Legal
Privacy policy
Effective August 5, 2026
Punctilio is a document sharing and e-signature service operated by PumpKin Baby Inc. and available at punctil.io. This policy explains what information we handle, why we handle it, where it lives, how long we keep it, and the choices you have.
Who this policy covers
Four kinds of people interact with Punctilio:
- Public-site and sign-in visitors: people who browse punctil.io, review product information, or open the sign-in page.
- Account holders: people who sign up, create workspaces, upload documents, and send links or signature requests.
- Shared-link viewers and uploaders: people who open a shared link, request access, or upload files to a request list. You don’t need an account for this.
- Signers: people invited to sign a document.
For account and billing information, and for inquiries you send us directly, we decide how the information is used and this policy is the full story. For everything a viewer, visitor, or signer provides through a shared link or signing request, the workspace that invited you decides why that information is collected, and we process it on that workspace’s behalf. If you have questions about why a workspace collected your information, contact the person or company that sent you the link. We’ll help them respond.
What we collect
If you browse public or sign-in pages
- Necessary request and preference data. Our hosting and security providers process ordinary request data needed to serve and protect the site. If you make a privacy choice, a first-party cookie stores your categories, consent version, and decision time. When either optional category is off, a first-party local-storage safety copy prevents an older allow cookie from taking effect if the newer cookie write is rejected. Both preference records last no more than six months.
- Optional analytics. If you allow Analytics, Vercel receives public or sign-in page paths, selected interaction events, the referrer URL supplied by your browser, country, region, city, device type, browser, operating system, and visitor and session identifiers. Vercel creates a hash from the incoming request to identify a visitor session, which has a 24-hour lifespan. The page being measured has its query string and fragment removed. A referring site with a permissive policy may still supply its own path or query in the referrer URL.
- Optional campaign measurement. If you allow Advertising measurement, we can store campaign tags, a public landing path, the paid-touch time, and an opaque OpenAI click reference. We do not use an OpenAI browser pixel.
- Deferred landing context. Before you choose, a sanitized landing record can remain in memory in the current tab so your choice can apply if you continue to account creation. It is not written to browser storage or sent as optional measurement before consent. Reloading or closing the tab clears it.
- Signup attribution. When a new signup creates a workspace, consented first-touch and paid-touch fields, your optional “How did you hear about us?” answer, and consent evidence can be copied into a service-only workspace record. Unless you withdraw the related optional category while signed in as the person who supplied that signup consent, those fields remain until the workspace is deleted. Withdrawal by that person removes the related first-touch or paid-touch fields but preserves the explicit “How did you hear about us?” answer and the consent record. The OpenAI click reference follows the shorter limits described below.
If you have an account
- Login details. Your email address and a password. That’s all: we don’t ask for your name. Passwords are hashed by our authentication provider and we never see them in plain text. Your login session is stored in your browser’s local storage, not in a cookie.
- Preferences. Your chosen theme, active workspace, and default room type.
- Workspace details. Workspace name, logo, brand color, public link slug, signing company name, room names and descriptions, and team invitations (the invited email address and who sent the invite). Workspace logos are stored in a public storage bucket, which means anyone with the URL can view them. Don’t upload confidential material as a logo.
- Billing. Punctilio costs $29.99 per month after a 7-day trial. Payments run through Stripe. Card and payment details are entered on Stripe’s hosted pages and never touch our systems. We store your Stripe customer and subscription identifiers, plan, seat count, and trial and billing period dates. When we create your Stripe customer record, we send Stripe your workspace name and the billing admin’s email address.
- Enterprise inquiries. If you submit our custom plan form, we store the contact email, company, seat and storage needs, budget, your free-text notes, and the IP address and browser details of the submission.
If you view a shared link
What we collect depends on how the workspace owner configured the link:
- Email-gated links. Your email address, plus any access fields the owner turned on: company, role, and reason for access. If the link requires it, an NDA acceptance timestamp and password verification state.
