Last updated 23 June 2026
This Privacy Policy explains how Firearms Records collects, uses, stores, shares, protects, retains, and otherwise processes personal data in connection with the Firearms Records platform, website, applications, dashboards, reports, exports, APIs, and related services (the Platform).
The Platform is operated by Firearms Records, established in England (Firearms Records, we, us, or our). Our legal and privacy contact email address is legal@firearmsrecords.co.uk.
ICO registration number: pending
This Privacy Policy is a privacy notice. It is not a blanket consent form. Where we rely on consent for a particular action, we will seek that consent separately or through a specific Platform flow.
1. Scope and key points
1.1. This Privacy Policy applies to Shooters, parents and guardians, Non-Adult Accounts, Clubs, RFDs, Police Force users, Home Office users, Organisation Users, trial users, administrators, support contacts, billing contacts, visitors, and anyone whose personal data is processed through the Platform.
1.2. The Platform is intended for users and organisations located in the United Kingdom. Unless expressly stated otherwise, firearms compliance functionality is designed primarily for England, Wales, and Scotland.
1.3. Firearms Records supports compliance recordkeeping. It is not a statutory firearms registry and does not replace statutory, legal, licensing, RFD, Club, Police Force, Home Office, insurance, or other obligations.
1.4. The Platform handles sensitive records. These may include identity information, address information, certificate information, supporting documents, Section 21 Declarations, firearm details, attendance records, usage records, RFD records, reports, custom Organisation documents, custom Organisation notes, audit logs, and access records.
1.5. Because the Platform is compliance and audit software, some records may be retained for extended periods even after access is revoked, consent is withdrawn, an Account is closed, a subscription is cancelled, or a user asks for erasure. We will only retain personal data where we have a lawful basis to do so.
1.6. We maintain internal privacy and data-protection governance documents for compliance and accountability. These include a Data Protection Impact Assessment, an Appropriate Policy Document where required, an internal Retention Schedule, Legal Hold controls, and related security, access-control, and audit records. These internal documents are not generally published, but this Privacy Policy summarises the parts that are relevant for users, including data categories, purposes, sharing, safeguards, rights, and retention criteria.
2. Definitions
Terms used in this Privacy Policy have the same meaning as in the Terms of Service unless stated otherwise. In particular:
- FAR Number means the Firearms Records identifier allocated to a FAR Record or Account.
- FAR Record means the Platform record associated with a Shooter or Non-Adult Account.
- Club means a shooting club or similar organisation using the Platform.
- RFD means a Registered Firearms Dealer.
- Organisation User means an individual acting for a Club, RFD, Police Force, Home Office team, employer, or other organisation.
- Snapshot means a point-in-time record captured for compliance, audit, evidential, or historical purposes.
- Compliance Evidence means records retained for compliance, audit, legal, insurance, investigation, safeguarding, or evidential purposes.
3. Controller and processor roles
3.1. Data protection roles may vary depending on the feature, record type, user type, Organisation type, and purpose of processing.
3.2. We usually act as a controller for:
- account creation and administration;
- FAR Number allocation;
- login, authentication, security, MFA, and verification;
- Platform operation;
- audit logs, access logs, security logs, and error logs;
- transactional emails;
- billing and payment administration;
- user feedback and support;
- Platform-wide compliance, misuse prevention, and investigation;
- cookie and storage technologies that we control;
- our own legal, regulatory, insurance, tax, accounting, and dispute-resolution purposes.
3.3. Clubs, RFDs, Police Forces, Home Office users, and other Organisations may act as independent controllers for their own purposes, including deciding why they need to access, create, verify, retain, disclose, export, or otherwise use records.
3.4. Where a Club creates membership records, attendance records, usage records, identity verification records, custom notes, custom documents, compliance records, reports, or exports for its own purposes, the Club will usually be responsible for its own use of that data.
3.5. Where an RFD uses the Platform for verification, transaction, acquisition, disposal, stock, transfer, customer evidence, or audit purposes, the RFD will usually be responsible for its own use of that data.
3.6. Police Forces and Home Office users are responsible for their own official access purposes, lawful authority, internal policies, retention, onward sharing, and use of any data they access, create, assert, modify, alter, attach, detach, obtain, disclose, delete, destroy, or otherwise process through the Platform, where such functionality is enabled and permitted.
3.7. Organisations may already be able to upload custom notes, documents, emails, files, evidence, attachments, public notes, private notes, and similar Organisation records through the Platform. This Privacy Policy covers that processing even where an Additional Agreement has not yet been signed. Additional Agreements may impose specific conditions, restrictions, access controls, retention rules, acceptable-use rules, data-sharing terms, or processing terms for particular Organisation types or features.
3.8. In some cases, we may act as a processor for an Organisation where we host, store, or process data on that Organisation’s documented instructions. Where required, this will be addressed in an Additional Agreement, data processing agreement, data sharing agreement, or organisation access agreement.
3.9. This Privacy Policy describes our processing. Organisations using the Platform may also need to provide their own privacy information to individuals.
