Vendors / Adjacent encroachers — ordering, middleware & back-office

Punchh

PAR's enterprise loyalty and offers engine — POS-agnostic in market but increasingly sold as a bundle with PAR's Brink POS, Bridg CDP and ordering, which is how the loyalty layer turns into a POS displacement motion.

scored live legacy rubric

Claims in scope
255
Scored
36
Assessed
34
Unknown
221
Not applicable
59
Cells challenged
1
87% of in-scope claims are unknown. This record measures what Punchh publishes at least as much as what it does. A vendor that documents little scores low here whether or not the capability exists. Absence of evidence is recorded as unknown, never as no.

Identity

Owner
PAR Technology Corporation (NYSE: PAR); now marketed as part of PAR Engagement alongside PAR's Bridg CDP (Bridg acquisition from Cardlytics closed March 24, 2026)
Parent
PAR Technology
Who it is for
Multi-unit restaurant and convenience-store brands running loyalty, offers and campaign marketing across many locations
Site
https://punchh.com/

Pricing

transparency: unknown · unit: unknown (quote-only; enterprise annual contract) · processor lock-in: no

Software
No published pricing anywhere on punchh.com or partech.com; enterprise contract-only.

Capabilities

Every claim is binary and checkable. Grades: A primary documentation · B product documentation · C pricing or feature page · D marketing claim · E third-party reporting · F inference with no source. A yes on a differentiator claim requires A or B.

Menu, modifiers & pricing engine

No

menu-pricing-nested-modifiers

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
No

menu-pricing-modifier-price-by-parent-size

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

menu-pricing-fractional-placement differentiator

Not scored by this record.

Unknown

menu-pricing-half-and-half-rule differentiator

Not scored by this record.

No

menu-pricing-topping-quantity-tiers

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

menu-pricing-size-style-matrix differentiator

Not scored by this record.

Unknown

menu-pricing-included-allowance differentiator

Not scored by this record.

Unknown

menu-pricing-combos

Not scored by this record.

Unknown

menu-pricing-upsell-prompts differentiator

Not scored by this record.

Unknown

menu-pricing-86-propagation

Not scored by this record.

Unknown

menu-pricing-countdown-auto-86 differentiator

Not scored by this record.

Unknown

menu-pricing-dayparting

Not scored by this record.

Unknown

menu-pricing-channel-price-books

Not scored by this record.

Unknown

menu-pricing-dual-pricing differentiator

Not scored by this record.

Unknown

menu-pricing-versioning-effective-dates differentiator

Not scored by this record.

Unknown

menu-pricing-franchise-hierarchy differentiator

Not scored by this record.

Unknown

menu-pricing-allergen-nutrition

Not scored by this record.

Unknown

menu-pricing-recipe-linkage differentiator

Not scored by this record.

Unknown

menu-pricing-3p-menu-push

Not scored by this record.

Unknown

menu-pricing-dynamic-pricing

Not scored by this record.

Payments & money movement

Unknown

payments-processor-choice differentiator

Not scored by this record.

Unknown

payments-published-rates differentiator

Not scored by this record.

Unknown

payments-dual-pricing differentiator

Not scored by this record.

Unknown

payments-surcharge-guardrails differentiator

Not scored by this record.

No

payments-emv-nfc

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

payments-softpos-tap-to-pay differentiator

Not scored by this record.

Unknown

payments-pay-at-table

Not scored by this record.

Unknown

payments-qr-guest-pay differentiator

Not scored by this record.

Unknown

payments-tip-adjust

Not scored by this record.

Unknown

payments-tip-pooling differentiator

Not scored by this record.

Unknown

payments-offline-store-and-forward differentiator

Not scored by this record.

Unknown

payments-offline-decline-liability differentiator

Not scored by this record.

Unknown

payments-gift-cards

Stored-value/gift is commonly bundled in this category but is not stated on Punchh's public pages.

F
Unknown

payments-house-accounts

Not scored by this record.

Unknown

payments-split-tender

Not scored by this record.

