Vendors / Adjacent encroachers — ordering, middleware & back-office
Punchh
PAR's enterprise loyalty and offers engine — POS-agnostic in market but increasingly sold as a bundle with PAR's Brink POS, Bridg CDP and ordering, which is how the loyalty layer turns into a POS displacement motion.
scored live legacy rubric
- Claims in scope
- 255
- Scored
- 36
- Assessed
- 34
- Unknown
- 221
- Not applicable
- 59
- Cells challenged
- 1
unknown, never as no.Identity
- Owner
- PAR Technology Corporation (NYSE: PAR); now marketed as part of PAR Engagement alongside PAR's Bridg CDP (Bridg acquisition from Cardlytics closed March 24, 2026)
- Parent
- PAR Technology
- Who it is for
- Multi-unit restaurant and convenience-store brands running loyalty, offers and campaign marketing across many locations
- Site
- https://punchh.com/
Pricing
transparency: unknown · unit: unknown (quote-only; enterprise annual contract) · processor lock-in: no
- Software
- No published pricing anywhere on punchh.com or partech.com; enterprise contract-only.
Capabilities
Every claim is binary and checkable. Grades: A primary documentation · B product documentation · C pricing or feature page · D marketing claim · E third-party reporting · F inference with no source. A yes on a differentiator claim requires A or B.
Menu, modifiers & pricing engine
menu-pricing-nested-modifiers
Migrated from the 2026-08-01 research pass; no source URL was recorded.
menu-pricing-modifier-price-by-parent-size
Migrated from the 2026-08-01 research pass; no source URL was recorded.
menu-pricing-fractional-placement differentiator
Not scored by this record.
menu-pricing-half-and-half-rule differentiator
Not scored by this record.
menu-pricing-topping-quantity-tiers
Migrated from the 2026-08-01 research pass; no source URL was recorded.
menu-pricing-size-style-matrix differentiator
Not scored by this record.
menu-pricing-included-allowance differentiator
Not scored by this record.
menu-pricing-combos
Not scored by this record.
menu-pricing-upsell-prompts differentiator
Not scored by this record.
menu-pricing-86-propagation
Not scored by this record.
menu-pricing-countdown-auto-86 differentiator
Not scored by this record.
menu-pricing-dayparting
Not scored by this record.
menu-pricing-channel-price-books
Not scored by this record.
menu-pricing-dual-pricing differentiator
Not scored by this record.
menu-pricing-versioning-effective-dates differentiator
Not scored by this record.
menu-pricing-franchise-hierarchy differentiator
Not scored by this record.
menu-pricing-allergen-nutrition
Not scored by this record.
menu-pricing-recipe-linkage differentiator
Not scored by this record.
menu-pricing-3p-menu-push
Not scored by this record.
menu-pricing-dynamic-pricing
Not scored by this record.
Payments & money movement
payments-processor-choice differentiator
Not scored by this record.
payments-published-rates differentiator
Not scored by this record.
payments-dual-pricing differentiator
Not scored by this record.
payments-surcharge-guardrails differentiator
Not scored by this record.
payments-emv-nfc
Migrated from the 2026-08-01 research pass; no source URL was recorded.
payments-softpos-tap-to-pay differentiator
Not scored by this record.
payments-pay-at-table
Not scored by this record.
payments-qr-guest-pay differentiator
Not scored by this record.
payments-tip-adjust
Not scored by this record.
payments-tip-pooling differentiator
Not scored by this record.
payments-offline-store-and-forward differentiator
Not scored by this record.
payments-offline-decline-liability differentiator
Not scored by this record.
payments-gift-cards
Stored-value/gift is commonly bundled in this category but is not stated on Punchh's public pages.
payments-house-accounts
Not scored by this record.
payments-split-tender
Not scored by this record.
