Welcome to PunchIn ("PunchIn," "we," "our," or "us"). PunchIn operates as a software-as-a-service ("SaaS") platform that provides recording studio owners with booking management, scheduling, payment processing, and calendar synchronization tools (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at punchin.studio, use our dashboard, or interact with our booking pages as an end-client.
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by the terms described herein. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
1. Information We Collect
We collect information that you provide directly to us, information that is generated automatically when you use the Service, and information from third-party services you choose to connect. The types of information we collect depend on how you interact with PunchIn.
A. Information You Provide Directly
Throughout this policy and our Terms of Service, we refer to three categories of users: "Studio Owners" are the account holders who register a studio on PunchIn; "Team Members" are managers or staff added to a studio account by the Studio Owner; and "Booking Clients" are end-users who book recording sessions through a studio's public booking page. Collectively, all users are referred to as "you" or "users."
Studio Owners & Team Members
- Email address and password (or Google OAuth credentials)
- Studio name, URL slug, description, and branding assets (logo, brand color, portal theme)
- Studio physical address (street address, city, state, ZIP code)
- Engineer/staff details: names, email addresses, phone numbers, bios, photos, and Instagram handles
- Room details: names, descriptions, photos, gear lists, capacity, and hourly rates
- Pricing rules, deposit percentages, and booking policies (lead time, cancellation, rescheduling, smoking policy)
- Notification preferences and scheduling configuration
Booking Clients
- Full name
- Email address
- Phone number (optional)
- Booking notes (optional, e.g. equipment needs or session preferences)
Calendar Export Data
- When a Booking Client adds a confirmed session to their personal calendar (via an ICS file download or Google Calendar link), the exported event contains the studio name, room name, session date and time, studio address, and any booking notes the client provided. This data is packaged for the client's convenience and transmitted to the client's chosen calendar application — PunchIn does not control or access the client's personal calendar.
B. Information Collected Automatically
When you use the Service, we automatically collect certain technical and usage information, including:
- IP Address: Your Internet Protocol address is captured when you submit a booking, and is used for fraud prevention, chargeback evidence, and enforcement of banned client restrictions. It is also recorded in three other places: on the rate-limiting counters described below; alongside your acceptance of our Terms of Service, as evidence of when and from where that acceptance was given; and, for PunchIn administrators only, in the administrative audit log described in the Security section, so that a privileged action can be traced to the person and machine that took it.
- Device & Browser Information: We may collect information about the device and browser you use to access the Service, including device type, operating system, and browser type, as transmitted through standard HTTP headers.
- Usage Data: We collect information about how you interact with the Service, such as pages visited, features used, and the dates and times of your visits.
- First-Party Product Analytics: We record a small, fixed set of events — page views, and steps through signup, checkout and studio setup — so we can see where the product is failing people. Each event carries the page path, the referring page, any campaign tags in the link you arrived through, and a session identifier. That identifier is created in your browser, is kept only for the current tab, and is destroyed when you close it: it links the pages of a single visit together and cannot follow you between visits or between websites. We do not record your IP address or your browser's user agent against these events, we do not use a cookie for them, and none of this is shared with any third party — the events are stored in our own database, not sent to an analytics company.
- Rate Limiting & Bot Protection: Booking, payment and team-invitation endpoints are rate limited by PunchIn itself, using counters stored in our own database and keyed on IP address (and, for bookings, on the email address supplied). Sign-in, sign-up and password-reset requests go directly from your browser to Supabase, our authentication provider, and are rate limited by Supabase rather than by us. Public booking submissions are protected by Cloudflare Turnstile, a CAPTCHA alternative that verifies you're not a bot; see Cloudflare's Privacy Policy.
- Email Delivery Events: Our email provider reports back what happened to each message we send you, and we record it. This includes your email address, the message subject, whether the message was delivered, delayed, rejected by your mail server (a “bounce”) and the reason given, and whether the message was reported as spam. We use this to detect and fix mail we are failing to deliver — without it, a booking confirmation can fail silently and nobody finds out. We do not track whether you opened a message or clicked a link in it; open and click tracking are switched off.
