GrantKey
HomeHow It WorksWho It's ForAboutContact
Get in touch

Privacy Policy

Effective Date: September 13, 2026
Last Updated: September 13, 2026

This Privacy Policy explains how Bower & Kip Properties, LLC, a Virginia limited liability company doing business as GrantKey (“GrantKey,” “we,” “us,” “our”), collects, uses, shares, and protects personal information.

It covers three groups of people:

  • Website visitors — anyone who visits grantkey.io.
  • Operators — property managers, hosts, and rental operators who subscribe to the GrantKey service (the “Service”).
  • Guests — people who text GrantKey because they cannot get into a rental property.

1. The Short Version

  • GrantKey exists to do one thing: when a guest can’t get into a short-term rental, GrantKey checks their reservation and tells them where the backup key is.
  • To do that, we receive the guest’s phone number, the name they give us, and reservation information (property, check-in and check-out times, guest name) from the operator’s booking system.
  • We do not sell personal information. We do not use it for advertising. We do not send marketing texts.
  • Mobile phone numbers and other mobile information are never shared with third parties or affiliates for marketing or promotional purposes.
  • For guest information, the operator decides what we do with it. We act on the operator’s instructions.
  • We keep guest text conversations only as long as needed to run and audit the service, then delete them.

2. Information We Collect

2.1 From Guests

When a guest texts the GrantKey number, we collect:

InformationSourceWhy
Mobile phone numberThe incoming text messageTo identify the conversation and reply
Name the guest providesThe guest, by textTo run the automated reservation check
Description of the problemThe guest, by textTo route the request correctly and keep an audit record. This is not an input to the verification check.
Message content, timestamps, and message IDsThe messaging carrier and our telephony providerTo operate the conversation, keep an audit record, and troubleshoot
Property the guest identifiesThe guest, by textTo match the request to the right property and operator

We do not ask guests for, and the Service is not designed to receive, government identification numbers, payment card numbers, dates of birth, precise geolocation, biometric data, or any special-category or sensitive personal information. Guests should not send that information to us. If a guest sends it anyway, we delete it when we identify it.

2.2 From Operators (including about their Guests)

We receive from operators, or from systems operators connect to us:

  • Operator business and contact information — business name, contact name, email, phone, billing address.
  • Property configuration — property names and aliases, backup key or lockbox location, lock codes, fallback contact name and phone number, and special instructions. The GrantKey phone number is assigned per operator, not per property.
  • Reservation data — guest names, check-in and check-out dates and times, and property assignment, drawn from the operator’s property-management system through calendar or iCal feeds.

Important: reservation data contains personal information about guests. Operators are responsible for having the right to share it with us and for giving guests any notice or obtaining any consent the law requires. See Section 7.

2.3 Payment Information

Subscription payments are processed by a third-party payment processor. We receive confirmation of payment and limited details such as the card brand and last four digits. We do not store full payment card numbers.

2.4 From Website Visitors

When you visit grantkey.io we may collect IP address, browser and device type, pages viewed, referring page, and approximate region, through server logs and analytics. If you submit a contact or signup form, we collect what you enter. See Section 10 for cookies.

2.5 Information We Do Not Collect

We do not collect precise location data. We do not use tracking pixels for advertising networks. We do not buy personal information from data brokers. We do not knowingly collect personal information from children under 13, and the Service is not directed to children; if we learn we have collected such information we will delete it.

3. How We Use Information

We use personal information to:

  1. Run the Service — receive a guest’s text, perform the automated reservation check, reply with backup key information or an escalation message, and notify the operator.
  2. Keep a key-release record — maintain logs of what was asked, what was decided, and what was sent, so an operator can review any access event. This is a security feature, not a marketing one.
  3. Support and troubleshoot — diagnose failures, correct configuration errors, and respond to operator requests.
  4. Bill and administer accounts — invoice operators, collect payment, and manage subscriptions.
  5. Secure the Service — detect and prevent fraud, abuse, unauthorized access, and misuse of key information.
  6. Improve the Service — analyze de-identified and aggregated usage patterns. We do not use guest message content to train generative AI models, and the reservation check itself does not use a generative AI model.
  7. Communicate with operators — send service, billing, security, and administrative messages. Operators may receive occasional product update emails and can opt out of the non-essential ones.
  8. Comply with law — meet legal, tax, accounting, and regulatory obligations and respond to lawful requests.