No

payments-refund-void-controls

Punchh has no register, and its own POS docs place the transaction at the integrating POS: 'the POS operator... first identifies the user by performing a user look-up... and then creates a check-in', with the POS sending order details to Punchh via API. The only refund/void surface Punchh itself ships is the POS Payments API for its Single Scan Flow — 'After a payment is accepted/processed, you can use the Refund Payment API to refund the payment', and the Void/Cancel Payment API is 'most commonly used when the POS has issues such as timeout or connectivity'. Those endpoints authenticate as the machine, not the employee ('Authorization: Token token=LOCATION_KEY_GOES_HERE, btoken=BUSINESS_KEY_GOES_HERE') — there is no per-employee or role credential in the POS API scheme, no manager-PIN or approval step anywhere in the payment operation docs, and the published webhook event list has no voided or refunded event. Role-gated void/refund authorization with an approver-identifying audit trail is a control of the third-party POS Punchh integrates with, not of Punchh. https://developers.partech.com/docs/dev-portal-pos/additional-topics/pos-payments · retrieved 2026-08-04

B
Unknown

payments-chargeback-tooling differentiator

Not scored by this record.

Unknown

payments-card-on-file differentiator

Not scored by this record.

Unknown

payments-payout-timing differentiator

Not scored by this record.

Unknown

payments-multi-entity-routing differentiator

Not scored by this record.

Unknown

payments-p2pe-pci4

Not scored by this record.

Delivery, dispatch & third-party channels

No

delivery-driver-roster

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
No

delivery-dispatch-board

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

delivery-route-map differentiator

Not scored by this record.

Unknown

delivery-driver-tracking differentiator

Not scored by this record.

Unknown

delivery-zones-polygon differentiator

Not scored by this record.

No

delivery-zone-pricing

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

delivery-address-validation

Not scored by this record.

Unknown

delivery-driver-comp differentiator

Not scored by this record.

Unknown

delivery-cash-reconcile

Not scored by this record.

Unknown

delivery-daas-dispatch

Not scored by this record.

Unknown

delivery-daas-fallback differentiator

Not scored by this record.

Unknown

delivery-3p-direct-integration differentiator

Not scored by this record.

Unknown

delivery-3p-injection

Not scored by this record.

Unknown

delivery-menu-push

Not scored by this record.

Unknown

delivery-86-sync

Not scored by this record.

Unknown

delivery-store-pause

Not scored by this record.

Unknown

delivery-3p-reconciliation differentiator

Not scored by this record.

Unknown

delivery-injection-error-visibility differentiator

Not scored by this record.

Unknown

delivery-tracking-page

Not scored by this record.

Unknown

delivery-promise-time differentiator

Not scored by this record.

Unknown

delivery-offline-behavior

Not scored by this record.

Digital ordering & guest-facing channels

Partial

digital-first-party-web

PAR Engagement bundles ordering with loyalty and marketing; ordering is a sibling module rather than Punchh itself. https://punchh.com/ · retrieved 2026-08-01

D
Partial

digital-menu-single-source

Punchh itself owns no menu record: menu items enter Punchh only as reference data the POS or ordering system sends with check-ins and redemptions, used to decide 'whether the offer is valid given the current cart items' and 'how many points a guest should earn', and the Online Ordering docs exist to 'Integrate Punchh Loyalty with your online ordering system' — the ordering channel is someone else's. Within the PAR Engagement bundle the first-party ordering channel is the sibling PAR Ordering product, whose page on punchh.com markets exactly this capability: 'Import menus directly from your POS, push updates instantly, and roll out changes in minutes not hours' and 'Control every menu across every channel from a single interface'. Shortfall: single-source menus require buying the sibling PAR Ordering product plus a supported POS menu import — Punchh alone has no digital menu — and the propagation claim rests on feature-page marketing, not admin-guide documentation. https://punchh.com/solutions/ordering/ · retrieved 2026-08-04

C
Unknown

digital-native-app differentiator

Not scored by this record.

Partial

digital-account-saved-payment

"One-Tap Loyalty" is marketed when the products integrate; saved tokenized cards and one-tap reorder are not separately documented. https://punchh.com/ · retrieved 2026-08-01

D
Unknown

digital-upsell-engine differentiator

Not scored by this record.

Unknown

digital-scheduled-pacing

Not scored by this record.

Unknown

digital-fulfillment-modes

Not scored by this record.

Unknown

digital-qr-table

Not scored by this record.

Unknown

digital-kiosk differentiator

Not scored by this record.

Unknown

digital-group-ordering

Not scored by this record.

Unknown

digital-catering-portal differentiator

Not scored by this record.

Unknown

digital-voice-ai-phone differentiator

Not scored by this record.

Unknown

digital-drivethru-ai

Not scored by this record.

Unknown

digital-sms-ordering

Not scored by this record.

Unknown

digital-google-order differentiator

Not scored by this record.

Unknown

digital-apple-business-connect

Not scored by this record.

Unknown

digital-loyalty-attach

Not scored by this record.

Unknown

digital-subscriptions

Not scored by this record.

Unknown

digital-promo-parity

Not scored by this record.

Unknown

digital-guest-data-ownership differentiator

Not scored by this record.

Unknown

digital-checkout-pci-sca

Not scored by this record.

Unknown

digital-surcharge-transparency differentiator

Not scored by this record.

Guest data, loyalty & marketing

Yes

guest-loyalty-unified-profile

Guest360 builds rich profiles combining loyalty, ordering and marketing behaviour across touchpoints, including pre-enrolment; merge rules not published. https://punchh.com/ · retrieved 2026-08-01

D
Unknown

guest-loyalty-thirdparty-identity-attach differentiator

Not scored by this record.

Partial

guest-loyalty-accrual-models

Tiers and personalized rewards are documented; points-per-dollar versus visit/punch accrual is not separately enumerated publicly. https://punchh.com/ · retrieved 2026-08-01

D
Unknown

guest-loyalty-tiers differentiator

Not scored by this record.

Unknown

guest-loyalty-offline-behavior differentiator

Not scored by this record.

Unknown

guest-loyalty-offer-stacking-rules differentiator

Not scored by this record.

Unknown

guest-loyalty-targeted-offers differentiator

Not scored by this record.

Unknown

guest-loyalty-rfm-segmentation differentiator

Not scored by this record.

Partial

guest-loyalty-lifecycle-automation

Segmentation plus real-time personalized offers across email, SMS, app and web; named always-on birthday/win-back templates not published. https://punchh.com/ · retrieved 2026-08-01

D
Unknown

guest-loyalty-native-email-sms differentiator

Not scored by this record.

Unknown

guest-loyalty-consent-management

Not scored by this record.

Unknown

guest-loyalty-10dlc-registration

Not scored by this record.

Unknown

guest-loyalty-campaign-attribution differentiator

Not scored by this record.

Unknown

guest-loyalty-data-export-portability differentiator

Not scored by this record.

Unknown

guest-loyalty-cdp-event-api differentiator

Not scored by this record.

Unknown

guest-loyalty-review-capture-routing differentiator

Not scored by this record.

Unknown

guest-loyalty-referral-program

Not scored by this record.

Unknown

guest-loyalty-wallet-pass differentiator

Not scored by this record.

Unknown

guest-loyalty-privacy-rights-tooling

Not scored by this record.

Unknown

guest-loyalty-redemption-fraud-controls

Not scored by this record.

Unknown

guest-loyalty-ai-offer-recommendation differentiator

Not scored by this record.

Unknown

guest-loyalty-stored-value-gift

Not scored by this record.

Labor & workforce

No

labor-clock-in-at-pos

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

labor-photo-punch-verification differentiator

Not scored by this record.

Unknown

labor-geofenced-mobile-punch

Not scored by this record.

Unknown

labor-offline-time-punch differentiator

Not scored by this record.

Partial

labor-granular-rbac

Punchh roles are built from individually toggled permissions under Settings > Admin Users > Roles > [role] — the help centre names discrete toggles such as 'Roles and Permissions Management', 'Settings Read Only', 'Settings Advanced' and 'Allow Access to Report Section' — and admins are separately scoped to locations, store numbers or location groups (Create Business Admin accepts location_ids, store_numbers, location_group_ids and role_id). Shortfall: some capabilities are hard-wired to the three built-in tiers and cannot be granted a la carte. Punchh states 'there is no a-la-carte permission that can be enabled for a role to allow access to all location data. An admin user's role must be granted at least Business Manager permissions', and building or modifying location groups 'is restricted to the Business Owner and Business Manager only. Thus, any other role will not be able to add or edit any location group by enabling any specific permission.' https://support.punchh.com/s/article/What-roles-in-Punchh-can-see-all-location-data-from-the-Dashboard · retrieved 2026-08-04

