Back

Privacy Policy

Punchdown AV · Last updated August 13, 2026 · v0.5-beta

Draft starting point, provided during beta and pending final legal review. Not legal advice.

Overview

This policy explains what we collect, why, how long we keep it, and your rights. We follow Canada's PIPEDA and, where it applies, the GDPR. Provider: Punchdown AV, Toronto, Ontario, Canada.

1. Two kinds of data

Account data (we are the controller): the information you give us to run your account — name, email, company name, role, and usage/log data.

Customer Data, including your clients' information (we are the processor): the catalog, quotes, projects, and any details about your clients that you enter. You (the integrator) are the controller of that data; we only process it to provide the Service, on your instructions.

2. What we collect and why

Account and profile: name, email, company, role — to create and secure your account.

Customer Data: products, quotes, projects, wiring/diagram data, and client details you enter — to provide the Service's features.

Client site access credentials: if you choose to use that feature, lock-box, gate, or alarm codes you record against a client, held encrypted and revealed only to your own people who enter your workspace PIN.

Jobsite photographs and notes your team uploads against a project, which may show the inside of a client's property.

Approval records: when a client approves a quote through a link you send, we store the name they typed, the time, and the fact of approval, as the record of that agreement between you and them.

Client portal activity: when your client signs in to their portal, the requests they raise and the updates shown to them.

Branding you upload, such as a logo. Branding files are served publicly so that clients viewing a quote without signing in can load them.

Usage and technical data: log data, device/browser info, and actions taken — to operate, secure, and improve the Service.

We do not sell your data or your clients' data, and we do not use it to train AI models.

3. AI processing

If you use the AI import feature, uploaded documents are sent to our AI provider (Anthropic) solely to extract product and structure data. Uploaded source documents are treated as untrusted, are not used to train models, and are deleted after extraction. Do not upload data you are not permitted to process.

4. Where your data lives (sub-processors)

We use vetted providers to run the Service: Supabase (database, authentication, file storage), Vercel (application hosting), and Anthropic (AI document extraction, only when you use that feature). Data is encrypted in transit (TLS) and at rest.

5. Retention and deletion

We keep Account Data while your account is active.

You can delete your data at any time: the workspace owner can close the account from Settings. Deletion is immediate and permanent. It is not scheduled or reversible, and neither you nor we can recover the data afterwards. If you would rather we acted on your behalf, contact us and we will erase it within 30 days. Either way, we may retain records the law requires us to keep.

Download your data before you close the account: Settings gives you a full export of your clients, projects, quotes, catalog and job records at any time. Site access credentials are excluded from exports by design. After closing we keep only a minimal record that the account existed and was closed, which contains no Customer Data. Uploaded AI-import source files are deleted after extraction.

6. Your rights

Depending on your location (PIPEDA / GDPR) you may: access the data we hold about you, correct it, download it (portability), delete it, or object to/restrict certain processing. To exercise these rights, contact privacy@punchdownav.com. For your clients' data, direct requests to the integrator (our customer) who controls it; we will assist them as processor.

7. Security

We protect data with row-level and application-level access controls, encryption in transit and at rest, least-privilege access, and audit logging. No system is perfectly secure; we will notify affected parties of a breach as required by law.

Client site access credentials receive additional protection: they are encrypted with a separate key, are never displayed in listings or exports, require a workspace PIN to reveal, and every reveal is recorded in the audit log. Which of your people know that PIN, and which of them should have access to a given client's codes, remains your decision and your responsibility.

Branding files are the one category we serve publicly, because a client must be able to load your logo without signing in. Do not place anything confidential there.

8. Accessibility

We aim to make the Service usable by everyone and work toward WCAG accessibility standards. If you encounter a barrier, contact hello@punchdownav.com.

9. Cookies

We use strictly necessary cookies for authentication and session management.

10. Children

The Service is not directed to children and is for business use only.

11. Changes

We may update this policy. We will post the new version with a new “Last updated” date and give notice of material changes.

12. Contact

Privacy questions: privacy@punchdownav.com · Punchdown AV, Toronto, Ontario, Canada.