Privacy policy
Last updated 16 August 2026
The short version: Punchline stores the minimum needed to run a loyalty card — who you are to the shop, and what you have earned there. We do not sell it, we do not advertise against it, and you can have a copy or have it deleted by asking at support@punchline.business.
Who we are
Punchline is loyalty software for independent businesses, built and operated from Alberta, Canada. It issues loyalty cards that live in Apple Wallet and Google Wallet on behalf of the businesses that use it.
We are governed by Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and, for commercial messages, by Canada’s Anti-Spam Legislation (CASL).
Two kinds of people, two different roles
This distinction decides who is responsible for what, so it comes first.
- Businesses that sign up for an account. Their information is ours to look after directly, and this policy governs it.
- Customers of those businesses who hold a loyalty card. That information belongs to the business. We hold and process it on their instructions, we do not use it for our own purposes, and the business’s own privacy policy governs what they do with it.
If you hold a loyalty card and want your information changed or removed, you can ask either the business or us — see support.
Business accounts
Signing in uses Google. When you do, Google gives us your name, email address, profile picture and Google account identifier. We use them to create your account, to know who is signing in, and to contact you about the service. Nothing more.
We do not receive or store your Google password. You can disconnect Punchline at any time from your Google account’s security settings, which stops us receiving anything further. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we do not sell it, do not use it for advertising, and do not let humans read it except with your permission, for security, or where the law requires it.
We also keep ordinary operational records — which pages of the dashboard were used and when, and error logs — to keep the service working and secure.
Loyalty card information
What a business collects when someone joins its program is set by that business. Typically it is some combination of:
- A name, and optionally an email address or mobile number.
- A birthday, stored as a month and a day only — never the year.
- The record of stamps, points or rewards earned and redeemed, including which location and when.
- Whether the card was added to a wallet, and whether it was later removed.
- Consent records, described below.
The stamp record is append-only. Corrections are added as new entries rather than by editing history, which is what lets a business resolve a dispute about what someone earned.
What we deliberately do not collect
- Birth years. A birthday campaign needs a month and a day. The year is sensitive identification data, so the field to store it does not exist.
- Payment card numbers. Nothing in Punchline moves money between a customer and a business. A gift card balance is a number in a ledger; the business holds the value and honours it at the counter.
- Raw device identifiers. Where we use a device fingerprint to catch fraudulent scanning, it is stored as a one-way hash.
- Personal detail in card numbers. A pass carries an opaque serial number with nothing personal in it, because passes get screenshotted and shared.
- Continuous location. Wallet passes can surface on a lock screen near a shop, but that is the phone deciding locally. The phone does not report your location to us and we do not track where you go.
Consent, and messages
Under CASL, consent to receive commercial messages has to be demonstrable. So we store it as evidence rather than as a checkbox: the channel, how it was given, when, and the exact wording that was on screen at the time.
That record cannot be filled in after the fact. If it does not exist, the consent does not exist. Every commercial message carries a way to withdraw it, and withdrawal takes effect promptly.
Messages about the card itself — a stamp added, a reward now available — are part of the service the cardholder asked for.
Cookies
This site sets no advertising or analytics cookies, and there is nothing here to consent to. Signing in to the dashboard sets one cookie, which keeps you signed in and does nothing else. Clearing it signs you out.
Who else sees it
We share personal information with service providers who make the product work, and with nobody else:
- Apple and Google, to deliver a pass to a wallet and to notify a device that a card has changed.
- Our hosting and database providers, who store the data on our behalf.
We do not sell personal information, we do not rent or trade it, and we do not use it to target advertising. We will disclose information if the law requires it, and we will tell the people affected unless we are forbidden from doing so. If we ever add another provider that handles personal information, this list changes before they do.
Where it is stored
Our infrastructure providers operate outside Canada, including in the United States, so personal information may be stored and processed there. While it is in another country it is subject to that country’s laws, including lawful access by its courts and government agencies.
How long we keep it
Business account information is kept while the account is open, and for a reasonable period afterwards to settle billing and meet record-keeping obligations.
Loyalty card information is kept while the business runs its program. When a business leaves, its data is deleted after a short window during which they can still export it. Consent records are kept for as long as the law requires us to be able to prove consent, which can outlast the rest.
Keeping it safe
Every piece of data belongs to exactly one business, and that boundary is enforced in the database itself rather than by application code remembering to filter. Access is over encrypted connections. Access tokens and contact details are kept out of our logs.
No system is perfect. If a breach creates a real risk of significant harm, we will notify the people affected and the Office of the Privacy Commissioner of Canada, as PIPEDA requires.
Your rights
Under PIPEDA you may:
- Ask what we hold about you and get a copy.
- Have it corrected if it is wrong.
- Withdraw consent, subject to legal and contractual limits.
- Ask for it to be deleted.
- Complain to us, and then to the Office of the Privacy Commissioner of Canada if our answer does not satisfy you.
Write to support@punchline.business. We will confirm who you are before acting, and we respond within 30 days. There is no charge.
Businesses using Punchline can export their full customer list to CSV at any time, on every plan including the free one. Your data is not held hostage to a subscription.
Children
Punchline is sold to businesses and is not directed at children. We do not knowingly collect information from a child. If you believe a child’s information has ended up in a program, tell us and we will remove it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects how we handle personal information, we will say so directly rather than relying on you to notice.
Contact
Questions, requests and complaints about privacy all go to support@punchline.business, which reaches the person responsible for privacy at Punchline.