Privacy Policy
Effective date: August 15, 2026
Controller: Bundle Up Technologies LLC
Postal address: 2108 N St, Sacramento, CA 95816, United States
Support and privacy contact: support@bundleup.tech
Phone: +1 (916) 538-5427
Punch Promoter is an offline, single-player boxing management game published by Bundle Up Technologies LLC. The app does not require an account. You play on your own device against a simulated world. There are no ads, we do not track you across other companies' apps or websites, and we do not sell your personal information.
Bundle Up Technologies LLC is the data controller responsible for the limited data described in this policy. If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, this policy explains the legal bases we rely on and the rights you have.
Information Stored On Your Device
Punch Promoter stores your game saves on your device. Save data can include your save slot, promoter name, promotion name, gym name, selected country, and simulated gameplay data such as boxers, gyms, fights, rankings, in-game messages, finances, staff, history, and awards.
We do not automatically transmit this save data to our servers, and we do not currently run a cloud-save service for it. Your operating system may include app data in device backups depending on your device and backup settings. Information that you voluntarily type into a feedback or support message is transmitted to us as described below, so do not paste or attach a save file or include information that is not needed to explain the issue.
Diagnostics
Punch Promoter uses Sentry to collect crash, error, session, and performance diagnostics when Settings → "Share crash reports" is enabled. These diagnostics help us find and fix bugs and keep the app stable. Sentry processes this data on infrastructure hosted in the United States.
We configure Sentry not to send default personally identifying information: we do not send your IP address, email, or username. Diagnostics can include technical device information (such as device model, operating system version, and app version), a diagnostic trail of recent in-app events (breadcrumbs), and memory readings that help us diagnose crashes. We avoid sending player-entered names or purchase receipts in diagnostics. Diagnostics are retained for 90 days.
You can turn diagnostics off at any time in Settings → "Share crash reports." Turning the setting off stops new Sentry diagnostics going forward.
The first version of the in-app feedback form does not create or send a Sentry event identifier and does not automatically link feedback to Sentry diagnostics. An authorized administrator may manually attach an existing diagnostic event reference while investigating a report, but doing so does not copy your feedback message or reply email into Sentry. When Share crash reports is off, submitting feedback does not create a new Sentry event.
Feedback and Support
You may privately send us a bug report, feature request, balance suggestion, or other feedback through the app or by email. We may also manually record a paraphrased report received by email or posted on a public forum so that we can investigate and triage it.
Depending on how you contact us and the choices you make, a feedback record can contain:
- The report type and message you submit.
- An optional reply email. We use it only to respond about the report or related support request, not to add you to a marketing or newsletter list.
- Optional technical details that you choose to include: app version, build number, platform, operating system version, device model, locale, and the app screen from which you opened feedback. The app shows these fields before you submit them, and the technical-details control is off by default.
- A random, single-submission identifier and the
FB-reference we return to you. These identify the report, not an account or persistent user profile. - Triage information created by our staff, such as status, priority, internal investigation notes, and the version in which an issue was resolved.
- An existing Sentry diagnostic event reference if an authorized administrator manually attaches one while investigating the report. The in-app form does not collect or send this reference.
- For a report recorded from email or a public forum, the source type and, when needed, a source URL. We aim to paraphrase the product issue and avoid retaining usernames, profile URLs, or unrelated personal information. A source URL may nevertheless identify the public post or author.
To prevent automated abuse, our server uses your network address briefly to enforce a submission limit. It immediately transforms the address into a keyed digest held in process memory for the short rate-limit window. We do not store the raw address or digest on the feedback record or expose it in the admin inbox.
The in-app feedback form does not accept save files, screenshots, attachments, purchase receipts, advertising identifiers, analytics identifiers, or persistent device identifiers. Please do not place sensitive personal information, another person's information, or confidential material in a feedback message. We do not put feedback text, reply emails, or technical context into analytics events.
