Session Punch · In Development

A punch card both sides can understand.

A digitally validated prepaid-session ledger for independent service providers—not a loyalty program, payment system, or scheduling suite.

For users

Keep prepaid sessions in agreement.

Designed for independent providers who sell packages of sessions and need a simple shared proof of what remains.

Client Punch Pass

Create a permanent client QR pass, share its human-readable image by the client’s preferred email or text channel, and replace it when needed.

Explicit punches

Scan through Google Code Scanner, review the client and balance, then confirm the punch. Manual punches require a reason.

Clear receipts

Every change shows before, change, and after balances. Receipts hand off to the provider’s normal messaging app.

Auditable corrections

Void a punch through an immutable reversal rather than deleting history. Negative balances remain representable rather than hidden.

Provider workflow

Reusable package shortcuts, low-balance highlighting, reminders, check-ins, global activity, and client activity stay in one local workspace.

Bounded scope

No payments, pricing, expiry, scheduling, service catalog, client account, client portal, cloud sync, ads, or analytics.

Current status: Android prototype v0.1.6, in development. Contact support@wildonionlabs.com for testing or collaboration.

For developers

A ledger, not a mutable counter.

Architecture

Kotlin and Jetpack Compose with Room/SQLite persistence. A compact Clients · Scan · Activity navigation model keeps the critical path permanently available.

Domain model

Balances are aggregate and fungible per client. Credits, punches, archive events, QR replacements, and reversals produce permanent client-level transactions.

QR lifecycle

A permanent random client token backs the Punch Pass. Replacing a pass invalidates the previous token and records the event; versioned filenames avoid share collisions.

Scanning

Permission-free Google Code Scanner handles acquisition, while ZXing generates pass imagery. Business confirmation remains explicit after scanning.

Platform boundaries

Email and SMS use Android intent handoff. The app records that a reminder/check-in was initiated but does not falsely claim the provider pressed Send in another app.

Failure choices

Corrections append reversals, clients archive instead of disappearing, pass replacement invalidates stale credentials, and local Room migrations preserve existing records.