payments-refund-void-controls
Punchh has no register, and its own POS docs place the transaction at the integrating POS: 'the POS operator... first identifies the user by performing a user look-up... and then creates a check-in', with the POS sending order details to Punchh via API. The only refund/void surface Punchh itself ships is the POS Payments API for its Single Scan Flow — 'After a payment is accepted/processed, you can use the Refund Payment API to refund the payment', and the Void/Cancel Payment API is 'most commonly used when the POS has issues such as timeout or connectivity'. Those endpoints authenticate as the machine, not the employee ('Authorization: Token token=LOCATION_KEY_GOES_HERE, btoken=BUSINESS_KEY_GOES_HERE') — there is no per-employee or role credential in the POS API scheme, no manager-PIN or approval step anywhere in the payment operation docs, and the published webhook event list has no voided or refunded event. Role-gated void/refund authorization with an approver-identifying audit trail is a control of the third-party POS Punchh integrates with, not of Punchh. https://developers.partech.com/docs/dev-portal-pos/additional-topics/pos-payments · retrieved 2026-08-04
payments-chargeback-tooling differentiator
Not scored by this record.
payments-card-on-file differentiator
Not scored by this record.
payments-payout-timing differentiator
Not scored by this record.
payments-multi-entity-routing differentiator
Not scored by this record.
payments-p2pe-pci4
Not scored by this record.
Delivery, dispatch & third-party channels
delivery-driver-roster
Migrated from the 2026-08-01 research pass; no source URL was recorded.
delivery-dispatch-board
Migrated from the 2026-08-01 research pass; no source URL was recorded.
delivery-route-map differentiator
Not scored by this record.
delivery-driver-tracking differentiator
Not scored by this record.
delivery-zones-polygon differentiator
Not scored by this record.
delivery-zone-pricing
Migrated from the 2026-08-01 research pass; no source URL was recorded.
delivery-address-validation
Not scored by this record.
delivery-driver-comp differentiator
Not scored by this record.
delivery-cash-reconcile
Not scored by this record.
delivery-daas-dispatch
Not scored by this record.
delivery-daas-fallback differentiator
Not scored by this record.
delivery-3p-direct-integration differentiator
Not scored by this record.
delivery-3p-injection
Not scored by this record.
delivery-menu-push
Not scored by this record.
delivery-86-sync
Not scored by this record.
delivery-store-pause
Not scored by this record.
delivery-3p-reconciliation differentiator
Not scored by this record.
delivery-injection-error-visibility differentiator
Not scored by this record.
delivery-tracking-page
Not scored by this record.
delivery-promise-time differentiator
Not scored by this record.
delivery-offline-behavior
Not scored by this record.
Digital ordering & guest-facing channels
digital-first-party-web
PAR Engagement bundles ordering with loyalty and marketing; ordering is a sibling module rather than Punchh itself. https://punchh.com/ · retrieved 2026-08-01
digital-menu-single-source
Punchh itself owns no menu record: menu items enter Punchh only as reference data the POS or ordering system sends with check-ins and redemptions, used to decide 'whether the offer is valid given the current cart items' and 'how many points a guest should earn', and the Online Ordering docs exist to 'Integrate Punchh Loyalty with your online ordering system' — the ordering channel is someone else's. Within the PAR Engagement bundle the first-party ordering channel is the sibling PAR Ordering product, whose page on punchh.com markets exactly this capability: 'Import menus directly from your POS, push updates instantly, and roll out changes in minutes not hours' and 'Control every menu across every channel from a single interface'. Shortfall: single-source menus require buying the sibling PAR Ordering product plus a supported POS menu import — Punchh alone has no digital menu — and the propagation claim rests on feature-page marketing, not admin-guide documentation. https://punchh.com/solutions/ordering/ · retrieved 2026-08-04
digital-native-app differentiator
Not scored by this record.
digital-account-saved-payment
"One-Tap Loyalty" is marketed when the products integrate; saved tokenized cards and one-tap reorder are not separately documented. https://punchh.com/ · retrieved 2026-08-01
digital-upsell-engine differentiator
Not scored by this record.
digital-scheduled-pacing
Not scored by this record.
digital-fulfillment-modes
Not scored by this record.
digital-qr-table
Not scored by this record.
digital-kiosk differentiator
Not scored by this record.
digital-group-ordering
Not scored by this record.
digital-catering-portal differentiator
Not scored by this record.
digital-voice-ai-phone differentiator
Not scored by this record.
digital-drivethru-ai
Not scored by this record.
digital-sms-ordering
Not scored by this record.
digital-google-order differentiator
Not scored by this record.
digital-apple-business-connect
Not scored by this record.
digital-loyalty-attach
Not scored by this record.
digital-subscriptions
Not scored by this record.
digital-promo-parity
Not scored by this record.
digital-guest-data-ownership differentiator
Not scored by this record.
digital-checkout-pci-sca
Not scored by this record.
digital-surcharge-transparency differentiator
Not scored by this record.
