Privacy Policy
Last updated: August 11, 2026
1. Information We Collect
BoundStack collects information you provide directly, including:
- Account information: name, email address, password (hashed), FFL number, shop name
- Firearm records: A&D book entries you create (manufacturer, serial number, acquisition/disposition data)
- Customer records: buyer information you enter for compliance purposes
- Usage data: page views, feature usage, error logs
2. How We Use Your Information
- To provide and maintain the BoundStack service
- To send transactional emails (account confirmation, password resets)
- To improve the platform and fix bugs
- We do not sell your data to third parties
- We use service providers only as needed to host, secure, communicate, monitor, and bill for the service, subject to the configured production environment
3. Data Security
Server-side application data is stored in the PostgreSQL database configured through the production DATABASE_URL; this policy does not name a database vendor because the deployment can change. Passwords are hashed using bcrypt with cost factor 12. Signed authentication tokens expire after 7 days. Production traffic is expected to use HTTPS through the configured hosting platform.
The browser stores the authentication token and limited account/UI state in localStorage, a random analytics visitor ID in localStorage, and a session ID in sessionStorage. The service worker caches public application-shell assets but does not cache authenticated API responses. A user-scoped gun-show queue may remain in localStorage until it is synchronized, discarded, or cleared at logout.
4. ATF Compliance Data
Your Acquisition & Disposition records, Form 4473 data, and customer records are your records. BoundStack stores them on your behalf. You remain responsible for current recordkeeping, official-form, retention, and reporting requirements. We do not audit or certify your records.
5. Local A&D Preflight and Migration Review
The public A&D CSV preflight reads the selected file inside your browser. File bytes, raw rows, serial numbers, names, addresses, FFL numbers, the raw filename, and the SHA-256 fingerprint are not sent to BoundStack by the preflight workflow. The local report may include the full fingerprint and redacted value previews when you choose to download or open it.
First-party preflight analytics are limited to the page, validator and rule versions, generic profile status, coarse row and issue-count buckets, elapsed-time bucket, and technical error class. If you separately request a migration review after seeing results, BoundStack receives the name and business email you enter, current-system category, migration timeframe, follow-up consent, and coarse result buckets. That form does not upload the CSV, filename, fingerprint, serial numbers, customer fields, or FFL number.
6. Data Retention
Application data is retained while the account is active and as required for operation, legal obligations, dispute handling, and backups. The current product does not expose an automated self-service deletion endpoint. Email a deletion request and wait for confirmation of scope and timing. You are responsible for exporting and retaining any records you must keep before deletion.
7. Your Rights
- Export your data at any time via CSV export
- Request account-data deletion review by emailing privacy@boundstack.org
- Update your information in Settings at any time
8. Cookies and Analytics
BoundStack uses localStorage (not cookies) to store your authentication token and a random visitor identifier. We use Vercel Web Analytics and first-party analytics to understand page views, active sessions, and feature usage. The first-party analytics records the page path, time, random visitor/session identifiers, and account ID when you are signed in. It does not store your IP address, browser user agent, firearm records, or customer records. We do not sell your data.
9. Service Providers
Depending on production configuration, BoundStack may use Vercel for hosting and web analytics, a PostgreSQL hosting provider for application data, Resend or configured SMTP for email, Stripe for Pro subscription billing, an SMS provider when explicitly configured, and Sentry when a DSN is configured. Each provider receives only the data required for its configured function. Stripe checkout is unavailable when production billing configuration is incomplete.
10. Contact
Privacy questions: privacy@boundstack.org