B
Partial

labor-manager-override-audit

Punchh keeps per-object Audit Logs used 'to determine who made changes to a user, setting or campaign' — reachable from the top right of an individual admin user, role, guest or campaign, and addressable by object type (dashboard.punchh.com/businesses/###/audit?item_type=AppMessage) — plus a Reports > Admin Activity report that 'pulls in all historical data around Admin gifting activity' and 'shows all admin activity since the inception of the business's Punchh platform'. Shortfall: this covers configuration changes and discretionary gifting, not an override-approval workflow — Punchh documents no second-approver override flow, and no page asserts the log is immutable or tamper-evident. Coverage is also uneven by the vendor's own account: the log is absent from section landing pages and a guest's audit log is blank unless the profile was changed manually. https://support.punchh.com/s/article/Why-does-the-Audit-Log-not-appear-as-expected-for-certain-sections-of-Punchh · retrieved 2026-08-04

B
Unknown

labor-native-scheduling differentiator

Not scored by this record.

Unknown

labor-demand-labor-forecast differentiator

Not scored by this record.

Unknown

labor-realtime-labor-percent differentiator

Not scored by this record.

Unknown

labor-overtime-prevention differentiator

Not scored by this record.

Unknown

labor-break-compliance-by-state differentiator

Not scored by this record.

Unknown

labor-fair-workweek-support

Not scored by this record.

Unknown

labor-minor-labor-rules

Not scored by this record.

Unknown

labor-tip-pooling-rules

Not scored by this record.

Unknown

labor-tip-distribution-audit-trail

Not scored by this record.

Unknown

labor-qualified-tips-w2-reporting differentiator

Not scored by this record.

Unknown

labor-native-payroll differentiator

Not scored by this record.

Unknown

labor-payroll-export-formats

Not scored by this record.

Unknown

labor-shift-swap-workflow differentiator

Not scored by this record.

Unknown

labor-digital-onboarding-i9

Not scored by this record.

Unknown

labor-server-performance-metrics differentiator

Not scored by this record.

Inventory, purchasing & cost control

No

inventory-recipe-bom-costing

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
No

inventory-unit-conversion-yields

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

inventory-theoretical-vs-actual differentiator

Not scored by this record.

Unknown

inventory-realtime-depletion differentiator

Not scored by this record.

Unknown

inventory-86-auto-sync differentiator

Not scored by this record.

No

inventory-count-modes

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

inventory-mobile-count-offline

Not scored by this record.

Unknown

inventory-vendor-catalogs-edi differentiator

Not scored by this record.

Unknown

inventory-invoice-ocr differentiator

Not scored by this record.

Unknown

inventory-price-change-alerts differentiator

Not scored by this record.

Unknown

inventory-par-auto-suggest differentiator

Not scored by this record.

Unknown

inventory-waste-logging

Not scored by this record.

Unknown

inventory-transfers

Not scored by this record.

Unknown

inventory-commissary

Not scored by this record.

Unknown

inventory-lot-traceability

Not scored by this record.

Unknown

inventory-shelf-life-expiry

Not scored by this record.

Unknown

inventory-bar-partial-bottle

Not scored by this record.

Unknown

inventory-cogs-gl-export

Not scored by this record.

Unknown

inventory-native-not-partner differentiator

Not scored by this record.

Unknown

inventory-menu-margin-linkage differentiator

Not scored by this record.

Reporting, BI & data access

Unknown

reporting-realtime-dashboard

Campaign and guest analytics are implied; live sales dashboard is out of scope.

F
No

reporting-eod-closeout

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
No

reporting-pmix-modifier-level

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

reporting-comps-voids-audit

Not scored by this record.

Unknown

reporting-cash-over-short

Not scored by this record.

Unknown

reporting-labor-productivity

Not scored by this record.

Unknown

reporting-server-scorecards differentiator

Not scored by this record.

Unknown

reporting-channel-profitability differentiator

Not scored by this record.

Unknown

reporting-multiloc-drilldown differentiator

Not scored by this record.

Unknown

reporting-custom-report-builder differentiator

Not scored by this record.

Unknown

reporting-scheduled-delivery

Not scored by this record.

Unknown

reporting-raw-warehouse-export differentiator

Not scored by this record.

Unknown

reporting-public-api differentiator

Not scored by this record.

Unknown

reporting-webhooks differentiator

Not scored by this record.

Unknown

reporting-api-not-upcharged differentiator

Not scored by this record.

Unknown

reporting-tier-paywall differentiator

Not scored by this record.

Unknown

reporting-history-retention differentiator

Not scored by this record.

Unknown

reporting-anomaly-alerts differentiator

Not scored by this record.

Unknown

reporting-nl-query

Not scored by this record.

Unknown

reporting-guest-cohorts differentiator

Not scored by this record.

Unknown

reporting-sales-forecast differentiator

Not scored by this record.

Unknown

reporting-tip-tax-compliance

Not scored by this record.

Multi-location, franchise & enterprise governance

Partial

multi-location-org-hierarchy

Operates across 275+ brands and 89k+ locations, so grouping exists; a named hierarchy object is not documented publicly. https://punchh.com/ · retrieved 2026-08-01

D
No

multi-location-central-menu-publish

Does not own the menu record.

F
Unknown

multi-location-local-override-policy differentiator

Not scored by this record.

No

multi-location-price-zones

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

multi-location-scheduled-publish differentiator

Not scored by this record.

Unknown

multi-location-new-store-template differentiator

Not scored by this record.

Unknown

multi-location-corp-vs-franchisee-roles differentiator

Not scored by this record.

Unknown

multi-location-royalty-calculation differentiator

Not scored by this record.

Unknown

multi-location-royalty-collection

Not scored by this record.

Unknown

multi-location-consolidated-reporting

Not scored by this record.

Unknown

multi-location-normalized-item-rollup differentiator

Not scored by this record.

Unknown

multi-location-cross-location-giftcard

Not scored by this record.

Unknown

multi-location-cross-location-loyalty

Not scored by this record.

Unknown

multi-location-multi-brand differentiator

Not scored by this record.

Unknown

multi-location-multi-tax-jurisdiction

Not scored by this record.

Unknown

multi-location-multi-currency-locale

Not scored by this record.

Unknown

multi-location-config-audit-log differentiator

Not scored by this record.

Unknown

multi-location-enterprise-sso differentiator

Not scored by this record.

Unknown

multi-location-enterprise-api differentiator

Not scored by this record.

Unknown

multi-location-central-labor-policy

Not scored by this record.

Integrations, API & extensibility

Yes

extensibility-public-api-docs

REPLACES an undated first-pass placeholder that said 'developer.punchh.com did not resolve at check time; API access appears partner-gated' -- while this same record has cited developers.partech.com since 2026-08-09 at grade A for extensibility-oauth-partner-apps and grade B for extensibility-webhooks-push. PAR Technology owns Punchh, so that portal is the first-party developer surface under the parent's name; searching for it under the acquired brand's own subdomain is what produced the absence. Re-established anonymously 2026-09-01 under our own UA: robots.txt is 76 bytes, one `User-agent: *` group whose only rule is `Allow: /`, plus a Sitemap line, and the paths below were matched mechanically against it rather than by eye. The site publishes a machine-readable manifest at /llms.txt (HTTP 200, 142,405 b, read whole) enumerating 531 pages across Commerce Engines (PAR Ordering, PAR POS), Engagement Tools (PAR Punchh), Operations Tools and a Scalar-rendered Docs tree. The Punchh material alone runs to nine API certification feature matrices (Kiosk, Loyalty Pay, Mobile SSO, Offers Ingestion, Online Ordering, Pay-on-the-Go, POS, Single Scan Flow, SMS), an 'Overview of Punchh API Integrations' getting-started page, 'Punchh API Security Guidelines' covering partner onboarding, 'Punchh API and Product FAQs', a 'Punchh Base URIs - Overview' naming sandbox and production environments, developer guides for Advanced Authentication, Offers Ingestion and Redemptions 2.0 basket locking, and a per-endpoint OpenAPI reference (for example the Online Ordering and SSO API's POST /oauth/token 'Get SSO Token' operation). Nothing on the route required an agreement, a login or a sales call. SPOT-CHECKED RATHER THAN ASSUMED, since a landing page is not the reference: /docs/dev-portal-webhooks-manager returned 200 with 45,981 b titled 'Events Framework - Overview of Webhooks Manager', and /docs/dev-portal-platform-functions returned 200 with 38,097 b titled 'Getting Started With Platform Functions API Integrations'. Note for anyone re-walking this host: /docs by itself is a 404 that renders about 30 KB of full site navigation. https://developers.partech.com/llms.txt · retrieved 2026-09-01

A
Unknown

extensibility-api-access-cost differentiator

Not scored by this record.