Guest data, loyalty & marketing
guest-loyalty-unified-profile
Guest360 builds rich profiles combining loyalty, ordering and marketing behaviour across touchpoints, including pre-enrolment; merge rules not published. https://punchh.com/ · retrieved 2026-08-01
guest-loyalty-thirdparty-identity-attach differentiator
Not scored by this record.
guest-loyalty-accrual-models
Tiers and personalized rewards are documented; points-per-dollar versus visit/punch accrual is not separately enumerated publicly. https://punchh.com/ · retrieved 2026-08-01
guest-loyalty-tiers differentiator
Not scored by this record.
guest-loyalty-offline-behavior differentiator
Not scored by this record.
guest-loyalty-offer-stacking-rules differentiator
Not scored by this record.
guest-loyalty-targeted-offers differentiator
Not scored by this record.
guest-loyalty-rfm-segmentation differentiator
Not scored by this record.
guest-loyalty-lifecycle-automation
Segmentation plus real-time personalized offers across email, SMS, app and web; named always-on birthday/win-back templates not published. https://punchh.com/ · retrieved 2026-08-01
guest-loyalty-native-email-sms differentiator
Not scored by this record.
guest-loyalty-consent-management
Not scored by this record.
guest-loyalty-10dlc-registration
Not scored by this record.
guest-loyalty-campaign-attribution differentiator
Not scored by this record.
guest-loyalty-data-export-portability differentiator
Not scored by this record.
guest-loyalty-cdp-event-api differentiator
Not scored by this record.
guest-loyalty-review-capture-routing differentiator
Not scored by this record.
guest-loyalty-referral-program
Not scored by this record.
guest-loyalty-wallet-pass differentiator
Not scored by this record.
guest-loyalty-privacy-rights-tooling
Not scored by this record.
guest-loyalty-redemption-fraud-controls
Not scored by this record.
guest-loyalty-ai-offer-recommendation differentiator
Not scored by this record.
guest-loyalty-stored-value-gift
Not scored by this record.
Labor & workforce
labor-clock-in-at-pos
Migrated from the 2026-08-01 research pass; no source URL was recorded.
labor-photo-punch-verification differentiator
Not scored by this record.
labor-geofenced-mobile-punch
Not scored by this record.
labor-offline-time-punch differentiator
Not scored by this record.
labor-granular-rbac
Punchh roles are built from individually toggled permissions under Settings > Admin Users > Roles > [role] — the help centre names discrete toggles such as 'Roles and Permissions Management', 'Settings Read Only', 'Settings Advanced' and 'Allow Access to Report Section' — and admins are separately scoped to locations, store numbers or location groups (Create Business Admin accepts location_ids, store_numbers, location_group_ids and role_id). Shortfall: some capabilities are hard-wired to the three built-in tiers and cannot be granted a la carte. Punchh states 'there is no a-la-carte permission that can be enabled for a role to allow access to all location data. An admin user's role must be granted at least Business Manager permissions', and building or modifying location groups 'is restricted to the Business Owner and Business Manager only. Thus, any other role will not be able to add or edit any location group by enabling any specific permission.' https://support.punchh.com/s/article/What-roles-in-Punchh-can-see-all-location-data-from-the-Dashboard · retrieved 2026-08-04
labor-manager-override-audit
Punchh keeps per-object Audit Logs used 'to determine who made changes to a user, setting or campaign' — reachable from the top right of an individual admin user, role, guest or campaign, and addressable by object type (dashboard.punchh.com/businesses/###/audit?item_type=AppMessage) — plus a Reports > Admin Activity report that 'pulls in all historical data around Admin gifting activity' and 'shows all admin activity since the inception of the business's Punchh platform'. Shortfall: this covers configuration changes and discretionary gifting, not an override-approval workflow — Punchh documents no second-approver override flow, and no page asserts the log is immutable or tamper-evident. Coverage is also uneven by the vendor's own account: the log is absent from section landing pages and a guest's audit log is blank unless the profile was changed manually. https://support.punchh.com/s/article/Why-does-the-Audit-Log-not-appear-as-expected-for-certain-sections-of-Punchh · retrieved 2026-08-04
labor-native-scheduling differentiator
Not scored by this record.
labor-demand-labor-forecast differentiator
Not scored by this record.
