Privacy policy
Last updated: 17 July 2026
1. Who is responsible for your data
RailScope (railscope.es) is an independent, non-commercial project that visualizes the Spanish rail network in real time. The data controller within the meaning of art. 4(7) GDPR is the operator of this site, reachable at [email protected]. RailScope is not affiliated with, endorsed by, or operated by Renfe or ADIF; their open data is reused under its own licences (see the Terms).
Given the project's size and non-commercial nature, no Data Protection Officer has been appointed (art. 37 GDPR does not require one here); the contact above handles all privacy matters.
2. Legal framework
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR).
- Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD), including its art. 7 on the age of consent (14 years).
- Ley 34/2002, de 11 de julio (LSSI-CE) — information-society services, including its art. 22.2 on cookies.
- Google API Services User Data Policy (including the Limited Use requirements) for the Google Sign-In integration.
3. What data we process
The public map, network status and train pages work without any account. If you create one, we process:
| Category | Data | Origin |
|---|---|---|
| Account | Username, e-mail address, optional display name, role | You (or Google, if you sign up with it) |
| Credentials | Salted password hash (bcrypt, cost 12) — never the password itself; encrypted TOTP secret and hashed backup codes if you enable 2FA | You |
| Sessions | Session identifiers (hashed), IP address, browser user-agent, creation/last-activity timestamps | Your device |
| Security audit | Authentication events: sign-ins, failed attempts, password changes, 2FA changes, role changes, account actions | Generated by the service |
| Content | Saved map filters; operator-access requests and their optional note | You |
| Technical access | IP address and request metadata processed transiently by our reverse proxy (Cloudflare) and web server for security and delivery | Your device |
| Google Sign-In | Google account identifier (subject), verified e-mail, name | Google, with your consent |
We do not process special-category data (art. 9 GDPR), we do not profile you, and we make no automated decisions with legal effects (art. 22 GDPR). Train data shown on the site is operational data about trains, not personal data.
4. Purposes and legal bases (art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing your account: authentication, saved filters, roles | Performance of a contract — art. 6(1)(b) |
| Security: sessions, lockouts, audit trail, abuse prevention, 2FA | Legitimate interest in securing the service — art. 6(1)(f) |
| E-mail verification codes at registration | Performance of a contract — art. 6(1)(b) |
| Linking or creating your account through Google Sign-In | Consent, expressed by choosing Google — art. 6(1)(a); revocable at any time |
| Responding to rights requests and legal obligations | Legal obligation — art. 6(1)(c) |
We do not use your data for advertising, we do not sell it, and we do not share it for others' marketing.
5. Google Sign-In data (Limited Use)
If you choose Google to sign in or register, RailScope requests only the basic OpenID scopes: openid, email, profile. We receive and store your Google account identifier, your verified e-mail address and your name, solely to create or link your RailScope account. We never see your Google password and we cannot access any other Google service (no Gmail, Drive, Calendar, Contacts or anything else).
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: no transfers to third parties, no advertising use, no sale, no human reading of the data beyond what account operation requires. You can withdraw RailScope's access at any time at myaccount.google.com/permissions; your RailScope account then keeps working with its password, or can be deleted (§9).
6. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While the account exists; erased/anonymized on deletion |
| Sessions | Expire after 12 hours (30 days with “remember me”); revoked or expired records are purged periodically |
| Verification codes | 15 minutes; only hashes are stored |
| Security audit trail | Up to 12 months, then deleted; anonymized immediately if you delete your account |
| Reverse-proxy logs (Cloudflare) | Short-lived operational logs under Cloudflare's own retention |
7. Recipients and processors
We share personal data with no one for their own purposes. The following providers process data on our behalf (art. 28 GDPR):
- Cloudflare, Inc. — reverse proxy, DDoS protection, TLS and caching for railscope.es (processes IP addresses and request metadata).
- Oracle Cloud (OCI) — infrastructure hosting the server and database (EU region).
- Google LLC — only if you choose Google Sign-In, as an independent controller of your Google account.
Data may also be disclosed where a legal obligation requires it (courts, authorities).
8. International transfers
Cloudflare and Google are U.S. companies. Transfers rely on the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses (art. 46 GDPR) as applicable, together with each provider's technical safeguards. The application server and database are hosted in the EU.
9. Your rights
Under arts. 15–22 GDPR and Title III LOPDGDD you may exercise, free of charge:
- Access — know what data we hold about you.
- Rectification — correct inaccurate data (display name is self-service; username/e-mail via the contact address).
- Erasure — the “Delete my account” option in your panel erases or irreversibly anonymizes your personal data.
- Restriction and objection — including to processing based on legitimate interest.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — e.g. unlink Google at any time, without affecting prior processing.
Write to [email protected] from the e-mail linked to your account (we may request additional verification). We answer within one month (art. 12.3 GDPR). If you believe your rights have been infringed, you can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid.
10. Minimum age
Creating an account requires being at least 14 years old (art. 7 LOPDGDD). We do not knowingly process data of younger children; if you believe a minor under 14 has registered, contact us and the account will be removed.
12. Security measures (art. 32 GDPR)
- TLS 1.2+ everywhere (HSTS), with Cloudflare WAF and rate limiting in front.
- Passwords hashed with bcrypt (cost 12); a minimum-strength policy is enforced.
- Optional TOTP two-factor authentication; secrets encrypted at rest (AES-256-GCM), backup codes stored only as hashes.
- Revocable server-side sessions; a password change ends every other session.
- Escalating account lockout against brute force; timing-safe credential checks.
- Full audit trail of authentication and administrative actions.
- Access to production systems restricted to the operator.
13. Changes and contact
Material changes to this policy will be reflected on this page with a new date; keep an eye on it. Questions: [email protected].