Privacy Policy
Effective date: [effective date]
Draft — pending legal review. This document is not yet in force; it will take effect once reviewed by counsel and dated.
1. Who we are
This policy explains how Railyard ("we", "us", "our") collects and uses personal data when you use Railyard at railyard.sh. For the personal data described here, Railyard is the data controller. We are registered in England and Wales (company number [Company registration number]), with a registered office at [Registered address].
For any privacy question or to exercise your rights, contact us at [email protected]. [Confirm whether a Data Protection Officer or UK/EU representative is appointed and add their details.]
2. The personal data we collect
We keep data collection to what the Service needs to work. We collect:
- Account data — your email address, and your name and avatar if your identity provider supplies them or you set them. We do not collect or store a password, because sign-in is passwordless.
- Organisation and membership data — which organisations you belong to and your role (owner, editor or viewer) in each.
- Content you create — the estate designs, device models, cabling, labels and other "Customer Data" you enter. This is your working data; we process it to provide the Service.
- Billing identifiers — for paid plans, a customer and subscription reference from our payment processor, Stripe, and your plan status. Your card details are entered directly with Stripe and are not received or stored by us.
- Security and audit data — a limited log of significant account and organisation actions, recording the actor's email, IP address and a short description, so we can investigate abuse and keep the Service secure.
- Sign-in tokens — short-lived, one-time email sign-in links and session records. These are stored only as one-way hashes, never in a form we could reuse to sign in as you.
Interface preferences (such as which organisation you last opened) are stored locally in your browser and are not sent to us.
3. How we use your data and our lawful bases
Under UK GDPR (and the EU GDPR where it applies), we rely on the following lawful bases:
- To provide the Service — creating your account, authenticating you, storing your designs, enabling collaboration and exports, and providing support. Lawful basis: performance of a contract with you (or steps taken at your request before entering one).
- To take payment and manage subscriptions — processing your plan, seats, renewals and invoices through Stripe. Lawful basis: performance of a contract, and our legitimate interests in running our business.
- To keep the Service secure — audit logging, rate limiting, abuse prevention and troubleshooting. Lawful basis: our legitimate interests in protecting the Service and its users, and legal obligation where security or record-keeping duties apply.
- To communicate with you — service and administrative messages such as sign-in links, billing notices and material changes to our terms. Lawful basis: performance of a contract and our legitimate interests. Any optional marketing would be sent only with your consent.
4. Sub-processors
We use a small number of trusted service providers to run Railyard. Each acts as our processor, under contract, and handles personal data only to provide its service to us.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Stripe | Payment processing, subscriptions and invoicing | Billing identifiers, payment details (entered directly with Stripe), plan status | [Confirm processing region] |
| [SMTP email provider] | Sending sign-in links and organisation invitation emails | Recipient email address, message content | [Confirm processing region] |
| Cloudflare | Network delivery, TLS termination and DDoS protection at the edge | IP address and request metadata in transit | [Confirm processing region] |
| Single sign-on provider (e.g. Google, Microsoft, GitHub) | Authentication — only where your organisation chooses to enable SSO | Identity profile (email, name, avatar) from your provider | Depends on the provider your organisation configures |
We keep this list current. Where the Service is self-hosted by your own organisation, the operator of that deployment may use a different set of providers.
5. International transfers
Where personal data is transferred outside the UK or European Economic Area — for example by a sub-processor above — we rely on an appropriate safeguard, such as UK/EU adequacy or Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant). [Confirm the specific transfer mechanism and storage regions for each provider once finalised.]
6. How long we keep data
- Account and Customer Data — kept while your account or organisation is active, and deleted when you delete the data or close your account (see section 7).
- Sign-in links and sessions — expire quickly; expired and used records are pruned automatically after a short grace window.
- Security and audit logs — retained for a limited period so we can investigate security and abuse, then deleted or anonymised. When you delete your account, we remove or anonymise the data in these logs that identifies you — such as your email address and IP address — while keeping a pseudonymised record of the action for security and accountability. [Confirm the exact audit-log retention period.]
- Billing records — retained by us and by Stripe as needed to meet accounting and tax obligations. [Confirm the statutory retention period, typically several years.]
7. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased in certain circumstances (the "right to be forgotten");
- receive your data in a portable, machine-readable format (portability);
- restrict or object to certain processing; and
- withdraw consent at any time where we rely on consent.
You can delete your account and its personal data yourself from your account settings, and you can export your design data at any time from within the Service. To exercise any other right, email us at [email protected]. We respond within one month.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority. We would welcome the chance to resolve your concern first.
8. Cookies and tracking
Railyard uses a single, strictly-necessary cookie to keep you signed in, plus a short-lived cookie used only during single sign-on. Both are essential to operate the Service, so no cookie-consent banner is required for them. We do not use third-party analytics, advertising or cross-site tracking, and we set no tracking cookies. Some interface preferences are stored locally in your browser and never sent to us.
9. How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption in transit, passwordless authentication with hashed credentials, role-based access control and tenant isolation between organisations. Our describes these controls in detail.
10. Children
The Service is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If a change is material, we will notify you by email or in the Service. The "effective date" above shows when the current version took effect.
12. Contact
For any privacy matter, contact Railyard at [email protected], or by post at [Registered address].