Privacy Policy

Effective date: September 21, 2026

Welcome to PunchIn ("PunchIn," "we," "our," or "us"). PunchIn operates as a software-as-a-service ("SaaS") platform that provides recording studio owners with booking management, scheduling, payment processing, and calendar synchronization tools (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at punchin.studio, use our dashboard, or interact with our booking pages as an end-client.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by the terms described herein. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

1. Information We Collect

We collect information that you provide directly to us, information that is generated automatically when you use the Service, and information from third-party services you choose to connect. The types of information we collect depend on how you interact with PunchIn.

A. Information You Provide Directly

Throughout this policy and our Terms of Service, we refer to three categories of users: "Studio Owners" are the account holders who register a studio on PunchIn; "Team Members" are managers or staff added to a studio account by the Studio Owner; and "Booking Clients" are end-users who book recording sessions through a studio's public booking page. Collectively, all users are referred to as "you" or "users."

Studio Owners & Team Members

  • Email address and password (or Google OAuth credentials)
  • Studio name, URL slug, description, and branding assets (logo, brand color, portal theme)
  • Studio physical address (street address, city, state, ZIP code)
  • Engineer/staff details: names, email addresses, phone numbers, bios, photos, and Instagram handles
  • Room details: names, descriptions, photos, gear lists, capacity, and hourly rates
  • Pricing rules, deposit percentages, and booking policies (lead time, cancellation, rescheduling, smoking policy)
  • Notification preferences and scheduling configuration

Beta Access Requests

PunchIn is invite-only right now. The Request Beta Access form is how a studio that doesn't have an account yet asks for one; we review each request by hand and, if it's a fit, follow up with a personal invite link.

  • Name and email address
  • Studio name, city, and number of rooms
  • Your role (owner, manager, engineer, or other)
  • How you currently take bookings (optional)
  • Anything else you tell us about your studio (optional)
  • Whether you asked to receive product updates — a separate, unchecked-by-default choice on the same form. Checking it subscribes you to the Marketing List described below, through the same consent process as joining it directly; leaving it unchecked has no effect on your beta access request either way.

Booking Clients

  • Full name
  • Email address
  • Phone number (optional)
  • Booking notes (optional, e.g. equipment needs or session preferences)

Calendar Export Data

  • When a Booking Client adds a confirmed session to their personal calendar (via an ICS file download or Google Calendar link), the exported event contains the studio name, room name, session date and time, studio address, and any booking notes the client provided. This data is packaged for the client's convenience and transmitted to the client's chosen calendar application — PunchIn does not control or access the client's personal calendar.

B. Information Collected Automatically

When you use the Service, we automatically collect certain technical and usage information, including:

