violation of applicable law, we will take steps to delete it.
11. Cookies and web analytics
Our website may use cookies and similar technologies for functionality and measurement. The specific cookies, vendors, consent-banner requirements, and opt-out mechanisms apply as provided by the laws applicable to your jurisdiction. Where required, we will present a consent mechanism before setting non-essential cookies.
12. Vendors and service providers
We rely on the following infrastructure vendors to operate the platform:
- Firebase / Google — authentication, Firestore database, Firebase Storage, and Firebase Cloud Messaging (push).
- Stripe — payment card tokenization and billing of provider platform fees and company subscriptions.
- Apple App Store / Google Play — app distribution and related platform services.
Additional processors (e.g., a background-screening provider, analytics, support tooling) may be engaged; those relationships and disclosures are governed by this Policy and applicable law. We bind processors to appropriate confidentiality and data-protection terms.
13. Contact and requests
Privacy questions and rights requests: privacy@keyzup.com. We will acknowledge and handle requests in accordance with applicable law. Intake channels, verification steps, and response timelines follow applicable law.
14. Changes to this Policy
We may update this Policy. We will update the effective date and, for material changes, provide additional notice through the app and/or email. Continued use after the effective date constitutes acknowledgement, subject to any consent requirements under applicable law.