- Unsubscribe Records: If you opt out of a category of notification email, we store your email address together with the category you opted out of, so that we can honour it. Reporting one of our messages as spam is treated as an opt-out from every optional notification category, and is recorded the same way.
- Terms Acceptance Records: When you accept our Terms of Service — as a Studio Owner in the dashboard, or as a Booking Client by ticking the box at checkout — we record that you accepted, when, which version you accepted, and the IP address it came from. We keep this because “did this person agree, and to what text” is the question that matters if a booking or a payment is later disputed, and a bare timestamp cannot answer it.
- Refund and Dispute Records: Where a booking is refunded, is owed a refund, or is disputed with a card issuer, we record the operational history alongside it — when a refund became due, when we reminded the studio, whether it was escalated, whether an administrator issued it, the payment processor's dispute identifier, whether evidence was submitted, and the outcome. This is what lets us tell whether a studio is honouring its own refund policy.
C. Information From Third-Party Services
- Google Sign-In (OAuth): If you sign in or sign up with Google, we request only the openid, email, and profile scopes, and receive your email address and basic profile information (such as your name and profile picture). We do not receive or store your Google password. This sign-in authorization is entirely separate from the Google Calendar integration below and grants PunchIn no access to your calendar or any other Google data.
- Google Calendar: If you separately choose to connect your Google Calendar, we request only the narrow scopes each feature needs — calendar.events (create, update and remove the booking events we place on your calendar, and receive change notifications), calendar.calendarlist.readonly (list your calendars so you can choose which one each room and engineer uses), calendar.freebusy (read busy/free times so we do not offer clashing slots), calendar.calendars (create a new calendar when you ask us to), and userinfo.email (identify the connected account). We do not request the broad Google Calendar scope, so we cannot change sharing permissions or delete your calendars. We store the OAuth refresh token to maintain the connection. This is a distinct authorization from Google Sign-In and can be granted or revoked independently.
- Events imported from a connected Google Calendar: When you assign one of your calendars to a room or engineer, PunchIn imports upcoming events on that calendar that it did not itself create, so your existing commitments appear in your Bookings and block out those times. For each imported event we store its title, start and end time, and the email address of the event's creator or organiser as recorded by Google. Imported events are labelled as manual imports, no payment is associated with them, and we never send any email to the people named on them — no confirmations, no session reminders, no cancellation notices. Only you and your studio's managers are notified, to let you know an import happened. Removing an imported booking from PunchIn deletes only our copy; the event on your Google Calendar is left untouched.
- Stripe: When payments are processed, Stripe provides us with transaction identifiers (payment intent IDs, customer IDs, subscription IDs). We do not receive, process, or store full credit card numbers, CVVs, or other raw payment credentials. All payment data is handled directly by Stripe.
2. Our Role: Controller and Processor
PunchIn handles two different kinds of personal data, and our legal role differs between them. Which one applies to you depends on how you use the Service.
- Booking Client data — the studio is the controller, PunchIn is the processor. When you book a session, the studio you booked with decides why and how your information is used. PunchIn processes it on that studio's behalf in order to run the booking. If you want your data corrected or deleted, the studio is the right first point of contact; we will assist them, and you can also contact us and we will route your request.
- Account and platform data — PunchIn is the controller. Studio Owner and team accounts, subscription and billing records, security and audit logs, and aggregated usage statistics are data we determine the purposes of ourselves, in order to operate, secure and improve the Service.
The terms governing our processing on a studio's behalf — including our obligations, sub-processor commitments, international transfer terms, and audit rights — are set out in the Data Processing Agreement at section 11 of our Terms of Service. Studio Owners accept that DPA by accepting the Terms; no separate signature is required.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: To create and manage accounts, process bookings, synchronize calendars, facilitate payments, and deliver the core scheduling platform.
