Last updated 23 June 2026
This Cookie and Storage Notice explains how Firearms Records uses cookies and browser storage in connection with the Firearms Records platform, website, applications, dashboards, reports, exports, APIs, and related services (the Platform).
Firearms Records is operated by Firearms Records, established in England (Firearms Records, we, us, or our). Our legal and privacy contact email address is legal@firearmsrecords.co.uk.
This notice should be read together with our Terms of Service and Privacy Policy.
1. Summary
1.1. We use a small number of cookies and browser storage technologies to operate, secure, and personalise the Platform.
1.2. We do not currently use Firearms Records analytics cookies, advertising cookies, marketing pixels, heatmaps, session replay, cross-site tracking, or similar non-essential tracking technologies. Cloudflare may provide traffic, security, and performance information, including through a performance beacon, as explained below.
1.3. We do not store your FAR Record, certificate details, firearm details, declarations, documents, Organisation records, permissions, access tokens, or refresh tokens in cookies or local storage.
1.4. Authentication and access decisions are handled primarily through a secure session identifier, XSRF/CSRF protection, and server-side access controls.
2. Current cookies and browser storage
The following table describes the cookies and browser storage used by Firearms Records at the date of this notice.
| Name or technology | Type | Purpose | Essential? | Typical duration / control |
|---|---|---|---|---|
firearms-records-session | First-party session cookie | Keeps you signed in, links your browser to the server-side session, and supports secure authenticated use of the Platform. This cookie is marked HttpOnly and Secure. | Yes | Session or limited duration determined by Platform session settings; cleared or invalidated on logout, session expiry, account/security changes, or browser/site-data clearing where applicable. |
XSRF-TOKEN | First-party security cookie | Helps protect the Platform against cross-site request forgery and unauthorised browser requests. This cookie is marked Secure. | Yes | Session or limited duration determined by Platform security settings; cleared or refreshed as part of normal security flows. |
firearms.theme | Local storage | Stores your selected interface theme: system, light, or dark. It does not contain FAR Numbers, identity data, certificate data, firearm data, Organisation records, access tokens, or refresh tokens. | Functional / preference | Stored until you change/reset your preference or clear browser site data. |
| Static UI resources | Browser cache | Allows the browser to cache non-sensitive application resources such as JavaScript, CSS, images, fonts, and other interface assets so that the Platform loads efficiently. | Functional / performance | Controlled by browser and cache headers. API responses and sensitive Platform data are not intended to be cached or stored. |
| Cloudflare performance beacon | Third-party performance script / beacon | Where enabled, Cloudflare may inject or load a performance monitoring beacon to collect page performance information, such as page-load timing and related performance metrics. This does not store your FAR Record, identity data, certificate data, firearm data, declarations, documents, or Organisation records in the browser. | Performance monitoring | Runs during relevant page views where enabled by Cloudflare; controlled by Cloudflare configuration and browser/script controls. |
3. Cloudflare security, routing, and performance technologies
3.1. We use Cloudflare for security, routing, rate limiting, web application firewall, content delivery, load balancing, performance monitoring, and related service-integrity purposes.
3.2. Cloudflare may set cookies or use similar technologies where needed for security checks, managed challenges, bot mitigation, rate limiting, routing, or service integrity. For example, a managed challenge may require a browser cookie or equivalent technology to confirm that the challenge has been completed.
3.3. Cloudflare technologies may apply to both the public website and the authenticated Platform. The exact Cloudflare cookies set may vary depending on traffic, risk signals, browser behaviour, security configuration, and whether a challenge is presented.
3.4. We do not list every possible Cloudflare security cookie in this notice because those cookies are set and controlled by Cloudflare depending on configuration and security context. We describe them by purpose instead: security, routing, availability, abuse prevention, and service integrity.
3.5. Cloudflare may also inject or load a performance monitoring beacon or script, including Cloudflare Web Analytics, Cloudflare Insights, Cloudflare Observatory RUM, or a similar Cloudflare performance beacon. This helps us understand page performance, loading behaviour, reliability, Core Web Vitals, and service availability.
3.6. Based on Cloudflare’s current documentation, the Cloudflare RUM/Web Analytics beacon collects performance data from browser performance APIs, does not store data in the browser, and does not access cookies, local storage, browser sessionStorage, IndexedDB, or similar browser storage. We do not use that Cloudflare performance beacon for advertising, behavioural marketing, cross-site tracking, heatmaps, or session replay.
4. Stripe payment technologies
4.1. Where payment functionality is used, we use embedded Stripe Checkout.
4.2. Stripe may use cookies, scripts, browser storage, device information, IP addresses, payment-session identifiers, and similar technologies for checkout, payment security, fraud prevention, transaction processing, billing, and compliance purposes.
4.3. Stripe technologies are used only where payment, billing, or checkout functionality is relevant. Stripe also provides its own terms and privacy information.
5. Public website and authenticated Platform
5.1. The public website does not set Firearms Records authentication cookies unless and until you begin a login, account, payment, or other Platform flow that requires them.
5.2. The authenticated Platform uses the session cookie, XSRF/CSRF protection, and server-side access controls to provide authenticated functionality.
5.3. Cloudflare security, routing, and performance technologies may apply to the public website and the authenticated Platform.
6. Browser cache and sensitive data
6.1. API responses, authenticated record data, documents, declarations, reports, certificate data, firearm data, and other sensitive Platform data are not intended to be cached or stored by the browser.
6.2. Non-sensitive UI resources, such as JavaScript and CSS files, may be cached by the browser to improve performance.
6.3. If you download, print, save, screenshot, or export documents or reports, copies may remain on your device, in your downloads folder, in your browser, in your operating system cache, or in other local storage controlled by you or your device. You are responsible for securing those local copies.
7. Technologies we do not currently use
7.1. Firearms Records does not currently use:
- advertising cookies;
- marketing pixels;
- third-party behavioural advertising tags;
- heatmaps;
- session replay;
- cross-site tracking;
- Firearms Records analytics cookies;
- browser fingerprinting for marketing analytics;
sessionStorage;- IndexedDB;
- service workers;
- progressive web app offline storage; or
- offline application cache.
7.2. Cloudflare Insights, Web Analytics, Observatory RUM, or similar Cloudflare-provided traffic or performance information may be used as described in our Privacy Policy. Based on our current implementation, this does not involve Firearms Records setting additional analytics cookies on your device, and Cloudflare states that its RUM/Web Analytics beacon does not store data in the browser or access cookies, local storage, browser sessionStorage, IndexedDB, or similar browser storage.
7.3. Server-side access logs, error logs, audit logs, report logs, lookup logs, security logs, and similar records are explained in our Privacy Policy. They are not generally browser storage technologies, although they may record technical information generated when your browser communicates with the Platform.
8. Managing cookies and preferences
8.1. You can change your theme preference at any time, including by selecting the system/default theme where available.
8.2. You can also clear cookies, local storage, cache, and site data through your browser settings.
8.3. Blocking or deleting the session cookie or XSRF/CSRF cookie may prevent the Platform from working correctly or at all.
8.4. Clearing local storage may reset your theme and other non-sensitive interface preferences.
9. Future analytics, tracking, or additional storage
9.1. We may introduce analytics, product measurement, performance monitoring, error analytics, marketing analytics, or similar technologies in the future.
9.2. If we introduce non-essential cookies, analytics, advertising, marketing pixels, heatmaps, session replay, cross-site tracking, or similar technologies that require consent or additional controls, we will update this notice and provide consent, opt-out, or preference controls where required by law.
10. Contact
For questions about this Cookie and Storage Notice, contact:
Firearms Records
Email: legal@firearmsrecords.co.uk