Privacy Policy
Last updated: July 23, 2026
1. Introduction
Welcome to The Punisher. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website and tell you about your privacy rights and how the law protects you.
2. Data We Collect
We may collect, use, store and transfer different kinds of personal data about you:
- Identity Data: name, username, or similar identifier
- Contact Data: email address
- Technical Data: IP address, browser type, device information
- Usage Data: information about how you use our website and services
- Design Data: Figma designs and implementation screenshots you upload
- Atlassian Integration Data: when you connect your Atlassian account, we temporarily hold a scoped OAuth access token to create Jira issues on your behalf. We do not store the contents of your Jira projects beyond what is necessary to process your requests.
3. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data to:
- Provide and maintain our visual testing service
- Process your subscription payments
- Send you important service updates
- Improve our website and services
- Comply with legal obligations
Email Communications: When you create an account you will receive essential transactional and service-related emails (e.g., billing confirmations, security alerts, and account notifications), which are necessary to provide the Service. Marketing communications (product updates, feature releases, promotional offers, and newsletters) are sent only if you have given explicit opt-in consent (for example, by ticking the consent box at sign-in). If you consent, a contact may be created in our email marketing platform (Brevo); if you do not consent, no marketing contact is created. You may withdraw consent or opt out at any time by clicking the "Unsubscribe" link in any marketing email or by contacting us at [email protected]. Please note that you cannot opt out of essential transactional or service-related emails (e.g., billing confirmations, security alerts, and account notifications).
Legal Bases (GDPR): Where the GDPR applies, we rely on the following lawful bases: (a) performance of a contract to provide the Service and process payments; (b) consent for non-essential marketing emails and non-essential cookies (which you may withdraw at any time); (c) legitimate interests to secure, maintain, and improve the Service; and (d) legal obligation for tax, accounting, and compliance requirements.
4. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
5. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
6. Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Right to withdraw consent
Right to complain: If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection supervisory authority. Our lead authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD — www.aepd.es). We would appreciate the chance to address your concerns first, so please contact us before contacting the authority.
6a. United States State Privacy Rights (CCPA/CPRA and similar)
If you are a resident of California or another US state with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah), you may have the right to: know/access the personal information we collect; request deletion; request correction; and opt out of the "sale" or "sharing" of personal information and of targeted advertising.
We do not sell your personal information for money. However, our use of analytics and advertising cookies (e.g., Google Analytics/Google Ads) may be considered "sharing" or "sale" under some US state laws. You can exercise your right to opt out by rejecting non-essential cookies in our cookie banner, or by emailing us at [email protected] with the subject "Do Not Sell or Share My Personal Information". We will not discriminate against you for exercising these rights.
6b. Australian Privacy Rights
If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You may request access to and correction of your personal information, and you may complain about a suspected breach of the APPs by contacting us at [email protected]. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC — www.oaic.gov.au). Some data may be disclosed to overseas recipients (including our subprocessors) as described in our Subprocessors page.
6c. Children's Privacy
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will delete it.
7. Third-Party Services
We use the following third-party services:
- Stripe: For payment processing
- Microsoft Azure AD: For authentication
- Figma API: To access your design files (with your permission)
- Atlassian (Jira): When you choose to connect your Atlassian account, we use the Atlassian OAuth 2.0 flow to request a scoped access token. This token is used solely to create and manage Jira issues on your behalf. We request only the minimum scopes required (read:jira-work, write:jira-work). You may revoke access at any time from your Atlassian account settings. Atlassian's privacy policy governs data processed on their platform.
Each of these services has their own privacy policy governing the use of your information. For a full list see our Subprocessors page.
8. Cookies
Our website uses cookies to distinguish you from other users. This helps us to provide you with a good experience when you browse our website and allows us to improve our site. For detailed information about the cookies we use, please see our Cookies Policy.
9. Contact Us & Data Protection Officer
Operator (data controller): PunisherLabsES (V. B. Badiuc). Address: Spain, Málaga, San Andrés 5.
Data Protection Officer (DPO) / Privacy Contact: Our DPO can be reached at [email protected].
If you have any questions about this privacy policy or our privacy practices, or wish to exercise any of your rights, please contact us at: [email protected]