- Communications: To send booking confirmations, cancellation and refund notices, shift assignment notifications, subscription reminders, client session reminders sent a configurable number of hours before a booked session, and other transactional emails necessary to operate the Service. Most email notifications are configurable per studio through notification preferences. Booking confirmations and essential financial notices such as refund confirmations are not: a client who has paid always receives a receipt.
- Fraud Prevention & Platform Integrity: To detect and prevent fraudulent transactions, enforce banned client restrictions, log blocked booking attempts, submit dispute evidence to payment processors, and protect studios from chargebacks. This includes matching bookings against banned client lists by email, phone number, and IP address.
- Payment Processing: To process subscription payments, booking deposits, and refunds through our payment processor (Stripe).
- Platform Monitoring & Administration: To monitor platform health, review disputes, track subscription activity, and respond to fraud. PunchIn administrators receive automated alerts and daily summaries that may include aggregated booking metrics, dispute details, subscription events, and banned client activity. Administrative actions (such as granting or revoking subscriptions) are logged with the administrator's identity and a timestamp for audit purposes.
- Studio Policy Transparency: Studio-configured booking policies (deposit percentage, cancellation window, late cancellation fee, minimum booking duration, rescheduling availability) are displayed to Booking Clients on the studio's public booking page so clients can make informed decisions before booking.
- Security: To authenticate sessions, enforce rate limiting on booking, payment and invitation endpoints, and enforce row-level access controls on data.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes, and to respond to lawful requests from public authorities.
4. How We Share Your Information
We do not sell your personal information. We share your information only in the following circumstances:
- Between Studios and Booking Clients: When a Booking Client reserves a session, their name, email, phone number (if provided), and booking notes are shared with the studio where they booked. Studio information (name, address, room details, engineer names) is displayed on public booking pages.
- Replies to Booking Emails Go to the Studio: Booking confirmations, session reminders, cancellation notices, and engineer shift notifications are sent by PunchIn but carry a Reply-To address belonging to the studio you booked with. If you reply to one of these emails, your reply — including your email address and anything you write — is delivered directly to that studio, not to PunchIn. The address used is the studio's published contact address, or, where the studio has not set one, the email address of the studio's account owner. Studio owners should be aware that this address is disclosed to every Booking Client and engineer who receives one of these emails, and that we are not a party to the resulting correspondence. Emails about your PunchIn account itself — sign-in codes, password resets, security alerts, and billing notices — instead reply to PunchIn support.
- Service Providers (Sub-processors): We share information with third-party service providers who process it on our behalf. Each one, the purpose it serves, and the categories of data it receives are listed in the sub-processor table immediately below.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
- Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business, your personal information may be transferred.
Sub-processors
The following third parties process personal data on our behalf in order to deliver the Service. Each is bound by data protection terms no less protective than those we commit to in the Data Processing Agreement at section 11 of our Terms of Service. All are located in the United States, and data processed through the Service is stored and processed there.
| Sub-processor | Purpose | Data it receives |
|---|
Supabase, Inc. Privacy Policy | Database, authentication and file storage — the primary store for all Service data | All account, studio, booking and Booking Client data; uploaded images |
Vercel, Inc. Privacy Policy | Application hosting and content delivery | Data in transit through the application; IP addresses and request metadata in server logs |
Stripe, Inc. Privacy Policy | Deposit and subscription payments, payouts to studios, and dispute management | Booking Client name, email, IP address, booking details and deposit amounts; Studio Owner billing and payout details |
Resend, Inc. Privacy Policy | Transactional email delivery and delivery-event reporting | Recipient email address, message subject and content, and delivery outcome (delivered, delayed, bounced, marked as spam) |
Google LLC Privacy Policy | Calendar synchronisation, and sign-in for Studio Owners who choose Google OAuth | Calendar events written to a connected calendar (client name, session times, room name); OAuth account identity and email address |
Cloudflare, Inc. Privacy Policy | DNS and network infrastructure; Turnstile bot verification on public booking submissions | IP address and the Turnstile verification token at the moment a booking is submitted |
Changes to this list. Before we add or replace a sub-processor that will process Booking Client personal data, we will update this table and notify Studio Owners by email at least thirty (30) days in advance. Studio Owners may object on data protection grounds during that period; the process, and the right to terminate without penalty if we cannot resolve an objection, is set out in section 11.D of the Terms of Service.