  • IP Address: Your Internet Protocol address is captured when you submit a booking, and is used for fraud prevention, chargeback evidence, and enforcement of banned client restrictions. It is also recorded in three other places: on the rate-limiting counters described below; alongside your acceptance of our Terms of Service, as evidence of when and from where that acceptance was given; and, for PunchIn administrators only, in the administrative audit log described in the Security section, so that a privileged action can be traced to the person and machine that took it.
  • Device & Browser Information: We may collect information about the device and browser you use to access the Service, including device type, operating system, and browser type, as transmitted through standard HTTP headers.
  • Usage Data: We collect information about how you interact with the Service, such as pages visited, features used, and the dates and times of your visits.
  • First-Party Product Analytics: We record a small, fixed set of events — page views, and steps through signup, checkout and studio setup — so we can see where the product is failing people. Each event carries the page path, the referring page, any campaign tags in the link you arrived through, and a session identifier. That identifier is created in your browser, is kept only for the current tab, and is destroyed when you close it: it links the pages of a single visit together and cannot follow you between visits or between websites. We do not record your IP address or your browser's user agent against these events, and we do not use a cookie for them. These events are stored in our own database. In addition, the milestone events among them — not page views, and never the session identifier — are forwarded to Google Analytics 4 in the reduced form described in the next bullet. The session identifier stays first-party and is never sent to Google.
  • Google Analytics 4 (Third-Party): Separately from the first-party analytics above, we use Google Analytics 4 ("GA4"), a service operated by Google LLC, to measure traffic and usage across the Service. Unlike our first-party analytics, GA4 data is sent to and processed by Google, not stored only in our own database. GA4 automatically collects the pages you view, the page you arrived from, device and browser information, and an approximate location derived from your IP address. GA4 also receives a small set of custom events mirroring specific milestones from our first-party analytics above — currently, starting the signup form, completing signup, starting checkout for a specific plan, and, for Studio Owners, progress through the studio setup wizard (viewing, completing or skipping a step). Each of these carries only the event name and, depending on the event, which plan tier (Solo, Pro or Enterprise) was selected at checkout or which wizard step (by number and name, e.g. "Rooms" or "Team") was involved — never your email, name, phone number, any booking identifier, or any free-text you enter anywhere in the Service. It sets a persistent cookie named _ga (and related _ga_* cookies) in your browser to recognize you as the same visitor across separate visits — this cookie does persist between visits, unlike the session identifier used by our first-party analytics. We have configured both of our GA4 properties with Google Signals turned off, and our GA4 tag itself instructs Google not to use the data it sends for ads personalization, so neither property is used to build cross-service advertising profiles or to serve you ads. Public booking pages may be measured under a separate GA4 property from the marketing site and dashboard, so that a studio's clients are counted apart from PunchIn's own visitors — the categories of data described in this section are the same either way; only which property receives them differs. See the sub-processor table below, section 7 (Data Retention) for how long GA4 keeps this data, and section 10 (Cookies & Tracking Technologies) for the cookie itself.
  • Rate Limiting & Bot Protection: Booking, payment and team-invitation endpoints are rate limited by PunchIn itself, using counters stored in our own database and keyed on IP address (and, for bookings, on the email address supplied). Sign-in, sign-up and password-reset requests go directly from your browser to Supabase, our authentication provider, and are rate limited by Supabase rather than by us. Public booking, beta access request, and waitlist submissions, and confirming a re-subscribe to our mailing list, are protected by Cloudflare Turnstile, a CAPTCHA alternative that verifies you're not a bot; see Cloudflare's Privacy Policy.
  • Email Delivery Events: Our email provider reports back what happened to each message we send you, and we record it. This includes your email address, the message subject, whether the message was delivered, delayed, rejected by your mail server (a “bounce”) and the reason given, and whether the message was reported as spam. We use this to detect and fix mail we are failing to deliver — without it, a booking confirmation can fail silently and nobody finds out. For transactional mail — booking confirmations, sign-in codes, password resets, and billing, refund and dispute notices — that is the whole of it: we do not record whether you opened the message or clicked a link in it, and open and click tracking are switched off on the system that sends them.
  • Marketing Email Engagement: For marketing email you have opted into, and only for that mail, we do measure engagement. Those messages carry a small invisible image that loads when the message is displayed, and their links are routed through a redirect that records the click before sending you on to the destination. From this we record whether and when a message was opened, and which links were clicked and when — and nothing else. We do not record your IP address, or the mail client or browser your device reported: our email provider offers both, and we strip them before anything is written to our database. We use it to judge whether what we send is worth sending, and to decide who receives a marketing message — for example, sending a follow-up only to people who opened the first one, or no longer sending to someone who has not opened anything in months. This is never applied to the transactional mail described above, which is sent through a separate system with tracking switched off. Unsubscribing from marketing email stops it entirely, and most mail clients can be set to block the image from loading if you would rather read the message without it — which also means we will not detect that open.
  • Marketing List: We keep one marketing email list, and joining the waitlist is how you subscribe to it — the launch announcement is one of the messages that list carries, not a list of its own. Joining subscribes you immediately; there is no separate confirmation email to click before you start receiving list mail. We also record how each address reached us (a waitlist signup, a named signup link, or added by us), so an address we added ourselves — which has not gone through this signup flow — is never mistaken for one that opted in. Some list messages are sent automatically rather than one at a time: a short series that begins after you join, or a message that follows when we add a label to your record (see Internal Subscriber Notes & Tags below). Each is still a marketing email sent only while you are subscribed, with the same unsubscribe link, and unsubscribing takes you out of any series you are part of before its next message. We store the email address you gave us, any name or studio name you supplied, and evidence of your consent — when you asked to join, the IP address and browser the request came from, and where on the site you asked from. We keep that consent evidence because “did this person actually ask to hear from us” is the question a spam complaint turns on, and a bare row in a table cannot answer it. Every message we send carries an unsubscribe link.
  • Signup Link Attribution: We publish named, shareable links (e.g. a link posted on social media or a partner's newsletter) so we can tell which channel brought in a signup. If you join through one, we record which link and, in aggregate, how many people clicked it and how many of those went on to subscribe — we do not receive or store anything about you before you actually submit the waitlist form; visiting the link alone is counted only as an anonymous click against that link, with no address attached. This lets us see which channels are worth using again, the same way the Marketing List consent evidence above lets us prove a subscriber actually opted in.
  • Internal Subscriber Notes & Tags: PunchIn administrators may attach short freeform notes and labels (e.g. “replied asking about pricing”, “VIP”) to a marketing subscriber's internal record, and every change to a subscriber — added, tagged, suppressed, and so on — is logged with a timestamp. Labels may also decide which marketing emails you receive, including starting one of the automated series described above. This is our own internal record-keeping about the relationship, not something you provide, is never shown to you or any other subscriber, and is deleted along with the rest of your record if you exercise the erasure right described in section 9.
  • Unsubscribe and Delivery Suppression Records: We keep two separate “do not email” records, because they mean different things. Opt-outs are your choice: when you unsubscribe from a category of email — through the link in a message, your mail app's one-click unsubscribe, our unsubscribe page, or by asking us — we store your email address, the category, and how you opted out, so that we can honour it. Delivery suppressions are not a choice anyone made: we record one when a message to you bounces permanently (your mail server reports that the address does not exist), when a message is reported as spam, or when our email provider refuses to deliver to the address. A spam report on a notification email suppresses every optional notification category; a spam report on a marketing email suppresses marketing email. We honour a suppression the same way as an opt-out, because continuing to send to a dead mailbox, or to someone who reported us, damages our ability to deliver mail to everyone else. We also keep a history of changes to both records — the address, the category, what changed, which of our systems or administrators changed it, and when — so we can show why an address is or is not being emailed. Neither record ever affects transactional mail such as booking confirmations, sign-in codes or billing notices. If you opted out of marketing email yourself and later ask to rejoin, we email you a confirmation link and lift the opt-out only when you click it — submitting the form is not enough on its own, because anyone could type your address into it. A delivery suppression is never lifted by re-joining; if the address starts working again, or you reported a message as spam by mistake, you can ask us to clear it using the contact details in section 12.
  • Terms Acceptance Records: When you accept our Terms of Service — as a Studio Owner in the dashboard, or as a Booking Client by ticking the box at checkout — we record that you accepted, when, which version you accepted, and the IP address it came from. We keep this because “did this person agree, and to what text” is the question that matters if a booking or a payment is later disputed, and a bare timestamp cannot answer it.
  • Refund and Dispute Records: Where a booking is refunded, is owed a refund, or is disputed with a card issuer, we record the operational history alongside it — when a refund became due, when we reminded the studio, whether it was escalated, whether an administrator issued it, the payment processor's dispute identifier, whether evidence was submitted, and the outcome. This is what lets us tell whether a studio is honouring its own refund policy.

