This Policy covers CloudFFL websites, CloudFFL OS, the CloudFFL FFL API, plugins, integrations, support, and related services operated by Longhorn Web Solutions, LLC, doing business as CloudFFL.
1. Scope
This Privacy Policy explains how Longhorn Web Solutions, LLC, doing business as CloudFFL ("CloudFFL," "we," "us," or "our"), collects, uses, shares, retains, and protects personal information when you visit our websites, communicate with us, create an account, or use CloudFFL products and services.
This Policy should be read with the Terms of Service and any applicable product addendum. It does not govern a third party's independent collection or use of information.
2. Our Privacy Roles
CloudFFL generally determines how information about website visitors, account owners, billing contacts, API users, support requesters, and business prospects is processed.
When CloudFFL OS processes personal information that a Customer enters into its managed instance—such as information about the Customer's employees, consumers, vendors, or transactions—CloudFFL generally processes that information on the Customer's behalf. The Customer determines why the information is collected and how it is used and is responsible for its notices, permissions, access decisions, and legal obligations.
If you have a question about information held by a CloudFFL Customer, contact that Customer first. We may refer your request to the Customer or assist the Customer in responding.
3. Information We Collect
Contact and Account Information
We may collect:
- name, email address, telephone number, job title, and business contact details;
- company name, business type, FFL information, service locations, and account profile information;
- usernames, authentication identifiers, role and permission information, and security events;
- communications, support requests, feedback, survey responses, and meeting information; and
- the products, plans, services, integrations, or demonstrations in which you express interest.
Billing and Commercial Information
We collect subscription, order, invoice, transaction, tax, billing contact, payment status, and cancellation information. Payment processors generally collect and process complete payment-card or bank details on our behalf; CloudFFL may receive tokens, limited payment details, and transaction status rather than the complete payment credential.
CloudFFL OS Customer Data
Depending on the Customer's configuration and use, CloudFFL OS may process business, employee, vendor, inventory, product, serial-number, transaction, accounting, customer, order, shipment, communication, FFL, compliance, and related operational information. Customers control what they enter, import, connect, and retain in their instance.
FFL API and Integration Data
We collect API account and key identifiers, endpoints requested, search parameters, timestamps, response codes, usage measurements, IP addresses, security signals, and related diagnostic data. Plugins and integrations may transmit configuration, location, dealer-selection, order context, or other information needed to perform the requested function.
The FFL API provides information derived in part from public government records and other sources. Public FFL records may include business and license-related information associated with individuals or sole proprietors.
Website, Device, and Analytics Information
When you use our websites or Services, we may collect:
- IP address, browser, device, operating system, language, and approximate location;
- pages viewed, referring pages, links clicked, session timing, and interaction events;
- cookie, analytics, campaign, and similar identifiers; and
- logs, crash data, performance measurements, and security events.
Agreement and Acceptance Records
When you accept terms or an order, we may record the document name, version, effective date, acceptance wording, timestamp, account, signer and business information, authority confirmation, IP address, user agent, checkout or subscription identifiers, and related audit evidence.
4. Sources of Information
We collect information:
- directly from you, your organization, and authorized users;
- automatically from websites, applications, APIs, infrastructure, and connected systems;
- from payment, authentication, hosting, analytics, email, support, and security providers;
- from Customers, integration partners, distributors, marketplaces, and other third parties you authorize;
- from public government records and other publicly available sources; and
- from business partners, referrals, and professional contacts.
5. How We Use Information
We use information to:
- provide, configure, provision, operate, meter, maintain, and improve the Services;
- create and secure accounts, authenticate users, issue credentials, and manage permissions;
- process orders, payments, renewals, credits, cancellations, and account changes;
- provide onboarding, training, support, incident response, and service communications;
- operate FFL search, geocoding, plugins, integrations, and related data services;
- monitor performance, analyze usage, troubleshoot errors, and develop features;
- detect, investigate, and prevent fraud, abuse, credential compromise, and security incidents;
- enforce agreements, document acceptance, resolve disputes, and protect legal rights;
- comply with legal obligations and respond to lawful requests; and
- send product, educational, or marketing communications where permitted, with available opt-out controls.