labor-realtime-labor-percent differentiator
Not scored by this record.
labor-overtime-prevention differentiator
Not scored by this record.
labor-break-compliance-by-state differentiator
Not scored by this record.
labor-fair-workweek-support
Not scored by this record.
labor-minor-labor-rules
Not scored by this record.
labor-tip-pooling-rules
Not scored by this record.
labor-tip-distribution-audit-trail
Not scored by this record.
labor-qualified-tips-w2-reporting differentiator
Not scored by this record.
labor-native-payroll differentiator
Not scored by this record.
labor-payroll-export-formats
Not scored by this record.
labor-shift-swap-workflow differentiator
Not scored by this record.
labor-digital-onboarding-i9
Not scored by this record.
labor-server-performance-metrics differentiator
Not scored by this record.
Inventory, purchasing & cost control
inventory-recipe-bom-costing
Migrated from the 2026-08-01 research pass; no source URL was recorded.
inventory-unit-conversion-yields
Migrated from the 2026-08-01 research pass; no source URL was recorded.
inventory-theoretical-vs-actual differentiator
Not scored by this record.
inventory-realtime-depletion differentiator
Not scored by this record.
inventory-86-auto-sync differentiator
Not scored by this record.
inventory-count-modes
Migrated from the 2026-08-01 research pass; no source URL was recorded.
inventory-mobile-count-offline
Not scored by this record.
inventory-vendor-catalogs-edi differentiator
Not scored by this record.
inventory-invoice-ocr differentiator
Not scored by this record.
inventory-price-change-alerts differentiator
Not scored by this record.
inventory-par-auto-suggest differentiator
Not scored by this record.
inventory-waste-logging
Not scored by this record.
inventory-transfers
Not scored by this record.
inventory-commissary
Not scored by this record.
inventory-lot-traceability
Not scored by this record.
inventory-shelf-life-expiry
Not scored by this record.
inventory-bar-partial-bottle
Not scored by this record.
inventory-cogs-gl-export
Not scored by this record.
inventory-native-not-partner differentiator
Not scored by this record.
inventory-menu-margin-linkage differentiator
Not scored by this record.
Reporting, BI & data access
reporting-realtime-dashboard
Campaign and guest analytics are implied; live sales dashboard is out of scope.
reporting-eod-closeout
Migrated from the 2026-08-01 research pass; no source URL was recorded.
reporting-pmix-modifier-level
Migrated from the 2026-08-01 research pass; no source URL was recorded.
reporting-comps-voids-audit
Not scored by this record.
reporting-cash-over-short
Not scored by this record.
reporting-labor-productivity
Not scored by this record.
reporting-server-scorecards differentiator
Not scored by this record.
reporting-channel-profitability differentiator
Not scored by this record.
reporting-multiloc-drilldown differentiator
Not scored by this record.
reporting-custom-report-builder differentiator
Not scored by this record.
reporting-scheduled-delivery
Not scored by this record.
reporting-raw-warehouse-export differentiator
Not scored by this record.
reporting-public-api differentiator
Not scored by this record.
reporting-webhooks differentiator
Not scored by this record.
reporting-api-not-upcharged differentiator
Not scored by this record.
reporting-tier-paywall differentiator
Not scored by this record.
reporting-history-retention differentiator
Not scored by this record.
reporting-anomaly-alerts differentiator
Not scored by this record.
reporting-nl-query
Not scored by this record.
reporting-guest-cohorts differentiator
Not scored by this record.
reporting-sales-forecast differentiator
Not scored by this record.
reporting-tip-tax-compliance
Not scored by this record.
Multi-location, franchise & enterprise governance
multi-location-org-hierarchy
Operates across 275+ brands and 89k+ locations, so grouping exists; a named hierarchy object is not documented publicly. https://punchh.com/ · retrieved 2026-08-01
multi-location-central-menu-publish
Does not own the menu record.
multi-location-local-override-policy differentiator
Not scored by this record.
multi-location-price-zones
Migrated from the 2026-08-01 research pass; no source URL was recorded.
multi-location-scheduled-publish differentiator
Not scored by this record.
multi-location-new-store-template differentiator
Not scored by this record.
multi-location-corp-vs-franchisee-roles differentiator
Not scored by this record.
multi-location-royalty-calculation differentiator
Not scored by this record.