We never use guest phone numbers or guest information to market anything — ours or anyone else’s.

3.1 Legal Bases (where required)

Where data protection law requires a legal basis, we rely on: performance of a contract (providing the Service to operators); legitimate interests (security, fraud prevention, service improvement, audit records); legal obligation; and, where applicable, consent. For guest personal information, the operator determines the legal basis for its processing and we act as its processor.

4. How We Share Information

We share personal information only as described here.

4.1 With the Operator

We tell the operator about interactions at its own properties — that a guest texted, the name and number involved, what was requested, and how the Service resolved it. The operator needs this to manage its property and its guest.

4.2 With Service Providers (Subprocessors)

We use third-party providers to run the Service. They may process personal information only to provide services to us, under contract, and may not use it for their own purposes.

CategoryWhat it doesData involved
Telephony / SMS providerSends and receives text messagesPhone numbers, message content, delivery metadata
Workflow automation platformRuns the verification logic and message flowAll data in the conversation
Cloud spreadsheet & calendar servicesStore conversation state, property configuration, and synced reservation dataGuest names, phone numbers, reservation times, property configuration
Reservation data sync toolingMoves operator reservation feeds into per-property calendarsGuest names, reservation times
Payment processorProcesses subscription paymentsOperator billing information
Email providerSends operator and administrative emailOperator contact information
Website hostingServes grantkey.ioVisitor log data

A current list of named providers is available on request at [privacy@grantkey.io]. We will update this Policy or that list when we add a provider that materially changes how information is handled.

4.3 Mobile Carriers

Text messages travel over mobile carrier networks. Carriers handle message routing and delivery under their own practices, and messaging to short-code or long-code numbers may be subject to carrier review for compliance purposes. We do not share mobile information with carriers, third parties, or affiliates for marketing or promotional purposes.

4.4 Legal and Safety

We may disclose information where we reasonably believe it is required by law, subpoena, warrant, or court order; necessary to enforce our terms; or necessary to protect the rights, property, or safety of GrantKey, an operator, a guest, or the public — including in response to a credible report of unauthorized entry or a threat to someone’s safety. Where we are legally permitted, we will notify the affected operator.

4.5 Business Transfers

If GrantKey is involved in a merger, acquisition, reorganization, financing, or sale of assets — including a reorganization that moves the GrantKey business into a separate legal entity — personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with materially similar protections.

4.6 What We Never Do

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use personal information for profiling that produces legal or similarly significant effects. We have not sold or shared personal information for these purposes in the preceding twelve months.

5. How Long We Keep Information

DataRetention
Guest text conversations and message content90 days after the conversation closes, then deleted
Conversation state records (in-progress verifications)Deleted or overwritten shortly after the conversation resolves
Key-release logs (date, property, outcome, phone number)12 months, for operator review and security investigation
Reservation data synced from operator systemsRetained while the reservation is current and for 30 days after check-out
Property configuration, including lock codesWhile the property is enrolled; deleted within 30 days after the property is removed or the subscription ends
Operator account and billing recordsDuration of the relationship plus the period required by tax and accounting law (generally 7 years)
Website logs and analytics12 months

We may retain information longer where necessary to comply with law, resolve a dispute, or preserve evidence relating to a security or access incident, and we will limit retention to that purpose.

6. How We Protect Information

We maintain administrative, technical, and physical safeguards appropriate to the size of our operation and the sensitivity of the data. Specifically:

  • Data is encrypted in transit.
  • Multi-factor authentication is enabled on the provider accounts that hold service data.
  • Access is limited to the small number of people who need it, on a least-privilege basis.
  • We keep key-release logs — a record of each time backup key information was requested and released, so an operator can review an access event. This is a log of guest access events. It is not a log of our own staff’s access to data.
  • Property configuration, including lock codes, is stored in a hosted spreadsheet on a commercial cloud provider, protected by that provider’s access controls and our account controls.
  • We review configuration and third-party access when we make material changes to the service.

Two honest limitations. First, text messages are not encrypted end to end. A message containing backup key information can be read by anyone with access to the recipient’s phone, and message content passes through carrier systems. Second, no system is perfectly secure. We cannot guarantee the security of information transmitted to or from us.

