Acceptable Use Policy
Effective Date: September 13, 2026
Last Updated: September 13, 2026
This Acceptable Use Policy (“AUP”) governs use of the GrantKey service (the “Service”) and is part of the GrantKey Terms of Service (grantkey.io/terms). Capitalized terms have the meanings given there. It applies to every Operator, and to every employee, contractor, cleaner, co-host, vendor, and other person an Operator allows to use or configure the Service.
Violating this AUP is a material breach. We may suspend or terminate the Service for a violation, in some cases without prior notice where the violation creates a risk of harm.
1. The Principle Behind This Policy
GrantKey discloses the location of a physical key. That makes misuse of the Service a physical-security problem, not just a terms problem. Every rule below follows from one idea: the Service may be used only to give a legitimate guest access to a property they are already entitled to enter, when the primary lock has failed.
2. Enrollment and Authority
You may not enroll a Property unless you:
- Own it, or manage it under a current agreement with the owner that permits you to configure backup access;
- Have the authority to disclose the backup key location and code for it; and
- Have confirmed that enrolling it does not violate any lease, mortgage, condominium or homeowners-association rule, insurance policy, or local short-term-rental ordinance.
You may not enroll a Property you do not control, a Property belonging to someone else without their authorization, or a residence occupied by a long-term tenant without that tenant’s knowledge and consent.
3. Prohibited Uses of the Service
You may not use the Service to:
Access and security
- Provide access to anyone who does not hold a current, valid reservation at the Property;
- Circumvent an eviction, a lockout of a tenant or occupant, a restraining or protective order, a law-enforcement action, or a dispute over who may enter a property;
- Enable entry to a property for the purpose of surveilling, harassing, intimidating, stalking, or confronting an occupant;
- Give yourself or a third party a covert or undisclosed means of entry to a property occupied by a guest, tenant, or owner;
- Disclose access information for any space a guest is not entitled to enter — an owner’s locked storage area, a neighboring unit, a shared building’s restricted areas;
- Serve as a property’s primary, sole, or advertised means of access, or as a replacement for working locks.
Emergencies and safety
- Present the Service to guests as an emergency, security, alarm, or urgent-response channel, or in any way that could cause a guest to text GrantKey instead of calling 911;
- Represent the Service as monitored by a person in real time, as a security system, or as a monitored alarm service.
Data and configuration
- Enter knowingly false, misleading, or placeholder Property configuration, or leave stale lock codes or keybox locations in place;
- Submit reservation or guest data you do not have the legal right to provide, or that you obtained in violation of a platform’s terms or of privacy law;
- Upload guest government identification numbers, payment card numbers, health information, or other sensitive personal information into any GrantKey field;
- Use guest information obtained through the Service for any purpose other than hosting that guest’s stay and meeting your own legal, tax, accounting, insurance, and dispute-resolution obligations;
- Use a real guest’s live reservation to test the Service. Onboarding tests and periodic verification tests are expected and permitted — use test reservations and test guest names that do not belong to a real guest.
Messaging
- Send, or configure the Service to send, any marketing, promotional, solicitation, survey, review-request, or upsell message to guests;
- Direct traffic to your GrantKey number from any source other than the Property’s own guest-facing materials — no advertising, listings, mass messaging, purchased lists, or public posting of the number as a general contact line;
- Use the assigned phone number for any purpose other than the Service, or represent it as your business’s general contact number;
- Do anything that would violate the Telephone Consumer Protection Act, carrier messaging rules, CTIA messaging principles, or applicable state telemarketing law.
Technical and commercial
- Access or attempt to access another Operator’s account, Properties, configuration, or data;
- Probe, scan, penetration-test, or attempt to defeat the verification logic, or submit deliberately false names or timing to test whether the check can be fooled, except with our prior written permission;
- Reverse engineer, copy, or attempt to extract the Service’s workflows, verification logic, or message templates;
- Resell, sublicense, white-label, or provide the Service to a third party, or use it for properties not covered by your Order Form;
- Use the Service to build or inform a competing product;
- Overload, disrupt, or interfere with the Service, our providers, or the carrier networks, including by automated or high-volume messaging;
- Introduce malicious code, or use the Service in connection with any unlawful activity.
4. Required Practices
You must:
- Rotate codes. Change a lockbox or keybox code within twenty-four (24) hours after it has been disclosed through the Service or before the next guest check-in at that Property, whichever is earlier, and in any event at least once every thirty (30) days for any Property that has had a reservation in the preceding thirty (30) days. This obligation applies whether or not you receive or read a disclosure notification from us. (This is the same obligation stated in Section 12(c) of the Terms of Service.)
- Site keyboxes sensibly. Place keyboxes where a disclosed location does not create an obvious security risk — not in plain public view, not on a street-facing door handle, not where a single photograph reveals both the box and the entry. These siting requirements control for purposes of Section 12(d) of the Terms of Service.
- Keep configuration current. Review Property configuration whenever you change a lock, keybox, code, fallback contact, or phone number, and immediately correct any error you discover.
- Keep a working primary access method and your own ability to help a guest the Service cannot serve.
- Keep the fallback contact reachable so escalated interactions get handled.
- Use approved placards and required disclosure language, kept legible and current, wherever the GrantKey number appears.
- Tell your guests in your check-in materials that the Service exists, what it is for, and that emergencies go to 911.
- Protect your account — unique credentials, no credential sharing, prompt removal of access for departed staff and vendors.
- Report problems — tell us promptly at [security@grantkey.io] if you suspect unauthorized access to your account, a wrongly disclosed code, a compromised keybox, or any access incident involving the Service.
- Supervise your people. You are responsible for everyone you give access to the Service, including cleaners, co-hosts, maintenance vendors, and virtual assistants.
5. Reporting Abuse
To report a violation of this AUP, a security concern, or suspected misuse of the Service — including by an Operator — contact:
[trust@grantkey.io] · (571) 406-4034
If you believe someone is in immediate danger, call 911 first.
We investigate credible reports. We may contact the Operator involved, request information, suspend affected Properties, or disable the Service for the account while we investigate.
6. Enforcement
Depending on the severity of a violation, we may: contact you to resolve it; require corrective action within a stated period; suspend one or more Properties or your whole account under Section 25(e) of the Terms of Service; terminate the Agreement under Section 25(b) of the Terms of Service; and, where we reasonably believe there is a credible risk to someone’s safety or that a crime has been committed, report the conduct to law enforcement and to the affected property owner.
We may act without prior notice where a violation creates an immediate risk of harm to a person, a property, another Operator, or our systems. Where we suspend without notice, we will tell you as soon as reasonably practicable and explain what is required to restore service. Suspension does not relieve you of the obligation to pay Fees for the suspended period unless we say otherwise in writing.
We have no obligation to monitor use of the Service, and our failure to enforce a provision of this AUP is not a waiver of our right to enforce it later.
7. Changes
We may update this AUP in accordance with Section 27(b) of the Terms of Service: any change that materially expands your obligations requires at least thirty (30) days’ notice, and other changes take effect when posted. The current version is always available at grantkey.io/aup.
GrantKey — a product of Bower & Kip Properties, LLC
866 Belvedere Boulevard, Charlottesville, VA 22901 · [legal@grantkey.io]
