◇Legal
Privacy Policy
Effective date: 11 July 2026
Hostspica ("we", "our", or "us") operates the PunchMemobile application ("App") and the website at www.punchme.online ("Site"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services.
By using PunchMe, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
1. Information We Collect
1.1 Account Information
- Mobile number — collected during sign-in via Firebase OTP authentication.
- Name, email, designation, department — provided by your employer during account setup.
- Date of birth, gender, blood group, address, emergency contact — optionally entered by the employee in the Profile section.
- Employee ID, joining date, shift assignment — set by your employer.
1.2 Biometric Data
- Face embeddings — when face recognition is enabled by your employer, the App captures a photo and generates a 192-dimensional numerical embedding using an on-device MobileFaceNet model. The embedding (not the original photo) is stored in Firestore and used for future attendance verification.
- Face liveness detection (eye openness, head pose) is performed on-device using Google ML Kit. Results are not stored.
- Device biometric authentication (fingerprint, face ID) may be used via Android's BiometricPrompt API. PunchMe never accesses or stores raw biometric data from the device sensor — this is handled entirely by the Android OS.
1.3 Location Data
- Precise GPS coordinates — collected at the time of check-in and check-out. Used to verify that the employee is within the configured office geofence.
- Location is collected only in the foreground when the user actively taps the punch button. PunchMe does not track location in the background.
- GPS accuracy and a mock-location flag are also recorded to detect GPS spoofing.
1.4 Camera / Photos
- Selfie photos — when selfie capture is enabled by your employer, a photo is taken at check-in and uploaded to Cloudflare R2 cloud storage via a Firebase-authenticated presigned URL.
- Photos are stored securely and accessible only to your employer's admin dashboard.
1.5 Device Information
- Device ID — stored in Firestore to prevent unauthorized use of the account from multiple devices.
- FCM registration token — used to deliver push notifications.
1.6 Usage Data
- Check-in and check-out timestamps, verification method used, face match score, and fraud flags — stored in Firebase Firestore as attendance records.
- This data is visible to your employer's authorized admin users.
2. How We Use Your Information
- To verify your identity at check-in and check-out
- To record attendance and generate reports for your employer
- To detect and flag fraudulent attendance attempts
- To send push notifications (attendance confirmations, leave updates, company notices)
- To provide and improve the PunchMe service
- To comply with legal obligations
We do not sell your personal data to third parties. We do not use biometric data for any purpose other than attendance verification within your employer's account.
3. Data Sharing
We share your data only in the following circumstances:
- Your employer — attendance records, selfie photos, face enrollment status, and fraud flags are accessible to your employer's authorized admin and HR users.
- Firebase / Google — authentication, database (Firestore), and push messaging (FCM) are provided by Google Firebase.
- Cloudflare — selfie photos are stored in Cloudflare R2 object storage.
- Google ML Kit — face detection is performed on-device using Google ML Kit. No image data is sent to Google servers by ML Kit in on-device mode.
- Legal requirements — we may disclose information if required by law, court order, or to protect the rights and safety of users.
4. Data Retention
- Attendance records are retained as long as your employer's account is active.
- Face embeddings are deleted when you or your employer deletes the face enrollment.
- Selfie photos are retained until your employer deletes them or until account termination.
- Upon account deletion, all personal data is deleted within 30 days.
5. Data Security
All data in transit is encrypted using HTTPS/TLS. Data at rest in Firestore and Cloudflare R2 is encrypted using AES-256. Face embeddings are stored as numerical arrays — the original face photo is not stored after enrollment. Access to data is controlled via Firebase Security Rules and authenticated API routes.
6. Your Rights
Under applicable Indian privacy laws (DPDP Act 2023) and GDPR where applicable, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Withdraw consent for biometric data processing
- Lodge a complaint with the appropriate data protection authority
To exercise these rights, contact your employer's HR administrator or email us at privacy@hostspica.com.
7. Children's Privacy
PunchMe is intended for use by working adults (18+). We do not knowingly collect personal information from anyone under 18. If we become aware that a minor has provided us with personal data, we will delete it promptly.
8. Third-Party Services
Our App uses the following third-party services, each governed by their own privacy policies:
- Google Firebase (Auth, Firestore, FCM, Cloud Functions)
- Google ML Kit (on-device face detection)
- Cloudflare R2 (selfie photo storage)
- Razorpay (payment processing)
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify users of material changes via the App or email. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related questions or data deletion requests: