Punchy — Privacy Policy
Effective Date: July 16, 2026 Last Updated: July 16, 2026
This Privacy Policy explains how Novasoft LLC (“Novasoft,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the Punchy time-tracking service available at punchy.live, app.punchy.live, and related applications, kiosks, and APIs (collectively, the “Service”). It is incorporated into and forms part of our Terms of Service.
Plain English: Punchy is a lightweight tool for tracking when an adult casual helper (a cleaner, gardener, tutor, caregiver, etc.) punches in and out. This page tells you exactly what data we hold, why, who we share it with, how long we keep it, and the rights you have. We deliberately collect very little. We use a privacy-respecting analytics tool to count page visits and see which features get used — it sets no cookies, records no sessions or keystrokes, is never linked to your name or email, and never runs on the kiosk your workers use — and we don’t run advertising trackers or sell data.
Two kinds of people are described in this policy. A “Customer” is the account holder who signs up and uses Punchy. A “Tracked Individual” is a person (usually a worker) whose name and punch times a Customer enters into Punchy. Tracked Individuals do not have accounts. For a Tracked Individual’s data, the Customer decides what is collected and why — Novasoft acts as a service provider/processor carrying out the Customer’s instructions (see Section 12).
Data Collection Summary
| Data | Whose | Source | Purpose | Retention |
|---|---|---|---|---|
| Email address | Customer | Registration | Account, login, transactional email | Until account deletion |
| Password (stored only as a bcrypt hash) | Customer | Registration | Authentication | Until account deletion |
| Timezone | Customer | Profile (default America/Los_Angeles) |
Display/formatting | Until account deletion |
| Punch-notification preference | Customer | Profile | Send optional punch emails | Until account deletion |
| Worker name | Tracked Individual | Entered by Customer | Identify the worker on time logs | Until removed by Customer or account deletion |
| Kiosk PIN (stored only as a bcrypt hash) | Tracked Individual | Set by Customer | Gate the kiosk so each PIN unlocks only one person | Until removed by Customer or account deletion |
| Punch in/out timestamps | Tracked Individual | Kiosk or Customer entry | Time tracking | Until account deletion |
| Payment amounts & descriptions | Tracked Individual | Entered by Customer | Record pay the Customer logs | Until account deletion |
| Worker notes (free text) | Tracked Individual | Entered by Customer | Messages to/about the worker | Dismissed notes purged after 30 days; otherwise until account deletion |
| Verification / reset tokens (stored only as a keyed hash) | Customer | Generated by us | Email verification, password reset, account-deletion confirmation | 10–60 minutes, then purged |
| Terms-acceptance record (document versions, timestamp, IP address, browser user-agent) | Customer | Captured once when you accept the Terms at registration | Evidence of which Terms of Service / Privacy Policy versions you accepted (see Terms of Service §17) | Account life + up to 5 years after account deletion (legal-claims archive; see §6) |
| Email delivery status (delivered / bounced / spam-complaint, last-update time) | Customer | Reported by our email provider (AWS SES) | Stop sending to addresses that bounce or report spam (a spam complaint also turns off punch notifications) | Until account deletion |
| IP address | Customer/visitor | Sent with your requests | Bot/abuse prevention via Cloudflare Turnstile; web-server request logs; your terms-acceptance record (once, at registration) | Turnstile: processed at the moment of the request, not kept by us; server logs: up to 30 days (CloudWatch); terms-acceptance record: account life + up to 5 years after deletion (§6) |
| Browser local storage (login token, profile) | Customer | Set in your browser | Keep you signed in; remember your profile | Until you log out or clear your browser |
| Web-server request logs (IP address, browser user-agent, requested URL, time) | Customer/visitor | Generated automatically on every request | Security, abuse prevention, debugging | Up to 30 days (CloudWatch) |
| Usage analytics events (page viewed, feature action, browser/device type, approximate location at U.S.-state level) | Customer/visitor | Collected automatically in the app and on our website (never on the kiosk) | Understand sign-up conversion and usability; improve the product | ~12 months (analytics provider’s current retention schedule; see §6) |
| Application/security logs containing your email address | Customer | Server-side operations | Security, debugging, operations | Up to 30 days (CloudWatch) |
1. Introduction
Novasoft LLC is the entity responsible for the Service. This policy applies to personal information we process through the Service. It does not apply to third-party websites or services we link to, or to a Customer’s own handling of Tracked Individual data outside of Punchy.
If you do not agree with this policy, please do not use the Service.
