United States availability
SitePunch is offered only to people located in the United States and supports only U.S. phone numbers. It is not offered to people located in the European Economic Area, United Kingdom, or Switzerland. Public informational pages may remain visible outside the United States.
SitePunch uses network-location and phone-number country signals to enforce these limits. Location signals can be inaccurate, so you may contact support if you believe access was blocked by mistake.
Who operates SitePunch
The operator responsible for this deployment is SitePunch. Privacy contact: [email protected].
What we collect
- Phone numbers used for login and project access.
- Profile data you choose to add, such as your display name.
- Project content, including punch list items, comments, uploaded photos, and timestamps. To diagnose upload problems, we retain limited technical details about the received file, such as its name, size, format, dimensions, image entropy, and a cryptographic fingerprint.
- Security and operational data such as one-time code records, session records, administrator passkey public keys and usage metadata, invite token records, IP addresses associated with login requests, and SMS logs.
- For confirmed U.S. visitors on selected public pages only: page paths without query parameters, page title, referrer, analytics identifiers, browser and device information, and approximate location.
- When an unexpected error occurs: the error type, a technical stack trace, a generalized route, the application release, and basic browser or system details needed to diagnose the failure.
Cookies and Google Analytics
SitePunch uses a strictly necessary session cookie for up to 30 days and a language-preference cookie for up to one year when you select a language. These cookies support access, security, and a preference you requested.
Google Analytics loads only when Cloudflare confirms that a visitor is in the United States, the browser does not send a Global Privacy Control signal, and the visitor opens the homepage, About, FAQ, or Field Notes. It does not load on login, contact, legal, account, dashboard, project, upload, or API routes. SitePunch sends paths without query parameters, disables Google signals and advertising personalization in the tag, and limits browser identifiers to 60 days without renewal.
SitePunch does not load the Google tag, send cookieless pings, or retain Google Analytics identifiers presented to this deployment when a request is not confirmed as originating in the United States or includes a Global Privacy Control signal.
Error monitoring
SitePunch uses Sentry to detect unexpected failures on public pages and in the authenticated product. This monitoring is operational and is not used for advertising, profiling, or behavioral analytics.
The integration is configured not to send request or response bodies, cookies, headers, query parameters, user identity, database content, session replays, or local variables. Project, item, invite, and file identifiers, along with phone numbers, login codes, and token-like values, are generalized or removed before transmission.
Error reports are kept in Sentry for up to the event-retention period configured for SitePunch's account and no longer than reasonably needed to investigate, remediate, and prevent recurring failures. SitePunch may delete reports sooner; limited data may be kept longer only when required by Sentry's agreement or applicable law. Sentry's Data Processing Addendum describes Sentry's role and the safeguards that apply to service data.
How we use it
- To send one-time login codes.
- To authenticate users, maintain sessions, and prevent abuse or fraud.
- To operate the project workflow, including sharing project data with authorized users.
- To maintain records, troubleshoot problems, and comply with legal obligations.
When information is shared
SitePunch may use service providers needed to operate the product, such as hosting, storage, and authentication vendors acting on behalf of this deployment.
Project data is also shared with the people who are given access to the same project. If you are granted access to a project, the owner and other authorized participants may see the information you add within that project.
Cloudflare supports delivery and security; the hosting provider stores and operates the application; Twilio delivers SMS messages; Sentry processes the limited technical error reports described above; and Google processes the limited U.S. public-page analytics described above.
Text messaging originator opt-in data and consent are not sold, rented, or shared for marketing or promotional purposes. They may be provided only to service providers that help deliver or support those messages, subject to their service obligations.
Retention and security
Login codes become invalid after 10 minutes and their records are deleted after 1 day. Sessions last for up to 30 days, and expired session records are deleted after an additional 7 days. SMS logs and revoked invitations are deleted after 90 days. Google Analytics browser identifiers are configured to expire after 60 days without renewal. Active account, access, and project records are kept while the service or project remains active and longer when needed for backups, disputes, or legal obligations. Phone numbers are encrypted in the database and masked in activity records.
No system is perfectly secure. You should avoid uploading information you would not want shared with the people who have access to the project.
Access, correction, and deletion
You may request access to, correction of, or deletion of your information by emailing the privacy contact above. SitePunch may request enough information to verify your identity and may retain records when needed for security, legal compliance, or dispute resolution.
SMS disclosures and your choices
SitePunch currently uses service-related SMS text messages for login only. These messages include one-time login codes requested during sign-in. Message frequency varies. You will receive up to one message per login request. Message and data rates may apply.
Reply STOP to opt out. Reply HELP for help or email [email protected]. Carriers are not liable for delayed or undelivered messages.
Customer care email: [email protected].
Support hours: Mon-Fri 9am-5pm ET.
Because this product relies on SMS for account access, revoking consent for these service-related texts or blocking them may prevent you from signing in to projects you have been granted access to.
State privacy rights
Some U.S. states require businesses to provide privacy notices or consumer privacy rights. If a state privacy law applies to this deployment, SitePunch will handle requests in the manner required by that law.
Changes to this policy
This policy may be updated as the product changes or legal requirements change. The current version will be posted on this page with a revised effective date.