PunchMonkey — Privacy Policy
Effective date: August 17, 2026 (supersedes the May 12, 2026 version)
Who we are
This policy covers the PunchMonkey mobile app (Google Play package
com.eaglin.punchmonkey; also the iOS version) and the PunchMonkey website and
server at punchmonkeyserver.com. Both are developed and operated by
Dean Eaglin ("we", "us"), the developer named on the app's Google Play listing.
Contact: ron.eaglin@gmail.com.
What PunchMonkey does
PunchMonkey is a checkpoint-tracking platform for races and events. Racers use the app to find a public event, join a race and team, and claim checkpoints by tapping an NFC tag, scanning a QR code, or checking in by GPS. Race directors manage events on this website. Results are shown on public results pages.
Information the app collects
Display name
Before joining a race you enter a display name. It is stored on our server and attached to the checkpoint claims you record. It appears on the public results pages for the events you take part in. As an anonymous racer you do not need an email address, password, or phone number.
Optional racer sign-in (Google, Facebook, Apple)
You may optionally sign in with Google, Facebook, or Apple to keep a race history. We store only an opaque account identifier from the provider, the provider name, your chosen display name, a profile handle, and your sharing preference. We do not store your password, email address, or the provider's access tokens. A public profile page listing your completed races is shown only if you turn sharing on. Signing in is never required to race.
Location
The app requests access to your device's precise location. Location is used to verify you are at a checkpoint when you claim it (GPS check-in) and may be recorded with a claim for scoring and dispute review. Location is used only while you are actively using the app to race; it is not tracked in the background, not shared with third parties, and not used for advertising.
Camera
The camera is used only to scan QR-code checkpoints. No photos or video are stored or transmitted.
NFC
NFC is used to read the checkpoint tag's identifier when you tap it. Nothing is written to your device or to other tags.
Device identifier
On first launch the app generates a random identifier for your device. It is sent with each checkpoint claim so the server can de-duplicate claims from the same device. It is not linked to any external account and is not shared with third parties.
Checkpoint claim records
Each claim records the checkpoint identifier, the method (NFC / QR / GPS), the time, the location (if applicable), your display name, and your team. These records are visible on the event's public results pages.
Website (race directors and administrators)
Race directors sign in to punchmonkeyserver.com to create and manage events, races, checkpoints, and the course maps they upload. Standard web-server logs (IP address, request path, time) are kept briefly for operations and security.
How we use the information
- To record checkpoint claims and score races.
- To display results and leaderboards to participants and spectators.
- To let race directors review activity and resolve disputes.
- To show you your own race history if you choose to sign in.
We do not use your information for advertising, we do not sell it, and there are no analytics or tracking SDKs in the app.
Sharing
Race results (display name, team, claim times) are public by design. Beyond that, data is shared only with the race director of the event you joined, and with the service provider needed to host the server. If you sign in with Google, Facebook, or Apple, that provider processes your sign-in under its own privacy policy.
Data retention and deletion
Claim records and event data are kept while the event exists on the platform; race directors and administrators may delete events and their data at any time. You may ask to have your display name removed from all claim records, or to have a racer account deleted, at any time — submit a data deletion request or email ron.eaglin@gmail.com. Uninstalling the app removes the local device identifier.
Security
All traffic between the app, this website, and the server is encrypted with HTTPS.
Children
PunchMonkey is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has submitted information, contact us and we will remove it.
Changes to this policy
Updates will be posted on this page with a new effective date.
Contact
Dean Eaglin — ron.eaglin@gmail.com