Unknown

extensibility-partner-revshare

Not scored by this record.

Unknown

extensibility-free-sandbox differentiator

Not scored by this record.

Partial

extensibility-oauth-partner-apps

Punchh publishes two credential schemes and neither is an OAuth 2.0 scoped grant. Platform Functions: 'All platform APIs require an admin key as a part of the authentication, which can be generated from the Punchh platform' and 'Once regenerated, the old admin key expires and cannot be used for any platform-level functions' — the OpenAPI parameter is a flat 'Authorization: Bearer BUSINESS_ADMIN_KEY_GOES_HERE'. Mobile and Online Ordering: a client id/secret pair that PAR's own sample app calls PUNCHH_OAUTH_CLIENT_ID / PUNCHH_OAUTH_SECRET, used to compute an x-pch-digest request header, and 'given to you by your PAR Punchh representative when you get access to a test environment'. Shortfall: revocation exists only as regenerating one business-wide admin key, there are no per-app scopes documented anywhere in the spec, and integration credentials are issued by PAR rather than granted and revoked by the operator. https://developers.partech.com/docs/dev-portal-platform-functions · retrieved 2026-08-04

A
Partial

extensibility-webhooks-push

Punchh ships a Webhooks Manager that 'allows brands to get information about events happening in real-time so that action can be taken within the same application or a different application', with configuration and audit logs under Platform > Settings > Webhooks Manager. Shortfall: the documented event set is loyalty-domain only — 'Users, Loyalty check-ins, Gift check-ins, Redemptions, Rewards, Redeemables, Marketing notifications, Transactional notifications, Coupons'. No order lifecycle events are subscribable: a paid transaction surfaces only as a loyalty or gift check-in, and there is no modified, voided or refunded event in the published list. https://developers.partech.com/docs/dev-portal-webhooks-manager · retrieved 2026-08-04

B
Unknown

extensibility-webhook-reliability differentiator

Not scored by this record.

Unknown

extensibility-order-injection-api

Not scored by this record.

Unknown

extensibility-menu-write-api differentiator

Not scored by this record.

Unknown

extensibility-data-symmetry differentiator

Not scored by this record.

Unknown

extensibility-published-rate-limits

Not scored by this record.

Unknown

extensibility-doordash-preferred differentiator

Not scored by this record.

Unknown

extensibility-first-party-delivery-integrations differentiator

Not scored by this record.

Unknown

extensibility-middleware-compatibility

Not scored by this record.

Unknown

extensibility-accounting-connectors

Not scored by this record.

Unknown

extensibility-payroll-export

Not scored by this record.

Unknown

extensibility-bi-data-warehouse differentiator

Not scored by this record.

Unknown

extensibility-app-marketplace

Not scored by this record.

Unknown

extensibility-custom-fields-scripting

Not scored by this record.

Unknown

extensibility-headless-embedded

Not scored by this record.

Unknown

extensibility-api-versioning-deprecation

Not scored by this record.

Unknown

extensibility-data-portability-exit differentiator

Not scored by this record.

Reliability, offline & operations

No

reliability-offline-order-entry

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

reliability-offline-card-auth differentiator

Not scored by this record.

Unknown

reliability-offline-decline-liability differentiator

Not scored by this record.

Unknown

reliability-lan-degraded-multi-terminal differentiator

Not scored by this record.

Unknown

reliability-local-transaction-engine differentiator

Not scored by this record.

No

reliability-offline-kds-printing

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
No

reliability-printer-fallback

Migrated from the 2026-08-01 research pass; no source URL was recorded.

F
Unknown

reliability-sync-conflict-handling

Not scored by this record.

Unknown

reliability-offline-feature-matrix

Not scored by this record.

Unknown

reliability-public-status-page

Not scored by this record.

Unknown

reliability-contractual-uptime-sla differentiator

Not scored by this record.

Unknown

reliability-incident-postmortems

Not scored by this record.

Unknown

reliability-247-live-support

Not scored by this record.

Unknown

reliability-onsite-install differentiator

Not scored by this record.

Unknown

reliability-menu-build-service differentiator

Not scored by this record.

Unknown

reliability-hardware-replacement-sla

Not scored by this record.

Unknown

reliability-backup-restore

Not scored by this record.

Unknown

reliability-pci-dss-4-attestation

Not scored by this record.