4. Personal data we collect
We may collect and process the following categories of personal data, depending on how the Platform is used. This table is not intended to be exhaustive. We may add new fields, documents, workflows, record types, reports, permissions, metadata, logs, or features from time to time. Where a new feature involves a materially new category of personal data, a materially new purpose, a materially new recipient, or a materially different privacy impact, we will update this Privacy Policy or provide additional privacy information where required. Minor variations within existing categories may not require a separate update.
| Category | Examples |
|---|---|
| Account data | Email address, password hash, date of birth, FAR Number, account status, email verification status, SSO verification status, roles, permissions, organisation membership, MFA status, login status. |
| Identity data | Title, legal first names, middle names, last name, previous names where provided, date of birth, identity verification status, identity document references, identity documents where uploaded. |
| Contact data | Email address, telephone number, alternative contact details, parent or guardian contact details, organisation contact details. |
| Address data | Current address, previous address where relevant, address lines, town/city, county, country, postcode, address verification information, proof-of-address documents where uploaded. |
| Certificate data | Firearm certificate details, shotgun certificate details, organisation certificate details, Club certificate or approval details, RFD certificate or registration details, certificate numbers, issuing force, expiry dates, renewal dates, status, document copies, supporting evidence, related notes. |
| Section 21 and declaration data | Section 21 Declarations, prohibited-person declarations, identity confirmations, address confirmations, legal-name confirmations, declaration timestamps, declaration history, declaration records, confirmation records, evidence of acceptance. |
| Firearm and armoury data | Firearm type, calibre, make, model, serial number, status, ownership or usage context, shared firearm records, Club armoury references, usage links, attendance links. |
| Attendance and usage data | Attendance dates, shooting ground, session, legal basis, supervision, guest/member status, firearm usage, ammunition usage, Club notes, staff records, membership progress, probationary status. |
| Organisation records | Club records, RFD records, Police Force records, Home Office records, membership records, onboarding records, custom notes, custom documents, public notes, private notes, identity verification records, incident records, safeguarding records, reports, exports, governance records, access records. |
| RFD records | Stock records, acquisition records, disposal records, transfer records, customer or source details, certificate verification details, firearm serial numbers, document references, transaction notes, audit records. |
| Police/Home Office access data | Lookup purpose, search data, case/reference details, documentation, records accessed, timestamps, user identity, organisation identity, access outcome, audit logs, notes or attachments created by authorised users. |
| Reports and exports | Generated reports, export files, report metadata, download status, expiry status, download logs, requesting user, recipients, retention holds, report contents. |
| Files and documents | Identity documents, address documents, certificate documents, Club forms, RFD forms, Organisation forms, uploaded evidence, screenshots, feedback attachments, custom files. |
| Feedback and support data | Feedback text, support messages, optional contact consent, screenshots submitted with browser permission, bug reports, feature requests, diagnostic information. |
| Billing and payment data | Customer name, organisation name, billing contact, billing address, invoice details, subscription status, payment method metadata, Stripe customer/payment references, payment status, refunds, credits. |
| Communications data | Emails sent to you, in-app messages, transactional notices, security notices, verification emails, support messages, delivery/bounce/complaint metadata where available. |
| Technical and audit data | IP address, user agent, browser, device, approximate country/location, session identifiers, timestamps, login events, access events, actions taken, records viewed, downloads, exports, errors, security events, administrative actions. |
| Cookie, storage, traffic, and performance data | Cookies, local storage, cache files, device/browser identifiers, security tokens, preference data, third-party routing or security data, Cloudflare traffic/performance/security insights, Cloudflare performance-beacon data where enabled, and future analytics data if introduced. |
4.1. Organisation access to Platform records. Information disclosed to, created in, uploaded to, generated by, or otherwise processed through the Platform may be made available to relevant Organisations and authorised Organisation Users where permitted by Platform functionality, role-based permissions, Organisation configuration, verification status, association or sharing flows, lookup functionality, purpose-capture requirements, Additional Agreements, applicable law, or another lawful basis.
4.2. Depending on the relevant workflow, permissions, Organisation type, and record state, this may include some or all of: identity information, legal names, email address, telephone number, date of birth, address information, certificate information, certificate documents, firearm and armoury information, Section 21 Declarations, attendance records, usage records, membership records, RFD verification or transaction records, Police Force or Home Office access records, Organisation notes, Organisation documents, emails, reports, exports, audit metadata, and other information collected, uploaded, generated, or retained through the Platform from time to time.
4.3. This does not mean that every Organisation or every Organisation User can access all information. Access is restricted according to Platform permissions, Organisation role, record relationship, workflow, verification status, lawful purpose, purpose capture, and audit controls. Organisations are responsible for ensuring that their Organisation Users are properly authorised and that they use, retain, disclose, export, and protect Platform data lawfully.
5. Minimum data for account creation
5.1. The current minimum information required to create an individual Firearms Records Account and obtain a FAR Number is:
- email address;
- date of birth;
- password; and
- verified email status.
Users must verify their email address before using the Platform. For most users, this means completing an email verification process sent by us. For users onboarded through single sign-on or another verified identity provider, email verification may be inferred from the verified SSO session or identity-provider assertion.
5.2. We may require additional information before allowing particular actions, including Club association, Section 21 Declaration completion, certificate tracking, firearm record creation, RFD verification, Police Force access, Home Office access, report generation, payment, or organisation administration.
5.3. Organisations are provisioned by us. Users cannot create a Club, RFD, or other Organisation on demand. Once an Organisation has been provisioned, that Organisation may invite, add, remove, or manage Organisation Users in accordance with the functionality, permissions, roles, verification status, and Additional Agreements that apply to that Organisation. Access to an Organisation must be expressly granted by the Organisation and/or by us, as applicable, and may be subject to onboarding, paperwork, role assignment, verification, SSO, Additional Agreements, and access controls.
5.4. We use date of birth for identification, matching, age-related controls, association requests, duplicate detection, account security, and compliance workflows.
6. Non-Adult Accounts
6.1. Individuals under 18 may not directly create or control their own Account.
6.2. A parent or guardian may create a Non-Adult Account for an individual under 18. The Non-Adult Account receives its own distinct FAR Number, but access and control are handled exclusively through the responsible parent or guardian Account until the individual reaches 18.
