Punchkeep privacy policy
Last updated: October 3, 2026
Punchkeep is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Punchkeep app for your CRM's app marketplace and the pages at hl.greatwork.company/packs, including members' credits pages and the front desk check-in screen.
What we collect
When you install Punchkeep on a business account, your CRM gives us access tokens for the permissions you approve. With them, for that business account only, we read and store:
- Your packages: names, session counts, expiry rules, the calendars they cover and the product and price ids that sell them, and your settings.
- Members: the CRM contact id and name of each person who has or shares a pack.
- Credits: each pack's balance and expiry, and a history of every credit added, used, returned, expired or adjusted, with the note and the name of the team member or "Payment", "Workflow" or "Calendar" that made it.
- Bookings on the calendars your packages cover: the appointment id, contact id, calendar id, start time and status, so we know whether a credit was used for it.
- Check-ins: when a member was checked in and the name the front desk typed.
- Trigger subscriptions: which of your workflows use our triggers.
From paid orders and invoices we read only the contact id and name, the product and price ids, quantities and whether the payment was live or a test. We never receive card or bank details. We do not read conversations, notes, other contact fields or contacts who never had a pack.
When you open Punchkeep inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and business account id). We use it to confirm you are signed in. When someone opens a credits page or the front desk screen, our server sees their IP address, which we use only to limit repeated requests and do not store.
Why we use it
Only to keep members' credit balances, use and return credits as bookings change, show members their balance, check them in, write the balance fields on the contact and start the workflows that use our triggers. We do not sell data, use it for advertising, or train models on it.
Where it goes
- Your CRM. We write three fields on the member's contact (Credits balance, Credits expire on, Credits page link), add a tag and a note when someone books without credits, and set an appointment's status to showed on check-in (or cancelled, if you turn that on for bookings without credits).
- The member. Their credits page shows their own balance, packs, recent activity and check-in code to anyone holding their private link.
- No one else. We use no subprocessors besides our host: a DigitalOcean server in New York, USA.
How it is protected
Access tokens, member names, package definitions, notes and settings are encrypted at rest with AES-256-GCM. All traffic uses HTTPS. Credits page links, check-in codes and front desk links are signed; a member's link and code can be replaced (the old ones stop working) and the front desk link can be reset or turned off at any time. The front desk link is kept in the part of the address that browsers never send to a server. Requests from your CRM are checked: webhooks by their digital signature, the app page by your CRM's signed user record, workflow actions and triggers by a secret key.
How long we keep it
Active packs and their history are kept while the app is installed. Packs that are used up, expired or removed are deleted, with their history, 24 months after they close. Booking and check-in records are deleted 6 months after the appointment. When you uninstall Punchkeep, or click Disconnect inside the app, we delete the access tokens and everything we keep for that business account right away. When a contact is deleted in your CRM, we delete that member's packs, history, bookings and check-ins. The contact fields, tags and notes we wrote in your CRM stay there, under your control. Server logs that may contain IP addresses are kept for up to 14 days.
Your rights
You can see every member, pack and ledger entry inside the app and delete everything by uninstalling. For access, correction or deletion requests under GDPR, UK GDPR or CCPA, email hello@greatwork.company. If you are a member of one of our customers, contact that business first; we act on their instructions as a processor.
Changes
We will post changes here and update the date above. Material changes are announced in the app.
Contact
hello@greatwork.company. We reply within one business day.