Legal

Privacy Policy

Last updated: April 13, 2026

Punchitect ("we," "us," or "our") is a construction punch list tool for architecture and design professionals. This policy explains what information we collect, how we use it, and your choices.

1. Information We Collect

Microsoft account data. When you sign in with Microsoft, we receive your name, email address, and Microsoft tenant ID via OAuth. We do not receive or store your Microsoft password.

Firm registration. When you register your firm, we store your firm name, email address, Microsoft tenant ID, and chosen storage configuration in Cloudflare KV (a cloud key-value store). This is required to provide the service.

Billing information. Payments are processed by Stripe. We store your Stripe customer ID and subscription status. We never see or store your full credit card number — that is handled entirely by Stripe. See Stripe's Privacy Policy.

Project files. Your project data (floor plans, photos, punch list items) is stored in your own Microsoft OneDrive or SharePoint, not on our servers. We access your files only to read and write project data on your behalf using the Microsoft Graph API with permissions you grant.

Usage data. Cloudflare Pages collects basic request logs (IP address, request path, response code) as part of standard CDN operation. We do not run third-party analytics.

2. How We Use Your Information

We do not sell your data. We do not use your data for advertising.

3. Data Storage and Security

Firm registration data is stored in Cloudflare KV infrastructure located in the United States. Your project files remain in your Microsoft OneDrive or SharePoint tenant and are subject to Microsoft's data residency settings for your organization.

We use HTTPS for all data in transit. Access to the Cloudflare KV store is restricted to our Cloudflare Pages Functions.

4. Data Retention

We retain firm registration and billing records for as long as your account is active. If you cancel your subscription and wish to have your firm record deleted from our systems, contact us at the address below and we will remove it within 30 days.

Your project files in OneDrive/SharePoint are entirely under your control — we do not retain copies.

5. Third-Party Services

6. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. If you are in the European Economic Area, you have rights under GDPR. If you are a California resident, you have rights under CCPA.

7. Children

Punchitect is intended for professional use and is not directed at children under 13. We do not knowingly collect data from children.

8. Changes to This Policy

We may update this policy from time to time. We will update the "Last updated" date above. Continued use of the service after changes constitutes acceptance of the revised policy.

9. Contact

Questions about this policy? Email us at tantalus0006@gmail.com.