Railcoonby teamARC

Privacy policy

Last updated: 3 October 2026

This is a translation for your convenience. If there is any discrepancy, the Spanish version prevails.

This policy explains what personal data we process in Railcoon, what for, for how long and what rights you have. It applies to the website railcoon.com and to the Railcoon app. It complies with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

1. Data controller

  • Controller: Luis Miguel Colorado Pérez
  • NIF (Spanish tax ID): 32705389X
  • Address: Travesía Centeás 8, 15350 Cariño (A Coruña), Spain
  • Privacy contact: hola@railcoon.com

We have not appointed a data protection officer because we are not required to do so.

2. What data we process, what for and on what basis

Data What for Legal basis
Account: email address, username, password (stored encrypted, never in plain text), language, sign-up date and last activity, and the version of the terms you accepted and when Creating and managing your account, logging in and recovering access Performance of the contract (art. 6.1.b GDPR): the Terms of use
Profile: photo, description, payment methods you choose to add (Bizum, Revolut, PayPal or your username on poker sites such as GGPoker, Winamax or CoinPoker), privacy and notification settings Showing your profile to the people in your groups and, to those who owe you money, how to pay you Performance of the contract
Activity: tournaments and packs you publish, percentages sold and bought, swaps, results, settlements, payments marked and confirmed, live updates, follows and ratings Providing the service: doing the sums and showing them to the people involved Performance of the contract
Groups: membership, role, invitations and the group log (joins, departures, role changes, moderation actions) Running groups and keeping a record of what happens in them, to prevent abuse and clear up disagreements Performance of the contract and legitimate interest (art. 6.1.f GDPR) in the security and transparency of the service
Email addresses of invited people: the one a member enters to invite someone Sending the invitation and checking that it is used by that person Legitimate interest of the inviting member, and our own legitimate interest in invitations working
Notifications: in-app notifications, browser push notification subscriptions and service emails Letting you know what is happening in your tournaments, swaps, payments and groups Performance of the contract. Push notifications also require you to give permission in your browser, which you can withdraw whenever you like
Support: messages you send us from Help and suggestions or with "I disagree" Handling your queries and complaints Performance of the contract and legitimate interest
Security: IP address, technical access logs, usage limits, account suspensions and the log of administration actions Protecting the service and users against fraud, abuse and attacks Legitimate interest
Legal compliance: any of the above data requested by an authority Responding to requests from judges, courts and authorities Legal obligation (art. 6.1.c GDPR)

We do not process data for advertising, we do not build commercial profiles and we do not sell or pass on your data to third parties. We do not make automated decisions with legal effects on you: Railcoon's calculations are based on the data entered by users, and account suspensions are decided by a person.

The data marked as required at sign-up (email address, username and password) are essential for us to provide the service. The rest of the profile data are optional.

3. Who sees your data

  • The people in your groups see your username, your profile, your tournaments and packs, and your activity in that group, according to your privacy settings. People who have deals with you (purchases, swaps, settlements) see the data of those deals. Your payment methods are only shown to people who owe you money, when they are about to pay you.
  • The admins of each group also see the group log and the debts between its members, so they can moderate it.
  • The Railcoon team may access data when necessary to provide support, resolve issues, moderate or comply with the law. Every administration action is logged.
  • Nothing is published outside Railcoon or shown in search engines.

4. Providers that process data on our behalf

We use these providers (data processors), with whom we have signed the contracts required by article 28 of the GDPR:

Provider Service Where the data are
Supabase, Inc. Database, authentication and photo storage Servers in the European Union (Ireland)
Vercel, Inc. Hosting of the website and the app Functions in the European Union (Dublin); global content delivery network
Resend (Plus Five Five, Inc.) Sending service emails United States
Raiola Networks, S.L. Contact email Spain
Browser push services (Google, Apple, Mozilla, Microsoft) Delivering push notifications Depends on your browser's provider. The content of notifications travels encrypted: the provider cannot read it

Some of these providers are US companies and may access data from there. In those cases, the international transfer is based on the EU-US Data Privacy Framework, if the provider has signed up to it, or on the European Commission's standard contractual clauses included in their contracts (art. 46 GDPR).

5. How long we keep data

  • Account, profile and activity: for as long as you have the account. When you delete it, we erase your profile and everything linked to it: tournaments, packs, purchases, swaps, settlements, ratings, notifications and subscriptions. Those records also disappear for the other people involved, so save anything you need beforehand.
  • Group log and log of administration actions: 3 years from each action, so that disagreements and abuse can be cleared up. If you delete your account, those entries no longer show your profile.
  • Email invitations: until they expire or are used, and then 30 days.
  • Support messages: for as long as needed to handle them and then 1 year.
  • Backups: the ones we make before technical changes to the database are deleted after 30 days. Our database provider may keep its own backups for a limited time.
  • Technical access logs: for as long as our providers keep them, usually a few days.

Where data must be kept to deal with possible legal liabilities, we will keep them blocked for the corresponding limitation periods (art. 32 LOPDGDD), available only to judges, courts and authorities.

6. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to hola@railcoon.com from your account's email address. We will reply within one month. If we need to verify your identity, we will ask you to.

You can do many things yourself in the app: edit your profile and your payment methods, change your privacy and notification settings, turn off push notifications, download a copy of your data or delete your account (in Settings).

If you believe we have not handled your rights properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).

7. Minimum age

Railcoon is only for people aged 18 or over. We do not knowingly process data of minors. If we detect an account belonging to a minor, we will delete it.

8. Security

We apply technical and organisational measures to protect your data: encrypted connection (HTTPS), encrypted passwords, access control in the database so that each person only sees what they are entitled to, two-step verification for the administration team and logging of their actions.

9. Changes to this policy

If we make significant changes to this policy, we will let you know in the app or by email before the change takes effect.