multi-location-royalty-collection
Not scored by this record.
multi-location-consolidated-reporting
Not scored by this record.
multi-location-normalized-item-rollup differentiator
Not scored by this record.
multi-location-cross-location-giftcard
Not scored by this record.
multi-location-cross-location-loyalty
Not scored by this record.
multi-location-multi-brand differentiator
Not scored by this record.
multi-location-multi-tax-jurisdiction
Not scored by this record.
multi-location-multi-currency-locale
Not scored by this record.
multi-location-config-audit-log differentiator
Not scored by this record.
multi-location-enterprise-sso differentiator
Not scored by this record.
multi-location-enterprise-api differentiator
Not scored by this record.
multi-location-central-labor-policy
Not scored by this record.
Integrations, API & extensibility
extensibility-public-api-docs
REPLACES an undated first-pass placeholder that said 'developer.punchh.com did not resolve at check time; API access appears partner-gated' -- while this same record has cited developers.partech.com since 2026-08-09 at grade A for extensibility-oauth-partner-apps and grade B for extensibility-webhooks-push. PAR Technology owns Punchh, so that portal is the first-party developer surface under the parent's name; searching for it under the acquired brand's own subdomain is what produced the absence. Re-established anonymously 2026-09-01 under our own UA: robots.txt is 76 bytes, one `User-agent: *` group whose only rule is `Allow: /`, plus a Sitemap line, and the paths below were matched mechanically against it rather than by eye. The site publishes a machine-readable manifest at /llms.txt (HTTP 200, 142,405 b, read whole) enumerating 531 pages across Commerce Engines (PAR Ordering, PAR POS), Engagement Tools (PAR Punchh), Operations Tools and a Scalar-rendered Docs tree. The Punchh material alone runs to nine API certification feature matrices (Kiosk, Loyalty Pay, Mobile SSO, Offers Ingestion, Online Ordering, Pay-on-the-Go, POS, Single Scan Flow, SMS), an 'Overview of Punchh API Integrations' getting-started page, 'Punchh API Security Guidelines' covering partner onboarding, 'Punchh API and Product FAQs', a 'Punchh Base URIs - Overview' naming sandbox and production environments, developer guides for Advanced Authentication, Offers Ingestion and Redemptions 2.0 basket locking, and a per-endpoint OpenAPI reference (for example the Online Ordering and SSO API's POST /oauth/token 'Get SSO Token' operation). Nothing on the route required an agreement, a login or a sales call. SPOT-CHECKED RATHER THAN ASSUMED, since a landing page is not the reference: /docs/dev-portal-webhooks-manager returned 200 with 45,981 b titled 'Events Framework - Overview of Webhooks Manager', and /docs/dev-portal-platform-functions returned 200 with 38,097 b titled 'Getting Started With Platform Functions API Integrations'. Note for anyone re-walking this host: /docs by itself is a 404 that renders about 30 KB of full site navigation. https://developers.partech.com/llms.txt · retrieved 2026-09-01
extensibility-api-access-cost differentiator
Not scored by this record.
extensibility-partner-revshare
Not scored by this record.
extensibility-free-sandbox differentiator
Not scored by this record.
extensibility-oauth-partner-apps
Punchh publishes two credential schemes and neither is an OAuth 2.0 scoped grant. Platform Functions: 'All platform APIs require an admin key as a part of the authentication, which can be generated from the Punchh platform' and 'Once regenerated, the old admin key expires and cannot be used for any platform-level functions' — the OpenAPI parameter is a flat 'Authorization: Bearer BUSINESS_ADMIN_KEY_GOES_HERE'. Mobile and Online Ordering: a client id/secret pair that PAR's own sample app calls PUNCHH_OAUTH_CLIENT_ID / PUNCHH_OAUTH_SECRET, used to compute an x-pch-digest request header, and 'given to you by your PAR Punchh representative when you get access to a test environment'. Shortfall: revocation exists only as regenerating one business-wide admin key, there are no per-app scopes documented anywhere in the spec, and integration credentials are issued by PAR rather than granted and revoked by the operator. https://developers.partech.com/docs/dev-portal-platform-functions · retrieved 2026-08-04
extensibility-webhooks-push
Punchh ships a Webhooks Manager that 'allows brands to get information about events happening in real-time so that action can be taken within the same application or a different application', with configuration and audit logs under Platform > Settings > Webhooks Manager. Shortfall: the documented event set is loyalty-domain only — 'Users, Loyalty check-ins, Gift check-ins, Redemptions, Rewards, Redeemables, Marketing notifications, Transactional notifications, Coupons'. No order lifecycle events are subscribable: a paid transaction surfaces only as a loyalty or gift check-in, and there is no modified, voided or refunded event in the published list. https://developers.partech.com/docs/dev-portal-webhooks-manager · retrieved 2026-08-04
extensibility-webhook-reliability differentiator
Not scored by this record.
