Privacy Policy

Last updated: August 6, 2026

This Privacy Policy describes how Keyway, operated as part of Ridge Systems (“we,” “us,” “our”), collects, uses and protects information when a business (“Shop”) and its staff use Keyway to run their locksmith shop. See our separate Data Processing Note for how we handle the customer data a Shop enters about its own customers.

1. Information we collect

We collect information in a few ways:

  • Account information: the email address and password you use to sign in (handled by Supabase Auth), your name, and your role within your Shop.
  • Shop information: your shop’s name, address, phone number, timezone, tax rate, and the parts, vendors, locations, job types and pricing you enter.
  • Customer and vehicle information you enter: names, phone numbers, emails and vehicle details for your own customers, which you control and which is covered in more detail in our Data Processing Note.
  • Usage information: standard server logs (timestamps, IP address, pages requested) generated by our hosting provider, Vercel. We do not currently use any third-party analytics or advertising tracking.

2. How we use it

We use the information above to:

  • Operate the Service, including authentication and keeping each Shop’s data separate from every other Shop’s.
  • Send transactional email through Resend: low-stock alerts, job-completion notices, user invitations, and account-related messages.
  • Provide support when you contact us.
  • Maintain the security and reliability of the Service.

3. Who we share it with

We don’t sell your information, and we never share one Shop’s data with another Shop. We share information with the service providers that run the infrastructure Keyway is built on, each acting under their own privacy and security commitments:

  • Supabase: hosts our database, handles authentication, and stores uploaded files (such as ticket photos).
  • Vercel: hosts and serves the application.
  • Resend: delivers the transactional emails described above.
  • Anthropic (Claude API): used only if you choose to use the optional “paste your spreadsheet” import feature. In that case, up to the first 20 rows of the data you paste are sent to Claude to suggest how your columns map onto Keyway’s fields. You always review and approve the suggested mapping before anything is imported, and the feature works without Claude too, using a built-in fallback, if that call fails or isn’t configured.

We may also disclose information if required by law, or in connection with a merger, acquisition or sale of assets, in which case we’ll give you notice where practical.

4. How we protect it

Every Shop’s data is isolated at the database level: every table that holds Shop data is tagged with that Shop’s ID, and row-level security policies enforced by the database itself, not just our application code, block any request from seeing another Shop’s rows. Data is encrypted in transit. Access to production data is limited, and we never use elevated database credentials in the code that serves your everyday requests.

5. Data retention

We retain your information for as long as your account is active. If you cancel, we retain your data for a reasonable period afterward in case you want to reactivate or export it, and then delete it, except where we’re required to keep records for legal or accounting reasons.

6. Cookies

We use a small number of essential cookies set by Supabase Auth to keep you signed in. We don’t use advertising or cross-site tracking cookies.

7. Your rights

You can access, correct or delete most of your account and Shop information directly within Keyway. For anything you can’t change yourself, or to request a full export or deletion of your account, contact us using the address below.

8. Children’s privacy

Keyway is business software intended for use by adults acting on behalf of a business. It’s not directed at, and we don’t knowingly collect information from, children.

9. Changes to this policy

We may update this policy from time to time. If we make a material change, we’ll give you reasonable notice, for example by email or an in-app notice, before it takes effect.

10. Contact

Questions about this policy, or requests about your information, can be sent to natearkell@gmail.com.