- Email verification codes. For links that verify your email, we send a 6-digit code. We store only a salted hash of the code, never the code itself. Codes expire within minutes. A record that your email was verified for a given link is kept for 30 days so you don’t have to re-verify constantly.
- Access logs. We record events such as link opened, file opened, page viewed, time spent per page, downloads, NDA acceptance, and security events. These events can include your email, your IP address, and your browser details. Workspace owners see this activity in their analytics, can receive it in notification emails, and can have it delivered to webhooks they configure. If the owner enabled watermarking, viewed pages may be stamped with your email address.
- Session security. Viewer sessions store your IP address and browser details, plus hashed fingerprints derived from them, to detect session hijacking. Failed password attempts are counted against a hashed version of your IP in 15-minute windows and cleared on success. Viewer session tokens expire after 8 hours, and link owners can revoke access instantly at any time.
When workspace members preview their own links, those views are excluded from recipient analytics and notifications. Viewer tracking applies to external recipients.
If you sign a document
- Signer details. Your name, email, role, and signing order, entered by the person who sent the request.
- Your signature. The typed or drawn signature and initials you provide, including a small image of a drawn signature, plus field values you fill in.
- Consent evidence. Before signing, you accept an electronic signature disclosure. We record the disclosure version, the time you accepted, and your IP address and browser details. This is the legal evidence of your consent to sign electronically.
- Audit trail. Every step of the signing ceremony (viewing, page views, field focus, access code checks, consent, decline, submission, sealing) is logged with a timestamp, IP address, and browser details. The completed envelope’s audit trail can be downloaded by the sender as a PDF or CSV that includes signer names, emails, and per-event IP addresses. Completed envelopes are locked against modification.
- Optional identity codes. If the sender requires it, a one-time access code is emailed to you. We store only a hash of the code, with an expiry and an attempt limit.
Documents and uploads
- Documents. Files uploaded to data rooms, their version history, and metadata (filename, size, type, uploader). Document buckets are private and served only through authorization-checked functions.
- Preview conversion. Office files are converted to PDF for preview by a conversion service we host. File bytes pass through it transiently during conversion.
- Room encryption. New rooms enable per-room encryption by default for supported files added directly through Files, with a separate key for each file. Recipient submissions are staged and malware-scanned, then encrypted before filing. Video and other unsupported types use standard protected storage. The room key is held on our servers, so this hardens storage at rest but is not zero-knowledge: we can still decrypt files to serve them.
- Visitor uploads. Files uploaded against a request list are held in a staging area (50 MB cap, documents and images only) and scanned for malware by a private scanning service before they’re accepted. We record the uploader’s email, filename, size, and scan result.
Emails and delivery records
All product email (verification codes, signing invites and reminders, view and download notifications, digests, security alerts) is sent through Resend. We keep delivery ledgers (recipient email and timestamp) to avoid duplicate sends, and a suppression list of addresses that bounced or complained. View and download notification emails sent to workspace owners include the viewer’s email, IP address, and browser details.
Security and anti-abuse
Rate limiting uses one-way hashes of truncated IP addresses; raw IPs are deliberately not stored there. Suspicious viewer activity can trigger a Cloudflare Turnstile challenge, which sends the challenge token and your IP address to Cloudflare for verification. Vercel BotID screens protected routes for automated traffic. None of this is used for advertising.
Why we use this information
- To provide the service: hosting documents, controlling access to links, running signing ceremonies, and delivering notifications.
- To give workspace owners the access records and audit trails they configured, which is a core feature of the product.
- To bill subscriptions through Stripe.
- To keep the service secure: malware scanning, rate limiting, session hijack detection, and bot screening.
- To create legally meaningful e-signature records, including consent evidence and audit trails.
- To respond when you contact us.
- With your choice, to understand visits to our public pages and whether a paid referral leads to a confirmed trial.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your documents for anything other than providing the service.