extensibility-order-injection-api
Not scored by this record.
extensibility-menu-write-api differentiator
Not scored by this record.
extensibility-data-symmetry differentiator
Not scored by this record.
extensibility-published-rate-limits
Not scored by this record.
extensibility-doordash-preferred differentiator
Not scored by this record.
extensibility-first-party-delivery-integrations differentiator
Not scored by this record.
extensibility-middleware-compatibility
Not scored by this record.
extensibility-accounting-connectors
Not scored by this record.
extensibility-payroll-export
Not scored by this record.
extensibility-bi-data-warehouse differentiator
Not scored by this record.
extensibility-app-marketplace
Not scored by this record.
extensibility-custom-fields-scripting
Not scored by this record.
extensibility-headless-embedded
Not scored by this record.
extensibility-api-versioning-deprecation
Not scored by this record.
extensibility-data-portability-exit differentiator
Not scored by this record.
Reliability, offline & operations
reliability-offline-order-entry
Migrated from the 2026-08-01 research pass; no source URL was recorded.
reliability-offline-card-auth differentiator
Not scored by this record.
reliability-offline-decline-liability differentiator
Not scored by this record.
reliability-lan-degraded-multi-terminal differentiator
Not scored by this record.
reliability-local-transaction-engine differentiator
Not scored by this record.
reliability-offline-kds-printing
Migrated from the 2026-08-01 research pass; no source URL was recorded.
reliability-printer-fallback
Migrated from the 2026-08-01 research pass; no source URL was recorded.
reliability-sync-conflict-handling
Not scored by this record.
reliability-offline-feature-matrix
Not scored by this record.
reliability-public-status-page
Not scored by this record.
reliability-contractual-uptime-sla differentiator
Not scored by this record.
reliability-incident-postmortems
Not scored by this record.
reliability-247-live-support
Not scored by this record.
reliability-onsite-install differentiator
Not scored by this record.
reliability-menu-build-service differentiator
Not scored by this record.
reliability-hardware-replacement-sla
Not scored by this record.
reliability-backup-restore
Not scored by this record.
reliability-pci-dss-4-attestation
Not scored by this record.
reliability-mfa-role-based-access
Not scored by this record.
reliability-self-serve-training
Not scored by this record.
reliability-failover-terminal-role differentiator
Not scored by this record.
reliability-cellular-backup
Not scored by this record.
Commercial, compliance & data ownership
commercial-month-to-month-contract differentiator
Not scored by this record.
commercial-no-early-termination-fee differentiator
Not scored by this record.
commercial-autorenew-terms-published
PAR publishes the consolidated Master Agreement (dated 11.14.25, v2.0) covering all PAR services, expressly including 'PAR Punchh Services'. Section 3(b): 'each Subscription Order shall automatically renew for successive (i) one-year periods at the end of the Initial Subscription Term, or (ii) if no Initial Subscription Term is set forth in the applicable Subscription Order, periods equal to and aligned with the Term of this Agreement (each a Renewal Subscription Term) at the end of the Initial Subscription Term, unless either Party provides the other party with at least sixty (60) days' notice of its intent not to renew the applicable Subscription Order.' Both the renewal term and the notice window are therefore public rather than quote-only. https://partech.com/doc/01-par-master-agreement-consolidated-all-par-services_website/?v=2 · retrieved 2026-08-04
commercial-processing-not-bundled differentiator
Not scored by this record.
commercial-interchange-plus-published differentiator
Not scored by this record.
commercial-rate-increase-clause differentiator
Not scored by this record.
commercial-pricing-published
No pricing shown on the Punchh homepage or PAR's Punchh product page; demo/contact only. https://punchh.com/ · retrieved 2026-08-01
commercial-module-unbundling differentiator
Not scored by this record.