Unknown

reliability-mfa-role-based-access

Not scored by this record.

Unknown

reliability-self-serve-training

Not scored by this record.

Unknown

reliability-failover-terminal-role differentiator

Not scored by this record.

Unknown

reliability-cellular-backup

Not scored by this record.

Commercial, compliance & data ownership

Unknown

commercial-month-to-month-contract differentiator

Not scored by this record.

Unknown

commercial-no-early-termination-fee differentiator

Not scored by this record.

Yes

commercial-autorenew-terms-published

PAR publishes the consolidated Master Agreement (dated 11.14.25, v2.0) covering all PAR services, expressly including 'PAR Punchh Services'. Section 3(b): 'each Subscription Order shall automatically renew for successive (i) one-year periods at the end of the Initial Subscription Term, or (ii) if no Initial Subscription Term is set forth in the applicable Subscription Order, periods equal to and aligned with the Term of this Agreement (each a Renewal Subscription Term) at the end of the Initial Subscription Term, unless either Party provides the other party with at least sixty (60) days' notice of its intent not to renew the applicable Subscription Order.' Both the renewal term and the notice window are therefore public rather than quote-only. https://partech.com/doc/01-par-master-agreement-consolidated-all-par-services_website/?v=2 · retrieved 2026-08-04

B
Unknown

commercial-processing-not-bundled differentiator

Not scored by this record.

Unknown

commercial-interchange-plus-published differentiator

Not scored by this record.

Unknown

commercial-rate-increase-clause differentiator

Not scored by this record.

No

commercial-pricing-published

No pricing shown on the Punchh homepage or PAR's Punchh product page; demo/contact only. https://punchh.com/ · retrieved 2026-08-01

B
Unknown

commercial-module-unbundling differentiator

Not scored by this record.

Yes

commercial-hardware-purchase-outright

Software-only loyalty layer; no proprietary hardware requirement. https://punchh.com/ · retrieved 2026-08-01

E
Unknown

commercial-hardware-not-locked differentiator

Not scored by this record.

Unknown

commercial-implementation-fee-published

Not scored by this record.

Unknown

commercial-data-export-self-serve

Not scored by this record.

Unknown

commercial-export-customer-and-loyalty differentiator

Not scored by this record.

Unknown

commercial-post-termination-export-window differentiator

Not scored by this record.

Unknown

commercial-data-ownership-clause differentiator

Not scored by this record.

Unknown

commercial-source-available-selfhost

Not scored by this record.

Unknown

commercial-pci-p2pe-tokenization

Not scored by this record.

Unknown

commercial-pci-dss-4-controls

Not scored by this record.

Unknown

commercial-soc2-attestation

Not scored by this record.

Unknown

commercial-privacy-dsar-tooling

Not scored by this record.

Unknown

commercial-wcag-kiosk-accessibility differentiator

Not scored by this record.

Unknown

commercial-dual-pricing-compliant differentiator

Not scored by this record.

Adversarial verification

An independent pass was instructed to refute this record, defaulting to downgrade when uncertain. It challenged 8 values — 1 upheld, 0 downgraded, 0 upgraded. This is published in full because a reader who can see which values were contested, on what evidence, and which way they moved has something no affiliate-funded comparison offers.

