Effective August 13, 2026
This policy explains what Foxx Cyber LLC, which operates RailCompliant ("we," "us"), collects when you use RailCompliant, why we collect it, and what control you have over it. It covers our website and the RailCompliant application.
The short version. We collect what we need to run a subscription software service and nothing else. We do not sell personal information. We do not run advertising or third-party tracking on our site. We do not use your railroad's records to train machine-learning models. Each railroad's data lives in its own isolated database schema, and you can export it or ask us to delete it.
Most personal information in RailCompliant is entered by our customers about their people — crew members, volunteers, and contract inspectors. For that information the railroad is the controller and decides what to collect and why; we are its processor and act on its instructions. If you are a crew member or volunteer and want to see, correct, or delete what is held about you, contact your railroad first. We will help them respond, and you can always reach us at [email protected].
For account holders and website visitors, we are the controller, and the rest of this policy describes what we do.
| Category | What it includes | Why |
|---|---|---|
| Account | Name, work email, hashed password, organization name and role | To create your account, authenticate you, and apply permissions |
| Customer Data | Locomotive, inspection, maintenance, parts, and labor records you enter — including the crew and volunteer names, roles, qualifications, and hours you choose to record | To provide the Service you are paying for |
| Billing | Subscription status, plan, billing contact, and a payment-processor customer reference. We never receive or store full card numbers | To bill your subscription and support billing questions |
| Technical | IP address, browser user agent, timestamps, pages requested, and error diagnostics | Security, abuse and fraud prevention, rate limiting, and debugging |
| Support | Tickets, messages, and any attachments you send us | To answer you and to keep a record of the issue |
We do not knowingly collect information from children. Railroads that record hours for volunteers under 18 should collect no more than they need and should have parental consent where their own law requires it.
We use a single essential cookie to keep you signed in. It is HttpOnly, restricted to our own site, and marked Secure in production. We do not use advertising cookies, analytics cookies, or third-party trackers, so there is no tracking to opt out of and no consent banner to click.
To provide, secure, and support the Service; to process payments; to send transactional email such as password resets, invitations, compliance-deadline notifications, and service notices; to detect and prevent abuse; to meet our own legal obligations; and to improve the product using aggregated, de-identified statistics that do not identify you, your railroad, or any individual. We do not use Customer Data to train machine-learning models, and we do not sell or share personal information for cross-context behavioral advertising.
We send marketing email only to people who ask for it, and every such message has an unsubscribe link. Transactional email about your own account is not marketing and continues while your account is open.
We share personal information only with service providers who process it on our behalf under contract, and only as needed to run the Service:
| Provider | Purpose |
|---|---|
| Railway | Application hosting, managed database, and file storage (United States) |
| Cloudflare | Network delivery, TLS, and denial-of-service protection |
| Stripe, Inc. | Subscription billing and payment processing |
| Resend | Transactional email delivery |
We may also disclose information if legally required — in response to a valid subpoena, court order, or lawful government request — or to protect our rights, users, or the public. Where we are permitted to, we will tell you first. If we are ever part of a merger, acquisition, or sale of assets, information may transfer with the business, and this policy continues to apply until replaced with notice to you.
The Service is hosted in the United States, and Customer Data is stored there. If you access the Service from outside the United States, you are sending information to the United States, where privacy law differs from your own.
We keep Customer Data for as long as your account is open. After termination you may request an export within 30 days, after which we may delete Customer Data from active systems; residual copies in routine backups age out on our normal backup cycle. We keep billing and tax records for as long as the law requires, and security logs for a limited period for abuse investigation.
Note that some records in the Service are deliberately immutable: the audit trail is hash-chained so that entries cannot be silently altered, which is the tamper-evidence the product exists to provide. Corrections are recorded as new entries rather than edits to old ones. Deleting an account removes the data; amending a single historical audit entry in place is not something the design allows.
Each railroad's records are held in a separate, logically isolated database schema, and every query is scoped to the schema of the authenticated session. Traffic is encrypted with TLS in transit. Passwords are stored using argon2id; session tokens are stored only as hashes. Uploaded images are re-encoded to strip embedded metadata and served through an authenticated, same-origin proxy. Third-party secrets are encrypted at rest with authenticated encryption. Access to production is limited to people who need it.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any regulator as applicable law requires, without undue delay.
Depending on where you live — including under the Colorado Privacy Act and similar U.S. state laws, and under the GDPR or UK GDPR if you are in Europe — you may have the right to access a copy of your personal information, correct it, delete it, obtain it in a portable format, opt out of sale or targeted advertising (we do neither), limit the use of sensitive information, and appeal a decision we make about a request. We do not use your information for automated decisions that produce legal or similarly significant effects.
To exercise a right, write to [email protected]. We will verify your identity through your account and respond within the time your law allows — generally 45 days, extendable once where permitted. You will not be charged or receive a worse service for asking. If you are unsatisfied with our response, you may appeal by replying to our decision, and you may complain to your state attorney general or supervisory authority.
Where we process personal information about people in Europe, we rely on our legitimate interest in operating the Service, on the necessity of processing to perform our contract with the customer, and on consent where the law requires it.
We will post any update here with a new effective date, and for material changes we will notify account holders by email or in the Service before the change takes effect.
RailCompliant — A product of Foxx Cyber LLC
[email protected]
See also our Terms of Service.