This addendum supplements the Master Terms of Service. It applies when a Customer creates, accesses, or uses a CloudFFL FFL API account, key, plugin, or integration.
1. Scope and Definitions
"FFL API" means CloudFFL's hosted application programming interface, FFL dealer data, developer documentation, API keys, plugins, software integrations, and related support. "Client Deployment" means the single production website, application, storefront, service, or other customer-facing implementation identified with the Customer's account.
Capitalized terms not defined in this Addendum have the meanings given in the Master Terms. If this Addendum conflicts with the Master Terms on a matter specific to the FFL API, this Addendum controls.
2. Single-Customer, Single-Deployment License
Each FFL API subscription is licensed to one named Customer for one production Client Deployment. The Customer may use the FFL API only for that Customer's own authorized business operations and within the plan entitlements associated with its account.
- One subscription may not serve multiple clients, unrelated businesses, production applications, storefronts, or deployments.
- Additional production deployments require separate subscriptions or prior written authorization from CloudFFL.
- Development, local testing, and staging environments are permitted only when they support the same licensed Customer and Client Deployment and are not made available as separate production services.
- Multiple API keys, users, domains, environments, or plugins do not expand the licensed Customer or Client Deployment.
- The Customer may not use the FFL API to operate a bureau, data-resale, lookup, white-label, or managed API service for third parties without a written agreement authorizing that use.
3. Agencies, Developers, and Service Providers
An agency, developer, consultant, or managed service provider may build or administer a Client Deployment for a Customer, but each client must have its own licensed account and subscription. The provider may access that account only on the client's behalf and must protect credentials as the client's authorized contractor.
A provider may not reuse or pool one account or API key across clients, include shared credentials in a reusable product, or charge third parties for access to CloudFFL data or API capacity unless CloudFFL has provided written reseller, agency, or multi-client authorization.
4. Accounts and API Keys
API keys are confidential credentials. The Customer must use reasonable security measures to keep keys out of public source code, client-side applications, browser bundles, public repositories, logs, support tickets, and other locations accessible to unauthorized persons.
- Keys may be used only by authorized systems and people supporting the licensed Client Deployment.
- Keys may not be sold, transferred, published, sublicensed, or shared with another customer or deployment.
- The Customer must rotate or revoke a key promptly after suspected compromise or personnel changes affecting access.
- The Customer is responsible for requests made with its keys until the key is revoked or CloudFFL confirms deactivation.
- CloudFFL may revoke or rotate a key when necessary to protect the Customer, the FFL API, data providers, or other users.
5. Credits, Usage, and Rate Limits
API credits, request allocations, key limits, billing periods, and rate limits are the entitlements displayed for the Customer's selected plan, account, checkout, or Order Form. Entitlements apply at the Customer account level and may be measured across all keys, users, plugins, and authorized environments associated with that account.
CloudFFL may reject, throttle, queue, or temporarily suspend requests that exceed available credits or documented rate limits, create excessive load, indicate automated abuse, or threaten the FFL API's availability or integrity. Unused entitlements do not carry over or transfer unless the applicable plan expressly states otherwise.
Trial access is based on the credit allocation associated with the trial account. Trial credits do not replenish, and trial access does not expire solely because time has passed. Trial access ends when the credits are exhausted, the Customer upgrades, CloudFFL terminates the trial for breach or abuse, or the Customer closes the account.
A Customer may not create or coordinate multiple trial accounts, identities, businesses, keys, or deployments to avoid trial, credit, rate, or account limits.
6. Permitted Use of FFL Data
Subject to the Agreement, the Customer may retrieve and display FFL data as reasonably necessary within the licensed Client Deployment for functions such as dealer search, dealer selection, shipment routing, license lookup, or related commerce workflows.
The Customer may cache limited results when reasonably necessary for performance and continuity, but must refresh or revalidate data often enough for its use case and must honor documented cache, attribution, deletion, or update requirements. Cached data remains subject to this Addendum and may not be used after the Customer's right to access the FFL API ends, except for records the Customer must lawfully retain.