5. Google API Services — Limited Use Disclosure
PunchIn's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request only the minimum Google scopes each feature needs, and each is a separate authorization handled by a separate Google Cloud project: Google Sign-In requests the openid, email, and profile scopes to authenticate you and identify your account; Google Calendar requests four granular Calendar scopes (calendar.events, calendar.calendarlist.readonly, calendar.freebusy, calendar.calendars) plus your account email, to provide two-way calendar synchronization and identify the connected calendar account. We do not request the broad Calendar scope. Signing in with Google never grants access to your calendar, and connecting your calendar is never done automatically at sign-in.
- We do not use Google user data for advertising purposes.
- We do not allow humans to read your Google data unless: (a) we have your express consent, (b) it is necessary for security purposes (e.g., investigating abuse), or (c) it is required by law.
- You may revoke our access to your Google Calendar data at any time by unlinking your Google account from the PunchIn dashboard or by revoking access through your Google Account permissions.
6. Fraud Prevention & Client Restrictions
To protect studios from fraudulent transactions and payment disputes, we maintain a banned client system. The following data practices apply:
- Automatic Banning: When a payment dispute (chargeback) is filed against a booking, the client associated with that booking is automatically added to the studio's banned client list. The banned record includes the client's name, email, phone number, and IP address from the original booking.
- Booking Restrictions: When a banned client attempts to make a new booking, we match against the banned list using email address, phone number, and IP address. If a match is found, the booking is blocked, and the attempt is logged (including the name, email, phone, and IP used in the attempt).
- Dispute Evidence: In the event of a payment dispute, we automatically compile an evidence packet for the studio — which may include the client's name, email address, IP address, the record of their acceptance of our Terms of Service, a description of the service provided, and the session date. A PunchIn administrator reviews that packet before it is submitted to Stripe; it is not filed automatically.
- Studio Control: Studio owners retain full control over their banned client list and may reinstate or manually ban clients at their discretion.
This is an automated decision, and you can contest it. The ban that follows a chargeback is applied by software, with no person reviewing it first, and its effect is that you can no longer book with that studio. We are telling you this plainly because a decision made by a machine that stops you transacting is exactly the kind you should be able to challenge. A ban applies only to the studio where the disputed booking was made — it is not shared with other studios and does not follow you across the platform. If you believe a ban is wrong, contact the studio, which can reinstate you at any time, or write to privacy@punchin.studio and we will review the record and refer it to the studio. If the dispute is later resolved in the studio's favour, the booking is restored and the ban is lifted automatically; if the dispute is lost, the ban remains until the studio reinstates you.
7. Data Retention
We retain your personal information for as long as your account is active. We want to be precise about which of the periods below are enforced automatically and which are not, because privacy policies routinely blur the two.
A daily job deletes the operational logs marked purged automatically below once they pass their retention window. Everything else — your account, your studio, your bookings and your Booking Clients' details — is removed when you delete your studio or your account, or when you ask us to and we are not required to keep it. There is no timer that erases your studio's own records for you, and we would rather say so than let you assume otherwise.
- Account Data: Retained for as long as your account exists. Deleting your account removes it, subject to the exceptions below. If you stop using the Service without deleting your account, your data remains until you delete it or ask us to.
- Booking Records: Retained for as long as the studio they belong to exists. Deleting a studio deletes its bookings and the Booking Client information within them immediately — we do not hold them back for a retention period. If you need booking records for tax or financial compliance, export them before deleting, because we cannot recover them afterwards. Stripe separately retains its own transaction records under its own policy, and those are not removed by deleting your studio.
- Banned Client Records: Retained for as long as the studio account is active to enforce booking restrictions and support future dispute evidence.
- Google Calendar Tokens: OAuth refresh tokens are deleted when you unlink your Google Calendar from the dashboard or when your account is terminated.