C. Information From Third-Party Services

  • Google Sign-In (OAuth): If you sign in or sign up with Google, we request only the openid, email, and profile scopes, and receive your email address and basic profile information (such as your name and profile picture). We do not receive or store your Google password. This sign-in authorization is entirely separate from the Google Calendar integration below and grants PunchIn no access to your calendar or any other Google data.
  • Google Calendar: If you separately choose to connect your Google Calendar, we request only the narrow scopes each feature needs — calendar.events (create, update and remove the booking events we place on your calendar, and receive change notifications), calendar.calendarlist.readonly (list your calendars so you can choose which one each room and engineer uses), calendar.freebusy (read busy/free times so we do not offer clashing slots), calendar.calendars (create a new calendar when you ask us to), and userinfo.email (identify the connected account). We do not request the broad Google Calendar scope, so we cannot change sharing permissions or delete your calendars. We store the OAuth refresh token to maintain the connection. This is a distinct authorization from Google Sign-In and can be granted or revoked independently.
  • Events imported from a connected Google Calendar: When you assign one of your calendars to a room or engineer, PunchIn imports upcoming events on that calendar that it did not itself create, so your existing commitments appear in your Bookings and block out those times. For each imported event we store its title, start and end time, and the email address of the event's creator or organiser as recorded by Google. Imported events are labelled as manual imports, no payment is associated with them, and we never send any email to the people named on them — no confirmations, no session reminders, no cancellation notices. Only you and your studio's managers are notified, to let you know an import happened. Removing an imported booking from PunchIn deletes only our copy; the event on your Google Calendar is left untouched.
  • Stripe: When payments are processed, Stripe provides us with transaction identifiers (payment intent IDs, customer IDs, subscription IDs). We do not receive, process, or store full credit card numbers, CVVs, or other raw payment credentials. All payment data is handled directly by Stripe.

2. Our Role: Controller and Processor

PunchIn handles two different kinds of personal data, and our legal role differs between them. Which one applies to you depends on how you use the Service.

  • Booking Client data — the studio is the controller, PunchIn is the processor. When you book a session, the studio you booked with decides why and how your information is used. PunchIn processes it on that studio's behalf in order to run the booking. If you want your data corrected or deleted, the studio is the right first point of contact; we will assist them, and you can also contact us and we will route your request.
  • Account and platform data — PunchIn is the controller. Studio Owner and team accounts, subscription and billing records, security and audit logs, and aggregated usage statistics are data we determine the purposes of ourselves, in order to operate, secure and improve the Service.

The terms governing our processing on a studio's behalf — including our obligations, sub-processor commitments, international transfer terms, and audit rights — are set out in the Data Processing Agreement at section 11 of our Terms of Service. Studio Owners accept that DPA by accepting the Terms; no separate signature is required.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: To create and manage accounts, process bookings, synchronize calendars, facilitate payments, and deliver the core scheduling platform.
  • Communications: To send booking confirmations, cancellation and refund notices, shift assignment notifications, subscription reminders, client session reminders sent a configurable number of hours before a booked session, and other transactional emails necessary to operate the Service. Most email notifications are configurable per studio through notification preferences. Booking confirmations and essential financial notices such as refund confirmations are not: a client who has paid always receives a receipt.
  • Fraud Prevention & Platform Integrity: To detect and prevent fraudulent transactions, enforce banned client restrictions, log blocked booking attempts, submit dispute evidence to payment processors, and protect studios from chargebacks. This includes matching bookings against banned client lists by email, phone number, and IP address.
  • Payment Processing: To process subscription payments, booking deposits, and refunds through our payment processor (Stripe).
  • Platform Monitoring & Administration: To monitor platform health, review disputes, track subscription activity, and respond to fraud. PunchIn administrators receive automated alerts and daily summaries that may include aggregated booking metrics, dispute details, subscription events, and banned client activity. Administrative actions (such as granting or revoking subscriptions) are logged with the administrator's identity and a timestamp for audit purposes.
  • Studio Policy Transparency: Studio-configured booking policies (deposit percentage, cancellation window, late cancellation fee, minimum booking duration, rescheduling availability) are displayed to Booking Clients on the studio's public booking page so clients can make informed decisions before booking.
  • Security: To authenticate sessions, enforce rate limiting on booking, payment and invitation endpoints, and enforce row-level access controls on data.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes, and to respond to lawful requests from public authorities.

4. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

  • Between Studios and Booking Clients: When a Booking Client reserves a session, their name, email, phone number (if provided), and booking notes are shared with the studio where they booked. Studio information (name, address, room details, engineer names) is displayed on public booking pages.
  • Replies to Booking Emails Go to the Studio: Booking confirmations, session reminders, cancellation notices, and engineer shift notifications are sent by PunchIn but carry a Reply-To address belonging to the studio you booked with. If you reply to one of these emails, your reply — including your email address and anything you write — is delivered directly to that studio, not to PunchIn. The address used is the studio's published contact address, or, where the studio has not set one, the email address of the studio's account owner. Studio owners should be aware that this address is disclosed to every Booking Client and engineer who receives one of these emails, and that we are not a party to the resulting correspondence. Emails about your PunchIn account itself — sign-in codes, password resets, security alerts, and billing notices — instead reply to PunchIn support.
  • Service Providers (Sub-processors): We share information with third-party service providers who process it on our behalf. Each one, the purpose it serves, and the categories of data it receives are listed in the sub-processor table immediately below.
  • Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
  • Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business, your personal information may be transferred.

Sub-processors

The following third parties process personal data on our behalf in order to deliver the Service. Each is bound by data protection terms no less protective than those we commit to in the Data Processing Agreement at section 11 of our Terms of Service. All are located in the United States, and data processed through the Service is stored and processed there.

Sub-processorPurposeData it receives
Supabase, Inc.
Privacy Policy
Database, authentication and file storage — the primary store for all Service dataAll account, studio, booking and Booking Client data; uploaded images
Vercel, Inc.
Privacy Policy
Application hosting and content deliveryData in transit through the application; IP addresses and request metadata in server logs
Stripe, Inc.
Privacy Policy
Deposit and subscription payments, payouts to studios, and dispute managementBooking Client name, email, IP address, booking details and deposit amounts; Studio Owner billing and payout details
Resend, Inc.
Privacy Policy
Transactional email delivery and delivery-event reportingRecipient email address, message subject and content, and delivery outcome (delivered, delayed, bounced, marked as spam)
Google LLC
Privacy Policy
Calendar synchronisation, and sign-in for Studio Owners who choose Google OAuthCalendar events written to a connected calendar (client name, session times, room name); OAuth account identity and email address
Google LLC (Google Analytics)
Privacy Policy
Website and product usage analytics (Google Analytics 4) — listed separately from the row above because it is a distinct product with its own data flow, even though the same company operates bothPages viewed, referring page, device and browser information, approximate location derived from IP address, and a persistent analytics cookie identifier (_ga)
Cloudflare, Inc.
Privacy Policy
DNS and network infrastructure; Turnstile bot verification on public booking, beta access request, and waitlist submissions, and on confirming a re-subscribe to our mailing listIP address and the Turnstile verification token at the moment a booking, beta access request, waitlist signup, or re-subscribe confirmation is submitted

Changes to this list. Before we add or replace a sub-processor that will process Booking Client personal data, we will update this table and notify Studio Owners by email at least thirty (30) days in advance. Studio Owners may object on data protection grounds during that period; the process, and the right to terminate without penalty if we cannot resolve an objection, is set out in section 11.D of the Terms of Service.

5. Google API Services — Limited Use Disclosure

PunchIn's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We request only the minimum Google scopes each feature needs, and each is a separate authorization handled by a separate Google Cloud project: Google Sign-In requests the openid, email, and profile scopes to authenticate you and identify your account; Google Calendar requests four granular Calendar scopes (calendar.events, calendar.calendarlist.readonly, calendar.freebusy, calendar.calendars) plus your account email, to provide two-way calendar synchronization and identify the connected calendar account. We do not request the broad Calendar scope. Signing in with Google never grants access to your calendar, and connecting your calendar is never done automatically at sign-in.
  • We do not use Google user data for advertising purposes.
  • We do not allow humans to read your Google data unless: (a) we have your express consent, (b) it is necessary for security purposes (e.g., investigating abuse), or (c) it is required by law.
  • You may revoke our access to your Google Calendar data at any time by unlinking your Google account from the PunchIn dashboard or by revoking access through your Google Account permissions.

6. Fraud Prevention & Client Restrictions

To protect studios from fraudulent transactions and payment disputes, we maintain a banned client system. The following data practices apply:

  • Automatic Banning: When a payment dispute (chargeback) is filed against a booking, the client associated with that booking is automatically added to the studio's banned client list. The banned record includes the client's name, email, phone number, and IP address from the original booking, along with the dispute reason so the studio can see why. A preliminary bank inquiry — a question about a charge that has not yet become a chargeback — does not trigger this ban; we log it and notify the studio, and the ban applies only if and when the inquiry becomes a chargeback.
  • Booking Restrictions: When a banned client attempts to make a new booking, we match against the banned list using email address, phone number, and IP address. If a match is found, the booking is blocked, and the attempt is logged (including the name, email, phone, and IP used in the attempt).
  • Dispute Evidence: In the event of a payment dispute, we automatically compile an evidence packet for the studio — which may include the client's name, email address, IP address, the record of their acceptance of our Terms of Service, a description of the service provided, and the session date. A PunchIn administrator reviews that packet before it is submitted to Stripe; it is not filed automatically.
  • Studio Control: Studio owners retain full control over their banned client list and may reinstate or manually ban clients at their discretion.

