Effective August 26, 2026
Privacy Policy
Train Tracker is a non-commercial app with no advertising, analytics, data sales, or cross-app tracking.
Voluntary ticket forwarding
Train Tracker does not scan, monitor, or connect to your mailbox. Each signed-in account can generate a private, single-use-looking forwarding address under gettraintracker.com. When you choose to forward a rail confirmation email to that address, the service parses the message to identify train-ticket details such as operator, route, service number, travel time, passenger, seat, coach, and booking reference, and imports it only when it has high confidence the message is a genuine rail ticket. Messages that do not look like rail tickets, are unusually large, or fail sender authentication checks are rejected outright and never stored. Train Tracker never sees any message you do not choose to forward, and cannot send, browse, or search your mailbox.
The raw forwarding token is never stored. The service keeps a random alias nonce and a one-way hash for recognition, then derives the address only when an authenticated app requests it using a secret held by Cloudflare. You can rotate your forwarding address at any time from Settings, which invalidates the previous address immediately, or turn off forwarding entirely, which invalidates the alias while keeping previously imported tickets available.
Legacy Gmail import (not currently offered)
Train Tracker previously offered an optional, read-only Gmail OAuth import as an alternative to forwarding. That entry point is not currently offered to users. If it is reintroduced, this policy will be updated first to describe how it works before it becomes available again.
Data protection and security
Train Tracker protects data in transit with HTTPS/TLS. Forwarding-alias metadata, imported ticket fields, and any attached PDF or image ticket are stored in private Cloudflare Durable Object storage, which Cloudflare encrypts at rest. Encryption keys and other operational secrets are held as managed Cloudflare Worker secrets and are not included in the app or source code.
Requests for forwarding-address status and imported-ticket records are scoped to the authenticated Train Tracker session. Train Tracker minimizes what it retains: it stores extracted ticket fields and, only when reasonably sized, a single ticket attachment, instead of the full forwarded message. Locally cached ticket attachments use iOS file protection. Forwarded message contents, passenger data, booking references, and forwarding addresses are never included in operational logs or public trip-share links.
Data used for notifications
If you enable notifications and track a trip, the app sends a random installation identifier, Apple Push Notification service token, device platform, selected train identifier, service date, boarding and destination station identifiers, and notification preferences to the Train Tracker service. This data is used only to monitor the selected trip and deliver requested change alerts.
Storage and deletion
Your saved live-trip details and locally cached ticket attachments are stored on your device with file protection so tickets remain available during travel. Notification subscriptions and forwarded ticket data are stored in Cloudflare infrastructure. When you stop tracking a trip, its server subscription is deactivated and is no longer polled. Turning off forwarding invalidates the address but keeps previously imported tickets available until you delete them individually or delete your account. Deleting your account deletes your forwarding alias and every ticket imported through it. You may also request deletion of inactive notification or import records at any time using the contact below.
Third-party services
The Train Tracker service retrieves rail information from Amtraker, Transitous, iRail, Renfe, Fintraffic Digitraffic, Entur, Chepe Express, and their underlying public-transport data sources. VIA Rail schedule and route-geometry information is licensed under the Open Government Licence – Canada 2.0; source information is available from VIA Rail Developer Resources. Transwa schedule data is available free of charge from Transperth; Mexican schedule-only coverage is based on the official Chepe Express timetable. If licensed and enabled, the service may also retrieve rail information from Ekispert for Japan and TDX for Taiwan. The app may contact Amtraker or Transitous directly when the service is unavailable. Apple processes push notification tokens, and Cloudflare processes the limited notification, rail-request, and voluntary ticket-forwarding data described above as infrastructure providers, including receiving mail sent to your forwarding address through Cloudflare Email Routing.
Sharing
A trip-share link contains a signed public train reference, service date, and optional boarding and destination station identifiers. It never includes forwarded message contents, ticket documents, passenger names, booking references, or barcodes. Anyone with the link can add the referenced train until the link expires. Train Tracker does not sell personal data or share it for advertising. Data is disclosed only to the infrastructure and rail-data providers needed to operate requested features, or when required by law.
Contact
Questions or deletion requests can be sent to jaguirre2192@gmail.com.