Courtesy translation. The version that applies is the Spanish one, at puntako.app/privacidad/. If the two ever disagree, the Spanish text is the one that counts.
Controller and contact
The controller is José Luis Hernando Sanz, in España. For privacy questions and requests about your data, write to hi@jlhernando.com. This policy covers puntako.app and the Puntako apps that link to it, the Garmin app included.
Data kept on your device
Puntako keeps locally the matches, names, photos you add, rules, times and preferences it needs to run the scoreboard. You can play without creating an account. On Garmin, a Quick match works with no account and no connection.
The local history belongs to the browser, profile or app where you created it. Signing in does not automatically upload that whole history. Do not add names, photos or other data about the people playing without telling them and having a valid basis for using them; nicknames work fine.
Account and syncing
If you choose to sign in, WorkOS handles the identification. Puntako uses the account identifier, email, name and profile picture that the sign-in provides. It also keeps the linked devices, their name, platform, and the dates they were registered and last used. This data lets it recognise your account, keep the session and revoke devices.
If you sync a match, the score, the actions, the times and the participant data needed to show and keep it are sent to puntako.app. The account lets you see the synced matches and the results you save to it; it does not replace every local history.
When you link a Garmin, Puntako keeps its identifier and the authorisation to talk to the service. The watch holds pending points while there is no connection and sends them when it is back. When a Quick match finishes, it can send the result to the linked account. Garmin Connect takes part in the communication between watch and phone, under its own terms.
The Puntako app for Garmin does not read GPS or heart rate, does not record a FIT activity and does not detect points on its own. Scoring and syncing a match does not create a sports activity in Garmin Connect.
Shared results and links
Syncing or saving a result to the service can create a link to look at it. When you open the share option, the app can also send an image of the result. The content can include the names, photos and court you entered. Anyone holding the public link can see it without signing in to your account. Do not include anything you would not want to share.
Sending an image or exporting a backup hands that file to the app or person you pick. Puntako cannot take back the copies their recipients keep.
What the data is used for
- Providing the account, scoreboard and syncing features you ask for. The basis is performing the service requested. The account is optional for the local scoreboard and necessary for the features tied to it.
- Answering your questions and protecting the service from unauthorised access and abuse. The basis is the legitimate interest in replying and keeping the service safe.
- Meeting legal obligations and rights requests where they apply.
This version carries no advertising or advertising profiles, and makes no automated decisions with legal effects. If a purpose that needs consent is added, it will be asked for separately and you will be able to withdraw it.
Providers and disclosures
Cloudflare hosts the pages and the syncing service. Requests include technical information, such as IP address and browser data, needed to reply and protect the service. WorkOS takes part when you use an account. The email provider takes part when you write to support; we receive the message and whatever you attach. Do not send passwords or access codes.
Communications with puntako.app use HTTPS. Providers may process data outside the European Economic Area, the United States included. Their processing agreements set out safeguards for those transfers, standard contractual clauses included where they apply. See the documents from WorkOS and Cloudflare. You can ask our privacy contact for information about how your data is processed.
Session and storage
The browser keeps a protected cookie for the session, and uses local storage and cache to remember preferences, save matches and work offline. The native apps keep their own sign-in credential in the system's protected storage. Signing out on one device is not the same as deleting the account, nor does it close every other session.
Retention
Local matches in the browser stay until you delete them or their data is cleared. On Garmin the history has limited room: it normally keeps the last ten matches and can hold up to twenty while there are results waiting to be uploaded. Older matches may be removed when those limits are reached; the watch is not a permanent archive. The account stays until it is deleted. Native sign-in records expire 30 days after they are created; expired records are removed when requests are handled. Sign-in and linking codes expire within ten minutes at most.
Synced matches and public results have no automatic expiry. You can delete your own account matches from the app where that option is available, revoke the match link, or ask support to take it down by sending the link. Technical revocation markers may be kept so that old retries cannot bring back a deleted match.
Support enquiries are kept for as long as they are needed to resolve them and to meet the related obligations or claims. Providers keep their own operational logs under their agreements and obligations. You can ask which retention criteria apply to your request.
How to delete your data
You can delete local matches from the history, or clear the puntako.app data in your browser settings. From your profile you can ask for the account to be deleted; the user is removed from the sign-in provider and its devices are revoked. Deleting the account does not automatically remove local histories, remote matches or public links, which are handled separately.
The account and data deletion page explains how to ask for deletion even without the app installed. Say whether you also want matches or published results taken down.
Your rights
You can request access, rectification, erasure, restriction, objection and portability where they apply, by writing to hi@jlhernando.com. Where processing is based on your consent, you can withdraw it without affecting what was processed before. You can also complain to the Spanish Data Protection Agency.
Say what you are asking for and the details needed to find it, such as the account email or the result link. We will check your identity proportionately; do not send identity documents unprompted.
Changes
Any material change will be published here before it takes effect.