7. Restricted Data Use
Except with CloudFFL's prior written authorization, the Customer may not:
- bulk extract, scrape, mirror, download, reconstruct, or maintain a substantial copy of the FFL API dataset;
- sell, license, publish, distribute, or provide raw FFL API data to another person or service;
- use the FFL API to create or enrich a competing FFL database, dealer-data API, downloadable dataset, or generalized lookup service;
- remove notices, provenance, restrictions, or technical controls applied to the data;
- combine requests, accounts, keys, caches, or deployments to evade usage or extraction limits; or
- represent that CloudFFL, ATF, or a listed FFL endorses the Customer or guarantees a dealer's suitability for a transaction.
8. Data Sources, Accuracy, and Verification
FFL data may be derived from public government records, geocoding services, customer submissions, third-party sources, and CloudFFL processing. Records may be delayed, incomplete, inaccurate, duplicated, geocoded incorrectly, or changed between updates.
The Customer is responsible for verifying license status, identity, address, expiration, transfer acceptance, business suitability, and other information directly with the licensee and appropriate authority before relying on it for a regulated transaction. The FFL API is an information tool and is not an official license verification, compliance determination, legal opinion, or authorization to complete a transaction.
9. Plugins and Integrations
CloudFFL may make plugins, modules, examples, or integration software available for supported platforms. Unless stated otherwise, those tools may be used only with the licensed Customer account and Client Deployment and require an active account with sufficient entitlements.
The Customer is responsible for:
- installation, configuration, testing, updates, backups, and compatibility with its platform and customizations;
- protecting API keys and server-side configuration;
- reviewing the checkout, dealer-selection, shipping, ammunition, magazine, age, and other workflows before production use;
- obtaining any required third-party platform accounts, licenses, permissions, or hosting; and
- monitoring the integration after platform, theme, extension, API, or legal changes.
CloudFFL may modify or discontinue a plugin or integration if the underlying platform changes, access is withdrawn, or continued support creates a security, legal, or operational risk.
10. Customer Data and API Logs
API requests may include search parameters, location information, identifiers, order context, or other Customer Data. The Customer must minimize personal information sent to the FFL API and may submit it only when the Customer has a lawful basis and appropriate notices or permissions.
CloudFFL may collect request metadata, endpoints, timestamps, response codes, key and account identifiers, IP addresses, usage measurements, and security signals to provide, meter, protect, troubleshoot, and improve the FFL API. Personal information is handled as described in the Privacy Policy.
11. Customer Compliance Responsibilities
The Customer is solely responsible for its website, application, transactions, representations, privacy notices, consumer disclosures, accessibility, taxes, shipping, product restrictions, and compliance with firearms, ammunition, export, sanctions, privacy, consumer-protection, and other applicable laws.
The Customer must not rely on an API response, plugin rule, location result, or status indicator as its only compliance control. The Customer must implement appropriate human review, exception handling, recordkeeping, and verification for its business.
12. Support and API Changes
Documentation, support channels, and response targets are those associated with the Customer's plan. CloudFFL may update endpoints, schemas, authentication, limits, documentation, or supported versions. When practical, CloudFFL will provide reasonable notice before a material breaking change to a generally available paid API.
The Customer is responsible for monitoring documentation and notices, maintaining a supported integration, handling error responses and rate limits, and testing changes before production deployment.
13. Suspension and Termination
CloudFFL may suspend or revoke API keys or account access for exhausted entitlements, nonpayment, credential compromise, excessive load, prohibited extraction or redistribution, use across unauthorized clients or deployments, trial abuse, unlawful use, or another material breach.
When access ends, the Customer must stop making requests, remove keys from systems it controls, stop representing that its integration is active, and delete cached or copied FFL API data except for data the Customer is legally required to retain. Sections concerning license restrictions, data use, intellectual property, compliance, disclaimers, liability, and obligations that by their nature survive will remain in effect.
14. Additional Disclaimers and Liability Boundaries
Without limiting the Master Terms, CloudFFL does not warrant the completeness, accuracy, timeliness, geocoding, availability, transfer policies, or regulatory suitability of FFL data, plugins, or API responses. CloudFFL is not responsible for a Customer's transaction decision, shipment, transfer, legal conclusion, cached data, integration implementation, or reliance on an API result.
The disclaimers, exclusions, and liability cap in the Master Terms apply to the FFL API, data, keys, plugins, integrations, usage enforcement, and related claims to the maximum extent permitted by law.
15. Questions
Questions about this Addendum may be sent to legal@cloudffl.com.