Privacy Policy

Last updated: August 11, 2026

1. Information We Collect

BoundStack collects information you provide directly, including:

2. How We Use Your Information

3. Data Security

Server-side application data is stored in the PostgreSQL database configured through the production DATABASE_URL; this policy does not name a database vendor because the deployment can change. Passwords are hashed using bcrypt with cost factor 12. Signed authentication tokens expire after 7 days. Production traffic is expected to use HTTPS through the configured hosting platform.

The browser stores the authentication token and limited account/UI state in localStorage, a random analytics visitor ID in localStorage, and a session ID in sessionStorage. The service worker caches public application-shell assets but does not cache authenticated API responses. A user-scoped gun-show queue may remain in localStorage until it is synchronized, discarded, or cleared at logout.

4. ATF Compliance Data

Your Acquisition & Disposition records, Form 4473 data, and customer records are your records. BoundStack stores them on your behalf. You remain responsible for current recordkeeping, official-form, retention, and reporting requirements. We do not audit or certify your records.

5. Local A&D Preflight and Migration Review

The public A&D CSV preflight reads the selected file inside your browser. File bytes, raw rows, serial numbers, names, addresses, FFL numbers, the raw filename, and the SHA-256 fingerprint are not sent to BoundStack by the preflight workflow. The local report may include the full fingerprint and redacted value previews when you choose to download or open it.

First-party preflight analytics are limited to the page, validator and rule versions, generic profile status, coarse row and issue-count buckets, elapsed-time bucket, and technical error class. If you separately request a migration review after seeing results, BoundStack receives the name and business email you enter, current-system category, migration timeframe, follow-up consent, and coarse result buckets. That form does not upload the CSV, filename, fingerprint, serial numbers, customer fields, or FFL number.

6. Data Retention

Application data is retained while the account is active and as required for operation, legal obligations, dispute handling, and backups. The current product does not expose an automated self-service deletion endpoint. Email a deletion request and wait for confirmation of scope and timing. You are responsible for exporting and retaining any records you must keep before deletion.

7. Your Rights

8. Cookies and Analytics

BoundStack uses localStorage (not cookies) to store your authentication token and a random visitor identifier. We use Vercel Web Analytics and first-party analytics to understand page views, active sessions, and feature usage. The first-party analytics records the page path, time, random visitor/session identifiers, and account ID when you are signed in. It does not store your IP address, browser user agent, firearm records, or customer records. We do not sell your data.

9. Service Providers

Depending on production configuration, BoundStack may use Vercel for hosting and web analytics, a PostgreSQL hosting provider for application data, Resend or configured SMTP for email, Stripe for Pro subscription billing, an SMS provider when explicitly configured, and Sentry when a DSN is configured. Each provider receives only the data required for its configured function. Stripe checkout is unavailable when production billing configuration is incomplete.

10. Contact

Privacy questions: privacy@boundstack.org