2. Information We Collect
We collect only what we need to run a simple time-tracking tool.
(a) Information Customers provide.
- Account information: email address and a password (which we immediately convert to a bcrypt hash — we never store or log your plaintext password).
- Profile settings: your timezone and whether you want punch-notification emails.
(b) Information about Tracked Individuals (entered by the Customer).
- The name of each Tracked Individual.
- A kiosk PIN the Customer sets for each Tracked Individual, which we immediately convert to a bcrypt hash — we never store or log the plaintext PIN. The PIN gates the kiosk so that it unlocks only the one Tracked Individual it belongs to.
- Punch in/out timestamps (created at the kiosk or entered by the Customer).
- Payment records — amounts and optional descriptions the Customer chooses to log. Punchy does not process or take payments; these are simply figures the Customer records.
- Worker notes — free text the Customer writes to or about a Tracked Individual.
Plain English: When you add a worker, you give us their name. When they punch in/out, we store the time. Anything else (pay figures, notes) is optional text you choose to type. We never ask the worker for an email, phone number, address, ID, or photo.
(c) Information collected automatically.
- IP address. When you register, log in, request a password reset, or resend a verification email, your IP address is sent to Cloudflare Turnstile to confirm you are not a bot; Turnstile processes it at the moment of the request. Your IP address also appears in our web-server request logs (below) and, once, in your terms-acceptance record (below). We do not otherwise store your IP address.
- Terms-acceptance record. When you create an account, we record which versions of the Terms of Service and this Privacy Policy you accepted, the time of acceptance, and the IP address and browser user-agent of that request — a single snapshot per acceptance, kept as evidence of your acceptance (see Terms of Service §17) for the life of your account and, in a minimal legal-claims archive, for up to 5 years after account deletion (see Section 6).
- Email delivery status. Our email provider (AWS SES) tells us whether email we send you was delivered, bounced, or was reported as spam. We keep the latest status and its timestamp so we stop sending to addresses that can’t receive mail; a spam complaint also turns off punch notifications for the account.
- Browser local storage. After you log in, the Service stores a session token and a copy of your profile (email, timezone) in your browser’s
localStorage. These stay on your device. - Server logs. Like virtually every web service, our web server keeps standard request logs — the requesting IP address, browser user-agent, requested URL, and time — and our application logs may record your email address alongside security and operational events. We use these logs only for security, abuse prevention, and debugging, and they are deleted automatically on the schedule in Section 6. Logs do not contain your password or raw tokens.
- Usage analytics. We collect anonymous usage events — the page viewed, the type of action taken (for example, “worker added”), your browser/device type, and your approximate location at the U.S.-state level (derived from your IP address, which our analytics provider processes at the moment of the request and does not store — never precise or GPS location). These events carry a random identifier that is not linked to your account or email; we never call our analytics with your identity, never record what you type, and never capture screens or session recordings. The kiosk pages used by Tracked Individuals run no analytics at all. If your browser sends a Do Not Track or Global Privacy Control signal, analytics does not run for you.
(d) What we do NOT collect. We do not collect or process: Social Security or government ID numbers; payment-card or bank-account numbers; biometric identifiers; precise geolocation (the Service disables geolocation, camera, and microphone access via a Permissions-Policy); health information; advertising identifiers; or cross-site tracking data. We do not use Google Analytics, advertising trackers, or social-media tracking tools. Our own usage analytics (Section 2(c)) is anonymous by design: it never identifies you, never records sessions or keystrokes, and never runs on kiosk pages.
3. How We Use Your Information
We use personal information to:
- create and secure your account, and authenticate logins;
- provide the core time-tracking features;
- send transactional/operational email — verification, password reset, account-deletion confirmation, security alerts (for example, when your kiosk is locked after repeated failed PIN attempts), and (if enabled) punch notifications that include the worker’s name, the action, and the time;
- protect the Service against bots, abuse, and fraud, and enforce rate limits;
- maintain security, debug problems, and keep operational records;
- comply with legal obligations.
We do not use personal information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
4. Cookies & Tracking
Plain English: We don’t use cookies at all — not for analytics, not for advertising. Our analytics keeps one random, anonymous identifier in your browser’s
localStorage, and you can switch analytics off entirely with your browser’s Do Not Track or Global Privacy Control setting.