6.3. The parent or guardian may provide, update, verify, share, revoke, or authorise information for the Non-Adult Account, including Club associations, Section 21 Declarations, identity information, address information, attendance records, certificate information where applicable, firearm usage records, and related compliance data.
6.4. We process Non-Adult Account data for the same broad purposes as adult Shooter data, but with additional access controls reflecting the parent or guardian responsibility model.
6.5. When the individual associated with a Non-Adult Account reaches 18, the parent or guardian is no longer eligible to manage that Account on the individual’s behalf. From that point, the parent or guardian’s access to the Non-Adult Account and FAR Record is restricted. The only function that may remain available to the parent or guardian is the functionality we provide to supply or confirm an email address for the individual and enable the account-promotion process.
6.6. If an email address has already been supplied for the Non-Adult Account, we may contact the individual after their 18th birthday and require them to verify their email address, create their own password where required, and accept the then-current Terms of Service, Privacy Policy, Cookie and Storage Notice, and any relevant notices before using the Platform directly.
6.7. If no email address has been supplied for the Non-Adult Account, we may contact the responsible parent or guardian to notify them that the individual has reached 18, that the parent or guardian is no longer eligible to manage the Account on that individual’s behalf, and that an email address must be supplied so that the standard email verification and account-promotion process can be completed.
6.8. Once the former Non-Adult Account is promoted, the FAR Number and FAR Record are moved to, or made accessible through, the newly created or promoted Adult Shooter Account. The former parent or guardian Account will no longer be able to see, manage, access, or act in respect of any record of the former Non-Adult Account through the Platform.
6.9. The account-promotion process requires the former Non-Adult to agree to the Terms of Service and acknowledge the Privacy Policy directly before using the Platform as an Adult Shooter.
7. How we collect personal data
We may collect personal data:
- directly from you when you create an Account, update your profile, upload documents, complete declarations, submit feedback, create records, make payments, or contact us;
- from a parent or guardian managing a Non-Adult Account;
- from a Club when it initiates an Association Request, creates attendance records, uploads documents, writes notes, records membership information, records usage, or generates reports;
- from an RFD when it creates verification, stock, acquisition, disposal, transfer, transaction, or audit records;
- from Police Force or Home Office users when they perform lookups, submit purposes, upload documentation, or access records;
- automatically through the Platform, including audit logs, access logs, security logs, error logs, cookies, local storage, browser cache, server-side session data, and browser/device metadata;
- from service providers such as hosting, storage, email, payment, DNS, security, and support providers;
- from documents, screenshots, reports, or files uploaded to the Platform;
- from communications and support interactions.
8. Purposes and lawful bases
We process personal data only where we have a lawful basis. The exact lawful basis may depend on the user, feature, organisation, and context.
| Purpose | Examples | Usual lawful basis |
|---|---|---|
| Account creation and administration | Creating Accounts, allocating FAR Numbers, verifying email, inferring verification through SSO, managing profiles, login and authentication. | Contract; legitimate interests; legal obligation where applicable. |
| Security and fraud prevention | MFA, password reset, suspicious activity detection, audit logs, access logs, account protection, misuse prevention. | Legitimate interests; contract; legal obligation. |
| Organisation provisioning and access control | Creating Organisation Accounts on behalf of Clubs, RFDs, Police Forces, Home Office teams, and other Organisations; granting and removing Organisation User access. | Contract; legitimate interests; legal obligation where applicable; Organisation’s own lawful basis. |
| Club association | Allowing a Club to request association; allowing the Shooter or parent/guardian to accept or reject; recording Snapshots. | Consent for the specific sharing action where used; contract; legitimate interests; Club’s own lawful basis. |
| Section 21 Declarations | Capturing a new declaration for each Club association; capturing identity, address, declaration, confirmation, and evidence relating to prohibited-person status and Club compliance; producing or making available a declaration record for the Club. | Contract; legitimate interests; legal obligation where applicable; DPA 2018 Schedule 1 condition for criminal offence data where applicable; legal claims where applicable; Club’s own lawful basis. |
| Attendance, usage, and membership records | Club attendance, membership status, probationary progress, firearm usage, ammunition usage, supervision, legal basis, notes. | Legitimate interests; contract; legal obligation where applicable; Club’s own lawful basis. |
| Firearm Sharing | Sharing firearm details with a Club or permitted Organisation on a firearm-by-firearm basis or through another explicit Platform flow if introduced. | Consent for the specific sharing action where used; contract; legitimate interests; Organisation’s own lawful basis. |
| RFD verification and transactions | RFD lookups, certificate checks, stock records, transfers, acquisitions, disposals, audit evidence. | Contract; legitimate interests; legal obligation where applicable; RFD’s own lawful basis. |
| Police Force and Home Office access | Verified official access, purpose capture, record lookup, documentation, audit logs, compliance review, notes or attachments created by authorised users. | Legal obligation where applicable; legitimate interests; substantial public interest where applicable; disclosure to public authorities where necessary and proportionate; public authority’s own lawful basis. |
| Organisation custom records | Organisation notes, public notes, private notes, emails, documents, attachments, supporting evidence, and Organisation-specific custom data. | Contract; legitimate interests; legal obligation where applicable; Organisation’s own lawful basis; legal claims where applicable. |
| Reports and exports | Creating, retaining, expiring, downloading, and auditing point-in-time reports and exports. | Contract; legitimate interests; legal obligation; legal claims; Organisation’s own lawful basis. |
| Billing and payments | Subscriptions, invoices, payments, refunds, credits, Direct Debit, card payments, accounting, tax records. | Contract; legal obligation; legitimate interests. |
| Transactional emails | Security notices, account notices, verification, password reset, MFA, certificate reminders, usage reminders, association notices, report notices. | Contract; legitimate interests; legal obligation where applicable. |
| Feedback and screenshots | Bug reports, product feedback, optional contact permission, optional screenshots. | Consent where contact permission or screenshot submission is optional; legitimate interests; contract where support-related. |
| Legal, regulatory, insurance, and dispute purposes | Responding to legal claims, preserving evidence, assisting investigations, enforcing terms, defending rights, insurance disclosures. | Legal obligation; legitimate interests; legal claims; substantial public interest where applicable. |
| Traffic, performance, and future analytics | Cloudflare traffic, performance, routing, security, challenge, and performance-beacon insights; product analytics, usage analytics, error analytics, marketing analytics, or tracking if introduced in future. | Legitimate interests for security, availability, performance monitoring, and service improvement where lawful; consent, opt-out, updated notice, or preference controls where required. |
9. Special category data and criminal offence data
9.1. The Platform may process information that is sensitive under data protection law or that requires additional protection. This may include:
- Section 21 Declarations and statements about whether a person is prohibited from possessing firearms or ammunition;
- information about criminal convictions, offences, allegations, restrictions, prohibitions, or the absence of such matters where captured in a declaration or compliance record;
- identity documents and supporting documents;
- information that may reveal health, disability, safeguarding, vulnerability, or other sensitive matters where uploaded by a user or Organisation;
- incident, safeguarding, disciplinary, or compliance records created by a Club or Organisation;
- Police Force, Home Office, legal, or investigation records where applicable.
9.2. We process these categories only where relevant to the Platform, where access is restricted, and where we have identified an appropriate lawful basis and additional condition where required.
9.3. Section 21 Declarations and related prohibited-person declarations may amount to criminal offence data, including where the declaration confirms the absence of a relevant conviction, sentence, prohibition, or restriction. They may also form part of a Club’s compliance evidence for determining whether a person may lawfully possess, handle, or use firearms or ammunition in a Club context.
9.4. Where Section 21 Declarations, prohibited-person declarations, or related eligibility records amount to criminal offence data, we process that data only where we have identified an Article 6 UK GDPR lawful basis and an applicable condition under Schedule 1 of the Data Protection Act 2018, or where processing is otherwise authorised or required by law. Depending on the context, those conditions may include processing that is necessary for preventing or detecting unlawful acts, complying with or supporting regulatory requirements relating to unlawful acts and dishonesty, obtaining and recording valid consent for a specific voluntary Platform action where consent is appropriate, establishing, exercising, or defending legal claims, or enabling lawful access or disclosure to Police Forces, the Home Office, or other competent authorities where necessary and proportionate. We document the applicable basis, condition, necessity, proportionality, safeguards, access controls, retention approach, and Legal Hold approach in our internal governance records.
9.5. We maintain internal data-protection governance documentation for compliance and accountability. This includes an Appropriate Policy Document for criminal offence data and any special category data processed under Schedule 1 conditions that require such a document, and a Data Protection Impact Assessment for the Platform. These documents help us document the lawful basis, Schedule 1 conditions, necessity and proportionality, safeguards, access controls, retention, risk assessment, and residual risks associated with sensitive compliance processing.
9.6. The Appropriate Policy Document, Data Protection Impact Assessment, detailed Retention Schedule, Legal Hold Policy, security implementation documents, and similar governance records are internal documents and are not generally published. We may provide or disclose them, in whole or in part, to the ICO, a court, regulator, auditor, professional adviser, competent authority, or contracting Organisation where we consider this necessary or appropriate, subject to confidentiality, security, privilege, and legal restrictions.
9.7. We use additional safeguards for sensitive records, including access control, encryption, audit logging, limited permissions, retention controls, purpose limitation, Legal Hold controls, Organisation access controls, and restricted staff access.
9.8. Where we process criminal offence data on behalf of a Club or other Organisation, that Organisation remains responsible for identifying and documenting its own lawful basis, Schedule 1 condition, retention requirements, and appropriate safeguards for its own purposes, unless an Additional Agreement states otherwise.
10. Club association, consent, and revocation
10.1. A Shooter or parent/guardian may give a Club their FAR Number and date of birth so the Club can initiate an Association Request.
10.2. The Club does not receive active access to the associated FAR Record until the Association Request is accepted through the Platform flow.
10.3. Before accepting, the Platform may show the categories of data that will be shared. This may include some or all of the following categories depending on the workflow, configuration, and permissions: legal name, identity details, contact details, address details, certificate details, Club membership records, attendance records, usage records, Club-held identity verification records, and related compliance information.
10.4. Accepting a Club Association Request may require a Section 21 Declaration and confirmation of identity and address information.
10.5. Firearms are not currently automatically disclosed when a Club Association Request is accepted. Firearm Sharing is currently separate and must be authorised on a firearm-by-firearm basis unless we introduce another explicit flow, subject to applicable law, notice, consent, settings, and safeguards where required.
10.6. If Club access is revoked, revocation stops ongoing active access to the live FAR Record and future updates. It does not automatically delete Snapshots, Club Records, Compliance Evidence, documents already disclosed, reports already generated, downloaded copies, attendance records, usage records, membership records, identity verification evidence, or records that a Club, RFD, Police Force, Home Office user, insurer, adviser, or we are legally entitled or required to retain.
11. Section 21 Declarations for Clubs
11.1. Section 21 Declarations are captured for Club compliance purposes. A new Section 21 Declaration may be required each time a Shooter or parent/guardian associates with, re-associates with, rejoins, renews an association with, or is otherwise linked to a Club, even if the same person is already associated with another Club, was previously associated with the same Club, or is effectively rejoining the same Club.
11.2. The declaration is captured through the Platform on behalf of the relevant Club and is stored as a Club-accessible compliance record, which may include a generated declaration document or record. The declaration is not collected because Firearms Records itself decides whether the person may shoot; it is collected to support the Club’s compliance, audit, evidential, and recordkeeping requirements.
11.3. Section 21 Declaration records may include legal names, date of birth, address information, declaration answers, timestamps, acceptance evidence, account identifiers, FAR Number, Club identifiers, and audit metadata.
11.4. Where a person associates with multiple Clubs, each Club may receive and retain its own declaration and related evidence. Revoking one Club’s access does not revoke or delete declarations or compliance evidence held by another Club, and does not remove historical declarations or related Compliance Evidence that have already been created. However, a Club whose access has been revoked may no longer be able to view or download the declaration through the Platform, even though the retained record may continue to exist for compliance, audit, evidential, legal, insurance, investigation, or other lawful purposes.
12. Firearm Sharing
12.1. Firearm Sharing may disclose firearm type, calibre, make, model, serial number, status, and usage-history references to a Club or permitted Organisation.
12.2. Firearm Sharing helps Club staff select the correct firearm when recording attendance and usage, so that usage history can be tracked against the correct firearm without manual reconciliation.
12.3. Firearm Sharing is recorded and may create a Snapshot or Compliance Evidence. Once disclosed and used in records, it may not be possible to fully reverse or erase the historical disclosure.
13. Organisation custom documents and notes
13.1. Organisations may upload custom documents, attach files, create custom notes, add emails, create public notes, create private notes, and record Organisation-specific data. This functionality may be available to Clubs, RFDs, Police Forces, Home Office users, or other Organisations, although the permitted record types, visibility options, and purposes may differ by Organisation type and permissions.
13.2. Organisation custom records may include identity documents, certificate copies, proof documents, Club forms, RFD forms, Police Force or Home Office documents, compliance notes, membership notes, transaction notes, incident notes, safeguarding notes, investigation notes, verification notes, correspondence, or other documents and notes relevant to the Organisation’s lawful purposes.
13.3. Organisation custom documents and notes may be visible only to that Organisation and, within that Organisation, only to users with specific permissions. An Organisation may be able to mark certain notes, documents, emails, or files as visible to the relevant individual where the Platform allows this. Clubs and RFDs may be permitted to create public notes, emails, documents, or files that are shared directly with the Shooter whose record is being noted against.
13.4. Organisations are responsible for ensuring that their custom documents, notes, emails, and files are lawful, relevant, proportionate, accurate, appropriately permissioned, and retained for no longer than necessary.
13.5. We may host, secure, audit, back up, and process Organisation custom documents and notes as part of the Platform. We may access them where necessary for support, security, legal, misuse, compliance, investigation, or operational purposes.
14. RFD data
14.1. RFDs may process records relating to stock, acquisitions, disposals, transfers, document references, certificate checks, customer evidence, transaction records, audit records, compliance notes, and supporting documents.
14.2. RFDs may use permitted lookup or verification data where enabled, which may include FAR Number, date of birth, certificate number, firearm serial number, and transaction-related details.
14.3. RFDs are responsible for using accessed records only for genuine, lawful, authorised RFD purposes and for complying with their own legal, regulatory, accounting, firearms, data protection, and recordkeeping obligations.
15. Police Force and Home Office access
15.1. Verified Police Force and Home Office users may access, create, assert, modify, alter, attach, detach, delete, destroy, or otherwise process Platform records where enabled, where permitted by their permissions and role, and where required onboarding, verification, purpose capture, and documentation requirements are met.
15.2. Access by Police Force and Home Office users is audited. We may log the user, Organisation, purpose, search terms, documentation, records accessed, timestamps, IP address, user agent, approximate country/location, outcome, and related metadata.
15.3. We may disclose personal data to Police Forces, Home Office users, law enforcement authorities, courts, regulators, insurers, or other parties where lawful, necessary, proportionate, required by law, required for legal claims, required for investigation, or required for public-safety, compliance, or safeguarding purposes.
15.4. We may not notify an individual about a disclosure or access event where notification would be unlawful, disproportionate, impracticable, prejudicial to an investigation, contrary to an official request, inconsistent with legal obligations, or harmful to security.
16. Reports and exports
16.1. Reports and exports may be generated for Club, RFD, Police Liaison Officer, Police Force, Home Office, insurer, internal governance, legal, audit, investigation, or compliance purposes.
16.2. Reports may include personal data and sensitive records. They may be downloaded, stored, printed, or disclosed by authorised recipients outside the Platform.
16.3. Reports are point-in-time Snapshots. They are generated from the records available to the Platform at the time of generation and are intended to reflect those records accurately at that time. Data may change after a Report is generated, including because records are corrected, supplemented, revoked, expired, replaced, deleted, anonymised, or placed under Legal Hold.
16.4. Unless we state otherwise, generated offline Reports are available to download through the Platform for 7 days. After that, the normal download link expires and the Report becomes non-downloadable through the standard interface.
16.5. We may retain Reports server-side after the download window expires for compliance, audit, legal, insurance, security, investigation, backup, or evidential purposes.
16.6. Generated Reports may contain export metadata, including the requesting user, Organisation, report type, generation time, purpose, export identifiers, record references, and other audit information.
17. Feedback and optional screenshots
17.1. Users may submit feedback, bug reports, support messages, or feature requests.
17.2. Users may choose whether they consent to being contacted about feedback where that option is presented.
17.3. Users may optionally submit a screenshot where the browser asks for permission and the user approves the screenshot capture.
17.4. Screenshots may contain personal data or sensitive Platform data visible on the user’s screen. Users should review screenshots carefully before submitting them where the Platform or browser allows review.
17.5. Feedback and screenshots may be used for support, investigation, debugging, product improvement, security review, record correction, and internal governance.
18. Audit logs, security logs, and technical logs
18.1. The Platform is designed as compliance and audit software. We log and audit interactions across the Platform.
18.2. Logs may include user identity, Account identifiers, Organisation identifiers, FAR Number references, record identifiers, IP address, user agent, browser, device information, approximate country/location, session identifiers, timestamps, actions taken, fields changed, records viewed, lookups performed, downloads, exports, reports generated, association actions, Firearm Sharing actions, revocation actions, administrative actions, errors, and outcomes.
18.3. Logs are used for security, access control, compliance, audit history, misuse detection, debugging, support, investigation, dispute resolution, legal claims, regulatory response, and evidential purposes.
18.4. Logs may be retained for extended periods because they form part of the Platform’s compliance, security, and audit framework.
19. Transactional emails and service communications
19.1. We may send transactional, security, account, verification, service, reminder, billing, legal, and compliance emails.
19.2. Examples include email verification, password reset, password change, email change, MFA change, security alerts, association requests, association responses, Firearm Sharing notices, access revocation notices, report notices, certificate expiry reminders, firearm or certificate usage reminders, account notices, subscription notices, payment notices, and important legal or service notices.
19.3. Some emails are necessary for account security, service operation, compliance, or legal reasons and cannot be opted out of while the Account remains active.
19.4. We do not currently send marketing emails. If we introduce marketing emails in future, we will handle them separately from mandatory service messages and provide consent or opt-out controls where required.
19.5. We may log email metadata, including recipient, template, event type, delivery status, bounce, complaint, timestamp, and message identifier, where available.
20. Cookies, local storage, browser storage, and cache
20.1. We use cookies, local storage, browser cache, server-side session data, access logs, error logs, audit logs, and similar technologies to provide, secure, operate, and improve the Platform.
20.2. The Cookie and Storage Notice explains these technologies in more detail.
20.3. We do not currently use Firearms Records analytics cookies, advertising cookies, marketing pixels, heatmaps, session replay, or cross-site behavioural tracking.
20.4. We use Cloudflare-provided traffic, performance, routing, security, challenge, and service-integrity information. Where enabled by Cloudflare, Cloudflare may inject or load a performance monitoring beacon or script into pages, including Cloudflare Web Analytics, Cloudflare Insights, Cloudflare Observatory RUM, or a similar Cloudflare performance beacon. This helps us understand page performance, loading behaviour, reliability, Core Web Vitals, and service availability.
20.5. The Cloudflare performance beacon is used for performance monitoring and service improvement. It is not used by Firearms Records for advertising, behavioural marketing, cross-site tracking, heatmaps, or session replay. Based on Cloudflare’s current documentation, the RUM/Web Analytics beacon collects performance data from browser performance APIs, such as timing and page-load information, does not store data in the browser, and does not access cookies, local storage, browser sessionStorage, IndexedDB, or similar browser storage.
20.6. Cloudflare performance and traffic data may still involve ordinary technical requests to Cloudflare, including request metadata handled by Cloudflare as part of routing, performance measurement, and security processing. Cloudflare may process such data through its global network. We explain Cloudflare routing and international processing further in section 23.
20.7. We may introduce additional analytics or tracking in future, but where law requires consent, opt-out, preference controls, or updated notice, we will update our notices and provide appropriate controls.
21. Payment data
21.1. We use Stripe and/or related payment methods to process payments, including debit cards, credit cards, invoices, bank transfer, and Direct Debit where enabled.
21.2. We do not intend to store full card numbers on our own systems. Payment details may be processed by Stripe or another payment provider, subject to their security controls and terms.
21.3. We may store payment metadata, customer references, subscription status, invoice status, payment history, refunds, credits, chargebacks, failed payment records, billing contacts, and accounting records.
22. Sharing personal data
22.1. We may share personal data by making information available through the Platform, by disclosing information outside the Platform, or by enabling authorised access, viewing, lookup, reporting, exporting, downloading, attachment, note, document, API, or workflow functionality. Sharing includes making information available through dashboards, association flows, Firearm Sharing flows, RFD verification or transaction functionality, Police Force or Home Office lookup functionality, reports, exports, downloads, notes, attachments, documents, or other Platform functionality.
22.2. We may share personal data with, or make personal data available to:
- the user or responsible parent/guardian;
- Clubs where an association is accepted, a record is created, a declaration is completed, Firearm Sharing occurs, or sharing is otherwise permitted;
- RFDs for permitted verification, transaction, stock, transfer, and compliance purposes;
- Police Forces and Home Office users where verified and where access or disclosure is lawful and appropriate;
- other Organisations and authorised Organisation Users where Platform functionality, permissions, purpose, verification, Additional Agreements, or applicable law allow;
- insurers where relevant and lawful, including where Clubs or Organisations use reports or evidence for insurance purposes;
- Stripe and payment providers for billing and payment processing;
- AWS and hosting, storage, backup, and email service providers;
- Cloudflare for DNS, security, routing, content delivery, and related traffic-processing purposes;
- support, security, monitoring, error logging, and infrastructure providers where used;
- professional advisers, including lawyers, accountants, auditors, insurers, and consultants;
- regulators, courts, law enforcement authorities, public authorities, and government bodies where lawful or required;
- another provider or successor if the Platform, business, assets, or operations are transferred, restructured, sold, or merged;
- other parties where you instruct us, consent, or where sharing is necessary for legal, compliance, security, investigation, or vital operational reasons.
22.3. Where personal data is made available to an Organisation, the Organisation is responsible for ensuring that its Organisation Users are authorised to access that data, that access is limited to appropriate roles and purposes, and that any onward use, disclosure, export, download, retention, deletion, or destruction is lawful.
22.4. We log and audit many sharing, access, lookup, report, export, download, and permission events so that we can support security, compliance, investigation, record integrity, and misuse prevention.
23. UK hosting, providers, and international routing
23.1. The Platform is designed and operated with UK data residency as a core principle.
23.2. Core customer data and backups are intended to be stored in the United Kingdom using UK-hosted infrastructure and storage where configured to do so.
23.3. We use AWS services for storage, backup, and email delivery, configured for UK hosting where applicable. We use UK-based hosting hardware for application hosting where applicable.
23.4. We use Cloudflare for DNS, security, routing, content delivery, managed challenges, performance monitoring, and related services. Cloudflare operates a global network. As a result, traffic metadata, routing data, security data, challenge data, performance-beacon data, IP addresses, request data, and other technical information may be processed outside the United Kingdom depending on how internet traffic is routed and how Cloudflare provides its services.
23.5. We use Stripe for payment processing. Stripe may process payment-related data in accordance with its own infrastructure, security, and international transfer arrangements.
23.6. If personal data is transferred outside the United Kingdom, we will use appropriate safeguards where required, such as adequacy regulations, standard contractual clauses, the UK International Data Transfer Agreement, the UK Addendum, or another lawful transfer mechanism.
24. Security measures
24.1. We apply technical and organisational measures designed to protect personal data, taking account of the sensitivity of the Platform and the risks involved.
24.2. Measures may include:
- encrypted drives for data storage;
- encrypted backups;
- S3 backup storage for high availability;
- strict access control;
- role-based permissions;
- MFA support;
- audit logging;
- access logging;
- encryption of selected database fields using AES-256;
- blind indices for selected searchable encrypted fields;
- HTTPS-only access;
- TLS for data in transit;
- HSTS, including preloading where configured;
- separation of access by role and Organisation;
- limited staff access;
- security monitoring and review;
- backup and restore controls;
- provider security controls.
24.3. No system is perfectly secure. Users and Organisations must also protect their devices, browsers, email accounts, local downloads, local storage, passwords, MFA methods, and exported records.
25. Retention
25.1. We retain personal data only for as long as we have a lawful reason to do so.
25.2. Because the Platform is compliance and audit software for a highly regulated sector, many records may need to be retained for extended periods.
25.3. While an Account or Organisation relationship remains active, documents and compliance records may be retained for the duration of that active relationship unless deleted, replaced, superseded, archived, restricted, or otherwise managed through ordinary Platform functionality or in accordance with applicable retention rules.
25.4. We maintain an internal Retention Schedule and related Legal Hold controls. The Retention Schedule is an internal governance document and is not generally published because it may contain operational, security, investigation, legal-hold, backup, and compliance-handling detail. This section provides a public summary of our retention criteria and retention approach rather than the full internal schedule.
25.5. We use retention criteria including legal requirements, firearms compliance requirements, Club compliance requirements, RFD compliance requirements, Police Force or Home Office requirements, insurance requirements, audit requirements, evidential value, limitation periods, disputes, investigations, safeguarding, security, fraud prevention, abuse prevention, backups, tax/accounting requirements, user relationship history, Organisation relationship history, and the need to preserve record integrity.
25.6. The following public summary explains the types of retention decisions we make. Exact periods, triggers, deletion workflows, anonymisation thresholds, backup expiry rules, and Legal Hold handling are documented in the internal Retention Schedule and may differ by record type, Organisation type, feature, purpose, lawful basis, and risk level.
| Data type | Public retention summary |
|---|---|
| Account records | Retained while needed to operate the Account and afterwards where needed for legal, security, compliance, audit, suppression, duplicate-prevention, or dispute purposes. |
| FAR Numbers and core identifiers | Retained where needed to preserve record integrity, prevent duplication, interpret historical records, maintain audit history, or support compliance evidence. |
| Club association Snapshots | Retained where needed to evidence historical association, consent, identity/address confirmation, declarations, membership, attendance, usage, or compliance activity. |
| Section 21 Declarations | Retained for the relevant Club and compliance context while needed for Club compliance evidence, statutory or regulatory expectations, attendance/membership history, legal claims, audit, insurance, public authority access, or evidential purposes. |
| Attendance and usage records | Retained while needed for Club compliance, membership administration, audit, insurance, public authority, legal, evidential, or dispute purposes. |
| Firearm Sharing records | Retained where needed to evidence historical firearm sharing, usage, attendance reconciliation, audit history, or disclosure to a permitted Organisation. |
| Organisation custom records | Retained in accordance with the relevant Organisation context, permissions, lawful basis, Additional Agreement where applicable, and any compliance, legal, audit, insurance, evidential, public authority, or Legal Hold requirement. |
| RFD records | Retained while needed for RFD verification, transaction, acquisition, disposal, stock, transfer, audit, regulatory, legal, insurance, or evidential purposes. |
| Police Force and Home Office records | Retained where needed for access accountability, audit, official-purpose evidence, misuse detection, public authority interaction history, legal, compliance, investigation, or evidential purposes. |
| Reports and exports | Download availability normally expires after 7 days, but server-side retention may continue where needed for compliance, audit, investigation, legal, insurance, backup, or evidential purposes. |
| Audit, access, security, and error logs | Retained for security, misuse detection, audit, compliance, investigation, dispute, platform integrity, and evidential purposes. |
| Billing and payment records | Retained for contract, accounting, tax, payment, dispute, chargeback, audit, and legal purposes. |
| Feedback and optional screenshots | Retained where needed for support, issue handling, product improvement, debugging, legal, security, or audit purposes. |
| Backups | Retained according to backup, resilience, high-availability, disaster-recovery, and security requirements. Deletion or anonymisation may not occur immediately in backups. |
| Security markers after closure | Limited pseudonymous, hashed, minimised, or restricted markers may be retained where necessary for duplicate prevention, abuse prevention, security, legal compliance, or access-control purposes. |
25.7. Once data is scheduled for deletion, we may delete, anonymise, aggregate, minimise, archive, or restrict it unless a Legal Hold, regulatory requirement, Organisation requirement, backup cycle, dispute, investigation, security requirement, or other lawful reason requires continued retention.
25.8. We may anonymise data instead of deleting it where appropriate. We may retain anonymised data indefinitely where it can no longer reasonably identify an individual.
25.9. Where a user exercises a data protection right, we may still retain data where permitted or required by law, including for compliance, audit, legal claims, security, investigation, insurance, safeguarding, or public authority purposes.
26. Withdrawal of consent and access revocation
26.1. Where we rely on consent for an ongoing processing activity, you may withdraw that consent. Withdrawal does not affect processing carried out before withdrawal.
26.2. Not every Platform action is ongoing consent-based processing. Some actions are one-way disclosures, point-in-time confirmations, or evidential events. For example, Firearm Sharing, Section 21 Declaration submission, Association Request acceptance, Report generation, document upload, feedback submission, screenshot submission, support contact, or disclosure already made to an Organisation may create records or Compliance Evidence that cannot be fully reversed merely by withdrawing consent later.
26.3. Withdrawing consent or revoking access may stop future sharing or live Platform access, but it does not automatically delete historical Snapshots, records, declarations, reports, downloaded copies, Organisation records, or Compliance Evidence already created or lawfully retained.
26.4. Where documents or reports were previously downloaded by a Club, RFD, Police Force, Home Office user, insurer, adviser, or other authorised recipient, we cannot delete those local copies through the Platform.
26.5. Where Platform download access is revoked or expires, previously downloaded files may remain accessible from the recipient’s local computer, systems, backups, email, document management system, or storage.
27. Your data protection rights
27.1. Depending on the circumstances, you may have rights to:
- be informed about how your personal data is used;
- access your personal data;
- rectify inaccurate personal data;
- erase personal data;
- restrict processing;
- object to processing;
- data portability;
- withdraw consent where processing is based on consent;
- complain to the Information Commissioner’s Office.
27.2. These rights are not absolute. They may be limited where we or another controller need to retain or process data for compliance, legal obligation, public authority access, legal claims, audit, investigation, safeguarding, security, insurance, or other lawful purposes.
27.3. To exercise a right, contact legal@firearmsrecords.co.uk.
27.4. We may need to verify your identity before responding. We may also need to consult a Club, RFD, Police Force, Home Office user, or other Organisation where the data relates to records controlled by them.
27.5. If the data is controlled by a Club, RFD, Police Force, Home Office team, or other Organisation, we may direct you to that Organisation or assist them as appropriate.
28. Account closure, deletion, and anonymisation
28.1. You may request account closure, deletion, or anonymisation by contacting us.
28.2. Account closure does not necessarily delete retained records, Snapshots, Compliance Evidence, Reports, audit logs, billing records, security logs, backups, or records controlled by Organisations.
28.3. We intend to support anonymisation or deletion where lawful and compatible with compliance, audit, evidential, legal, security, insurance, investigation, and public authority requirements. Specific anonymisation rules, triggers, workflows, and timeframes are managed through our internal Retention Schedule and Legal Hold controls.
28.4. Where we anonymise data, we may preserve record structure, timestamps, Organisation records, attendance context, usage context, and audit history in a form that no longer reasonably identifies the individual where practicable.
29. Automated processing
29.1. The Platform may use automated rules to generate reminders, expiry prompts, lack-of-usage prompts, security alerts, report expiry, access restrictions, role checks, duplicate warnings, workflow states, and date-based status changes.
29.2. We may automatically change the Platform state, status, flag, prompt, warning, visibility, or workflow of a record where a relevant date passes, including certificate expiry dates, document expiry dates, report download expiry dates, review dates, trial dates, subscription dates, or retention dates. These automated state changes are operational Platform functions and do not by themselves constitute official firearms licensing decisions, Police Force decisions, Home Office decisions, RFD statutory decisions, or Club membership decisions.
29.3. We do not intend the Platform to make official firearms licensing decisions, Police Force decisions, Home Office decisions, RFD statutory decisions, or Club membership decisions solely by automated means.
29.4. Organisations remain responsible for reviewing Platform records and making their own decisions lawfully and appropriately.
30. Complaints
30.1. If you have a privacy concern, contact us first at legal@firearmsrecords.co.uk so we can try to resolve it.
30.2. You may also complain to the Information Commissioner’s Office. The ICO’s website is https://ico.org.uk/.
31. Changes to this Privacy Policy
31.1. We may update this Privacy Policy from time to time.
31.2. We will use reasonable efforts to notify users of material changes where practicable. We may make changes without advance notice where necessary for legal, regulatory, security, technical, operational, or urgent reasons.
31.3. If we introduce new material analytics, tracking, marketing, data sharing, or sensitive processing, we will update this Privacy Policy and provide consent or choice where required by law.
32. Contact
Firearms Records
Email: legal@firearmsrecords.co.uk
ICO registration number: pending