Privacy notice
Keywindow operates the Keywindow beta. Contact us at the contact address in your beta invitation.
What we collect
- Your SmartThings account identifier, access tokens, selected lock identifiers and lock labels.
- Compatibility diagnostics supplied by SmartThings, such as integration type, manufacturer and model identifiers, driver ID, hub ID, profile ID and capabilities.
- Your name, email address, listing settings and time zone when supplied by you or SmartThings.
- Guest or visitor names, optional recipient email addresses, access windows, encrypted PINs and the status of scheduled codes.
- Lock events reported by SmartThings, including keypad unlocks, code slots and unusual events.
- Technical logs needed to operate, secure and diagnose the service.
We only collect a guest, cleaner or visitor email address when you choose to send that person a door code. Door-code emails contain the PIN by design. Operational logs and owner failure alerts do not.
Why we use it
We process account and lock data to provide the service under our contract with you. We process security logs and limited operational data for our legitimate interests in keeping Keywindow reliable and preventing misuse. Where law requires consent, we ask for it separately.
SmartThings and other providers
Keywindow sends commands to and reads data from Samsung SmartThings at your request. Hosting and email providers process data for us under their own security and data-processing terms. The current list is on our subprocessors page.
Hosts and guest data
If you use Keywindow for a rental or business, you decide why guest and visitor data is entered. You are normally the controller for that data and Keywindow acts as your processor. Our data-processing terms apply.
Retention
We keep account data while your account is active. Expired schedules may be retained as history until you delete your account. Account deletion removes the account, schedules, events and stored lock records from the live database. Encrypted backups may retain deleted data for a limited operational recovery period.
Security
SmartThings tokens and stored PINs are encrypted at rest. Connections use HTTPS. Access is controlled by a signed, secure session cookie. No online service can eliminate every risk, so you must retain a backup method of entry during the beta.
Your choices and rights
You can turn notification types off, download an account export, disconnect SmartThings and delete your account from Settings. Depending on where you live, you may also have rights to access, correct, erase, restrict or object to processing, and to complain to the UK Information Commissioner or your local regulator.
Cookies
Keywindow uses only essential cookies for sign-in, security and your selected time zone. We do not currently use advertising or analytics cookies.
Changes
We will identify material changes in the app and ask you to accept revised terms where appropriate.