If we become aware of a security breach affecting personal information, we will notify affected operators without undue delay and cooperate with them in meeting any notification obligations, and will make any notifications the law requires of us.

7. Roles: Who Decides What (Operators and Guests)

For guest personal information, the operator is the controller (or “business”) and GrantKey is the processor (or “service provider”). The operator decides which properties are enrolled, what reservation data reaches us, and what backup key information we disclose. We act on the operator’s instructions.

This means:

  • Guests with questions about their stay, their reservation, or why their information was shared should contact their operator or host first. The operator can also reach us on the guest’s behalf.
  • We will still handle a guest request directed to us — see Section 8 — and will route it to the operator where the operator is the right decision-maker.
  • Operators are responsible for their own privacy notices to guests, and for having the legal right to provide guest information to us.

For operator business and account information, and for website visitor information, GrantKey is the controller.

8. Your Privacy Rights

Depending on where you live, you may have the right to: know what personal information we hold about you and how we use it; get a copy of it; correct it; delete it; opt out of sale, targeted advertising, or certain profiling (we do none of these); and not be discriminated against for exercising these rights. Some jurisdictions also allow an authorized agent to make a request for you, and provide a right to appeal a denial.

To make a request, email [privacy@grantkey.io] with enough detail for us to locate your information — for guests, the phone number used to text GrantKey and the approximate date. We will verify your request using information already in our possession, and will not ask for more sensitive information than necessary to do so.

We will respond within the period the applicable law requires (generally 45 days, extendable once where permitted, with notice).

Guests: your operator decides. Because your host or property manager controls guest information in this service, we will normally refer a guest request to that operator and tell you that we have done so. That is the default, not the exception — the operator is the party that can actually grant or deny the request. We will still confirm to you what information we hold and will delete information we hold on our own behalf where we are able to.

Appeals. If we deny your request, you may appeal by replying to our decision with the word “Appeal” and your reasons. We will respond within 60 days. Virginia residents who are dissatisfied with the outcome may contact the Virginia Attorney General’s Office; residents of other states may contact their own attorney general.

Do Not Track and opt-out preference signals. We do not sell or share personal information for targeted advertising, so a browser opt-out signal has nothing to act on; we honor Global Privacy Control signals where we are required to.

9. Text Messages and Opt-Out

The GrantKey text service is guest-initiated — we message a guest only after that guest texts us first, and only in that conversation. We do not send promotional or marketing texts to guests, ever.

  • Reply STOP to any GrantKey message to stop receiving messages from that number. Replying STOP means we will not be able to help with a lockout at that property, so guests should contact their operator directly instead.
  • Reply HELP for information about the service and how to reach the operator.
  • Message and data rates may apply. Message frequency varies and depends on the conversation.

Full details are in our SMS Terms (grantkey.io/sms).

10. Cookies and Analytics

The Site uses cookies and similar technologies that are strictly necessary for it to function. If and when we deploy an analytics tool, it may set analytics cookies to help us understand traffic and improve the Site. We do not use advertising or cross-site tracking cookies. Where required, we will present a cookie notice and obtain consent for non-essential cookies. You can also control cookies through your browser settings, though disabling necessary cookies may break parts of the Site.

11. International Users

GrantKey operates in the United States and the Service is intended for properties and operators in the United States. Information we collect is stored and processed in the United States, where privacy laws may differ from those in your country. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

12. Changes to This Policy

We may update this Policy. We will change the “Last Updated” date and, for changes that materially affect how we handle personal information, give operators at least 30 days’ notice by email or through the Service before the change takes effect. The current version is always posted at grantkey.io.

13. Contact Us

Questions, requests, or complaints:

GrantKey — a product of Bower & Kip Properties, LLC
866 Belvedere Boulevard, Charlottesville, VA 22901
[privacy@grantkey.io] · (571) 406-4034

Guests: if your question is about your reservation or your stay, please contact your host or property manager first — they can resolve most questions faster than we can.

GrantKey

The digital doorman for short-term rentals. A Bower & Kip product.

GrantKey is operated by Bower & Kip Properties, LLC d/b/a GrantKey.
support@grantkey.io · (571) 406-4034

Site
HomeHow It WorksWho It's For
Company
AboutContactGet in touch
© 2026 GrantKey. A Bower & Kip product.
Terms · Privacy · SMS Terms · How texting works ·Acceptable Use