This is an automated decision, and you can contest it. The ban that follows a chargeback is applied by software, with no person reviewing it first, and its effect is that you can no longer book with that studio. We are telling you this plainly because a decision made by a machine that stops you transacting is exactly the kind you should be able to challenge. A ban applies only to the studio where the disputed booking was made — it is not shared with other studios and does not follow you across the platform. If you believe a ban is wrong, contact the studio, which can reinstate you at any time, or write to privacy@punchin.studio and we will review the record and refer it to the studio. If the dispute is later resolved in the studio's favour, the booking is restored and the ban is lifted automatically; if the dispute is lost, the ban remains until the studio reinstates you.

7. Data Retention

We retain your personal information for as long as your account is active. We want to be precise about which of the periods below are enforced automatically and which are not, because privacy policies routinely blur the two.

A daily job deletes the operational logs marked purged automatically below once they pass their retention window. Everything else — your account, your studio, your bookings and your Booking Clients' details — is removed when you delete your studio or your account, or when you ask us to and we are not required to keep it. There is no timer that erases your studio's own records for you, and we would rather say so than let you assume otherwise.

  • Account Data: Retained for as long as your account exists. Deleting your account removes it, subject to the exceptions below. If you stop using the Service without deleting your account, your data remains until you delete it or ask us to.
  • Booking Records: Retained for as long as the studio they belong to exists. Deleting a studio deletes its bookings and the Booking Client information within them immediately — we do not hold them back for a retention period. If you need booking records for tax or financial compliance, export them before deleting, because we cannot recover them afterwards. Stripe separately retains its own transaction records under its own policy, and those are not removed by deleting your studio.
  • Banned Client Records: Retained for as long as the studio account is active to enforce booking restrictions and support future dispute evidence.
  • Google Calendar Tokens: OAuth refresh tokens are deleted when you unlink your Google Calendar from the dashboard or when your account is terminated.
  • Administrative Audit Logs: Records of administrative actions (e.g., granting subscriptions, account impersonation) are retained indefinitely for security and compliance purposes.
  • Payment Data: Transaction identifiers (Stripe payment intent IDs, customer IDs) are retained as part of booking records. Full payment details are retained by Stripe in accordance with their own retention policies.
  • Email Delivery Events: Bounce, delivery-failure and spam-report records are purged automatically after 90 days, and are used only to diagnose delivery problems. Our email provider retains its own copy under its own policy.
  • Queued Email Retries: When an email fails to send (a temporary provider outage or rate limit), we hold the message's parameters — recipient, subject, content, and, for the small number of message types that include one (such as a booking confirmation's calendar invite), the attachment — so it can be retried automatically rather than silently lost. A message that eventually sends, or that permanently fails and is abandoned, is purged automatically 90 days later. A message still actively retrying is never purged by this window, no matter how long it takes.
  • Blocked Booking Attempts: Records of a banned client's attempt to book again are purged automatically after 12 months — long enough to show a studio a pattern, not indefinite.
  • Expired Team Invitations: An invitation that was never accepted expires and can no longer be used. Twelve months after it expires it is purged automatically, since by then it is only an email address with nothing attached to it.
  • Expired Beta Invitations: During our private beta, we hand-issue invitations to a small number of studios we've reached out to directly. An invitation that was never accepted expires and can no longer be used. Twelve months after it expires it is purged automatically, for the same reason as expired team invitations above. An accepted invitation is kept as part of that account's history.
  • Beta Access Requests: We keep a submitted request, and our decision on it, while the beta is invite-only, the same way we keep Business Outreach Contacts below — it is not built from our existing users' data, and it exists to help us decide who to invite next. You can ask us to remove a request at any time using the contact details in section 12; doing so does not affect a separate Marketing List subscription from the same address, if you opted into one.
  • Session Reminder and Webhook Ledgers: Internal markers that stop us sending a reminder twice or processing a payment event twice are purged automatically after 90 days. They contain no contact details.
  • Product Analytics Events: Purged automatically after 400 days. That window is closest to the 14 months Google Analytics 4 retains its user-level data (below) — the more comparable of GA4's two windows, since these events are not cleared out within weeks the way GA4's own event-level data is — so the two are not wildly different, and it comfortably exceeds a year so a year-over-year comparison of the product's own usage stays possible. They carry no name, email address, IP address or user agent, and their session identifier expires with your browser tab, so they cannot be traced back to you afterwards.
  • Google Analytics 4 Data: Held by Google, not by us, under Google's own retention configuration, which is the same on both GA4 properties described in section 1.B — the main site and dashboard, and the separate property for public booking pages. Google keeps event-level data for two months and user-level data for fourteen months, the longer window letting Google still recognize a returning visitor across sessions without holding each individual event that long, and it automatically deletes each kind of data at the end of its own window. Aggregated reporting data that is no longer tied to an individual is unaffected by either window. This is a separate retention period from every other row in this table, because GA4 data lives in Google's systems and PunchIn does not control it directly.
  • Marketing List: How long we keep your entry depends on where it stands, because the three cases are not alike. Joining the waitlist yourself subscribes you immediately, so this first case only ever applies to an address we added ourselves without you subscribing through it: if that entry is still not a live subscription 90 days later, it is purged automatically — we will never send to an address that never actually subscribed, so keeping it serves no purpose. If you are subscribed, we keep it for as long as you are, together with the record of your consent; it is a live subscription, not an old log. If you have unsubscribed, bounced, or reported us as spam, we keep it indefinitely, for the same reason as the unsubscribe records below: forgetting it is what would cause us to start emailing you again. If instead you ask us to erase your entry entirely (see the Right to Deletion in section 9), we delete the record itself — including any internal notes and tags described below — but still keep the minimum needed to honour your opt-out, exactly as described for the unsubscribed case, so erasure can never result in being emailed again by mistake.
  • Marketing Email Engagement: The individual click records — which link, and when — are purged automatically after 400 days, the same window as our product analytics, which is long enough to compare one year's campaigns against the next. What outlives them is a per-message summary — whether each marketing email we sent you was delivered, how many times it was opened or clicked, and when first and last — kept for as long as your Marketing List entry exists and deleted with it, because it is what lets us leave out people who have stopped reading. As set out in section 1, none of this includes your IP address or the mail client or browser your device reported.
  • Signup Link Attribution: Which named link you joined through is stored on your Marketing List entry and follows the same retention as that entry, including deletion on erasure. The link's own click and signup counters are aggregate numbers with no subscriber identity attached — they are not personal information and are retained indefinitely as part of the link's own record, the same way a campaign's totals outlive individual click records above.
  • Internal Subscriber Notes & Tags: Retained for as long as your Marketing List entry exists, and deleted along with it — on erasure, or automatically when a never-subscribed entry is purged after 90 days.
  • Business Outreach Contacts: Separately from the marketing list above, we keep a record of recording studios we may contact about PunchIn. This holds business contact details published by the studio itself — the studio's name, address, website, a business email address, and which booking software it appears to use — together with a note of any message we sent and any reply. It is not built from our users' data, and no Booking Client information ever enters it. We keep an entry while the studio is a realistic prospect, and review the list at least once a year. If you ask us not to contact you, we keep the minimum needed to honour that — your email address and the fact you opted out — indefinitely, for the same reason as the unsubscribe records below: deleting it is what would cause us to contact you again. You can ask us to remove an entry at any time using the contact details in section 12.
  • Unsubscribe and Delivery Suppression Records: Retained indefinitely, and deliberately so. An opt-out or a suppression is only meaningful if it outlives the account, booking or mailing list that prompted it — deleting the record would cause us to start emailing you again. The history of changes to these records is kept for as long as the records themselves, because it is the evidence of why an address is or is not being emailed.

