The short version. NexusFFL is software a federally licensed firearms dealer uses to keep records the federal government requires that dealer to keep. Almost all of the personal information in NexusFFL is not ours — it belongs to the dealer’s records, and we hold it strictly on that dealer’s instructions. We do not sell it, we do not advertise against it, we do not use it to train anything, and we do not share it with anyone except the small set of vendors listed on our Subprocessors page.
1. Who we are, and the two very different roles in this policy
NexusFFL is operated by [LEGAL ENTITY NAME] (“NexusFFL,” “we,” “us”), [REGISTERED BUSINESS ADDRESS].
Two kinds of people appear in this policy, and the difference matters:
- Dealers. Our customers are federally licensed firearms dealers (FFLs). When a dealer signs up, we collect information about that business and the people who work there. For that information, we are the party that decides what to collect and why — a controller.
- Firearm purchasers and transferees. A dealer’s own customers never have an account with us and never sign up with us. Their information reaches us because the dealer entered it (or the buyer typed it into the dealer’s in-store form) to satisfy the dealer’s federal recordkeeping obligations. For that information the dealer is the controller and NexusFFL is only a processor / service provider. We handle it on the dealer’s documented instructions and for no purpose of our own.
If you bought a firearm and want to know what a dealer holds about you, or want something corrected, contact that dealer, not us. We cannot make substantive changes to a licensee’s federal records on our own initiative, and federal law tightly constrains what may be changed at all. We will support the dealer in responding to you — see section 9.
2. What we hold about firearm purchasers (on a dealer’s behalf)
This is the most sensitive data in the system, so we describe it exactly rather than generally. The electronic ATF Form 4473 record can contain every field of the current ATF Form 4473 (5300.9, revised August 2023), including:
- Identity: full legal name, current residence address (street, city, county, state, ZIP, and whether the address is inside city limits), place of birth, and date of birth.
- Physical description: height, weight, and sex.
- Government identifiers: Social Security number (Form 4473 question 16 — optional on the form and optional in NexusFFL), Unique Personal Identification Number (UPIN, question 17), and alien or admission number (question 20) where applicable.
- Ethnicity and race as recorded under question 18.
- Citizenship status and, if not a U.S. citizen, the country of citizenship.
- Identification document type/issuing authority, number, and expiration date, plus any supplemental identification, and, for military purchasers, permanent-change-of-station base, effective date, and order number.
- The buyer’s answers to question 21 (a) through (n) and the buyer’s written certification. These questions concern matters such as whether the buyer is the actual transferee, and criminal-history, indictment, fugitive, controlled-substance, adjudication, commitment, domestic-violence, restraining-order, and renunciation-of-citizenship status. A “yes” or “no” here is inherently sensitive information about a person.
- A signature image (a PNG captured on a signature pad or the buyer’s own phone screen), plus the certification date and, if the transfer happens on a later day, a recertification signature and date.
- Transaction and background-check data: NICS contact date, NICS transaction number and response (proceed / denied / cancelled / delayed, including delayed-response follow-ups), any state permit relied on in lieu of a NICS check (state, type, number, issue and expiration dates), and gun-show name and address for a transfer away from the licensed premises.
- The firearm(s) linked to that person: manufacturer, importer, model, caliber, type, and serial number, together with acquisition and disposition dates and the name of the party the firearm was acquired from or transferred to.
We also hold, again on the dealer’s behalf:
- Scanned paper Forms 4473 the dealer uploads (image or PDF file, plus indexed buyer name, transaction date and number, firearm description and serial, and a SHA-256 fingerprint of the file).
- Attachments a dealer uploads against a record — typically scanned paperwork or NFA documents — and their filename, type, size, uploader and upload time.
- Point-of-sale transaction data: line items, prices, tax, tender, receipt numbers, and any customer name or contact detail the dealer typed onto a sale. Firearm line items are linked to the underlying A&D record.
- Correction history. Once a Form 4473 is certified, we never overwrite it: corrections are stored as separate, appended entries recording the old value, the new value, the reason, who made it, and when. The same applies to A&D record corrections. This is deliberate — it is what makes the record defensible — but it means an entry cannot simply be erased.
We are working to reduce this footprint. Social Security number is optional on ATF Form 4473 and optional in NexusFFL. [CONFIRM WITH COUNSEL: whether to stop storing SSN entirely, or to store it encrypted at the column level rather than as plain text in the database file.]
3. What we collect directly (dealers, staff, and visitors)
- Waitlist. While signups are gated pre-launch, the only thing our marketing site collects is an email address, an optional business name, and a short tag recording which page the submission came from. Nothing else. Our marketing pages carry a cookieless analytics script (Plausible) that records aggregate page views and referrers only; it sets no cookies, collects no personal data, builds no visitor profile, and does not track anyone across other websites. There are no advertising pixels and no cross-site trackers.
- Account and staff records. Name, email address, a bcrypt hash of the password (never the password itself), role (owner, staff, or inspector), and optional location label.
- Business settings. Business name and address, Federal Firearms License number, state, and license, SOT and insurance expiration dates — used to print the dealer’s own forms and to raise expiration reminders.
- Business documents a dealer uploads to the org document vault (for example the FFL itself, insurance certificates, lease or zoning documents) and their expiration dates.
- Audit log. Every consequential action in the app is written to a hash-chained, append-only audit log with a timestamp and the signed-in staff member’s name. It exists so a dealer can prove to an inspector that records were not altered, so entries are not editable or deletable by anyone, including us.
- Operational logs. Our hosting provider records ordinary web-server request and application logs. [CONFIRM: log retention period at the hosting provider, and whether request logs capture IP addresses and full URLs.]
- Billing. [BILLING PROCESSOR AND WHAT IT COLLECTS — not yet in place; NexusFFL does not currently take subscription payments.]
4. Cookies
NexusFFL sets one cookie: the session cookie that keeps a signed-in user signed in. It is httpOnly (unreadable to JavaScript), sameSite=strict (never sent to another site), and marked secure in production. That cookie is strictly necessary to provide the service you asked for.
We use Plausible Analytics on our marketing pages to see which pages people find useful. It is deliberately chosen for being cookieless: it sets no cookies, stores no identifiers on your device, collects no personal data, and cannot follow you to any other website. We see aggregate counts — page views, referring sites, rough country — and never an individual person.
Why there is no cookie banner: consent requirements under the GDPR/ePrivacy rules and US state privacy laws attach to cookies and similar identifiers that are not strictly necessary. We set exactly one strictly necessary cookie and no analytics cookies at all, so there is nothing here that requires your consent. If we ever adopt a tool that does, we will ask first.
5. How we use it
We use dealer data to run the service: authenticate users, keep each business’s records separate, generate the dealer’s forms and reports, raise compliance reminders, deliver the integrations a dealer switches on, provide support, bill for the service, and keep the system secure and available.
Buyer data we use for one purpose only: to store, render, index, back up and return it to the dealer who put it there. Specifically, we do not:
- sell personal information, or share it for cross-context behavioral advertising;
- use one dealer’s data to benefit another dealer, or aggregate buyer data across dealers for any product, analytics, benchmarking or marketing purpose;
- use customer data to train machine-learning models;
- disclose buyer data to any government agency except as legally compelled — see section 10.
6. Who we share it with
The complete, current list of vendors that may process customer data is published at nexusffl.com/subprocessors.html. In summary:
- Railway hosts the application, the database and uploaded files, in a United States region. Every customer record passes through and rests on infrastructure Railway operates.
- Payment and accounting providers — only if a dealer connects one. NMI (via the dealer’s own gateway account) and, as a secondary option, Stripe; and for bookkeeping, Intuit QuickBooks Online or Xero. Nothing is sent to any of them unless that dealer connects it. Accounting sync sends sale totals, not 4473 or buyer-identity data (Xero additionally receives whatever customer name the dealer typed on a point-of-sale transaction, if any).
- Endpoints a dealer chooses. A dealer can register outbound webhooks. When they do, NexusFFL posts event payloads — including the full A&D record for an acquisition or disposition, which contains the transferee’s name and the firearm’s serial number — to a URL that dealer controls. We do not control what happens to data after it leaves for a dealer-configured endpoint. A dealer that turns webhooks on is responsible for the destination.
We may also disclose information if the business is sold or reorganized (with notice, and subject to the same commitments), and to our own professional advisors under confidentiality obligations.
7. Where your data lives, and how it is protected
NexusFFL runs on Railway in a United States region (US East, iad), with the database and uploaded files stored on a persistent volume mounted at /data. Records are not stored, replicated or processed outside the United States. This is not merely a preference: ATF Ruling 2016-1 conditions electronic A&D recordkeeping on records being maintained on a server located within the United States.
Protections that are actually implemented today:
- Every table is scoped to an organization ID, and every query filters by it — that is the isolation boundary between one dealer’s records and another’s.
- Passwords are hashed with bcrypt (cost 12), with a minimum length enforced; login attempts are rate limited.
- Sessions use
httpOnly, sameSite=strict, production-only secure cookies.
- TLS in transit; HTTP Strict Transport Security, a restrictive Content-Security-Policy, frame denial and MIME-sniffing protection are set by the application.
- All database access is parameterized; roles (owner / staff / read-only inspector) are enforced server-side, not just in the interface.
- Attachments and scanned 4473s require an authenticated session — they are not at guessable public URLs.
- The audit log is hash-chained and verifiable; certified Forms 4473 carry a content fingerprint so alteration is detectable.
- Buyer self-entry links are single-use, expire in 20 minutes, are revoked when a new one is issued, and can only reach the buyer’s own section of one form — never another record, and never the seller-only fields.
- Third-party integration secrets (OAuth refresh tokens, a dealer’s gateway key) are encrypted at rest with AES-256-GCM under a key held only in the server environment.
- Outbound webhook URLs are resolved and re-checked at delivery time to block internal, loopback and cloud-metadata addresses.
- Nightly backups are encrypted with AES-256 before they are written.
Stated honestly: the application database itself is a file on an encrypted-at-rest host volume; NexusFFL does not currently apply its own field-level encryption to Form 4473 data such as SSN. NexusFFL holds no SOC 2, ISO 27001, or PCI attestation, and has not undergone an independent security audit or penetration test. [CONFIRM RAILWAY VOLUME ENCRYPTION-AT-REST IN WRITING; DECIDE ON FIELD-LEVEL ENCRYPTION AND AN INDEPENDENT SECURITY REVIEW BEFORE MAKING ANY STRONGER CLAIM.]
Access by our own people: NexusFFL’s operator console shows business-level information — which businesses exist, plan and subscription status, staff account lists, settings such as license expiration dates, and record counts. It does not surface the contents of any dealer’s A&D records or Forms 4473. Direct access to the underlying database is limited to [NAMED OPERATIONS PERSONNEL] and used only for maintenance, backup and support, on request or to resolve a fault.
8. How long we keep it
Retention here is driven by federal law, not by our preference. A licensee must retain acquisition and disposition records and Forms 4473 for the periods federal firearms regulations require — a term measured in years and, for A&D records, effectively for the life of the business. NexusFFL therefore does not offer a “delete this record” button for A&D entries or certified Forms 4473, and corrections are appended rather than overwritten.
- While a dealer is a customer: we retain their records for as long as they use the service, and they can export at any time.
- After a dealer leaves: we retain their data for [POST-TERMINATION RETENTION WINDOW] so they can retrieve it, then delete it on the schedule set out in our Data Processing Addendum — unless the dealer instructs otherwise or law requires longer.
- If a dealer goes out of business: under ATF Ruling 2022-01 (condition 15) and the underlying regulations, that licensee’s records must be delivered to the ATF National Tracing Center. We will assist the dealer in producing a complete, usable export for that purpose. The obligation to make the delivery is the licensee’s.
- Waitlist entries: kept until launch outreach is complete, and removed on request at [PRIVACY CONTACT EMAIL]. [SET A FIXED WAITLIST RETENTION PERIOD.]
- Backups: encrypted nightly archives are pruned on a rolling retention window (currently 90 days), so deleted data can persist in backups until it ages out.
9. Your choices and rights
If you are a firearm purchaser: your relationship is with the dealer. Send access, correction or deletion requests to that dealer. When a dealer asks us to help answer one, we will. Be aware that federal recordkeeping law limits what any dealer can change or delete in a completed Form 4473 or bound-book entry, and that a request to erase such a record will usually have to be refused for that reason — that refusal is the dealer’s decision to make, on their attorney’s advice.
If you are a dealer or a staff user: you can access and correct your account details in the app, export your full bound book as CSV at any time, and close your account. Contact [PRIVACY CONTACT EMAIL] for anything you cannot do yourself.
[COUNSEL: CONFIRM WHICH STATE PRIVACY LAWS APPLY — INCLUDING THE FLORIDA DIGITAL BILL OF RIGHTS, AND CALIFORNIA/VIRGINIA/COLORADO-STYLE STATUTES REACHING BUYERS RESIDENT IN THOSE STATES — AND ADD THE REQUIRED RIGHTS, APPEAL PROCESS, AND “DO NOT SELL OR SHARE” DISCLOSURES. THIS DRAFT INTENTIONALLY DOES NOT ASSERT WHICH STATUTES APPLY.]
10. Law enforcement and legal requests
We do not give any government agency standing or routine access to customer data. If we receive a subpoena, warrant, court order or other compulsory demand for a dealer’s records, our policy is to notify that dealer promptly so they can respond or object, unless we are legally prohibited from telling them. An inspection of a licensee’s records by ATF is conducted with that licensee — NexusFFL provides a read-only inspector role the dealer can grant, and the dealer decides whether to use it.
11. If something goes wrong
We maintain a written incident response plan. If we determine that a security breach affected personal information we hold for a dealer, we will notify that dealer without unreasonable delay and no later than 10 days after determination, as Florida’s data-breach statute requires of a third-party agent, and cooperate with them on any notice they owe to individuals or regulators. Where the obligation falls on us directly, we will notify affected individuals within 30 days, and the Florida Department of Legal Affairs within 30 days where 500 or more Florida residents are affected.
12. Children
NexusFFL is business software sold to licensed dealers and is not directed to children. We do not knowingly collect information from children. Federal law sets minimum ages for firearm purchases, so a Form 4473 in the system should never describe a child.
13. Changes to this policy
If we make a material change we will update the date at the top of this page and notify dealers at [NOTICE METHOD AND ADVANCE NOTICE PERIOD] before it takes effect.
[LEGAL ENTITY NAME]
[REGISTERED BUSINESS ADDRESS]
[PRIVACY CONTACT EMAIL]
[NEXUSFFL HAS NOT APPOINTED A DATA PROTECTION OFFICER AND MAKES NO CLAIM TO HAVE ONE. IF A STATUTE OR CUSTOMER CONTRACT REQUIRES A NAMED PRIVACY CONTACT OR EU/UK REPRESENTATIVE, IT MUST BE APPOINTED AND NAMED HERE.]