If you do not provide an email, we cannot reply. Keep the FB- reference if you may later ask us to locate or delete an anonymous report.
Analytics
Punch Promoter uses Amplitude to understand basic app usage, such as app opens, screen views, paywall views, purchase flow events, restore flow events, and weekly gameplay progression. We use these events to understand product health and improve the app. Amplitude processes this data on infrastructure hosted in the United States.
Analytics use an anonymous, automatically generated device identifier. We do not set a user ID, and we disable Amplitude's collection of IP address, city, region, carrier, and advertising identifier. Analytics events do not include player-entered names, gym names, promotion names, feedback messages, reply emails, or free-form save data.
- If you are in the EEA, the United Kingdom, or Switzerland, we ask for your consent at first launch before any analytics run. Analytics stay off unless you opt in.
- Everyone can turn analytics on or off at any time in Settings → "Share anonymous usage data."
Purchases
Punch Promoter offers Promoter Pass as a one-time in-app purchase. The current Promoter Pass benefit is extra save slots. Apple is the merchant of record: purchases are processed by the Apple App Store, and we do not receive your payment card number from the app store. RevenueCat is used with an anonymous identifier to validate purchases and manage the Promoter Pass entitlement.
Consent and Your Controls
We keep your choices in your hands:
- First launch (EEA, UK, and Switzerland). Before analytics run, we ask whether you want to share anonymous usage data. Analytics remain off until you opt in.
- Settings toggles. You can change your mind at any time:
- "Share anonymous usage data" controls Amplitude analytics.
- "Share crash reports" controls Sentry diagnostics.
- Feedback. Sending feedback is optional. You choose whether to provide a reply email and whether to include the technical details shown by the app. Pressing Submit sends only the displayed feedback fields that you chose to include.
- Turning a setting off stops the corresponding future collection. It does not delete information already collected; see the deletion section below.
How We Use Information
We use the information described in this policy to:
- Provide, maintain, secure, and troubleshoot Punch Promoter.
- Validate purchases and restore entitlements.
- Respond to support requests when you give us a way to reply.
- Investigate, triage, and resolve bug reports and other feedback.
- Analyze feedback themes and basic product health to decide how to improve the game.
- Prevent spam, automated submissions, fraud, and misuse.
- Meet legal, accounting, and App Store obligations.
We do not use a feedback reply email for marketing, sell feedback information, or publish a private report as a testimonial without separate permission.
Legal Bases for Processing
For users in the EEA, the United Kingdom, and Switzerland, the General Data Protection Regulation (and equivalent UK and Swiss law) requires us to have a legal basis for processing personal data. Our bases are:
- On-device game data — not automatically transmitted to us, so we do not process the copy held only on your device.
- Purchases — performance of a contract (Article 6(1)(b)), so we can deliver and restore the Promoter Pass you buy. Apple acts as the merchant of record for the payment itself.
- Diagnostics (Sentry) — our legitimate interests (Article 6(1)(f)) in keeping the app stable and fixing bugs. You can opt out at any time in Settings.
- Analytics (Amplitude) — your consent (Article 6(1)(a)) where consent is required, which is why we ask at first launch in the EEA, the UK, and Switzerland. Where consent is not required, we rely on our legitimate interests (Article 6(1)(f)) in understanding product health, with an opt-out available to everyone in Settings.
- Feedback and support — performance of a contract (Article 6(1)(b)) where processing is needed to provide support you request, and our legitimate interests (Article 6(1)(f)) in responding to users, investigating problems, securing the service, and improving the game. We minimize reports recorded from public sources and do not use an optional reply email for unrelated marketing.
- Legal compliance — compliance with legal obligations (Article 6(1)(c)) and the establishment, exercise, or defense of legal claims where applicable.
Service Providers
We use service providers to operate and improve the app:
- DigitalOcean to host our feedback API and database in the United States.
- Sentry for crash, error, session, and performance diagnostics.