Cookies, browser storage, and analytics
Optional measurement is off by default. Public pages do not show a first-visit prompt. You can make a choice from the public-site footer, while creating an account, or from account settings. You can allow optional measurement, use necessary storage only, or choose Analytics and Advertising measurement separately. Necessary storage remains active so Punctilio can provide the service and remember your privacy choice.
- Privacy choice. The
punctilio_privacyfirst-party cookie stores your optional choices, consent version, and decision time for six months. The live-site cookie is host-only, Secure, and SameSite=Lax. - Necessary storage. The
sidebar:statecookie remembers whether your signed-in sidebar is open for seven days. Your login session, theme, security tokens, and requested interface preferences also use browser storage. - Analytics. If you allow it, Vercel Analytics measures public and sign-in page visits and selected interactions. It is cookieless and does not run inside the signed-in product, shared rooms, recipient uploads, or signing pages. A first-touch campaign record is treated as expired after 90 days and deleted on your next public or sign-in visit.
- Advertising measurement. If you allow it after arriving from a paid campaign, we keep a recent paid-touch record for up to 30 days or until signup. If the visit leads to a confirmed trial, our server can report a
trial_startedevent to OpenAI. The event includes the OpenAI click reference, event time, a one-way event ID unique to the trial, action source, trial plan ID, and an opt-out flag that prevents future user-level personalization. It includes no email, hashed email, IP address, browser details, workspace name, or raw Punctilio or Stripe customer or subscription ID.
We do not install an OpenAI browser pixel, use advanced matching, Google Analytics, or session replay. We honor Global Privacy Control as necessary-only, and optional measurement stays off after the signal is removed until you explicitly change your choices. You can change your choice from the public-site footer or account settings. See our cookies and measurement page for the storage list and retention details.
Service providers
We share information with these providers, each only to do its job:
- Supabase. Database, authentication, file storage, and server functions. Handles most data described in this policy.
- Vercel. Web hosting, page analytics, and bot screening. Handles request data and, when you allow Analytics, cookieless public-page and sign-in analytics.
- OpenAI. Advertising conversion measurement. When you allow Advertising measurement and a paid OpenAI visit leads to a confirmed trial, OpenAI receives the click reference and limited trial event described above. We do not send OpenAI user details or document activity.
- Stripe. Billing. Handles payment details (entered on Stripe’s pages), the billing admin’s email, and the workspace name.
- Resend. Email delivery. Handles recipient addresses and email content.
- AgentMail. Inbound company email. Handles messages and attachments sent to our support and general inboxes.
- Sentry. Application error monitoring. Handles error reports and technical request context. Performance tracing and session replay are disabled, and the SDK’s default PII collection is off. URL query strings and fragments are removed from error events and navigation breadcrumbs before transmission.
- GitHub. Source control and scheduled disaster-recovery automation. Approved Storage object bytes pass through an ephemeral GitHub-hosted runner before backup encryption; the job does not write unencrypted backup artifacts to the runner’s filesystem.
- Cloudflare. Turnstile security challenges and private disaster-recovery storage. Handles challenge tokens and the challenged visitor’s IP address, and holds backup copies of workspace data that we encrypt before upload.
- Railway. Hosts our document conversion and malware scanning services. Handles file bytes in transit during conversion and scanning.
Workspace owners also receive viewer and signer information as described above, including through notification emails and webhooks they configure. Once information reaches a workspace owner’s own systems, their practices apply.
Our core application runs on Supabase and Vercel; the other providers above handle their listed supporting functions. Contact us if you need details about current hosting or disaster-recovery storage regions.
How long we keep information
- Account data: until you close your account. Closing your account removes your workspace memberships and preferences. We keep your login email and a closure record, including any reason you provide, so we can honor the closure and prevent abuse.
- Workspace data: until the workspace is deleted. Deletion from the active service is permanent, and the workspace cannot be reopened. Active database records cascade, stored files (documents, sealed PDFs, audit reports, logos, staged uploads, archives) are removed, and the Stripe subscription is cancelled. A cleanup job retries until active copies are gone. Isolated disaster-recovery backup copies may persist for up to 30 days. We encrypt these copies before upload, and Cloudflare holds them privately and encrypted at rest. They are not available through the product or for routine restoration. Their storage lifecycle schedules deletion earlier, we monitor retention, and we retain them no longer than 30 days. If file cleanup is delayed, a preview or download link already issued can remain usable for up to 15 minutes.
- Rooms: deleting a room removes its files, versions, share links, viewer sessions, and request uploads.
- Viewer email verification codes: deleted within 10 minutes, or immediately on use. Verified-email records last 30 days.
- Viewer sessions: tokens expire after 8 hours; session records are removed when the link is deleted.
- Access log events: retained indefinitely, including after the related link, room, or workspace is deleted. These records, which can include viewer emails and IP addresses, are kept as a security and audit history. You can ask us to delete records about you (see your rights below).
- Signing records: signer details, signatures, consent evidence, and audit trails are kept until the envelope or workspace is deleted, since they are the legal record of the signature.
- Staged visitor uploads: cleaned up 24 hours after they’re superseded, rejected, or filed. Files flagged as malware are quarantined for 30 days, then deleted.
- Email suppression: soft bounces expire after 7 days; hard bounces and complaints are kept permanently so we don’t email those addresses again.
- Enterprise inquiries: kept until you ask us to delete them.
- Optional marketing records: first-touch records are treated as expired after 90 days. Paid-touch records are treated as expired after 30 days or cleared at signup. Expired records are deleted on your next public or sign-in visit. Refusing or withdrawing the related category removes its optional browser record. When you are signed in as the person who supplied the signup consent, withdrawal also removes the related first-touch or paid-touch fields from the service-only workspace record. If that person is signed out, server cleanup runs the next time they sign in on the same browser with that category still off. Choices made by other workspace members affect their browser only. The explicit “How did you hear about us?” answer and consent record are preserved.
- Server-side conversion records: an OpenAI click reference is removed after confirmed delivery, after the seven-day delivery window, or when the paid touch becomes more than 30 days old. A signed-in withdrawal also cancels a not-yet-sent conversion tied to that user's consent and removes all server-side paid-touch fields. A provider request already in flight may finish. The one-way event ID and delivery metadata, including event name, fixed source URL, status, attempts, errors, and timing, remain with the workspace until the workspace is deleted.
- Data held by Stripe follows Stripe’s own retention practices.
Security
Passwords, link passwords, share tokens, session tokens, verification codes, and signer access codes are all stored as hashes, never in plain text. Document buckets are private and access-checked; the only public bucket is workspace logos. New rooms use per-file encryption for supported direct uploads, and recipient uploads are malware-scanned before they are encrypted and filed. Rate limiting and fingerprinting use hashed, truncated identifiers.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. California residents may also have rights to know, delete, correct, and opt out of uses treated as a sale or sharing under applicable law. Punctilio does not sell personal information. You can turn Advertising measurement off at any time through Privacy choices and can contact us about any additional opt-out request.
To exercise any right, email support@punctil.io from the address involved. We may ask you to verify the request. If your information was collected because a workspace shared a link with you or asked you to sign, we may refer the request to that workspace or coordinate with them, since they control why it was collected. We will not discriminate against you for exercising your rights.
You can also act directly: account holders can close their account or delete workspaces from settings, and workspace admins can delete rooms, revoke links, and cancel sessions at any time.
Children
Punctilio is a business tool and is not directed at anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
When we make material changes, we’ll update the effective date at the top and, for significant changes, notify account holders by email or in the app. Continued use after the effective date means the updated policy applies.
Contact
PumpKin Baby Inc.
support@punctil.io