Punch List & Site Audit — Privacy Policy
Effective Date: July 26, 2026
Punch List & Site Audit ("the App") is developed by Mobile Card Games & Travel Apps LLC. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.
1. Data We Collect
Punch List & Site Audit stores your work on your device and, via Apple's CloudKit, in your own private iCloud account. We do not operate a server that holds your projects or photos, and no account with us is required.
- Projects and snags: The project names, snag descriptions, statuses, and company settings you enter.
- Snag photos: Photos you take with the camera or pick from your photo library to document construction issues, along with any annotations you draw on them.
- Purchase information: Subscription transactions are processed by Apple; the App never sees your payment card details.
- Usage analytics: Anonymous app-usage events collected via Firebase Analytics (see Third-Party Data Sharing).
- Install attribution: An anonymous Apple Search Ads attribution token (see below).
2. How We Use Your Data
- Your projects, snags, and photos exist solely so you can document site issues and generate reports. PDF reports are created on your device, and sharing or exporting a report happens only when you initiate it through the share sheet — you choose who receives it.
- Camera and photo-library access are used only to attach photos to snags; annotations are stored non-destructively alongside the original image.
- Analytics and attribution data help us understand, in aggregate, how the App is used and which Apple Search Ads campaigns lead to installs and purchases.
3. iCloud Sync
Your projects, snags, and photos are synced across your devices through CloudKit into your own private iCloud database, tied to your Apple ID. This data goes to Apple's iCloud servers under Apple's privacy policy (apple.com/legal/privacy) — not to any server we operate. We cannot access, read, or retrieve anything in your private iCloud database.
4. Apple Search Ads Attribution
On first launch, the App requests an attribution token from Apple's AdServices framework to measure which Apple Search Ads campaign, ad group, and keyword led to the install. The token is opaque, contains no personal information, does not use the advertising identifier (IDFA), and does not require tracking permission. The resulting campaign identifiers are used in aggregate to measure which ads are worth running.
5. Third-Party Data Sharing
The App shares data with the following third parties:
- Google Firebase Analytics (Google privacy policy): Receives anonymous app-usage events, including a purchase event when a subscription is bought or renewed, plus the Apple Search Ads campaign identifiers described above. No photos, project content, names, emails, or advertising identifiers (IDFA) are sent to Firebase.
- RevenueCat (revenuecat.com): Manages subscription purchases. RevenueCat receives purchase and transaction data from Apple along with a random anonymous app-user ID — never your name, email, or project data.
- Apple: iCloud sync (your private database) and Search Ads attribution, as described above.
Your photos and project data are never sent to any third party other than your own iCloud account. We do not sell, rent, or share your data.
6. Data Storage and Retention
- On your device: All projects, snags, photos, and company settings are stored in the App's local database.
- In your iCloud: The same data is mirrored to your private iCloud database and remains there under your Apple ID's control.
- On our servers: None — we operate no backend server.
- Deletion: Deleting a project or snag in the App removes it locally and from your iCloud sync. Uninstalling the App removes local data; iCloud data can be managed through your device's iCloud settings.
7. Data Security
iCloud sync is handled by Apple's CloudKit over encrypted connections into your private database. Communication with Firebase, RevenueCat, and Apple's attribution service uses encrypted HTTPS.
8. Your Rights
You can:
- Delete any project, snag, or photo in the App at any time.
- Deny camera or photo-library permission and still use the App without photos.
- Manage or delete the App's iCloud data via Settings → Apple ID → iCloud on your device.
- Remove all local data by uninstalling the App.
We hold no server-side copy of your personal data — your content lives on your device and in your own iCloud account — so there is nothing for us to access or delete on request beyond the anonymous analytics described above. If you have questions, email us at v5cqpsj4e3u4@opayq.com.
9. Children's Privacy
The App is not directed at children under 13. We do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.
11. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
v5cqpsj4e3u4@opayq.com