- Our own cookies: None. We keep you logged in using browser
localStorage(a session token and your profile), not cookies. - Analytics storage: our usage analytics (Section 2(c)) stores a random identifier in
localStorage— not a cookie — that is not linked to your account, is not shared with or readable by any other site, and cannot follow you across the web. We honor Do Not Track and Global Privacy Control: if your browser sends either signal, analytics does not run and nothing is stored. - Strictly necessary third-party: Cloudflare Turnstile, our anti-bot check, loads from Cloudflare on our registration, sign-in, forgot-password, and resend-verification pages. It sets no cookies; it stores a single strictly-necessary value (
cf.turnstile.u) in local storage on Cloudflare’s ownchallenges.cloudflare.comorigin to manage its bot-detection challenge — not on our site, and not for advertising or analytics. Cloudflare’s handling of the technical signals it processes for this check (IP address, user-agent, TLS fingerprint, and sitekey) is described in its Turnstile Privacy Addendum. This is essential security functionality. - No analytics or marketing cookies are used anywhere in the Service.
Because we use no advertising storage and our analytics is anonymous and cookie-free, there is no cookie-consent banner to manage — and the Do Not Track / Global Privacy Control signals give you a one-setting opt-out of analytics.
5. How We Share Information (Subprocessors)
We do not sell or “share” personal information (as those terms are defined under California law), and we do not disclose it for cross-context behavioral advertising. We disclose personal information only to:
| Recipient | Role | Data involved | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting (Elastic Beanstalk), database (RDS PostgreSQL), and email delivery (SES) | All stored data; outbound email contains recipient email and (for punch notifications) the worker’s name and punch time | United States (us-east-2) |
| Cloudflare | Anti-bot challenge (Turnstile) | The challenge token and your IP address at the moment of an auth request | Cloudflare global network |
| PostHog, Inc. | Usage analytics (Section 2(c)) | Anonymous usage events (page views, feature actions, browser/device type); your IP address is processed transiently to derive approximate (U.S.-state-level) location and then discarded — it is not stored with events | United States (event processing & storage); ingestion requests transit Cloudflare’s global edge network (a PostHog subprocessor under PostHog’s DPA) |
We may also disclose information when required by law, to enforce our Terms, to protect the rights, safety, or security of Novasoft, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy and will notify you as required by law).
We engage these providers as service providers/subprocessors under contracts that restrict their use of personal information to providing services to us: for AWS, the AWS Data Processing Addendum, which is incorporated into the AWS Service Terms and applies automatically to every AWS customer; for Cloudflare, the Cloudflare Data Processing Addendum, incorporated by reference into Cloudflare’s Self-Serve Subscription Agreement; and for PostHog, the PostHog Data Processing Agreement.
6. Data Retention & Deletion
- Account deletion (true erasure, one narrow exception). When you delete your account through the in-app flow and confirm via the emailed link, we permanently delete your account record and all associated data — every Tracked Individual, all punch and payment records (including entries previously soft-deleted), all worker notes, and all tokens — from our live database in a single cascading operation. The one exception: we keep a minimal copy of your terms-acceptance record (your email address, the document versions you accepted, the acceptance time, IP address, and browser user-agent) for up to 5 years after deletion, used solely to establish or defend legal claims (see Terms of Service §17), then deleted automatically.
- During normal use. Removing a worker deactivates them and deleting a time entry soft-deletes it (kept with a reason for accuracy/audit); such data remains until you delete the whole account.
- Automatic purges. Expired verification tokens are purged daily; short-lived request-deduplication records are purged hourly; dismissed worker notes are purged after 30 days.
- Backups. Deleted data may persist in encrypted disaster-recovery backups for up to 35 days before being overwritten on the normal backup cycle. Backups are not used for any other purpose.
- Logs. Web-server request logs (IP address, user-agent, requested URL, time) and application logs (which can include your email address) are retained in CloudWatch for up to 30 days.
- Analytics events. Anonymous usage-analytics events (Section 2(c)) are retained by our analytics provider (PostHog) under its current retention schedule — at the time of this policy, approximately 12 months — then deleted automatically. We review this setting periodically and will update this policy if it materially changes. These events contain no account identifiers, so they are not affected by — and cannot be traced back to — a deleted account.
Plain English: Delete your account and your data is genuinely gone from our live system right away; only routine encrypted backups may keep a copy for a short window before they cycle. The one thing we keep longer is a small receipt showing you accepted our Terms — for up to 5 years, in case there is ever a legal dispute — and then that goes too.
7. Your California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights regarding personal information we hold as a business (primarily Customer account data):
- Right to Know / Access — request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to Delete — request deletion of your personal information (the in-app account-deletion flow accomplishes this directly, subject to the narrow legal-claims retention of your terms-acceptance record described in Section 6).