commercial-hardware-purchase-outright
Software-only loyalty layer; no proprietary hardware requirement. https://punchh.com/ · retrieved 2026-08-01
commercial-hardware-not-locked differentiator
Not scored by this record.
commercial-implementation-fee-published
Not scored by this record.
commercial-data-export-self-serve
Not scored by this record.
commercial-export-customer-and-loyalty differentiator
Not scored by this record.
commercial-post-termination-export-window differentiator
Not scored by this record.
commercial-data-ownership-clause differentiator
Not scored by this record.
commercial-source-available-selfhost
Not scored by this record.
commercial-pci-p2pe-tokenization
Not scored by this record.
commercial-pci-dss-4-controls
Not scored by this record.
commercial-soc2-attestation
Not scored by this record.
commercial-privacy-dsar-tooling
Not scored by this record.
commercial-wcag-kiosk-accessibility differentiator
Not scored by this record.
commercial-dual-pricing-compliant differentiator
Not scored by this record.
Adversarial verification
An independent pass was instructed to refute this record, defaulting to downgrade when uncertain. It challenged 8 values — 1 upheld, 0 downgraded, 0 upgraded. This is published in full because a reader who can see which values were contested, on what evidence, and which way they moved has something no affiliate-funded comparison offers.
Capability claims
| Claim | As first scored | Verdict | What the verifier found |
|---|---|---|---|
| labor-granular-rbac | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-partial | The placeholder marked an unexamined cell. Punchh's help centre documents named, individually toggled permissions inside custom roles (Settings > Admin Users > Roles > [role]: 'Roles and Permissions Management', 'Settings Read Only', 'Settings Advanced', 'Allow Access to Report Section'), and the Create Business Admin OpenAPI operation takes role_id plus location_ids, store_numbers and location_group_ids, so scoping is per-role and per-location. It is not fully a la carte: Punchh states there is 'no a-la-carte permission that can be enabled for a role to allow access to all location data' and that building or modifying location groups 'is restricted to the Business Owner and Business Manager only'. Both halves present, one materially limited, hence partial rather than yes. source |
| labor-manager-override-audit | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-partial | The placeholder marked an unexamined cell. Punchh documents per-object Audit Logs used 'to determine who made changes to a user, setting or campaign', addressable by item_type at dashboard.punchh.com/businesses/###/audit, plus a Reports > Admin Activity report covering 'all admin activity since the inception of the business's Punchh platform'. Attribution and after-the-fact query are therefore documented. Withheld from yes because no PAR page asserts immutability or tamper-evidence, no override-approval workflow exists in a loyalty platform with no void/comp/drawer actions, and Punchh itself describes patchy coverage (log absent from section landing pages; guest log blank unless the profile was manually changed). source |
| extensibility-oauth-partner-apps | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-partial | The placeholder marked an unexamined cell. PAR's developer portal enumerates the actual credential schemes: platform APIs use a single business admin key ('Authorization: Bearer BUSINESS_ADMIN_KEY_GOES_HERE') generated in the Punchh platform, where regenerating it expires the old key; mobile and online-ordering integrations use a client id/secret pair issued by a PAR Punchh representative and folded into an x-pch-digest header, per PAR's own x_pch_digest_generator sample app. Some revocation exists and the credentials are OAuth-named, so this is not clean absence, but no scopes and no operator-granted per-app permissions are documented anywhere in the spec — partial with the shortfall named, not yes and not no. source |
| extensibility-webhooks-push | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-partial | The placeholder marked an unexamined cell. The Punchh Webhooks Manager is documented as real-time push, which settles the polling half of the claim. The published event list is enumerated and closed for the current release — Users, Loyalty check-ins, Gift check-ins, Redemptions, Rewards, Redeemables, Marketing notifications, Transactional notifications, Coupons — and contains no order lifecycle events, so the modified/voided/refunded half is documented as absent. Enumerated alternatives with the claimed item missing is the shortfall; partial. source |
