Privacy Policy

Effective Date: August 23, 2026

This Privacy Policy ("Policy") explains how Punch Software Inc. ("Punch," "Company," "we," "us," or "our") collects, uses, discloses, and protects information when you access or use the Punch AI-powered purchasing agent platform and related services ("Service").

The Service includes Punch's AI-powered construction purchasing, purchase order, invoice, expense, reporting, supplier and material workflow, accounting integration, email and document processing, and automation features.

By using the Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree, do not use the Service. If a customer has a signed subscription agreement, order form, data processing addendum (DPA), or other written agreement with Punch that contains different privacy, data-processing, or data-use terms, that signed agreement controls for that customer to the extent of any conflict with this Policy.

1. Information We Collect

We collect the following categories of information to operate and improve the Service:

A. Information You Provide Directly

This includes:

  • Company, account, and user contact information
  • Supplier information and supplier contacts
  • Purchase orders, invoices, quotes, expenses, daily reports, and other financial documents
  • Emails, email metadata, attachments, and other documents uploaded to the Service
  • Project and job data, cost codes, vendor lists, customer lists, and material/SKU data
  • Workflow rules, approval rules, and other configuration data
  • Communications with our support team
  • Preferences and settings

B. Information Automatically Collected

We automatically collect:

  • Log data (timestamps, usage patterns, errors)
  • Device and browser information
  • IP address and approximate location
  • AI agent activity logs and usage logs
  • Authentication logs, access times, and security events
  • Data processing statistics and integration logs

C. Email and Document Data

When you connect your email or storage accounts, we may collect:

  • Email bodies
  • Attachments (PDFs, images, spreadsheets)
  • Supplier correspondence
  • Invoices, quotes, shipping notices, or purchase order confirmations
  • Metadata (senders, recipients, timestamps)

We only process email content to provide the Service.

D. Third-Party System Data

If you link third-party systems (e.g., accounting software, cloud storage), we may collect:

  • Vendor lists
  • Customer lists
  • Material and SKU data
  • Project or job cost codes
  • Accounting records and financial data from connected accounting systems
  • Integration logs and sync history

You control which integrations are active.

E. Derived Data / Platform Data

Through operation of the Service, Punch generates aggregated, de-identified, normalized, or system-level information ("Derived Data" or "Platform Data"), such as:

  • Supplier and material directories
  • Taxonomies, mappings, and labels
  • Extraction, classification, coding, matching, normalization, and automation rules
  • Analytics, usage insights, and system performance data
  • Model and workflow improvements

Derived Data is designed not to identify any customer or reveal customer-specific non-public business information.

F. Sensitive Data Restriction

The Service is not designed for special-category or regulated data. Customers should not submit protected health information, payment card data, biometric data, government identifiers, children's data, or other sensitive or special-category data to the Service unless Punch expressly agrees in writing.

2. How We Use Your Information

We use User Data and other information to:

A. Operate and Deliver the Service

Including:

  • Generating purchase orders
  • Parsing invoices
  • Matching POs to invoices
  • Communicating with suppliers
  • Sending emails on your behalf
  • Automating workflows
  • Providing analytics and reporting

B. Improve the AI Agent and System Performance

We use customer data to provide, secure, maintain, support, analyze, and improve the Service, including to:

  • Improve Punch's own automation, extraction, classification, matching, and workflow logic
  • Improve accuracy of AI-assisted workflows and integrations
  • Fix errors and debug issues
  • Optimize system speed and performance
  • Detect anomalies or improper configurations

Punch will not use customer data to train third-party general-purpose AI models or foundation models for model improvement unless the customer expressly agrees in writing.

C. Customer Support and Service

We use data to:

  • Communicate with you
  • Resolve issues
  • Verify account status
  • Provide onboarding and training
  • Deliver updates, notices, and alerts

D. Compliance, Security, and Legal Purposes

We may use data to:

  • Detect and prevent fraud
  • Enforce our Terms of Service
  • Respond to legal requests
  • Maintain security and audit logs

E. Create Aggregated and Anonymized Insights

Punch may use aggregated and de-identified Derived Data to develop and improve:

  • Supplier and material directories, taxonomies, and mappings
  • Extraction, classification, coding, matching, and normalization rules
  • System analytics and product performance
  • Internal forecasting and operational tooling

Punch will not use customer-specific pricing data, purchasing data, invoice data, supplier terms, or other customer-specific commercial data for cross-customer pricing benchmarks, external benchmarking products, or supplier-network products unless the customer separately opts in or agrees in writing. This does not restrict Punch's use of aggregated or de-identified Derived Data that does not identify the customer or reveal customer-specific non-public business information.

3. How We Share Information

We do not sell personal information. We only share information as described below.

A. Third-Party Service Providers

We use trusted third-party processors to operate the Service, such as:

  • Cloud hosting providers
  • Email providers and email integration services
  • OCR and document processing vendors
  • LLM and AI providers, such as OpenAI, Anthropic, or similar providers
  • Analytics, logging, and monitoring tools
  • Accounting systems and other integration providers
  • Customer support systems

These processors handle data only as needed to provide and support the Service and are subject to appropriate confidentiality, security, or data-processing obligations.

