Privacy policy
This policy explains what personal information RailBuddy collects when you use Rail Buddy, why we collect it, who we disclose it to, and how you can access it, correct it or complain about how we have handled it.
Last updated 30 July 2026
Who we are
Rail Buddy is operated by RailBuddy ("we", "us", "our"). We are based in South Australia.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the Act does not strictly apply to us, we apply the APPs as our standard anyway.
Rail Buddy is not operated by, affiliated with or endorsed by any rail operator or safeworking authority. We are not your employer, and this policy is separate from any privacy policy your operator applies to you.
Your live position never leaves your device
Rail Buddy positions you along the road using your device's own location. That position is used entirely in your browser to draw the road ahead. It is never sent to us, never stored on our servers, and never disclosed to anyone — not to your operator, not to an analytics provider, not to us.
This is deliberate. A driver's live position along a rail corridor is about as sensitive as location data gets, and the safest way to hold it is not to hold it. There is no location history to request, because none exists. You can revoke the browser's location permission at any time; the app keeps working and simply stops following you.
What we collect
Information you or your administrator give us
- Your username and display name, which identify your account.
- Your PIN. We store only a one-way cryptographic hash and a per-account salt; we never store and cannot recover the PIN itself.
- The company or operator your account belongs to, so you see the right rail network and layers.
- Anything you send us by email, including in a support or privacy enquiry.
We do not collect your email address — accounts are username-based, and accounts are created by an administrator rather than by self-registration.
Content you create
- Pins and segments you add — landmarks, notes and marked stretches of road, with the coordinates you placed them at and the layer you put them on. These are attached to your account so you can edit them and so a restore can put them back.
- A pin on a public layer is visible to other users of that layer. A pin on your private layer is not.
Information created by your use of the service
- Account status — whether your account is active and whether it holds admin rights, and when it was created.
- Technical and security logs. Your IP address, the request path and your browser's user-agent string, recorded so we can rate-limit abuse and investigate security incidents.
What we deliberately do not collect
- Your location, as described above.
- Payment details. Rail Buddy does not take payments from drivers.
- Anything about your driving performance. Rail Buddy is not a monitoring tool and produces no record that could be used to assess you.
- Sensitive information as defined by the Privacy Act. Please do not send it to us.
Why we collect it
- To create and operate your account and sign you in.
- To show you the right rail network, layers and the content you created.
- To keep the service secure and available: rate limiting, abuse detection and incident investigation.
We do not sell personal information, and we do not use your information for third-party advertising or profiling.
Who we disclose it to
| Provider | Purpose | What it receives |
|---|---|---|
| Cloudflare | Network delivery and abuse protection | Your IP address and request metadata, in transit |
That is the whole list. No analytics of any kind runs anywhere in Rail Buddy. Rail Buddy's elevation information comes from Open-Meteo, and its station and asset layers from OpenStreetMap and public operator data. Rail Buddy asks those services only about coordinates on the rail network — never about you, your device or your position — so no personal information is sent to them.
We may also disclose information where we are required or authorised to by law, or where it is reasonably necessary to protect someone's safety.
Overseas disclosure
Cloudflare (a global network) processes data outside Australia. Before disclosing personal information overseas we take reasonable steps, as APP 8 requires, to satisfy ourselves that the recipient handles it consistently with the APPs. Our own application database and backups are held in Australia.
How we protect it
- All traffic is served over HTTPS.
- PINs are stored only as salted, one-way hashes.
- The database is not reachable from the public internet.
- Requests are rate-limited and abusive sources are blocked automatically.
- Access to production data is limited to those who need it to run the service.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as the Notifiable Data Breaches scheme requires.
How long we keep it
- Account information — while your account exists, and for a short period afterwards so an accidental deletion can be reversed.
- Pins and segments you created — until you or an administrator delete them. Content on a shared public layer may be retained after your account closes, because other users depend on it; ask us if you would rather it were removed.
- Security and access logs — a rolling window, currently no more than 90 days.
When we no longer need personal information, we delete it or de-identify it.
Accessing and correcting your information
You can view and update your details and your own content while signed in. You may also ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account. Email [email protected].
We will respond within 30 days. There is no charge for requesting access. If we refuse access or correction we will tell you why in writing, and how to complain.
Complaints
If you think we have mishandled your personal information, please tell us first at [email protected]. We will acknowledge your complaint and aim to resolve it within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
Cookies
Cookies and similar storage are covered separately in our cookie policy.
Changes to this policy
We may update this policy as the service changes. The "last updated" date above always reflects the current version. If a change materially affects how we handle your personal information, we will tell you in the app before it takes effect.