Skip to main content
KKeyWe

Privacy

Last updated : 2026

Courtesy translation. The French version is the authoritative text.

Data controller

KeyWe — [legal form, registered office, trade register]. For any question about your data: bonjour@keywe.io.

What we process, and why

We only collect what serves the service. No data is ever sold or used for advertising.

Manage your account and dashboard

Data:
Name, email, phone, password (hashed)
Legal basis:
Performance of the contract (art. 6.1.b)
Retention:
For the life of the account, then anonymised on deletion

Handle drop-off, custody and handover of keyrings

Data:
Unit name, tag, drop-off point, pickup codes, recipient identity
Legal basis:
Performance of the contract (art. 6.1.b)
Retention:
Until account deletion; a recipient's identity is erased 30 days after a code is used, revoked or expired

Prove a keyring's chain of custody

Data:
Movement log: type, date, place, slot, tag scan
Legal basis:
Legitimate interest — being able to establish who held the keys, and when
Retention:
Kept without limit, but purged of all identity on account deletion

Notify you (drop-off, pickup, return, overdue)

Data:
Email, name, unit and drop-off-point reference
Legal basis:
Performance of the contract (art. 6.1.b)
Retention:
Notifications deleted with the account

Collect payments and keep accounts

Data:
Amount, date, transaction reference
Legal basis:
Legal obligation (art. 6.1.c) — art. L123-22 of the Commercial Code
Retention:
10 years, unlinked from any person after account deletion

Process « become a partner » applications

Data:
Shop and contact name, email, phone, address
Legal basis:
Pre-contractual steps (art. 6.1.b)
Retention:
3 years from last contact

Recipients of a code

When a host shares access, they pass us the name and email of the person concerned. This data is used only to send the pickup code and identify the handover at the counter. The recipient can request its erasure at any time at bonjour@keywe.io, without having an account with us.

Who else has access

Our technical providers, strictly for the use below, under a data-processing agreement (art. 28):

  • SupabaseDatabase and authentication hosting
  • VercelWebsite and server-side processing hosting
  • StripePayment collection (no banking data passes through KeyWe)
  • ResendDelivery of notification emails
  • OpenStreetMapDrop-off point map tiles — your IP address is sent to the tile server when the map is displayed
  • API Adresse (data.gouv.fr)Geocoding of drop-off-point addresses, called from our servers

The site's server processing runs in the Paris region. Some of these providers are established outside the European Union; transfers then rely on the European Commission's standard contractual clauses. The hosting region chosen for the database is [to be specified].

Cookies

KeyWe sets no advertising or analytics cookies. The only cookies used carry your login session: strictly necessary to the service, they are exempt from consent (art. 82 of the French Data Protection Act). That's why you don't see a banner on this site.

Security

Access to data is partitioned at the database level itself: every request is filtered by row-level security rules, so a host cannot reach another's keyrings. The movement log is technically tamper-proof, pickup codes expire, and API keys are stored only as a fingerprint.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability. Two of them are exercised directly from your dashboard, without writing to us:

  • Portability — export your history as CSV.
  • Erasure — delete your account yourself. Your identity is destroyed; the movement log and accounting entries are kept but made anonymous, which takes them outside the scope of the GDPR (recital 26).

Manage my data from my dashboard →

For the other rights, write to bonjour@keywe.io. You may also lodge a complaint with the CNIL.

The bracketed details remain to be completed by the publisher before going live.