6. How We Share Information
We may share information:
- With service providers: hosting, infrastructure, payment, email, analytics, authentication, monitoring, security, support, and professional-service providers that process information for us.
- At the Customer's direction: with integrations, marketplaces, processors, compliance providers, distributors, shipping services, developers, or other parties a Customer enables.
- Within an account: with account owners, administrators, authorized users, and representatives of the Customer organization.
- For legal and safety reasons: when reasonably necessary to comply with law, legal process, or lawful government requests; enforce agreements; investigate fraud or abuse; or protect rights, safety, systems, and users.
- For business transactions: in connection with financing, diligence, a merger, acquisition, restructuring, sale of assets, or similar transaction, subject to appropriate protections.
- With consent: when you or the applicable Customer asks or authorizes us to do so.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are defined by applicable state privacy laws.
7. Customer-Enabled Integrations
When a Customer connects a third-party service, the Customer directs CloudFFL to exchange information with that service. The third party may independently collect, use, retain, or disclose information under its own agreement and privacy policy. Customers should review third-party terms, permissions, and data practices before enabling an integration.
8. Cookies and Analytics
We use cookies, local storage, pixels, scripts, and similar technologies for essential functionality, security, preferences, measurement, and analytics. Our marketing website uses Plausible Analytics and may use Google Analytics to understand visits and interactions. These services may receive device, usage, and network information as configured.
Browser and device controls can limit cookies or similar technologies, but disabling essential storage may affect login, security, preferences, or Service functionality.
9. Security
We use administrative, technical, and physical safeguards designed to protect information based on its nature and the Services involved. Measures may include access controls, authentication, encryption, logging, monitoring, backups, network controls, vendor management, and incident-response procedures.
No system, transmission, or storage method is completely secure. Customers and users are responsible for protecting their credentials, devices, networks, exports, and access permissions and for promptly reporting suspected compromise.
10. Retention
We retain information for as long as reasonably necessary to provide the Services, maintain accounts, complete transactions, support Customers, secure systems, enforce agreements, document acceptance, resolve disputes, and comply with legal obligations. Retention varies by information type, Customer instructions, account status, backup rotation, and legal requirements.
When a CloudFFL OS subscription ends, production Customer Data is handled according to the applicable Order Form, offboarding notice, and CloudFFL OS Addendum. Information may remain in restricted backups until normal expiration and may be retained longer for legal, security, fraud-prevention, or dispute purposes.
11. Privacy Rights and Choices
Depending on where you live and the context in which we process information, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to appeal a decision. You may also opt out of non-essential marketing communications using the link in the message or by contacting us.
We may need to verify your identity and authority before completing a request. Applicable law may permit or require us to retain certain information or decline part of a request. Authorized agents may submit requests when they provide legally sufficient authorization.
For information controlled by a CloudFFL Customer, submit the request to that Customer. We will assist the Customer as required by our agreement and applicable law.
12. Data Location and Transfers
CloudFFL and its service providers may process information in the United States and other locations where they operate. Those locations may have different data-protection laws from your jurisdiction. Where required, we use appropriate contractual or other safeguards for cross-border transfers.
13. Children
CloudFFL Services are intended for businesses and are not directed to children under eighteen. We do not knowingly collect personal information directly from children for their own use of the Services. Customers are responsible for ensuring that information they process through CloudFFL OS is collected and used lawfully.
14. Changes to This Policy
We may update this Policy as our Services, providers, or legal obligations change. We will post the updated version and effective date. When a change materially affects how we process personal information, we will provide additional notice when appropriate or required by law.
15. Contact
To ask a privacy question or submit a request, contact:
Longhorn Web Solutions, LLC, doing business as CloudFFL
Email: privacy@cloudffl.com
Website: cloudffl.com/contact