Privacy policy
Traintrackr answers questions about public train times. It keeps as little about you as it can.
Last updated: 30 September 2026.
Who is responsible
Traintrackr is run by Hugo Rodger-Brown, who is the data controller under UK data protection law (the UK GDPR and the Data Protection Act 2018). Contact: support@traintrackr.live.
What is processed
| Data | Why | Kept for |
|---|---|---|
| Your email address | To send you a sign-in code. It is passed to the email provider and not stored by Traintrackr. | Not stored |
| An account ID: a keyed hash of your email address, which can't be turned back into the address | To recognise your account when you sign in, and to apply the fair-use limit | 180 days after the account was last used |
| The dates the account was created and last used | To delete accounts that are no longer used | With the account |
| A record that a code was sent to an account ID, and when | To limit how many codes can be sent | 24 hours |
| Access tokens, stored as hashes, with the account ID | To keep your assistant connected | Access tokens 1 hour; refresh tokens 90 days. The hash of a refresh token that has been replaced is kept until the token would have expired, to notice a copy of it being used. |
| The name and return addresses of the app that connects (such as Claude) | To run the sign-in. This describes the app, not you. | Until removed |
| Your IP address, with the time and address of each request | Request logs kept by the hosting provider, used to investigate faults and abuse | 14 days |
| A count of your recent requests, held in memory: against your account, or against your IP address before you have signed in | The fair-use limit, and a limit on how often one address can start a sign-in | Minutes; cleared on restart |
| Emails you send to support, and the replies | To answer your question | 12 months after the conversation ends, unless you ask for earlier deletion |
The questions your assistant sends to Traintrackr, such as a station name and a time, are used to produce the answer. They are not stored and not written to logs. Station codes are sent to the Rail Data Marketplace's Darwin service to fetch live times, with nothing that identifies you.
Traintrackr does not see your conversation with the assistant, only the requests the assistant makes to it.
What Traintrackr doesn't do
- It sets no cookies.
- It uses no analytics and no advertising.
- It does not sell or share your data for marketing.
- It sends no email other than the sign-in code you ask for, and replies to email you send to support.
Lawful basis
The data is processed on the basis of legitimate interests: providing the service you asked for, and protecting it from abuse.
Who processes it, and where
- Render hosts the service and its database in Frankfurt, Germany, and keeps the request logs.
- Resend delivers the sign-in email, and receives your email address and the code to do so. Resend is based in the United States and stores data there. Transfers from the UK are covered by the UK Extension to the EU-U.S. Data Privacy Framework, under which Resend is certified.
- Google (Google Workspace) receives and stores email sent to support@traintrackr.live, and the replies to it. Transfers from the UK are covered by the UK Extension to the EU-U.S. Data Privacy Framework, under which Google is certified.
The assistant you use, such as Claude or ChatGPT, is provided by another company under its own privacy policy.
Your rights
You can ask for a copy of the data held about you, for it to be corrected or deleted, or for its use to be restricted, and you can object to its use. Email support@traintrackr.live from the address you sign in with. Deleting an account removes its ID and tokens, and disconnects your assistant.
You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.
Changes
Changes to this policy are published on this page, with the date.