Privacy Policy — Punchwell, by Sturdyhaus

DRAFT — pending attorney review. This page is a working draft written in plain language. It has not yet been reviewed by a lawyer, and several details below are still placeholders shown in [brackets]. Do not treat it as final or as legal advice. Where this draft and the final, attorney-reviewed version disagree, the final version controls.

Last updated: [DATE]
Applies to: the Punchwell storefront at [sturdyhaus.com], operated by [LEGAL ENTITY NAME] (“Sturdyhaus,” “we,” “us,” “our”), and the account/billing system at [app.sturdyhaus.com] — a WHMCS portal hosted and operated on our behalf by our billing partner, Kevlar Hosting.


The short version

This policy covers two things only: our website ([sturdyhaus.com]) and our account and billing system ([app.sturdyhaus.com]). That’s where we collect a small amount of information so you can buy, renew, and get support for Punchwell.

The Punchwell plugin itself is different. Punchwell is self-hosted software that runs inside your WordPress site. It does not phone home, it sends us no data, and we have no access to your employee, attendance, or payroll records. We literally cannot see them. (More on this below — see “About the plugin”.)

We try to collect as little as possible, we don’t sell your data, and we tell you plainly who the few outside services are that help us run the business.


1. Who we are

Punchwell is a product of [LEGAL ENTITY NAME], trading as Sturdyhaus, located at [BUSINESS ADDRESS].

If you have any question about this policy or your data, contact us at [privacy@sturdyhaus.com] (or by mail at the address above). For anything we should treat as a formal data-protection request, see Section 9.


2. What this policy does and does not cover

It covers:

  • The Sturdyhaus marketing website ([sturdyhaus.com]).
  • The Punchwell account/billing portal at [app.sturdyhaus.com] — a WHMCS system operated for us by our billing partner Kevlar Hosting (see Section 5) — where you create an account, buy or renew a license, manage billing, and open support tickets.

It does not cover:

  • The Punchwell plugin running on your own WordPress site. That software is self-hosted. It collects no data on our behalf and transmits nothing to us. Any employee, attendance, leave, or payroll data your team enters lives in your WordPress database, on your server, under your control. For that data, you are the controller and your own privacy policy applies. (See “About the plugin”.)
  • Third-party websites we may link to. Their privacy practices are their own.

3. What we collect, and why

We only collect what we need to sell and support the software. Here’s the whole list.

Account information

When you create an account or buy a license, we collect: your name, email address, a password (stored hashed, not in plain text), and optionally a company name. This lets us give you an account, deliver your license key and downloads, and contact you about your purchase.

Billing information

When you buy or renew, we collect billing details — name, billing address, and the email tied to the purchase — plus a record of your orders, invoices, licenses, and renewals.

We do not store full credit-card numbers. Card payments are processed by our payment processor ([PAYMENT PROCESSOR — e.g. Stripe / PayPal]); your card details go to them, not to us. We receive back only a confirmation and limited reference data (for example, the card brand and last four digits, and a token used for renewals). See Section 5 for who that is.

Support information

When you open a support ticket or email us, we collect whatever you choose to put in your message — your question, and any details, screenshots, or files you attach. We use this only to help you. Please don’t paste real employee data or sensitive personal information into a support ticket; describe the problem instead, and redact screenshots where you can.

Website and technical information

When you visit our site, our servers and tools may log standard technical data: IP address, browser type, pages viewed, referring page, and timestamps. This is ordinary web-server and security logging. We also use cookies and may use analytics — see Section 4.

What we don’t collect

We don’t ask for and don’t want: government ID numbers, payment-card numbers (those go to the processor), your employees’ data, or any “special category” / sensitive personal data. If you send us something we don’t need, we’ll delete it.


4. Cookies and analytics

[PLACEHOLDER — confirm before publishing.] The exact cookies and analytics tools below depend on what we actually deploy. Update this section to match the live configuration, and make sure any cookie banner / consent tool reflects it.

We use cookies (small files stored by your browser) for a few purposes:

  • Essential cookies — needed for the site and the account/billing portal to work (for example, keeping you logged in and securing forms). These can’t be switched off without breaking the site.
  • Preference cookies — remember choices like display settings, where applicable.
  • Analytics cookies[if used] help us understand which pages are useful and where people get stuck, using [ANALYTICS PROVIDER — e.g. a privacy-friendly, cookieless analytics tool / Google Analytics / Plausible / none]. [State whether analytics is anonymized / IP-truncated / cookieless.]

We do not use advertising or cross-site tracking cookies [confirm].

Your choices: you can control or block cookies in your browser settings; blocking essential cookies may break parts of the site. [If a consent banner is used: describe it here and how to change consent later.]


5. Who we share data with (processors)

We don’t sell your personal information, and we don’t share it for anyone else’s advertising. We do rely on a few trusted service providers (“processors”) to run the business. Each only gets what it needs to do its job, and each is bound to protect it.

Provider What it does What it handles
[PAYMENT PROCESSOR — e.g. Stripe / PayPal] Processes payments and renewals Card/payment details, billing identity
[EMAIL PROVIDER — e.g. transactional email / SMTP service] Sends account, license, receipt, and support emails Your name and email, message contents
[WEBSITE HOSTING PROVIDER] Hosts our marketing website Whatever is stored or logged on our web server
Kevlar Hosting (billing partner) Hosts and operates our account/billing portal (WHMCS) at kevlarhosting.biz, presented to you as app.sturdyhaus.com Your account, license, order/renewal, and support-ticket data
[ANALYTICS PROVIDER, if any] Website usage measurement Technical/usage data per Section 4
[SUPPORT / HELPDESK TOOL, if separate from WHMCS] Manages support tickets Your support messages and contact info

[Confirm this list and add or remove rows to match the live stack. Our WHMCS account/billing portal is operated on our behalf by our billing partner Kevlar Hosting (kevlarhosting.biz), presented to customers as app.sturdyhaus.com; it is the system of record for account/billing data. Confirm the payment processor and website host.]