Deleting Your Account or Studio

You can permanently delete your account at any time from your account settings in the PunchIn dashboard. Deleting your account removes your authentication credentials (email address, password hash, and any connected Google sign-in identity) and your team memberships in other studios. Deletion is immediate and irreversible.

If you own one or more studios, deleting your account also deletes each of them; you can also delete a single studio on its own from Studio Config → Danger Zone. Before anything is removed, we show you exactly which studios, upcoming bookings and team members are affected, and if a studio has a subscription that could still be charged we ask you to confirm that you want it ended — nothing is cancelled without that confirmation. Deleting a studio permanently removes the data belonging to that studio, including its rooms, engineers, on-call shifts, bookings and the Booking Client information contained within them, calendar connections and stored OAuth tokens, banned-client records, and pending team invitations. Any active subscription for that studio is cancelled immediately as part of deletion, and PunchIn's access to your connected Google Calendar is revoked at Google — not merely disconnected on our side. If Google is unreachable at that moment the deletion still goes ahead, and the failure raises an alert for us to follow up rather than passing silently. You can always confirm and remove our access yourself from your Google Account permissions.

When you delete a studio or your account we ask you to choose a reason for leaving, with an optional comment. That answer is stored without your name, email address, user ID or studio name — only the reason, your comment, and which plan you were on — so it cannot be traced back to you once your account is gone. If a subscription is cancelled as part of the deletion, the same reason is attached to the cancellation record held by Stripe. Please don't put personal information in the comment.

Deletion is comprehensive but not unlimited. To the extent permitted or required by law, we retain certain records after you delete your account or studio, including: transaction and payout records held by Stripe; administrative audit logs; and information we are required to keep for tax, accounting, fraud-prevention, or dispute-resolution purposes. Residual copies may persist in encrypted backups for a limited period before being routinely overwritten. Team invitations addressed to your email address are retained while they are still valid, so that you may accept them if you create a new account later; the inviting studio owner can cancel one at any time, and an invitation that has been expired for twelve months is deleted automatically.