| commercial-autorenew-terms-published | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-yes | The placeholder marked an unexamined cell, and the prior pass had recorded pricing.transparency as unknown/quote-only, which is true of price but not of terms. PAR publishes the consolidated Master Agreement (11.14.25, v2.0) on partech.com covering 'PAR Punchh Services' by name; it states one-year automatic renewal of each Subscription Order unless a party gives 'at least sixty (60) days' notice of its intent not to renew'. Both the renewal period and the notice window are publicly readable, which is exactly what the claim asks for. source |
| payments-refund-void-controls | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-no | The placeholder marked an unexamined cell. This is positive evidence of absence, not silence: PAR's POS developer docs define the integration model with the third-party POS operator performing the sale and sending order data to Punchh, and Punchh's own refund/void surface is limited to the POS Payments API (Create / Refund / Void-Cancel for Single Scan Flow payments), authenticated with machine credentials only — 'Authorization: Token token=LOCATION_KEY_GOES_HERE, btoken=BUSINESS_KEY_GOES_HERE' — with no per-employee credential in the scheme. No manager-PIN or approval step appears in the payment docs, and the closed webhook event list already recorded on this record contains no voided or refunded event. Register-side void/refund authorization is the integrating POS's control, not Punchh's; consistent with this record's other register-capability cells (labor-clock-in-at-pos, reliability-offline-order-entry) scored no. source |
| digital-menu-single-source | unknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass." | resolve-to-partial | The placeholder marked an unexamined cell. Punchh's developer docs show menu items reach Punchh only as inbound reference data on check-ins and redemptions (offer validation, points, analytics) — Punchh generates no ordering menu of its own, and its Online Ordering section integrates loyalty into 'your online ordering system'. The single-source capability exists in the bundle via the sibling PAR Ordering product, marketed on punchh.com as 'Import menus directly from your POS, push updates instantly' and 'Control every menu across every channel from a single interface' — but that is a feature page (grade C), it is a separate PAR Engagement module rather than Punchh, and it presupposes a supported POS menu import. Partial with the sibling-module dependency named, matching how this record already scores digital-first-party-web. source |
| commercial-autorenew-terms-published | yes, grade A - cited to https://partech.com/doc/01-par-master-agreement-consolidated-all-par-services_website/?v=2 | upheld | Grade only, value and evidence untouched. Vendor LEGAL pages (terms, EULA, MSA, product-specific terms) are graded B corpus-wide - measured, not argued: 217 of 259 claims citing a legal-shaped URL are B. This claim was one of 21 stragglers still at A across 8 vendors. Each was inspected and every one is a genuine contract rather than a technical document, so the loose URL predicate produced no false positives here. The ladder does not name contracts explicitly, which is why this keeps recurring. source |
Sources
Every URL this record cites. 23 in total.
- https://punchh.com/
- https://developers.partech.com/engagement-tools/par-punchh
- https://developers.partech.com/docs/dev-portal-platform-functions
- https://developers.partech.com/docs/dev-portal-platform-functions/apis/platform-functions-api/tag/business-admin-users/get/api2/dashboard/roles
- https://developers.partech.com/docs/dev-portal-webhooks-manager
- https://developers.partech.com/docs/dev-portal-developer-resources
- https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
- https://github.com/PAR-Technology-Sample-Applications/x_pch_digest_generator
- https://support.punchh.com/s/article/What-roles-in-Punchh-can-see-all-location-data-from-the-Dashboard
- https://support.punchh.com/s/article/What-permissions-are-required-to-invite-or-edit-Admin-Users
- https://support.punchh.com/s/article/How-to-give-access-to-build-and-modify-locations-groups-within-a-specific-role
- https://support.punchh.com/s/article/Why-does-the-Audit-Log-not-appear-as-expected-for-certain-sections-of-Punchh
- https://support.punchh.com/s/article/Which-Audit-Log-contains-Announcements
- https://support.punchh.com/s/article/What-is-the-default-time-frame-for-the-Admin-Activity-report
- https://support.punchh.com/s/article/Why-is-the-Admin-Activity-Report-stuck-loading
- https://support.punchh.com/s/article/Where-can-you-see-the-audit-logs-for-Webhook-Manager-Configuration
- https://partech.com/doc/01-par-master-agreement-consolidated-all-par-services_website/?v=2
- https://developers.partech.com/docs/dev-portal-pos/
- https://developers.partech.com/docs/dev-portal-pos/additional-topics/pos-payments
- https://developers.partech.com/docs/dev-portal-pos/additional-topics/make-first-pos-call
- https://developers.partech.com/docs/dev-portal-online-ordering/additional-topics/menu-items
- https://punchh.com/solutions/ordering/
- https://developers.partech.com/llms.txt