Privacy policy
This policy explains how personal data is handled when you browse or use Railzeno.
Data controller and contact
The operator of Railzeno determines why and how personal data is used for the service.
- Data controller
- ACFA
- Privacy contact email
- contact@railzeno.com
Personal data concerned
Public railway searches do not require an account. The data handled depends on the feature you choose to use:
| Category | Examples and circumstances |
|---|---|
| Public search | Search terms, station, train, route, date and time range sent to return the requested result. They are not attached to an account when searching publicly. |
| Language and consent preferences | Selected language and the accept-or-refuse cookie choice stored on the device. |
| Contact messages | Email address, name if provided, subject, message, attachments and the information needed to answer the request. |
| Accounts and alerts | Email address, authentication data, selected trains or stations, alert thresholds, quiet hours, consent records and delivery status. |
| Security and technical logs | IP address, request date, requested URL, browser or device information, response code, error details and security events, where logged by the infrastructure. |
| Optional audience measurement | Limited visit and navigation data only if an audience measurement provider is configured and you accept optional cookies. |
The service is not designed to collect special-category or sensitive personal data. Please do not include such information in a contact message.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer public searches and provide the requested service. | Performance of the service requested and the controller's legitimate interest in operating an information service. |
| Create an account, store alert rules and deliver selected notifications, when activated. | Performance of the service requested by the user; consent where it is specifically required for a communication channel. |
| Answer messages, correction requests and reports. | Legitimate interest in responding and, depending on the request, steps taken at the user's request. |
| Secure, diagnose, prevent abuse and maintain the service. | Legitimate interest in protecting the service and users, and compliance with legal obligations where applicable. |
| Understand aggregate use and improve the website through an optional measurement tool. | Consent, which can be refused or withdrawn at any time. |
| Keep evidence or respond to a lawful request or dispute. | Compliance with a legal obligation or legitimate interest in establishing, exercising or defending legal claims. |
Fields identified as required are necessary to process the relevant request. Without them, the message, account or alert may not be created or delivered. Public search remains available without an account.
Service alerts are not marketing messages. Any future newsletter or commercial communication would require a separate choice and a simple unsubscribe mechanism.
Recipients and processors
Access is limited to authorised persons and providers that need the data to operate the service. The planned or configured providers are:
- Hosting and infrastructure
- OVH SAS
- Database
- PostgreSQL auto-hébergé sur une infrastructure OVH SAS en France
- Transactional email
- Resend
- Optional audience measurement
- Umami
Providers act under contractual and confidentiality obligations appropriate to their role. Data may also be disclosed when required by law, a competent authority or the defence of legal rights.
International transfers
L’hébergement et la base de données sont opérés en France chez OVH SAS. Les emails transactionnels sont traités par Resend (Plus Five Five, Inc.) ; leurs données de compte, métadonnées, journaux et enregistrements API sont stockés aux États-Unis. Resend encadre ces transferts par son accord de traitement des données, les clauses contractuelles types de l’Union européenne et, lorsqu’il s’applique, le cadre UE–États-Unis de protection des données.
The optional audience-measurement provider configured for the website is Umami.
Where a transfer outside the European Economic Area occurs, the controller must identify the applicable adequacy decision or appropriate safeguard, such as standard contractual clauses, and make useful information available on request.
Retention periods
Data is kept only for the period needed for each purpose, then deleted or anonymised unless a legal obligation or documented dispute requires a longer period.
| Data | Planned retention rule |
|---|---|
| Language cookie | Up to 12 months, or until deleted through browser settings. |
| Cookie choice | 6 months from the choice, or until it is changed or deleted. |
| Contact messages | Up to 12 months after the last useful exchange, then longer only when needed for a legal claim or obligation. |
| Account and alert rules | While the account or alert remains active, then deletion after the operational backup cycle unless retention is legally required. |
| Notification delivery records | Up to 90 days for delivery, deduplication and troubleshooting, unless an incident requires documented longer retention. |
| Technical and security logs | Up to 30 days by default, with documented longer retention only for a security incident, legal obligation or claim. |
These rules must also be enforced in the hosting, database, backup, logging and email systems before production data is accepted.
Security
Reasonable technical and organisational measures are used according to the risk, including access restriction, secret separation, encrypted transport, updates, backups, logging controls and incident procedures. No internet service can guarantee absolute security.
If a personal-data breach creates a legal notification obligation, the competent authority and affected people will be informed within the applicable conditions and time limits.
Your rights
Depending on the processing and applicable law, you may exercise the following rights:
- access your personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion where the legal conditions are met;
- request restriction of processing in the cases provided by law;
- object to processing based on legitimate interests for reasons relating to your situation;
- receive data you provided in a structured format where portability applies;
- withdraw consent at any time without affecting processing carried out before withdrawal.
To exercise a right, describe the request and the account or email concerned by writing to contact@railzeno.com.
You may also lodge a complaint with the data-protection authority in your country. In France, contact the CNIL.
Minors and automated decisions
The service is intended for general travel information and is not specifically directed at children. A parent or guardian can contact the controller about a minor's data.
The service does not currently make a decision producing legal or similarly significant effects based solely on automated processing. Railway estimates and alerts are informational aids.
Changes and effective date
This policy may change when the service, providers or legal requirements evolve. Material changes will be dated and, when appropriate, highlighted through the website or an account communication.
Last updated: August 12, 2026.