Data Processing Note
Last updated: August 6, 2026
Keyway is used by locksmiths (“Shops”) to store records about their own customers: names, phone numbers, emails, and vehicle details. This note explains, in plain language, how that data is handled. It’s aimed at Shops evaluating whether Keyway fits their own privacy obligations to their customers.
Who does what
Each Shop decides what customer information to collect and why, for its own business purposes, such as tracking a job and letting a customer check on it. In that sense, the Shop is the party responsible for that data. Keyway stores it and moves it (for example, to send an email) on the Shop’s behalf, and only on the Shop’s instructions, expressed through however Shop staff use the product.
What customer data Keyway stores
- Customer name, phone number and email, as entered by Shop staff.
- Vehicle details attached to a customer: VIN, year, make, model, plate and colour.
- Ticket history: job type, status, quoted and final totals, notes, and any photos attached to a job.
- A record of consent and delivery for any email sent about a ticket, kept so a Shop can show it obtained and honoured consent if ever asked.
Where it’s stored and who processes it
Customer data lives in the same Supabase-hosted database as the rest of a Shop’s account, isolated from every other Shop by database-enforced access rules keyed to each row’s Shop ID. It’s served by our application, hosted on Vercel. Emails about a ticket (for example, “your key is ready for pickup”) are sent through Resend. No customer data is sent to the Claude API; that integration is used only for the optional parts-catalog import feature and never touches customer records.
The customer status page
Each ticket has a private, hard-to-guess link a Shop can share with its customer. That page shows only the vehicle, the job’s status, and, once complete, pickup information. It requires no login and shows nothing beyond what the customer already gave the Shop themselves.
Deletion
A Shop can delete a customer’s record from within Keyway. If a Shop closes its account, its customer data is retained for a reasonable period in case of reactivation, then deleted, as described in our Privacy Policy.
Security incidents
If we become aware of a security incident affecting a Shop’s data, including its customer records, we’ll notify the affected Shop without undue delay so they can meet their own notification obligations to their customers.
Questions
If your Shop needs a formal data processing agreement for its own compliance purposes, or has questions about anything above, contact natearkell@gmail.com.