8. Data Security

We implement commercially reasonable administrative, technical, and physical security measures to protect your personal information, including:

  • Encryption of data in transit via TLS/SSL across all connections
  • Encryption of data at rest within our database infrastructure
  • Row-level security (RLS) policies that ensure studio data is only accessible to authorized account holders
  • Service role key separation between client-facing and administrative database operations
  • Rate limiting on booking, payment and invitation endpoints to prevent automated abuse; authentication requests are rate limited by Supabase, our authentication provider
  • Optional two-factor authentication (TOTP) for Account Holders, enrolled from Security & 2FA in the dashboard
  • Secure storage of third-party OAuth tokens and API credentials, revoked with Google when you unlink your calendar
  • Administrative action audit logging with user identity, timestamp, and action details

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

If there is a breach. If we discover a breach of security affecting your personal information, we will notify you and any regulator we are required to notify, without unreasonable delay and within the timeframes applicable law sets. Where the affected data belongs to a studio's Booking Clients, we notify that studio, because it is the controller of that data and the party responsible for notifying the individuals — and we will help it do so.

9. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. These may include:

  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Rectification: You may request that we correct any inaccurate or incomplete information.
  • Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions (e.g., data we are required to retain for financial compliance).
  • Right to Data Portability: You may request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to Withdraw Consent: Where processing is based on consent (e.g., Google Calendar integration), you may withdraw consent at any time by unlinking the integration from your dashboard or by contacting us.
  • Right to Opt Out: Every optional notification email we send carries an unsubscribe link in its footer, and a one-click unsubscribe control that most mail applications display next to the sender's name. Either one takes effect immediately and needs no account, no login and no reply. Studio Owners can additionally adjust notification categories in the studio dashboard. Reporting one of our messages as spam also opts you out of every optional category. Essential messages — booking confirmations, sign-in codes, password resets, security alerts, and billing or refund notices — are sent because you or your studio took an action that requires them, and cannot be switched off by anyone while the underlying account or booking is active; if you pay a deposit, you always get a confirmation. Two client-facing messages sit in between: cancellation notices and session reminders are on by default but each studio can turn them off for its own clients, so whether you receive those is the studio's decision rather than ours or yours.

To exercise any of these rights, please submit a request to privacy@punchin.studio. We will respond within 45 days for requests under US state privacy laws, and within one month for requests under the GDPR. Each may be extended once, by a further period allowed under the applicable law, where a request is complex or we have received several from you — if we need an extension we will tell you within the original period and explain why. We may need to verify your identity before acting, and we will only ask for what is needed to do that.

Authorized agents. You may use an authorized agent to submit a request on your behalf. We may ask the agent for written proof of your authorization, and may still ask you to verify your identity with us directly.

If we say no, you can appeal. If we decline your request, we will tell you why. You may appeal by replying to that decision within 45 days, and we will respond to the appeal within 60 days. If we uphold the refusal, you may complain to your state Attorney General — in Virginia, Colorado and Connecticut this route is required by law to be offered to you — or, in the EEA or UK, to your data protection authority.

We will not penalise you for asking. We will not deny you the Service, charge you a different price, or give you a lower quality of service because you exercised any privacy right described in this policy.

United States State Privacy Rights

If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you may have the rights described above — to know, access, correct, delete and port your personal information, and to opt out of its sale, its sharing for targeted advertising, and certain profiling. The table below sets out what we collect in the categories those laws use.

Statutory categoryWhat this means for PunchInWhy we collect it
IdentifiersName, email address, phone number, IP address, account and studio identifiersTo run accounts and bookings, and to prevent fraud
Customer recordsStudio address, engineer contact details, billing and payout details held by StripeTo operate the Service and take payment
Commercial informationBookings, deposits, refunds, disputes, subscription recordsTo provide the Service and meet financial obligations
Internet or network activityDevice and browser information from standard HTTP headers, request logs, rate-limit countersSecurity, abuse prevention and keeping the Service running
Professional informationEngineer bios, photos, roles and schedules published by a studioTo display a studio's staff and availability
Audio or visual informationRoom and engineer photos, studio logos and branding uploaded by a studioTo display a studio's booking page
InferencesFor marketing subscribers only: how recently you opened or clicked our marketing email. We do not build profiles or derive any other characteristics about you.To decide which marketing emails to send you
Sensitive personal informationNone collected deliberately. We do not collect government identifiers, precise geolocation, health, biometric, racial, religious or sexual-orientation data. Passwords are stored only as irreversible cryptographic hashes we cannot read.

Where it comes from. We collect this information directly from you; automatically from your use of the Service; from the studio you booked with; and from the third-party services you choose to connect, listed in the sub-processor table above.

We do not sell your personal information for money or anything else of value. We do use one third-party analytics cookie — Google Analytics 4, described in section 1.B above and section 10 below — and we want to be precise about what that does and does not mean under the CCPA and comparable state laws, rather than give you a blanket assurance that no longer fits. Whether sending data to Google through GA4 counts as “sharing” personal information (that is, disclosing it for cross-context behavioural advertising) turns on how Google is permitted to use it, which in turn depends on the GA4 property's configuration. We have configured both of our GA4 properties with Google Signals and ads-personalization features turned off, so Google receives GA4 data as a service provider processing it to give us analytics, not to build advertising profiles, and we do not otherwise disclose personal information to any third party for cross-context behavioural or targeted advertising. On that configuration, GA4 does not constitute a “sale” or “share” of personal information as those terms are defined under California and other state privacy laws. Because we do not sell or share personal information on that basis, we are not required to publish a “Do Not Sell or Share My Personal Information” link, and we do not display one; if that configuration ever changes, we will publish one and update this section first. We have not sold personal information in the preceding twelve months, and, on the configuration described above, we have not shared it either. We do not knowingly sell or share the personal information of anyone under 16.