Capability claims

ClaimAs first scoredVerdictWhat the verifier found
labor-granular-rbacunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-partialThe placeholder marked an unexamined cell. Punchh's help centre documents named, individually toggled permissions inside custom roles (Settings > Admin Users > Roles > [role]: 'Roles and Permissions Management', 'Settings Read Only', 'Settings Advanced', 'Allow Access to Report Section'), and the Create Business Admin OpenAPI operation takes role_id plus location_ids, store_numbers and location_group_ids, so scoping is per-role and per-location. It is not fully a la carte: Punchh states there is 'no a-la-carte permission that can be enabled for a role to allow access to all location data' and that building or modifying location groups 'is restricted to the Business Owner and Business Manager only'. Both halves present, one materially limited, hence partial rather than yes. source
labor-manager-override-auditunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-partialThe placeholder marked an unexamined cell. Punchh documents per-object Audit Logs used 'to determine who made changes to a user, setting or campaign', addressable by item_type at dashboard.punchh.com/businesses/###/audit, plus a Reports > Admin Activity report covering 'all admin activity since the inception of the business's Punchh platform'. Attribution and after-the-fact query are therefore documented. Withheld from yes because no PAR page asserts immutability or tamper-evidence, no override-approval workflow exists in a loyalty platform with no void/comp/drawer actions, and Punchh itself describes patchy coverage (log absent from section landing pages; guest log blank unless the profile was manually changed). source
extensibility-oauth-partner-appsunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-partialThe placeholder marked an unexamined cell. PAR's developer portal enumerates the actual credential schemes: platform APIs use a single business admin key ('Authorization: Bearer BUSINESS_ADMIN_KEY_GOES_HERE') generated in the Punchh platform, where regenerating it expires the old key; mobile and online-ordering integrations use a client id/secret pair issued by a PAR Punchh representative and folded into an x-pch-digest header, per PAR's own x_pch_digest_generator sample app. Some revocation exists and the credentials are OAuth-named, so this is not clean absence, but no scopes and no operator-granted per-app permissions are documented anywhere in the spec — partial with the shortfall named, not yes and not no. source
extensibility-webhooks-pushunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-partialThe placeholder marked an unexamined cell. The Punchh Webhooks Manager is documented as real-time push, which settles the polling half of the claim. The published event list is enumerated and closed for the current release — Users, Loyalty check-ins, Gift check-ins, Redemptions, Rewards, Redeemables, Marketing notifications, Transactional notifications, Coupons — and contains no order lifecycle events, so the modified/voided/refunded half is documented as absent. Enumerated alternatives with the claimed item missing is the shortfall; partial. source
commercial-autorenew-terms-publishedunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-yesThe placeholder marked an unexamined cell, and the prior pass had recorded pricing.transparency as unknown/quote-only, which is true of price but not of terms. PAR publishes the consolidated Master Agreement (11.14.25, v2.0) on partech.com covering 'PAR Punchh Services' by name; it states one-year automatic renewal of each Subscription Order unless a party gives 'at least sixty (60) days' notice of its intent not to renew'. Both the renewal period and the notice window are publicly readable, which is exactly what the claim asks for. source
payments-refund-void-controlsunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-noThe placeholder marked an unexamined cell. This is positive evidence of absence, not silence: PAR's POS developer docs define the integration model with the third-party POS operator performing the sale and sending order data to Punchh, and Punchh's own refund/void surface is limited to the POS Payments API (Create / Refund / Void-Cancel for Single Scan Flow payments), authenticated with machine credentials only — 'Authorization: Token token=LOCATION_KEY_GOES_HERE, btoken=BUSINESS_KEY_GOES_HERE' — with no per-employee credential in the scheme. No manager-PIN or approval step appears in the payment docs, and the closed webhook event list already recorded on this record contains no voided or refunded event. Register-side void/refund authorization is the integrating POS's control, not Punchh's; consistent with this record's other register-capability cells (labor-clock-in-at-pos, reliability-offline-order-entry) scored no. source
digital-menu-single-sourceunknown / F — placeholder: "No public documentation located during the 2026-08-01 research pass."resolve-to-partialThe placeholder marked an unexamined cell. Punchh's developer docs show menu items reach Punchh only as inbound reference data on check-ins and redemptions (offer validation, points, analytics) — Punchh generates no ordering menu of its own, and its Online Ordering section integrates loyalty into 'your online ordering system'. The single-source capability exists in the bundle via the sibling PAR Ordering product, marketed on punchh.com as 'Import menus directly from your POS, push updates instantly' and 'Control every menu across every channel from a single interface' — but that is a feature page (grade C), it is a separate PAR Engagement module rather than Punchh, and it presupposes a supported POS menu import. Partial with the sibling-module dependency named, matching how this record already scores digital-first-party-web. source
commercial-autorenew-terms-publishedyes, grade A - cited to https://partech.com/doc/01-par-master-agreement-consolidated-all-par-services_website/?v=2upheldGrade only, value and evidence untouched. Vendor LEGAL pages (terms, EULA, MSA, product-specific terms) are graded B corpus-wide - measured, not argued: 217 of 259 claims citing a legal-shaped URL are B. This claim was one of 21 stragglers still at A across 8 vendors. Each was inspected and every one is a genuine contract rather than a technical document, so the loose URL predicate produced no false positives here. The ladder does not name contracts explicitly, which is why this keeps recurring. source

Sources

Every URL this record cites. 23 in total.