RailCompliant
Pricing Sign in Start free trial
Legal

Privacy Policy

Effective August 13, 2026

This policy explains what Foxx Cyber LLC, which operates RailCompliant ("we," "us"), collects when you use RailCompliant, why we collect it, and what control you have over it. It covers our website and the RailCompliant application.

The short version. We collect what we need to run a subscription software service and nothing else. We do not sell personal information. We do not run advertising or third-party tracking on our site. We do not use your railroad's records to train machine-learning models. Each railroad's data lives in its own isolated database schema, and you can export it or ask us to delete it.

1. Two roles: our customers, and their people

Most personal information in RailCompliant is entered by our customers about their people — crew members, volunteers, and contract inspectors. For that information the railroad is the controller and decides what to collect and why; we are its processor and act on its instructions. If you are a crew member or volunteer and want to see, correct, or delete what is held about you, contact your railroad first. We will help them respond, and you can always reach us at [email protected].

For account holders and website visitors, we are the controller, and the rest of this policy describes what we do.

2. What we collect

CategoryWhat it includesWhy
Account Name, work email, hashed password, organization name and role To create your account, authenticate you, and apply permissions
Customer Data Locomotive, inspection, maintenance, parts, and labor records you enter — including the crew and volunteer names, roles, qualifications, and hours you choose to record To provide the Service you are paying for
Billing Subscription status, plan, billing contact, and a payment-processor customer reference. We never receive or store full card numbers To bill your subscription and support billing questions
Technical IP address, browser user agent, timestamps, pages requested, and error diagnostics Security, abuse and fraud prevention, rate limiting, and debugging
Support Tickets, messages, and any attachments you send us To answer you and to keep a record of the issue

We do not knowingly collect information from children. Railroads that record hours for volunteers under 18 should collect no more than they need and should have parental consent where their own law requires it.

3. Cookies

We use a single essential cookie to keep you signed in. It is HttpOnly, restricted to our own site, and marked Secure in production. We do not use advertising cookies, analytics cookies, or third-party trackers, so there is no tracking to opt out of and no consent banner to click.

4. How we use information

To provide, secure, and support the Service; to process payments; to send transactional email such as password resets, invitations, compliance-deadline notifications, and service notices; to detect and prevent abuse; to meet our own legal obligations; and to improve the product using aggregated, de-identified statistics that do not identify you, your railroad, or any individual. We do not use Customer Data to train machine-learning models, and we do not sell or share personal information for cross-context behavioral advertising.

We send marketing email only to people who ask for it, and every such message has an unsubscribe link. Transactional email about your own account is not marketing and continues while your account is open.

5. Who we share it with

We share personal information only with service providers who process it on our behalf under contract, and only as needed to run the Service:

ProviderPurpose
RailwayApplication hosting, managed database, and file storage (United States)
CloudflareNetwork delivery, TLS, and denial-of-service protection
Stripe, Inc.Subscription billing and payment processing
ResendTransactional email delivery

We may also disclose information if legally required — in response to a valid subpoena, court order, or lawful government request — or to protect our rights, users, or the public. Where we are permitted to, we will tell you first. If we are ever part of a merger, acquisition, or sale of assets, information may transfer with the business, and this policy continues to apply until replaced with notice to you.

6. Where data is stored

The Service is hosted in the United States, and Customer Data is stored there. If you access the Service from outside the United States, you are sending information to the United States, where privacy law differs from your own.

7. How long we keep it

We keep Customer Data for as long as your account is open. After termination you may request an export within 30 days, after which we may delete Customer Data from active systems; residual copies in routine backups age out on our normal backup cycle. We keep billing and tax records for as long as the law requires, and security logs for a limited period for abuse investigation.

Note that some records in the Service are deliberately immutable: the audit trail is hash-chained so that entries cannot be silently altered, which is the tamper-evidence the product exists to provide. Corrections are recorded as new entries rather than edits to old ones. Deleting an account removes the data; amending a single historical audit entry in place is not something the design allows.

8. Security

Each railroad's records are held in a separate, logically isolated database schema, and every query is scoped to the schema of the authenticated session. Traffic is encrypted with TLS in transit. Passwords are stored using argon2id; session tokens are stored only as hashes. Uploaded images are re-encoded to strip embedded metadata and served through an authenticated, same-origin proxy. Third-party secrets are encrypted at rest with authenticated encryption. Access to production is limited to people who need it.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any regulator as applicable law requires, without undue delay.

9. Your rights

Depending on where you live — including under the Colorado Privacy Act and similar U.S. state laws, and under the GDPR or UK GDPR if you are in Europe — you may have the right to access a copy of your personal information, correct it, delete it, obtain it in a portable format, opt out of sale or targeted advertising (we do neither), limit the use of sensitive information, and appeal a decision we make about a request. We do not use your information for automated decisions that produce legal or similarly significant effects.

To exercise a right, write to [email protected]. We will verify your identity through your account and respond within the time your law allows — generally 45 days, extendable once where permitted. You will not be charged or receive a worse service for asking. If you are unsatisfied with our response, you may appeal by replying to our decision, and you may complain to your state attorney general or supervisory authority.

Where we process personal information about people in Europe, we rely on our legitimate interest in operating the Service, on the necessity of processing to perform our contract with the customer, and on consent where the law requires it.

10. Changes to this policy

We will post any update here with a new effective date, and for material changes we will notify account holders by email or in the Service before the change takes effect.

11. Contact

RailCompliant — A product of Foxx Cyber LLC
[email protected]

See also our Terms of Service.

RailCompliant Home Pricing Terms Privacy © 2026 Foxx Cyber LLC · A product of Foxx Cyber LLC