Effective Date: September 17, 2026
Punch List & Site Audit ("the App") and the website punchlistapp.net are operated by Mobile Card Games & Travel Apps LLC ("we", "us"). This Privacy Policy explains what data we collect, how it is used, where it is stored, and the choices you have.
The App has two ways of storing your work. The solo app (including the Pro subscription) keeps everything on your device and in your own private iCloud account; we operate no server that holds your projects. PunchList Business ("Teams") lets several people at one company share projects; team data is stored on servers we operate, as described in Section 4. Sections 1–3 apply to everyone; Section 4 applies only if you sign in to a team.
Your projects, snags, and photos are synced across your devices through CloudKit into your own private iCloud database, tied to your Apple ID. This data goes to Apple's iCloud servers under Apple's privacy policy (apple.com/legal/privacy) — not to any server we operate. We cannot access, read, or retrieve anything in your private iCloud database.
On first launch, the App requests an attribution token from Apple's AdServices framework to measure which Apple Search Ads campaign, ad group, and keyword led to the install. The token is opaque, contains no personal information, does not use the advertising identifier (IDFA), and does not require tracking permission. The resulting campaign identifiers are used in aggregate to measure which ads are worth running.
This section applies only when you sign in to a team under Settings › Team. Team features are optional; the solo app works without any account.
Projects, snags, and snag photos that belong to a team project are uploaded to servers we operate so that every member of the team can see and edit them, including from separate devices and separate Apple IDs. Each device also keeps a full local copy so the App keeps working offline. Content in your personal (non-team) projects is never uploaded to our servers.
Business subscriptions are purchased on punchlistapp.net and billed by Stripe, Inc. (stripe.com/privacy). When you subscribe, Stripe collects your billing email, company name, billing address, VAT or tax ID (if provided), and payment card details. Card numbers never touch our servers. Stripe sends us the billing email, the team billing code you entered, the number of seats, and the subscription status so we can activate and size your team. Stripe sends invoices and receipts to the billing email. You can update billing details, change seats, or cancel through the Stripe customer portal linked from the Business page.
We share data only with the service providers listed below, only for the purposes described, and never sell, rent, or share it for advertising.
| Provider | What it receives | Why |
|---|---|---|
| Apple (iCloud, App Store, AdServices) | Solo-app sync into your private iCloud database; Pro purchase transactions; Search Ads attribution token | Sync, purchases, ad measurement |
| Google Firebase Analytics (privacy policy) | App opens, session duration, feature-usage events (including a purchase event when a subscription is bought or renewed), device information, a random app-instance identifier, and Search Ads campaign identifiers. No photos, project content, names, emails, or advertising identifiers (IDFA). | Aggregate usage analytics |
| RevenueCat (privacy policy) | Pro purchase and transaction data from Apple with a random anonymous app-user ID. Never your name, email, or project data. | Solo Pro subscription management |
| Supabase | Team account data and team content described in Section 4 | Hosting for PunchList Business |
| Transactional email provider | Your work email address and the one-time sign-in code | Delivering team sign-in codes |
| Stripe | Billing contact, company and tax details, payment card | Business subscription billing |
| Twilio | Phone number entered on the website | Sending one SMS download link |
| Google Fonts | IP address (font request) | Serving website fonts |
Photos and project content from the solo app are never sent to any third party other than your own iCloud account. Team content is stored only with our hosting provider and shared only with the members of your team.
iCloud sync is handled by Apple's CloudKit over encrypted connections into your private database. Communication with our team servers, Firebase, RevenueCat, Stripe, and Apple's attribution service uses encrypted HTTPS. Team data is protected by row-level access rules and encryption at rest. Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider. No method of transmission or storage is completely secure, but we take reasonable technical and organizational measures to protect your data.
You can:
Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR), the UK GDPR, Canada's PIPEDA, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, delete, and port it, and to object to or restrict certain processing. For the solo app there is typically nothing for us to access or delete on request, because we do not hold your data. For team accounts and website data, contact us at the email below and we will respond as required by applicable law, normally within 30 days. You also have the right to lodge a complaint with your local data-protection authority.
Business customers: Where a company uses PunchList Business to process its employees' or clients' personal data, the company is the controller of that data and we process it on the company's behalf under this policy and our terms. Contact us if your organization requires a data-processing agreement.
The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.
In the event of a data breach affecting user data on any system we operate, we will notify affected users and, where required, the relevant authorities as applicable law requires. We may update this Privacy Policy from time to time; changes are reflected by updating the "Effective Date" at the top of this page, and material changes affecting team accounts will also be announced by email to team owners.
If you have questions about this Privacy Policy or your data, please contact us at:
Business subscription and billing questions: support@punchlistapp.net