B. Integrations You Configure

If you connect third-party systems, your data may be shared based on:

  • API interactions
  • Data sync settings
  • Vendor email exchanges
  • Automated workflows

You control which integrations are active.

C. Legal Compliance

We may disclose information to comply with:

  • Subpoenas
  • Court orders
  • Regulatory requests
  • Lawful investigations

We will notify you when legally permitted.

D. Business Transfers

If Punch is involved in a merger, acquisition, financing, or sale, User Data may be transferred as part of that transaction.

E. SMS Messaging Consent

All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

This includes, but is not limited to: phone numbers used for SMS communications, records of consent to receive text messages, timestamps and method of consent, and any opt-in or opt-out preferences.

4. Data Ownership

Customers retain ownership of their raw customer data, including invoices, purchase orders, supplier information, email content uploaded or connected to the Service, internal workflows, pricing data, and other customer business information.

Punch does not claim ownership over customer data. Punch processes customer data only as needed to provide, secure, maintain, support, analyze, and improve the Service, including AI-assisted workflows and integrations, and as otherwise permitted by this Policy or a signed agreement with the customer.

5. Aggregated, De-Identified, and Platform Data

Punch may create and use Derived Data and Platform Data — including supplier and material directories, taxonomies, mappings, labels, extraction and classification rules, matching and normalization logic, automation rules, analytics, usage insights, and system performance data — to operate, improve, and secure the Service.

Derived Data and Platform Data are designed not to identify any customer or reveal customer-specific non-public business information. Punch will not use customer-specific commercial data for external pricing benchmarks or supplier-network products without the customer's separate opt-in or written agreement.

6. Data Processing With AI/LLM Providers

Punch uses third-party AI providers and vendors to provide the Service. Customer data may be sent to these providers to:

  • Parse documents
  • Classify emails
  • Extract invoice fields
  • Generate summaries
  • Interpret text
  • Improve purchase order suggestions

These providers process customer data only as needed to provide and support the Service and are subject to appropriate confidentiality, security, or data-processing obligations. Punch will not use customer data, and does not authorize AI providers to use customer data, to train third-party general-purpose AI models or foundation models for model improvement unless the customer expressly agrees in writing.

7. Data Security

We use industry-standard security controls including:

  • Encryption at rest and in transit
  • Secure access controls
  • Network firewalls
  • Audit logging
  • Continuous monitoring
  • Secure development practices

No system is 100% secure, and we cannot guarantee absolute security.

8. Data Retention & Deletion

Retention

Punch retains customer data while the customer's account is active and as needed to provide the Service. Following termination, Punch may retain customer data as required for legal compliance, dispute resolution, security, backup retention, and other legitimate business purposes. Backup copies may persist for a limited period in accordance with normal backup rotation. Punch may retain Derived Data and Platform Data that does not identify the customer or reveal customer-specific non-public business information.

Export and Deletion

Customers may request export or deletion of their customer data. Upon a verified request or account termination, Punch will delete customer data from active production systems within a reasonable period, subject to the retention exceptions above. Backups will be overwritten in accordance with normal rotation cycles. Aggregated and de-identified Derived Data will be retained.

To request export or deletion, contact hello@buildwithpunch.com.

9. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access User Data
  • Correct inaccurate information
  • Delete certain information
  • Request an export of data
  • Restrict processing in limited circumstances
  • Withdraw consent to integrations
  • Object to certain uses

We will honor applicable lawful requests.

10. Customer Responsibilities

To protect your data, you must:

  • Secure your login credentials
  • Secure your email accounts
  • Maintain your own internal access controls
  • Ensure authorized personnel review and approve AI actions
  • Keep connected system credentials up to date
  • Notify us immediately of unauthorized access

Punch is not liable for breaches caused by:

  • Compromised customer email accounts
  • Insecure customer networks
  • Misconfigured access controls
  • User negligence

11. International Data Transfers

We may transfer data to the United States or other countries. We use appropriate safeguards including:

  • Contractual protections
  • Industry-standard security measures
  • Privacy frameworks (when available)

12. Children's Privacy

The Service is a B2B product intended for use by businesses and their authorized personnel. It is not directed to children, and Punch does not knowingly collect information from children. Customers should not submit children's data to the Service.

13. Signed Agreement Controls

If a customer has a signed subscription agreement, order form, data processing addendum, or other written agreement with Punch that contains different privacy, data-processing, or data-use terms, that signed agreement controls for that customer to the extent of any conflict with this Policy.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will include:

  • Updated "Effective Date"
  • 30 days' notice for material changes

Your continued use of the Service constitutes acceptance.

15. Contact Us

If you have questions, requests, or concerns, contact us:

Punch Software Inc.

Email: hello@buildwithpunch.com