- Right to Correct — request correction of inaccurate personal information (you can edit your timezone and notification settings in-app; to correct the email address on your account, contact privacy@punchy.live).
- Right to Opt Out of Sale/Sharing — we do not sell or share personal information, so there is nothing to opt out of; we provide this disclosure for transparency.
- Right to Limit Use of Sensitive Personal Information — we do not collect sensitive personal information, so this right is not triggered.
- Right to Non-Discrimination — we will not discriminate against you for exercising any of these rights.
Categories collected (CCPA §1798.140(v)): identifiers (email, worker name); professional/employment-related information (punch times and pay figures a Customer logs about a worker); and internet/electronic network activity (IP address and browser user-agent — held in short-lived web-server logs and in your one-time terms-acceptance record — browser local storage, and anonymous usage-analytics events as described in Section 2(c)). We have not sold or shared any of these categories and do not collect sensitive personal information.
How to exercise. Use the in-app controls, or email privacy@punchy.live. We will verify your request through your account credentials and respond within the timeframes required by law (generally 45 days). You may use an authorized agent. If we decline a request, you may appeal by replying to our response.
8. Users Outside the United States
The Service is operated from the United States and is intended for users in the United States only. We do not target, market to, or offer the Service to individuals outside the United States, and we do not monitor the behavior of individuals located outside the United States.
The Service is for users in the United States only; please do not use it from outside the United States.
9. Data Security
We use technical and organizational measures appropriate to the limited data we hold, including:
- Passwords stored only as bcrypt hashes; plaintext passwords are never stored or logged.
- Email/verification tokens stored only as keyed (HMAC-SHA-256) hashes, so a database leak alone cannot reproduce a working link.
- Stateless authentication using signed (HMAC-SHA-256) JSON Web Tokens with a short (1-hour) lifetime.
- Encryption in transit (HTTPS/TLS) with HSTS, plus a strict Content-Security-Policy,
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, aReferrer-Policy, and aPermissions-Policythat disables camera, microphone, and geolocation. - Anti-bot protection (Cloudflare Turnstile) and per-account rate limiting on sensitive actions.
- Data hosted in AWS (
us-east-2) with managed database backups.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Important: your kiosk URL is an unauthenticated link, and the kiosk is gated by a per-person PIN that you set. Opening the URL alone does not reveal your Tracked Individuals’ names; a valid PIN unlocks only the one person it belongs to. PINs are stored only as salted hashes (never in plaintext). Keep the kiosk URL and every PIN private, rotate the URL if it may have been exposed, and reset a PIN if it may have been shared too widely.
10. International Data Transfers
We store and process personal information in the United States (AWS us-east-2). Two kinds of transient traffic — Cloudflare Turnstile anti-bot challenges (Section 4) and analytics event delivery, which reaches PostHog through a Cloudflare-operated proxy (Section 5) — may transit Cloudflare’s global edge network, whose locations are dynamically assigned; no data is stored there. The Service is intended for US users only (see Section 8). If you nonetheless access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction.
11. Children’s Privacy and Minors
The Service is for adults only. Customers must be at least 18 years old to hold an account (see Terms of Service §1.1), and Customers must not add any person under 18 years old as a Tracked Individual. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18 — whether a Customer or a Tracked Individual.
If we learn that we have collected the personal information of a person under 18, we will delete it. To report such data, contact privacy@punchy.live.
12. Data of Tracked Individuals
Tracked Individuals’ data is provided by, and controlled by, the Customer. For that data, Novasoft acts as a service provider/processor and processes it only to provide the Service to the Customer and on the Customer’s instructions; we do not use it for our own purposes (other than de-identified, aggregated analytics as described in our Terms).
If you are a Tracked Individual and want to access, correct, or delete information about you in Punchy, please contact the Customer who tracks you (they control the record), or contact us at privacy@punchy.live and we will assist and route your request to the responsible Customer as appropriate. The Customer is responsible for providing any notices to, and obtaining any consents from, the Tracked Individuals they add (see Terms of Service §6).
13. Changes to This Policy & Contact
Changes. We may update this policy by posting a revised version at punchy.live/privacy and updating the “Last Updated” date. We will provide additional notice (by email or in-product) of material changes when reasonably practicable.
Contact.
- Privacy requests and questions: privacy@punchy.live
- General support: support@punchy.live
- Legal notices: legal@punchy.live (Novasoft LLC)