We may also disclose information if required by law (for example, a valid legal request), or to protect our rights, security, or users — and, if we ever sell or transfer the business, as part of that transaction (you’d be notified).


6. Where your data is stored / international transfers

[PLACEHOLDER — confirm hosting and processor locations.]

Our website and account/billing portal are hosted in [REGION / COUNTRY]. Some of our processors (above) may store or process data in [REGION(S)]. If you’re in the EU/UK and your data is transferred outside your region, we rely on appropriate safeguards [e.g. Standard Contractual Clauses / the relevant adequacy decision] to protect it. [Confirm the specific mechanism with counsel.]


7. How long we keep it (retention)

We keep personal data only as long as we have a reason to.

  • Account and license records — kept while your account is active, and for a reasonable period afterward so we can honor renewals, support, and your purchase history.
  • Billing and invoice records — kept as long as needed to meet tax, accounting, and legal obligations [typically [N] years — confirm with counsel for your jurisdiction].
  • Support tickets — kept for [RETENTION PERIOD] so we can follow up and improve support, then deleted or anonymized.
  • Web/analytics logs — kept for [RETENTION PERIOD], then deleted or aggregated.

When we no longer need data, we delete or anonymize it. You can ask us to delete your data sooner — see your rights below.


8. Your privacy rights

Depending on where you live, you have rights over your personal data. We honor these rights for everyone where we reasonably can, regardless of location.

If you’re in the EU / UK (GDPR / UK GDPR), you can ask to:

  • Access the personal data we hold about you, and get a copy.
  • Correct data that’s wrong or incomplete.
  • Delete your data (“right to be forgotten”), subject to records we must keep by law (like invoices).
  • Restrict or object to certain processing.
  • Port your data — receive it in a portable format.
  • Withdraw consent at any time, where we relied on consent (this doesn’t affect what we already did lawfully).
  • Complain to your data-protection authority.

Legal bases we rely on (GDPR): performing our contract with you (account, license, support); our legitimate interests (running, securing, and improving the business); your consent (where we ask for it, e.g. certain analytics or marketing email); and legal obligation (e.g. keeping tax records).

If you’re in California (CCPA / CPRA), you can ask to:

  • Know what personal information we’ve collected about you and how we use it.
  • Access and delete that information, subject to legal exceptions.
  • Correct inaccurate information.
  • Opt out of “sale” or “sharing” of personal information. We do not sell or share your personal information in the way those laws define it, and we don’t process it for cross-context behavioral advertising. [Confirm against the live analytics/ad configuration.]
  • Not be discriminated against for exercising these rights.

How to make a request: email us at [privacy@sturdyhaus.com] from the address tied to your account, or use [the contact method at app.sturdyhaus.com]. We may need to verify your identity before acting. We’ll respond within the time the law requires [GDPR: typically one month; CCPA: typically 45 days]. An authorized agent may make a request on your behalf with proof of authorization.


9. Contact and complaints

Questions, requests, or concerns about your data:

  • Email: [privacy@sturdyhaus.com]
  • Mail: [LEGAL ENTITY NAME], [BUSINESS ADDRESS]

If you’re in the EU/UK and you believe we’ve handled your data improperly, you can also complain to your local data-protection authority — though we’d appreciate the chance to put it right first.


10. Children

Our website, store, and software are for businesses and aren’t directed at children. We don’t knowingly collect personal data from anyone under [16 / the age set by your jurisdiction]. If you believe a child has given us data, contact us and we’ll delete it.


11. Security

We take reasonable measures to protect the data we hold — encryption in transit (HTTPS), hashed passwords, access controls, and keeping payment-card handling with our PCI-compliant payment processor rather than on our own systems. No method of storage or transmission is perfectly secure, so we can’t guarantee absolute security, but we work to protect your information and to limit what we collect in the first place.


12. Changes to this policy

We may update this policy as our business, tools, or the law change. We’ll post the new version here with a fresh “Last updated” date, and for material changes we’ll give clearer notice where appropriate [e.g. email to account holders]. The current version always lives at [sturdyhaus.com/legal/privacy/].


About the Punchwell plugin

This deserves repeating, because it’s the heart of how Punchwell works:

Punchwell is self-hosted. Your team’s data stays on your server, and it never comes to us.

  • The plugin runs inside the WordPress site you already operate.
  • Your employee, attendance, leave, and payroll records live in your WordPress database — they are never transmitted to Sturdyhaus.
  • Punchwell has no call-home: all outbound network code was removed and verified, so the plugin does not send usage data, telemetry, or license check-ins to us. [If a future update/licensing channel is added, this section must be revised to describe exactly what it sends.]
  • The only external content the plugin loads is standard WordPress fare you can turn off: optional YouTube tutorial embeds and Gravatar avatars. Those involve third parties (Google / Automattic) on your site, not us.

For the data your business stores in Punchwell, your organization is the data controller and your own privacy obligations apply. We’re not a processor of that data, because we never receive it.


Reminder: this is a draft for attorney review. Replace every [bracketed] placeholder, confirm the cookie/analytics and processor sections against the live configuration, and have counsel verify retention periods, international-transfer mechanisms, and the GDPR/CCPA language for your specific entity and jurisdiction before publishing.