Opt-out preference signals. Browsers and extensions can send a Global Privacy Control (GPC) signal, which asks a site not to sell or share personal information. We do not sell or share personal information at all, so there is nothing for that signal to switch off, and we do not currently detect it — we would rather tell you that plainly than claim a control we have not built. If we ever began selling or sharing personal information, we would honour GPC and would say so here first. We also do not respond to the older browser “Do Not Track” header, for which no common standard was ever agreed.

Automated decisions. We do not use profiling to make decisions producing legal or similarly significant effects about you, with one exception we describe in full in section 6 above: a chargeback automatically bans the client from booking again at that studio. That section explains how to contest it.

A note on thresholds. Most of these state laws apply only to businesses above a revenue or consumer-volume threshold, and PunchIn is below them today. We are giving you these disclosures and honouring these rights regardless, rather than waiting until we are compelled to.

European Economic Area Residents (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases: (a) your consent (e.g., connecting Google Calendar); (b) the performance of a contract (e.g., providing the Service pursuant to our Terms of Service); (c) our legitimate interests (e.g., fraud prevention and platform security); and (d) compliance with legal obligations. You have the right to lodge a complaint with your local data protection authority.

These legal bases describe the data for which PunchIn is the controller. Where you booked a session with a studio, that studio is the controller for your booking data and is responsible for establishing its own legal basis — see section 2 above. Direct requests to exercise your rights over booking data to the studio you booked with; if you contact us instead, we will pass the request on and assist the studio in responding.

International transfers. PunchIn and all of the sub-processors listed above are located in the United States, so personal data originating in the EEA or the UK is transferred to and processed in the United States. Where that transfer requires a legal mechanism, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, which are incorporated into the Data Processing Agreement at section 11 of our Terms of Service. The Service is not currently offered for transfers of personal data originating in Switzerland; if you need one, contact us before transferring any Swiss-origin data.

10. Cookies & Tracking Technologies

We use cookies and similar technologies for both functional purposes and, as of the date below, third-party analytics:

  • Authentication Cookies: Session cookies to keep you logged in and manage your authenticated state. These are essential for the Service to function.
  • Security Cookies: Session security tokens to protect authenticated requests.
  • Preference Cookies: A cookie recording which studio you are currently viewing, so the dashboard shows the right one when you return. It holds a studio identifier only, and is readable only by our server.
  • _ga and _ga_* (Google Analytics 4): Set by Google, not by us, when the Service loads the Google Analytics 4 tag described in section 1.B. _ga distinguishes your browser as a unique visitor; _ga_* (a property-specific name) persists your session state for GA4's own reporting. Unlike every other cookie in this list, these do persist across separate visits — per Google's documentation, _ga and _ga_* expire two years after they are set or last updated. You can block or delete them at any time through your browser's cookie settings, or opt out of Google Analytics entirely using Google's browser add-on.

Beyond the GA4 cookies above, we do not use advertising cookies or third-party tracking pixels, and we do not participate in interest-based or cross-site advertising. We have configured Google Analytics with Google Signals and ads-personalization features turned off — see section 9's CCPA discussion for what that means for “sale” and “sharing” under state privacy law.

Our own analytics is separate from this, and does not use a cookie. As described in section 1.B, we also measure product usage ourselves, first-party, alongside Google Analytics. That measurement uses no cookie at all: its session identifier is held in your browser's session storage, which differs from a cookie in two ways that matter — it is never attached to requests automatically, and it cannot be read by any other site. It is erased when you close the tab, no third party receives it, and it is not joined to your IP address or user agent, neither of which we record against it. Google Analytics, described above, works differently and is the exception to all of this: it is third-party, it does use a persistent cookie, and Google does receive it.

11. Children's Privacy

Creating a PunchIn account requires you to be 18 or older, and account holders confirm this when they accept our Terms of Service. Booking a session does not require an account, and we do not ask a Booking Client's age or verify it — we want to be straightforward about that rather than imply a check we do not perform. Recording studios are booked by musicians of every age, and where a person under 18 is booking, or is being booked for, a parent or guardian should review this policy and the studio's booking policies and agree to them on that person's behalf. The studio, as the party with the direct relationship, is responsible for any age requirement its own sessions carry.

The Service is not directed to children. We do not knowingly collect personal information from a child under 13, and we do not seek age, date of birth or any other information that would identify one. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. If you believe we hold information about a child, contact us at privacy@punchin.studio and we will act on it.

12. Third-Party Links & Services

The Service may contain links to third-party websites or services that are not operated by us (e.g., Stripe payment pages, Google authentication). We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policy of every site you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective date" at the top. If the changes are significant, we will provide a more prominent notice, such as an email notification. Your continued use of the Service after such modifications constitutes your acknowledgment and agreement to the updated Privacy Policy.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, our data practices, or if you would like to exercise your privacy rights, please contact us: