Privacy Policy
Ship2FFL
Last Updated: July 24, 2026
This Privacy Policy describes how Ship2FFL ("we", "us", or "our") collects, uses, and shares information when you use our Shopify application, our WooCommerce plugin, or the merchant portal at ship2ffl.snap.dev.
Information We Collect
Store Information (Shopify)
When you install our Shopify app, we collect:
- Shopify store domain
- Store owner name and email address
- OAuth access tokens required to integrate with your store
Merchant Accounts and Licenses (WooCommerce and Other Platforms)
When you create an account at ship2ffl.snap.dev or purchase a subscription, we collect:
- Your email address, used to sign you in and send account emails
- Subscription and license records (plan, status, license key, and the store domain your license is activated on)
Payments are processed by Stripe. Your card details are provided directly to Stripe and are never stored on our servers. When your store's plugin validates its license, the request includes your license key and store domain.
Customer Information
When customers use the FFL selector during checkout, we may process:
- ZIP code or geographic coordinates (latitude/longitude) to find nearby FFL dealers
- Selected FFL dealer information for the order
We do not store customer personal information. Location data is used only to query our dealer database and is not retained after the request is completed.
FFL Dealer Data
Our database contains publicly available FFL dealer information sourced from the ATF, including:
- Business name and address
- License number and type
- Phone number
- Geographic coordinates
How We Use Information
We use the information we collect to:
- Provide the FFL dealer locator functionality during checkout
- Authenticate and authorize your store or merchant account
- Manage subscriptions, licenses, and billing
- Send transactional emails such as sign-in links and billing notices
- Maintain and improve our services
- Respond to support requests
Data Storage and Security
- Store and account data (OAuth sessions, merchant accounts, licenses) is stored in Supabase with encryption at rest
- FFL dealer data is cached and served via Netlify's CDN
- All data transmission uses HTTPS encryption
- We implement industry-standard security measures to protect your data
Third-Party Services
Our services use the following third-party providers:
- Shopify: For app integration and checkout functionality (Shopify version)
- Stripe: For payment processing (non-Shopify subscriptions)
- Supabase: For database storage and account authentication
- Resend: For sending transactional emails such as sign-in links
- Netlify: For hosting and CDN services
Each service has its own privacy policy governing their data practices.
Data Retention
- Session data: Retained while your app installation is active
- Merchant account and license data: Retained while your account exists, and as needed for billing and legal records
- Location queries: Not retained; processed in real-time only
- FFL dealer data: Updated monthly from public ATF records
Your Rights
You have the right to:
- Access: Request information about data we hold related to your store
- Deletion: Request deletion of your store data by uninstalling the app
- Portability: Request a copy of your store's configuration data
Data Deletion
When you uninstall the Shopify app:
- Your Shopify OAuth session data is automatically deleted
- No customer data is retained as we do not store it
To delete a merchant portal account and its associated license records, cancel any active subscription and contact us at contact@snap.dev. Some billing records may be retained where required by law.
Children's Privacy
Our service is not directed to individuals under 18. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
GDPR Compliance
For users in the European Economic Area:
- Legal basis: We process data based on legitimate business interests and contractual necessity
- Data transfers: Data may be transferred to servers in the United States
- DPO: Contact us for data protection inquiries
- Supervisory authority: You have the right to lodge a complaint with your local data protection authority