FFL Overwatch (“Company,” “we,” “us,” or “our”) provides compliance, inventory, financial, and AI-assisted tools for Federal Firearms Licensees (“the Service”). This Privacy Policy (“Policy”) describes how we collect, use, disclose, and protect personal information and business data when you access or use the Service at app.ffloverwatch.com and related properties.
This Policy applies to all personal information (as defined under applicable U.S. privacy laws) and business/customer data you upload, connect, or generate through the Service. This Policy supplements any agreements between you and FFL Overwatch (e.g., Terms of Service) and prevails in case of conflict regarding privacy.
The Service is directed exclusively to U.S.-based Federal Firearms Licensees and U.S. residents. We do not target or offer the Service to individuals or businesses outside the United States.
1. Information We Collect
We collect the following categories of information:
Information You Provide Directly. When you create an account, subscribe, or use the Service, you may provide: name, email address, business name, phone number, FFL license information, and payment details (processed by Stripe). FFL license information is treated as sensitive business data and is processed solely to enable compliance features of the Service, in a manner consistent with applicable federal regulations (e.g., ATF requirements for FFL holders).
Automatically Collected Data. We automatically collect usage and device data, including: IP addresses (from which general geolocation may be inferred), browser type and version, pages visited, feature usage patterns, access timestamps, and error logs. This data helps us improve the Service and diagnose issues.
Business Data You Upload or Connect. Through your use of the Service, we process business data you upload or connect, including: invoices, financial records, acquisition records, supplier information, customer communications, and inventory data. This data belongs to you. We do not sell, license, or otherwise distribute your business data to any third party. All business data is encrypted at rest (AES-256-GCM) and in transit (TLS/HTTPS), and is stored in per-tenant isolated environments. We access your business data only as necessary to provide the Service's core functionality on your behalf.
Financial Data via Plaid. If you connect financial accounts through Plaid, we receive transaction data, account balances, and related financial information as described in Section 5.
For reference under applicable state privacy laws (e.g., CCPA/CPRA), the categories above correspond to: Identifiers (name, email, phone, IP address); Commercial information (business name, FFL license details, invoices, inventory); Financial information (payment details via Stripe, transaction data via Plaid); Geolocation data (inferred from IP address); Internet/electronic network activity (usage data, browser type, pages visited); Professional information (supplier and customer data you upload).
We collect limited sensitive personal information (e.g., inferred geolocation from IP, financial data via Plaid) only as necessary to provide the Service, and we provide opt-out and limitation rights where required by applicable law.
2. How We Use Information
We use your information for the following purposes:
- Performance of contract: Provide, maintain, and improve the Service; process transactions and send billing communications; provide customer support.
- Legitimate interests: Monitor for security threats and abuse; improve the Service through aggregated analytics; develop and refine AI models using anonymized data.
- Legal obligations: Comply with applicable laws, regulations, court orders, and government requests.
- With your consent: Send product updates, announcements, and marketing communications (with opt-out at any time).
We use aggregated, anonymized data to improve our AI models, UPC Learning Layer, and extraction accuracy. We ensure such data cannot be re-identified to any individual user or tenant. Individual business data is never shared between tenants.
3. How We Share Information
We do not sell, rent, or lease your personal or business data to third parties. We do not share personal information for cross-context behavioral advertising.
We share data only with the following categories of service providers, bound by written data processing agreements requiring them to use data only for specified purposes, implement appropriate security, and assist with rights requests:
- Stripe — Payment processing (PCI DSS compliant)
- Plaid — Financial account connectivity (see Section 5)
- AI Providers (Google Gemini, OpenAI, Anthropic) — AI feature functionality, using only the minimum data necessary for each request. We have data processing agreements prohibiting these providers from using your data to train their models absent your explicit opt-in or BYOK configuration.
- Hetzner — Infrastructure hosting (data stored in U.S. data centers)
- Fastbound — Bound book integration (using your credentials and your data, under your direct control)
We may disclose information when required by law, court order, or government regulation, or when necessary to protect the rights, safety, or property of the Company or its users.
4. AI Data Processing
When you use AI-powered features, portions of your data are sent to third-party AI providers for processing. This may include: invoice text for extraction, email content for drafting assistance, financial data for cashflow analysis, and product data for pricing recommendations.
Data minimization: You control what data is sent to AI features. We minimize data transmitted (e.g., sending only relevant excerpts rather than full records) and do not retain AI inputs or outputs beyond what is needed to fulfill the immediate request, unless you explicitly save outputs within the Service.
Provider safeguards: AI providers process data according to their respective privacy policies and data processing agreements. We select providers with strong data protection commitments and do not permit them to use your data for training their models.
BYOK (Bring Your Own Keys): You can bring your own API keys for direct control over your AI provider relationship, including choosing your own provider terms and data handling.
Automated decision-making: Certain AI features (e.g., pricing recommendations, cashflow simulations) involve automated analysis. These features provide recommendations and insights for your review — no significant decisions are made solely by automated means without your involvement. We will provide pre-use notices and opt-out or explanation rights for automated decision-making technology (ADMT) as required under applicable regulations. If applicable law provides you a right to opt out of automated decision-making or to request an explanation, you may exercise that right by contacting us at [email protected].
5. Financial Account Connectivity (Plaid)
FFL Overwatch uses Plaid Inc. (“Plaid”) to connect your financial accounts and retrieve transaction data to power the Service's cashflow modeling and budgeting features. By using these features, you grant FFL Overwatch and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from your relevant financial institution(s). You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.
FFL Overwatch does not store your bank account login credentials. Plaid handles all credential management and financial institution authentication directly. You may revoke Plaid's access to your financial accounts at any time through Plaid Portal.
We act as a “service provider” (or equivalent designation) under applicable privacy laws with respect to financial data obtained through Plaid. We do not sell or share this data for cross-context behavioral advertising or any purpose other than providing the Service.
6. Data Security
We implement industry-standard security measures to protect your data:
- AES-256-GCM encryption for all sensitive credentials and business data at rest
- Per-tenant data isolation at the database level — your data is never mixed with other tenants
- TLS/HTTPS encryption for all data in transit
- JWT-based authentication with short-lived access tokens
- Role-based access control (RBAC) within your organization
- Rate limiting and abuse detection
- Structured audit logging for security-sensitive operations
- Periodic security risk assessments
Despite these measures, no system is impenetrable. In the event of a data breach, we will notify affected users and applicable regulators as required by law within statutory timelines. See Section 13 for additional detail.
7. Data Storage
All data is processed and stored in the United States (Hetzner U.S. data centers). We do not transfer personal information to recipients outside the United States in the ordinary course of business.
8. Data Retention
We retain your data for as long as your account is active and as needed to provide the Service. After account termination, you have 30 days to export your data. Following the export period, we delete your Customer Data, except where retention is required by law or for legitimate business purposes:
- Billing and tax records: Up to 7 years, as required by applicable tax and financial regulations.
- Dispute resolution records: Retained for the duration of any active dispute plus applicable statutes of limitation.
- Security and audit logs: Retained for up to 2 years for incident investigation and compliance.
Anonymized, aggregated data (such as UPC lookup entries without tenant identifiers) may be retained indefinitely to improve the Service for all users.
We review retention practices periodically and delete or anonymize data when it is no longer needed for its stated purpose.
9. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information.
- Portability: Export your data in a portable, machine-readable format.
- Opt-out of marketing: Unsubscribe from marketing communications at any time.
- Restrict processing: Request that we limit certain data processing activities.
- Opt-out of sale/sharing: We do not sell personal information. If we ever change this practice, we will provide a clear opt-out mechanism.
- Opt-out of automated decision-making: Where applicable, request human review of automated decisions.
- Limit sensitive PI: Request that we limit the use of sensitive personal information to what is necessary for the Service.
- Authorized agents: You may authorize an agent to submit privacy requests on your behalf with proof of written authorization.
We do not discriminate against users for exercising their privacy rights. Verification of your identity may be required before we process your request.
We recognize Global Privacy Control (GPC) signals and other legally recognized opt-out preference signals to the extent required by applicable law.
These rights apply to the extent provided under applicable law in your jurisdiction, including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Indiana (INCDPA), Kentucky (KCDPA), Rhode Island (RI-DTPPA), and other states with comprehensive privacy laws (currently approximately 20 states).
To exercise any of these rights, contact us at [email protected]. We will respond to verifiable requests within 45 days (extendable by an additional 45 days with notice if reasonably necessary).
10. Cookies and Tracking
We use essential cookies for authentication and session management. We use analytics cookies to understand how the Service is used and to improve the user experience. You can control cookie preferences through your browser settings. The Service remains functional with analytics cookies disabled, though some features may be affected.
Do Not Track / GPC:We honor Global Privacy Control (GPC) signals. We do not currently respond to browser-level “Do Not Track” (DNT) signals, as there is no uniform industry standard for DNT compliance.
11. CCPA / CPRA / State Privacy Laws
We comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), including applicable 2026 regulations on risk assessments and automated decision-making technology (“ADMT”), and extend equivalent rights to residents of all U.S. states with comprehensive privacy legislation, including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Indiana (INCDPA), Kentucky (KCDPA), Rhode Island (RI-DTPPA), and other states (currently approximately 20 states).
We conduct privacy risk assessments for applicable high-risk processing activities as required under updated CCPA/CPRA regulations (effective January 1, 2026).
Under these laws, you have the right to:
- Know what personal information we collect, how it is used, and with whom it is shared.
- Request deletion of your personal information, subject to legal exceptions.
- Opt out of the sale of personal information. We do not sell personal information.
- Non-discrimination for exercising your privacy rights.
- Limit the use of sensitive personal information to what is necessary for the Service.
12. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided personal information, we will take steps to delete that information promptly.
13. Breach Notification
In the event of a security breach involving your personal information, we will notify affected users and applicable regulatory authorities as required by law, within the timelines prescribed by applicable breach notification statutes (e.g., within 60 days for most U.S. state laws, or as otherwise required). Notifications will describe the nature of the breach, the data involved, and steps you can take to protect yourself.
14. International Users
The Service is not directed to users in the European Economic Area, United Kingdom, or other non-U.S. jurisdictions. If GDPR or equivalent law unexpectedly applies to your data, please contact us at [email protected] for information regarding the applicable data controller, lawful bases for processing, and your rights under applicable law.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated with at least 30 days' notice via email or in-app notification. Your continued use of the Service after the effective date of any updated Policy constitutes acceptance of the changes.
16. Contact Information
For questions, concerns, or to exercise your privacy rights:
Email: [email protected]
Company: FFL Overwatch (operated by RED Team Depot, LLC)
Address: Creedmoor, NC 27522, United States
Note: This Privacy Policy is provided for informational purposes. We recommend review by a qualified privacy or data protection attorney, particularly given the specialized regulatory environment applicable to Federal Firearms Licensees.