- Amplitude for basic product analytics.
- RevenueCat for purchase validation, entitlement status, and purchase restore support.
- Apple App Store for in-app purchase billing and purchase records.
These providers process information on our behalf or as otherwise described in their own terms. We do not sell personal information, and we do not receive your payment card number from the app store.
International Data Transfers
The service providers named above process data in the United States. If you use Punch Promoter from the EEA, the United Kingdom, or Switzerland, this means your data may be transferred to and processed in the United States. Where required, these transfers are covered by appropriate safeguards, such as the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU-US Data Privacy Framework and its UK and Swiss extensions.
Data Security
We use reasonable safeguards to protect data handled by the app and its service providers. Data sent from the app uses HTTPS/TLS. Feedback is available only to authorized administrators with feedback permissions. We limit field lengths, validate source links, rate-limit public submissions, and keep audit entries free of feedback messages, reply emails, and internal-note contents.
We configure diagnostics and analytics so they are not intended to include player-entered names, feedback content, free-form save data, purchase receipts, purchase tokens, or payment card numbers.
Data Retention and Deletion
Game save data stored only on your device remains there until you delete the save slot, delete the app, or your operating system removes the data. Device backups may retain app data depending on your device and backup settings.
We apply the following maximum retention periods unless a longer period is required for legal, security, fraud-prevention, purchase-restoration, or accounting reasons:
- In-app, forum, and email feedback records, technical context, source URL, and internal triage notes: until 12 months after the report is closed or 24 months after submission, whichever occurs first.
- Optional reply email stored with feedback: until 90 days after the report is closed or 12 months after submission, whichever occurs first.
- Support emails in our mailbox: up to 24 months after the last correspondence.
- Sentry diagnostics: 90 days.
- Amplitude analytics: 24 months.
- RevenueCat and purchase records: for the lifetime of the entitlement record and as otherwise required for purchase restoration, fraud prevention, accounting, or law.
Authorized staff can permanently delete a live feedback record. Deleted information may remain temporarily in database backups: our deployment schedules local backups for deletion after 14 days, and we configure the same maximum before copying feedback data to an offsite backup provider. Backup copies are not used for ordinary operations and, if restored for disaster recovery, deletion and redaction rules are reapplied.
To request access to or deletion of feedback, contact support@bundleup.tech and provide the FB- reference or the reply email used with the report. If you submitted anonymously and no longer have the reference, we may be unable to identify the report; we will not collect additional identity information solely to locate it.
To request deletion of data associated with diagnostics, analytics, or purchases, contact support@bundleup.tech. Some information may be retained where required for the reasons described above.
Your Privacy Rights
Depending on where you live, and in particular if you are in the EEA, the United Kingdom, or Switzerland, you may have rights over your personal data. These can include the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data.
- Restrict how we process your data.
- Portability — receive your data in a portable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time where we rely on it. You can do this yourself for analytics using the Settings toggle described above, and withdrawing consent does not affect processing that already took place.
To exercise a right, contact us at support@bundleup.tech. We may need enough information to verify and fulfill the request, but we will not require an anonymous reporter to create an account. You may also have the right to lodge a complaint with your local data protection supervisory authority.
Tracking and Advertising
Punch Promoter does not show ads and does not track users across other companies' apps or websites for advertising.
Children's Privacy
Punch Promoter is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. Please do not submit personal information if you are under 13.
If we learn that a person under 13 submitted personal information without the required parental consent, we will promptly delete it. Where applicable to a general-audience support request, we may use an email address once to answer the request and will delete the address and associated personal information promptly afterward; if no response is needed, we will delete it immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will show the revised effective date at the top of this page and, where required or appropriate for a material change, provide an additional notice.
Questions
To ask privacy questions or exercise your privacy rights, contact support@bundleup.tech, call +1 (916) 538-5427, or write to Bundle Up Technologies LLC, 2108 N St, Sacramento, CA 95816, United States.