- Administrative Audit Logs: Records of administrative actions (e.g., granting subscriptions, account impersonation) are retained indefinitely for security and compliance purposes.
- Payment Data: Transaction identifiers (Stripe payment intent IDs, customer IDs) are retained as part of booking records. Full payment details are retained by Stripe in accordance with their own retention policies.
- Email Delivery Events: Bounce, delivery-failure and spam-report records are purged automatically after 90 days, and are used only to diagnose delivery problems. Our email provider retains its own copy under its own policy.
- Blocked Booking Attempts: Records of a banned client's attempt to book again are purged automatically after 12 months — long enough to show a studio a pattern, not indefinite.
- Expired Team Invitations: An invitation that was never accepted expires and can no longer be used. Twelve months after it expires it is purged automatically, since by then it is only an email address with nothing attached to it.
- Session Reminder and Webhook Ledgers: Internal markers that stop us sending a reminder twice or processing a payment event twice are purged automatically after 90 days. They contain no contact details.
- Product Analytics Events: Retained while they are useful for understanding how the product is used. They carry no name, email address, IP address or user agent, and their session identifier expires with your browser tab, so they cannot be traced back to you afterwards.
- Unsubscribe Records: Retained indefinitely, and deliberately so. An opt-out is only meaningful if it outlives the account, booking or mailing list that prompted it — deleting the record would cause us to start emailing you again.
Deleting Your Account or Studio
You can permanently delete your account at any time from your account settings in the PunchIn dashboard. Deleting your account removes your authentication credentials (email address, password hash, and any connected Google sign-in identity) and your team memberships in other studios. Deletion is immediate and irreversible.
If you own one or more studios, you must delete each studio first (from Studio Config → Danger Zone) before your account can be deleted. Deleting a studio permanently removes the data belonging to that studio, including its rooms, engineers, on-call shifts, bookings and the Booking Client information contained within them, calendar connections and stored OAuth tokens, banned-client records, and pending team invitations. Any active subscription for that studio is cancelled immediately as part of deletion, and PunchIn's access to your connected Google Calendar is revoked at Google — not merely disconnected on our side. If Google is unreachable at that moment the deletion still goes ahead, and the failure raises an alert for us to follow up rather than passing silently. You can always confirm and remove our access yourself from your Google Account permissions.
Deletion is comprehensive but not unlimited. To the extent permitted or required by law, we retain certain records after you delete your account or studio, including: transaction and payout records held by Stripe; administrative audit logs; and information we are required to keep for tax, accounting, fraud-prevention, or dispute-resolution purposes. Residual copies may persist in encrypted backups for a limited period before being routinely overwritten. Team invitations addressed to your email address are retained while they are still valid, so that you may accept them if you create a new account later; the inviting studio owner can cancel one at any time, and an invitation that has been expired for twelve months is deleted automatically.
8. Data Security
We implement commercially reasonable administrative, technical, and physical security measures to protect your personal information, including:
- Encryption of data in transit via TLS/SSL across all connections
- Encryption of data at rest within our database infrastructure
- Row-level security (RLS) policies that ensure studio data is only accessible to authorized account holders
- Service role key separation between client-facing and administrative database operations
- Rate limiting on booking, payment and invitation endpoints to prevent automated abuse; authentication requests are rate limited by Supabase, our authentication provider
- Optional two-factor authentication (TOTP) for Account Holders, enrolled from Security & 2FA in the dashboard
- Secure storage of third-party OAuth tokens and API credentials, revoked with Google when you unlink your calendar
- Administrative action audit logging with user identity, timestamp, and action details
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
If there is a breach. If we discover a breach of security affecting your personal information, we will notify you and any regulator we are required to notify, without unreasonable delay and within the timeframes applicable law sets. Where the affected data belongs to a studio's Booking Clients, we notify that studio, because it is the controller of that data and the party responsible for notifying the individuals — and we will help it do so.
9. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. These may include:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Rectification: You may request that we correct any inaccurate or incomplete information.
- Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions (e.g., data we are required to retain for financial compliance).
- Right to Data Portability: You may request a copy of your data in a structured, commonly used, machine-readable format.
- Right to Withdraw Consent: Where processing is based on consent (e.g., Google Calendar integration), you may withdraw consent at any time by unlinking the integration from your dashboard or by contacting us.
- Right to Opt Out: Every optional notification email we send carries an unsubscribe link in its footer, and a one-click unsubscribe control that most mail applications display next to the sender's name. Either one takes effect immediately and needs no account, no login and no reply. Studio Owners can additionally adjust notification categories in the studio dashboard. Reporting one of our messages as spam also opts you out of every optional category. Essential messages — booking confirmations, sign-in codes, password resets, security alerts, and billing or refund notices — are sent because you or your studio took an action that requires them, and cannot be switched off by anyone while the underlying account or booking is active; if you pay a deposit, you always get a confirmation. Two client-facing messages sit in between: cancellation notices and session reminders are on by default but each studio can turn them off for its own clients, so whether you receive those is the studio's decision rather than ours or yours.
To exercise any of these rights, please submit a request to privacy@punchin.studio. We will respond within 45 days for requests under US state privacy laws, and within one month for requests under the GDPR. Each may be extended once, by a further period allowed under the applicable law, where a request is complex or we have received several from you — if we need an extension we will tell you within the original period and explain why. We may need to verify your identity before acting, and we will only ask for what is needed to do that.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may ask the agent for written proof of your authorization, and may still ask you to verify your identity with us directly.
If we say no, you can appeal. If we decline your request, we will tell you why. You may appeal by replying to that decision within 45 days, and we will respond to the appeal within 60 days. If we uphold the refusal, you may complain to your state Attorney General — in Virginia, Colorado and Connecticut this route is required by law to be offered to you — or, in the EEA or UK, to your data protection authority.
We will not penalise you for asking. We will not deny you the Service, charge you a different price, or give you a lower quality of service because you exercised any privacy right described in this policy.
United States State Privacy Rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you may have the rights described above — to know, access, correct, delete and port your personal information, and to opt out of its sale, its sharing for targeted advertising, and certain profiling. The table below sets out what we collect in the categories those laws use.
| Statutory category | What this means for PunchIn | Why we collect it |
|---|
| Identifiers | Name, email address, phone number, IP address, account and studio identifiers | To run accounts and bookings, and to prevent fraud |
| Customer records | Studio address, engineer contact details, billing and payout details held by Stripe | To operate the Service and take payment |
| Commercial information | Bookings, deposits, refunds, disputes, subscription records | To provide the Service and meet financial obligations |
| Internet or network activity | Device and browser information from standard HTTP headers, request logs, rate-limit counters | Security, abuse prevention and keeping the Service running |
| Professional information | Engineer bios, photos, roles and schedules published by a studio | To display a studio's staff and availability |
| Audio or visual information | Room and engineer photos, studio logos and branding uploaded by a studio | To display a studio's booking page |
| Inferences | None. We do not build profiles or derive characteristics about you. | — |
| Sensitive personal information | None collected deliberately. We do not collect government identifiers, precise geolocation, health, biometric, racial, religious or sexual-orientation data. Passwords are stored only as irreversible cryptographic hashes we cannot read. | — |
Where it comes from. We collect this information directly from you; automatically from your use of the Service; from the studio you booked with; and from the third-party services you choose to connect, listed in the sub-processor table above.
We do not sell or share your personal information. We do not sell it for money or anything else of value, and we do not “share” it as that term is defined under California and other state privacy laws — that is, we do not disclose it to anyone for cross-context behavioural or targeted advertising. We use no advertising cookies, no analytics cookies and no third-party tracking pixels. Because we do not sell or share personal information, we are not required to publish a “Do Not Sell or Share My Personal Information” link, and we do not display one. We have not sold or shared personal information in the preceding twelve months, and we do not knowingly sell or share the personal information of anyone under 16.
Opt-out preference signals. Browsers and extensions can send a Global Privacy Control (GPC) signal, which asks a site not to sell or share personal information. We do not sell or share personal information at all, so there is nothing for that signal to switch off, and we do not currently detect it — we would rather tell you that plainly than claim a control we have not built. If we ever began selling or sharing personal information, we would honour GPC and would say so here first. We also do not respond to the older browser “Do Not Track” header, for which no common standard was ever agreed.
Automated decisions. We do not use profiling to make decisions producing legal or similarly significant effects about you, with one exception we describe in full in section 6 above: a chargeback automatically bans the client from booking again at that studio. That section explains how to contest it.
A note on thresholds. Most of these state laws apply only to businesses above a revenue or consumer-volume threshold, and PunchIn is below them today. We are giving you these disclosures and honouring these rights regardless, rather than waiting until we are compelled to.
European Economic Area Residents (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases: (a) your consent (e.g., connecting Google Calendar); (b) the performance of a contract (e.g., providing the Service pursuant to our Terms of Service); (c) our legitimate interests (e.g., fraud prevention and platform security); and (d) compliance with legal obligations. You have the right to lodge a complaint with your local data protection authority.
These legal bases describe the data for which PunchIn is the controller. Where you booked a session with a studio, that studio is the controller for your booking data and is responsible for establishing its own legal basis — see section 2 above. Direct requests to exercise your rights over booking data to the studio you booked with; if you contact us instead, we will pass the request on and assist the studio in responding.
International transfers. PunchIn and all of the sub-processors listed above are located in the United States, so personal data originating in the EEA or the UK is transferred to and processed in the United States. Where that transfer requires a legal mechanism, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, which are incorporated into the Data Processing Agreement at section 11 of our Terms of Service. The Service is not currently offered for transfers of personal data originating in Switzerland; if you need one, contact us before transferring any Swiss-origin data.
10. Cookies & Tracking Technologies
We use cookies and similar technologies strictly for functional purposes:
- Authentication Cookies: Session cookies to keep you logged in and manage your authenticated state. These are essential for the Service to function.
- Security Cookies: Session security tokens to protect authenticated requests.
- Preference Cookies: A cookie recording which studio you are currently viewing, so the dashboard shows the right one when you return. It holds a studio identifier only, and is readable only by our server.
We do not use analytics cookies, advertising cookies, or third-party tracking pixels. We do not participate in interest-based or cross-site advertising.
One clarification, because “no analytics cookies” can be read too broadly. We do measure how the product is used, as described in section 1.B — but not with cookies and not through anyone else. The session identifier those measurements use is held in your browser's session storage, which differs from a cookie in two ways that matter: it is never attached to requests automatically, and it cannot be read by any other site. It is erased when you close the tab. No third party receives it, and it is not joined to your IP address or user agent, neither of which we record against it.
11. Children's Privacy
Creating a PunchIn account requires you to be 18 or older, and account holders confirm this when they accept our Terms of Service. Booking a session does not require an account, and we do not ask a Booking Client's age or verify it — we want to be straightforward about that rather than imply a check we do not perform. Recording studios are booked by musicians of every age, and where a person under 18 is booking, or is being booked for, a parent or guardian should review this policy and the studio's booking policies and agree to them on that person's behalf. The studio, as the party with the direct relationship, is responsible for any age requirement its own sessions carry.
The Service is not directed to children. We do not knowingly collect personal information from a child under 13, and we do not seek age, date of birth or any other information that would identify one. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. If you believe we hold information about a child, contact us at privacy@punchin.studio and we will act on it.
12. Third-Party Links & Services
The Service may contain links to third-party websites or services that are not operated by us (e.g., Stripe payment pages, Google authentication). We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policy of every site you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective date" at the top. If the changes are significant, we will provide a more prominent notice, such as an email notification. Your continued use of the Service after such modifications constitutes your acknowledgment and agreement to the updated Privacy Policy.
14. Contact Us
If you have any questions or concerns about this Privacy Policy, our data practices, or if you would like to exercise your privacy rights, please contact us: