Data Deletion
This is a courtesy English translation. In case of any discrepancy, the Spanish version prevails.
This page explains how to request deletion of your data and what we store, with particular detail on the WhatsApp channel. It complements our Privacy Notice, which remains the primary document.
1. Two kinds of people, two different answers
PunchyPass handles data for two groups that should not be confused, because a request is resolved differently for each:
- The business: the person who opens a PunchyPass account and, if they choose to, connects their WhatsApp Business number.
- The end customer: the person who joins a business's loyalty program and collects stamps. Here PunchyPass acts on behalf of the business, which decides what happens to that data.
If you are a customer of a business and want your data deleted, write to us anyway: we route the request to the business it belongs to and confirm back to you.
2. What we store for the WhatsApp channel
When a business connects its WhatsApp Business number, we store only what the channel needs to work:
- The WhatsApp Business Account and phone number identifiers as issued by Meta, plus the display number and the approved name.
- The access token Meta issues for that number, encrypted at rest. It is what lets us reply on the business's behalf.
- A technical record of each message: whether it was inbound or outbound, the person's number, the message type, the date, and an error code if it failed.
What we do not store
We do not store message content. What a person writes is used to decide the reply at that moment and then discarded; it is not stored and is not sent to any other system. The technical record keeps that a message arrived and of what type, never what it said.
We also do not use WhatsApp conversations for advertising, do not share them with third parties for that purpose, and do not train models on them.
The data we do keep about an end customer (name, contact details, date of birth and their stamps) is what that person supplied when joining the loyalty program, not anything they wrote over WhatsApp.
3. How to disconnect WhatsApp
A business can disconnect its number at any time. Doing so revokes the access token, stops us receiving and replying on that number, and deletes the connection data described in section 2.
Disconnecting the number does not delete customers already enrolled in the loyalty program: that data belongs to the business and is removed through a separate request, as described below.
4. How to request deletion of your data
Send your request to contacto@punchypass.com with:
- Your name and a contact email address.
- What you want deleted: your whole account, only the WhatsApp connection, or your data as a customer of a business (naming which one).
- Any document supporting your request.
We will respond within a maximum of 20 business days of receiving it. If the request is granted, we then have 15 additional business days to carry it out. These are the periods set by Mexico's Federal Law on the Protection of Personal Data Held by Private Parties.
We will confirm by email once the deletion is done.
5. What we keep even if you request deletion
We keep only the minimum records the law requires of us, principally the tax receipts for subscriptions already charged, for the applicable period. We do not use them for any other purpose.
6. Contact
For any question about this page or about how we handle your data: contacto@punchypass.com.