Privacy Policy
Effective Date: September 13, 2026
Last Updated: September 13, 2026
This Privacy Policy explains how Bower & Kip Properties, LLC, a Virginia limited liability company doing business as GrantKey (“GrantKey,” “we,” “us,” “our”), collects, uses, shares, and protects personal information.
It covers three groups of people:
- Website visitors — anyone who visits grantkey.io.
- Operators — property managers, hosts, and rental operators who subscribe to the GrantKey service (the “Service”).
- Guests — people who text GrantKey because they cannot get into a rental property.
1. The Short Version
- GrantKey exists to do one thing: when a guest can’t get into a short-term rental, GrantKey checks their reservation and tells them where the backup key is.
- To do that, we receive the guest’s phone number, the name they give us, and reservation information (property, check-in and check-out times, guest name) from the operator’s booking system.
- We do not sell personal information. We do not use it for advertising. We do not send marketing texts.
- Mobile phone numbers and other mobile information are never shared with third parties or affiliates for marketing or promotional purposes.
- For guest information, the operator decides what we do with it. We act on the operator’s instructions.
- We keep guest text conversations only as long as needed to run and audit the service, then delete them.
2. Information We Collect
2.1 From Guests
When a guest texts the GrantKey number, we collect:
| Information | Source | Why |
|---|---|---|
| Mobile phone number | The incoming text message | To identify the conversation and reply |
| Name the guest provides | The guest, by text | To run the automated reservation check |
| Description of the problem | The guest, by text | To route the request correctly and keep an audit record. This is not an input to the verification check. |
| Message content, timestamps, and message IDs | The messaging carrier and our telephony provider | To operate the conversation, keep an audit record, and troubleshoot |
| Property the guest identifies | The guest, by text | To match the request to the right property and operator |
We do not ask guests for, and the Service is not designed to receive, government identification numbers, payment card numbers, dates of birth, precise geolocation, biometric data, or any special-category or sensitive personal information. Guests should not send that information to us. If a guest sends it anyway, we delete it when we identify it.
2.2 From Operators (including about their Guests)
We receive from operators, or from systems operators connect to us:
- Operator business and contact information — business name, contact name, email, phone, billing address.
- Property configuration — property names and aliases, backup key or lockbox location, lock codes, fallback contact name and phone number, and special instructions. The GrantKey phone number is assigned per operator, not per property.
- Reservation data — guest names, check-in and check-out dates and times, and property assignment, drawn from the operator’s property-management system through calendar or iCal feeds.
Important: reservation data contains personal information about guests. Operators are responsible for having the right to share it with us and for giving guests any notice or obtaining any consent the law requires. See Section 7.
2.3 Payment Information
Subscription payments are processed by a third-party payment processor. We receive confirmation of payment and limited details such as the card brand and last four digits. We do not store full payment card numbers.
2.4 From Website Visitors
When you visit grantkey.io we may collect IP address, browser and device type, pages viewed, referring page, and approximate region, through server logs and analytics. If you submit a contact or signup form, we collect what you enter. See Section 10 for cookies.
2.5 Information We Do Not Collect
We do not collect precise location data. We do not use tracking pixels for advertising networks. We do not buy personal information from data brokers. We do not knowingly collect personal information from children under 13, and the Service is not directed to children; if we learn we have collected such information we will delete it.
3. How We Use Information
We use personal information to:
- Run the Service — receive a guest’s text, perform the automated reservation check, reply with backup key information or an escalation message, and notify the operator.
- Keep a key-release record — maintain logs of what was asked, what was decided, and what was sent, so an operator can review any access event. This is a security feature, not a marketing one.
- Support and troubleshoot — diagnose failures, correct configuration errors, and respond to operator requests.
- Bill and administer accounts — invoice operators, collect payment, and manage subscriptions.
- Secure the Service — detect and prevent fraud, abuse, unauthorized access, and misuse of key information.
- Improve the Service — analyze de-identified and aggregated usage patterns. We do not use guest message content to train generative AI models, and the reservation check itself does not use a generative AI model.
- Communicate with operators — send service, billing, security, and administrative messages. Operators may receive occasional product update emails and can opt out of the non-essential ones.
- Comply with law — meet legal, tax, accounting, and regulatory obligations and respond to lawful requests.
We never use guest phone numbers or guest information to market anything — ours or anyone else’s.
3.1 Legal Bases (where required)
Where data protection law requires a legal basis, we rely on: performance of a contract (providing the Service to operators); legitimate interests (security, fraud prevention, service improvement, audit records); legal obligation; and, where applicable, consent. For guest personal information, the operator determines the legal basis for its processing and we act as its processor.
4. How We Share Information
We share personal information only as described here.
4.1 With the Operator
We tell the operator about interactions at its own properties — that a guest texted, the name and number involved, what was requested, and how the Service resolved it. The operator needs this to manage its property and its guest.
4.2 With Service Providers (Subprocessors)
We use third-party providers to run the Service. They may process personal information only to provide services to us, under contract, and may not use it for their own purposes.
| Category | What it does | Data involved |
|---|---|---|
| Telephony / SMS provider | Sends and receives text messages | Phone numbers, message content, delivery metadata |
| Workflow automation platform | Runs the verification logic and message flow | All data in the conversation |
| Cloud spreadsheet & calendar services | Store conversation state, property configuration, and synced reservation data | Guest names, phone numbers, reservation times, property configuration |
| Reservation data sync tooling | Moves operator reservation feeds into per-property calendars | Guest names, reservation times |
| Payment processor | Processes subscription payments | Operator billing information |
| Email provider | Sends operator and administrative email | Operator contact information |
| Website hosting | Serves grantkey.io | Visitor log data |
A current list of named providers is available on request at [privacy@grantkey.io]. We will update this Policy or that list when we add a provider that materially changes how information is handled.
4.3 Mobile Carriers
Text messages travel over mobile carrier networks. Carriers handle message routing and delivery under their own practices, and messaging to short-code or long-code numbers may be subject to carrier review for compliance purposes. We do not share mobile information with carriers, third parties, or affiliates for marketing or promotional purposes.
4.4 Legal and Safety
We may disclose information where we reasonably believe it is required by law, subpoena, warrant, or court order; necessary to enforce our terms; or necessary to protect the rights, property, or safety of GrantKey, an operator, a guest, or the public — including in response to a credible report of unauthorized entry or a threat to someone’s safety. Where we are legally permitted, we will notify the affected operator.
4.5 Business Transfers
If GrantKey is involved in a merger, acquisition, reorganization, financing, or sale of assets — including a reorganization that moves the GrantKey business into a separate legal entity — personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with materially similar protections.
4.6 What We Never Do
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use personal information for profiling that produces legal or similarly significant effects. We have not sold or shared personal information for these purposes in the preceding twelve months.
5. How Long We Keep Information
| Data | Retention |
|---|---|
| Guest text conversations and message content | 90 days after the conversation closes, then deleted |
| Conversation state records (in-progress verifications) | Deleted or overwritten shortly after the conversation resolves |
| Key-release logs (date, property, outcome, phone number) | 12 months, for operator review and security investigation |
| Reservation data synced from operator systems | Retained while the reservation is current and for 30 days after check-out |
| Property configuration, including lock codes | While the property is enrolled; deleted within 30 days after the property is removed or the subscription ends |
| Operator account and billing records | Duration of the relationship plus the period required by tax and accounting law (generally 7 years) |
| Website logs and analytics | 12 months |
We may retain information longer where necessary to comply with law, resolve a dispute, or preserve evidence relating to a security or access incident, and we will limit retention to that purpose.
6. How We Protect Information
We maintain administrative, technical, and physical safeguards appropriate to the size of our operation and the sensitivity of the data. Specifically:
- Data is encrypted in transit.
- Multi-factor authentication is enabled on the provider accounts that hold service data.
- Access is limited to the small number of people who need it, on a least-privilege basis.
- We keep key-release logs — a record of each time backup key information was requested and released, so an operator can review an access event. This is a log of guest access events. It is not a log of our own staff’s access to data.
- Property configuration, including lock codes, is stored in a hosted spreadsheet on a commercial cloud provider, protected by that provider’s access controls and our account controls.
- We review configuration and third-party access when we make material changes to the service.
Two honest limitations. First, text messages are not encrypted end to end. A message containing backup key information can be read by anyone with access to the recipient’s phone, and message content passes through carrier systems. Second, no system is perfectly secure. We cannot guarantee the security of information transmitted to or from us.
If we become aware of a security breach affecting personal information, we will notify affected operators without undue delay and cooperate with them in meeting any notification obligations, and will make any notifications the law requires of us.
7. Roles: Who Decides What (Operators and Guests)
For guest personal information, the operator is the controller (or “business”) and GrantKey is the processor (or “service provider”). The operator decides which properties are enrolled, what reservation data reaches us, and what backup key information we disclose. We act on the operator’s instructions.
This means:
- Guests with questions about their stay, their reservation, or why their information was shared should contact their operator or host first. The operator can also reach us on the guest’s behalf.
- We will still handle a guest request directed to us — see Section 8 — and will route it to the operator where the operator is the right decision-maker.
- Operators are responsible for their own privacy notices to guests, and for having the legal right to provide guest information to us.
For operator business and account information, and for website visitor information, GrantKey is the controller.
8. Your Privacy Rights
Depending on where you live, you may have the right to: know what personal information we hold about you and how we use it; get a copy of it; correct it; delete it; opt out of sale, targeted advertising, or certain profiling (we do none of these); and not be discriminated against for exercising these rights. Some jurisdictions also allow an authorized agent to make a request for you, and provide a right to appeal a denial.
To make a request, email [privacy@grantkey.io] with enough detail for us to locate your information — for guests, the phone number used to text GrantKey and the approximate date. We will verify your request using information already in our possession, and will not ask for more sensitive information than necessary to do so.
We will respond within the period the applicable law requires (generally 45 days, extendable once where permitted, with notice).
Guests: your operator decides. Because your host or property manager controls guest information in this service, we will normally refer a guest request to that operator and tell you that we have done so. That is the default, not the exception — the operator is the party that can actually grant or deny the request. We will still confirm to you what information we hold and will delete information we hold on our own behalf where we are able to.
Appeals. If we deny your request, you may appeal by replying to our decision with the word “Appeal” and your reasons. We will respond within 60 days. Virginia residents who are dissatisfied with the outcome may contact the Virginia Attorney General’s Office; residents of other states may contact their own attorney general.
Do Not Track and opt-out preference signals. We do not sell or share personal information for targeted advertising, so a browser opt-out signal has nothing to act on; we honor Global Privacy Control signals where we are required to.
9. Text Messages and Opt-Out
The GrantKey text service is guest-initiated — we message a guest only after that guest texts us first, and only in that conversation. We do not send promotional or marketing texts to guests, ever.
- Reply STOP to any GrantKey message to stop receiving messages from that number. Replying STOP means we will not be able to help with a lockout at that property, so guests should contact their operator directly instead.
- Reply HELP for information about the service and how to reach the operator.
- Message and data rates may apply. Message frequency varies and depends on the conversation.
Full details are in our SMS Terms (grantkey.io/sms).
10. Cookies and Analytics
The Site uses cookies and similar technologies that are strictly necessary for it to function. If and when we deploy an analytics tool, it may set analytics cookies to help us understand traffic and improve the Site. We do not use advertising or cross-site tracking cookies. Where required, we will present a cookie notice and obtain consent for non-essential cookies. You can also control cookies through your browser settings, though disabling necessary cookies may break parts of the Site.
11. International Users
GrantKey operates in the United States and the Service is intended for properties and operators in the United States. Information we collect is stored and processed in the United States, where privacy laws may differ from those in your country. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.
12. Changes to This Policy
We may update this Policy. We will change the “Last Updated” date and, for changes that materially affect how we handle personal information, give operators at least 30 days’ notice by email or through the Service before the change takes effect. The current version is always posted at grantkey.io.
13. Contact Us
Questions, requests, or complaints:
GrantKey — a product of Bower & Kip Properties, LLC
866 Belvedere Boulevard, Charlottesville, VA 22901
[privacy@grantkey.io] · (571) 406-4034
Guests: if your question is about your reservation or your stay, please contact your host or property manager first — they can resolve most questions faster than we can.
