Skip to content
RailScope

Privacy policy

Last updated: 17 July 2026

1. Who is responsible for your data

RailScope (railscope.es) is an independent, non-commercial project that visualizes the Spanish rail network in real time. The data controller within the meaning of art. 4(7) GDPR is the operator of this site, reachable at [email protected]. RailScope is not affiliated with, endorsed by, or operated by Renfe or ADIF; their open data is reused under its own licences (see the Terms).

Given the project's size and non-commercial nature, no Data Protection Officer has been appointed (art. 37 GDPR does not require one here); the contact above handles all privacy matters.

2. Legal framework

  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR).
  • Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD), including its art. 7 on the age of consent (14 years).
  • Ley 34/2002, de 11 de julio (LSSI-CE) — information-society services, including its art. 22.2 on cookies.
  • Google API Services User Data Policy (including the Limited Use requirements) for the Google Sign-In integration.

3. What data we process

The public map, network status and train pages work without any account. If you create one, we process:

CategoryDataOrigin
AccountUsername, e-mail address, optional display name, roleYou (or Google, if you sign up with it)
CredentialsSalted password hash (bcrypt, cost 12) — never the password itself; encrypted TOTP secret and hashed backup codes if you enable 2FAYou
SessionsSession identifiers (hashed), IP address, browser user-agent, creation/last-activity timestampsYour device
Security auditAuthentication events: sign-ins, failed attempts, password changes, 2FA changes, role changes, account actionsGenerated by the service
ContentSaved map filters; operator-access requests and their optional noteYou
Technical accessIP address and request metadata processed transiently by our reverse proxy (Cloudflare) and web server for security and deliveryYour device
Google Sign-InGoogle account identifier (subject), verified e-mail, nameGoogle, with your consent

We do not process special-category data (art. 9 GDPR), we do not profile you, and we make no automated decisions with legal effects (art. 22 GDPR). Train data shown on the site is operational data about trains, not personal data.

4. Purposes and legal bases (art. 6 GDPR)

PurposeLegal basis
Providing your account: authentication, saved filters, rolesPerformance of a contract — art. 6(1)(b)
Security: sessions, lockouts, audit trail, abuse prevention, 2FALegitimate interest in securing the service — art. 6(1)(f)
E-mail verification codes at registrationPerformance of a contract — art. 6(1)(b)
Linking or creating your account through Google Sign-InConsent, expressed by choosing Google — art. 6(1)(a); revocable at any time
Responding to rights requests and legal obligationsLegal obligation — art. 6(1)(c)

We do not use your data for advertising, we do not sell it, and we do not share it for others' marketing.

5. Google Sign-In data (Limited Use)

If you choose Google to sign in or register, RailScope requests only the basic OpenID scopes: openid, email, profile. We receive and store your Google account identifier, your verified e-mail address and your name, solely to create or link your RailScope account. We never see your Google password and we cannot access any other Google service (no Gmail, Drive, Calendar, Contacts or anything else).

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: no transfers to third parties, no advertising use, no sale, no human reading of the data beyond what account operation requires. You can withdraw RailScope's access at any time at myaccount.google.com/permissions; your RailScope account then keeps working with its password, or can be deleted (§9).

6. How long we keep data

DataRetention
Account and profileWhile the account exists; erased/anonymized on deletion
SessionsExpire after 12 hours (30 days with “remember me”); revoked or expired records are purged periodically
Verification codes15 minutes; only hashes are stored
Security audit trailUp to 12 months, then deleted; anonymized immediately if you delete your account
Reverse-proxy logs (Cloudflare)Short-lived operational logs under Cloudflare's own retention

7. Recipients and processors

We share personal data with no one for their own purposes. The following providers process data on our behalf (art. 28 GDPR):

  • Cloudflare, Inc. — reverse proxy, DDoS protection, TLS and caching for railscope.es (processes IP addresses and request metadata).
  • Oracle Cloud (OCI) — infrastructure hosting the server and database (EU region).
  • Google LLC — only if you choose Google Sign-In, as an independent controller of your Google account.

Data may also be disclosed where a legal obligation requires it (courts, authorities).

8. International transfers

Cloudflare and Google are U.S. companies. Transfers rely on the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses (art. 46 GDPR) as applicable, together with each provider's technical safeguards. The application server and database are hosted in the EU.

9. Your rights

Under arts. 15–22 GDPR and Title III LOPDGDD you may exercise, free of charge:

  • Access — know what data we hold about you.
  • Rectification — correct inaccurate data (display name is self-service; username/e-mail via the contact address).
  • Erasure — the “Delete my account” option in your panel erases or irreversibly anonymizes your personal data.
  • Restriction and objection — including to processing based on legitimate interest.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — e.g. unlink Google at any time, without affecting prior processing.

Write to [email protected] from the e-mail linked to your account (we may request additional verification). We answer within one month (art. 12.3 GDPR). If you believe your rights have been infringed, you can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid.

10. Minimum age

Creating an account requires being at least 14 years old (art. 7 LOPDGDD). We do not knowingly process data of younger children; if you believe a minor under 14 has registered, contact us and the account will be removed.

11. Cookies and local storage

RailScope uses only cookies that are strictly necessary to provide the service you request, which art. 22.2 LSSI-CE exempts from consent banners:

NameTypePurposeDuration
railscope_sessionFirst-party, HTTP-onlyKeeping you signed in12 h / 30 days
railscope_oauthFirst-party, HTTP-onlySecuring the Google sign-in handshake (PKCE state)10 minutes
theme (localStorage)First-partyRemembering light/dark preferenceUntil cleared
Cloudflare cookies (e.g. __cf_bm)TechnicalBot mitigation and security at the network edgeUnder 1 day

There are no advertising, analytics or third-party tracking cookies of any kind.

12. Security measures (art. 32 GDPR)

  • TLS 1.2+ everywhere (HSTS), with Cloudflare WAF and rate limiting in front.
  • Passwords hashed with bcrypt (cost 12); a minimum-strength policy is enforced.
  • Optional TOTP two-factor authentication; secrets encrypted at rest (AES-256-GCM), backup codes stored only as hashes.
  • Revocable server-side sessions; a password change ends every other session.
  • Escalating account lockout against brute force; timing-safe credential checks.
  • Full audit trail of authentication and administrative actions.
  • Access to production systems restricted to the operator.

13. Changes and contact

Material changes to this policy will be reflected on this page with a new date; keep an eye on it. Questions: [email protected].