Privacy Policy
Last updated: 18 September 2026
Who is responsible for your information
RailFolio is operated by Paul Wyn Martin, trading as RailFolio. I am responsible for deciding how and why your personal information is used.
For privacy questions, requests or complaints, email support@railfolio.com.
RailFolio is intended for people aged 18 and over.
Information used to provide RailFolio
RailFolio uses your email address, display name, account identifiers and authentication information to create and manage your account, sign you in and help you recover access.
Information you choose to add can include a profile photograph, local station and favourite train. Sightings can contain photographs, train details, notes, location names and coordinates, and dates and times. RailFolio also processes your comments and likes.
Reports, blocking records, relevant content and support correspondence are used to investigate problems, respond to enquiries and help protect the community, including reports that an account may belong to someone under 18. Information may also be used where necessary to meet a specific legal obligation.
RailFolio's current app code does not include analytics, advertising SDKs, crash-reporting software or device fingerprinting. It stores the signed-in session and recovery state locally on the device, and requests camera, photo-library and location access only when the member uses those features. Supabase and Resend may process provider-level security, authentication and delivery logs under their own terms; their documented storage and retention arrangements are recorded in the accompanying storage review.
What other people can see
Sighting photographs, display names, comments and any location details and coordinates included in a sighting are public. An exact map pin can reveal a home or other private place even if its label only names a town. Check your chosen location before publishing.
Your account email and password are not published with your sightings. Blocking a member does not make a public photograph private. People may keep copies of content you have made public; removing content from RailFolio cannot remove copies held independently by others.
Why information is used
The following lawful bases apply to RailFolio's processing of personal information:
Contract: information necessary to provide the account and community features you request, such as signing in, publishing sightings and using comments, likes and maps.
Legitimate interests: information needed to answer enquiries, investigate reports, apply blocks, protect members from abuse and keep the service secure. RailFolio uses only relevant information, limits access to authorised reviewers and keeps the impact on members under review.
Legal obligation: information processed or retained where required by applicable law, including handling data-protection rights requests and valid requests from public authorities.
Optional device permission is not, by itself, a determination of the lawful basis for every subsequent use of that information.
Where information comes from
Information comes directly from you when you register, use the app, publish content or contact support. Other members may provide information about you in photographs, comments or reports. Service providers may supply account-security and email-delivery information.
Service providers and other recipients
Supabase Pte. Ltd: account authentication, database and photograph storage. The project's primary hosting region is Ireland (eu-west-1).
Resend (Plus Five Five, Inc.): signup verification and password-reset email delivery, including the recipient address, message content and delivery information.
GoDaddy / Microsoft 365 Email Essentials: the support@railfolio.com mailbox, used for support correspondence and privacy requests.
Apple and Google map services: on iOS, RailFolio uses the native Apple MapKit/Apple Maps service through react-native-maps; on Android, it uses Google Maps through react-native-maps. When a member opens or uses a map, the relevant provider may process map requests, approximate device location and any coordinates needed to display the map under its own terms. RailFolio sends the sighting location selected by a member to Supabase so it can display the sighting and its map pin.
Other members and the public: the community content described above.
Organisations entitled to receive information under applicable law: only when disclosure is required.
Supabase and Resend act as processors for application data handled on my behalf. They may separately act as controllers for their own business-account and service-administration information.
What the providers hold when you use RailFolio
Using RailFolio means that different providers process different parts of your information:
Supabase stores and processes your RailFolio account, authentication records, profile information, sightings, photographs, comments, likes, blocks, reports and the location details you submit with a sighting. Its primary database, authentication service and photo storage are hosted in Ireland, although provider support, infrastructure, logs and subprocessors may involve other countries.
Resend processes the email address and message information needed to send signup confirmations and password-reset messages, together with delivery and security logs. Resend states that message content and logs are stored in the United States.
Apple may process map requests, approximate device location and map-related coordinates when you use RailFolio on iPhone or iPad.
Google may process map requests, approximate device location and map-related coordinates when you use RailFolio on Android.
These providers do not automatically receive every item of information in your RailFolio account. Each receives information needed for the feature being used, or for the provider service described above, under its own privacy terms and data-processing arrangements. RailFolio does not sell your personal information to these providers.
Processing outside the UK
RailFolio's primary Supabase database, authentication service and photo storage are hosted in Ireland. This does not mean every supporting service or access to information stays in Ireland: provider support, infrastructure, logs, content delivery and subprocessors can involve other countries.
Resend stores email content and delivery logs in the United States. Choosing Ireland as its sending region affects email routing, not storage location.
Supabase's and Resend's data-processing agreements incorporate contractual transfer safeguards, including the UK Addendum to the EU Standard Contractual Clauses for relevant UK transfers. Their agreements apply through their service terms. You can contact support@railfolio.com for information about the safeguards relevant to your information.
No UK-only storage promise is made.
How long information is kept and deletion
RailFolio uses the following retention periods:
Account and current profile information: while the account is held, until account deletion, unless a specific legal obligation requires particular information to be kept.
Sightings, photos, comments and likes: until the member deletes the relevant content or account. Content can also be removed through moderation, or when the sighting it belongs to is deleted.
Block records: until unblocked or an associated account is deleted.
Ordinary support emails and attachments: completed enquiries are deleted six months after resolution.
Privacy requests, complaints, moderation matters and disputes: deleted 12 months after resolution, unless a specific legal duty or documented hold requires longer.
Resolved moderation reports: deleted 12 months after resolution, or earlier where deletion of the associated account or content removes them.
Open complaints or reports: kept while being investigated and reviewed regularly.
Specific ongoing disputes or legally required records: only the information necessary for that purpose is kept. It is deleted when the reason for keeping it ends.
Account and photograph deletion
Account deletion removes the files in the member's photo-storage folder before deleting the authentication account. The application's schema defines cascading deletion of associated sightings, likes, comments, blocks and reports. A failed request can require a retry; the app should not report completion until the server succeeds.
Deleting an individual sighting removes its database record and then attempts to remove its photo. If photo removal fails, the app tells the member to contact support. Such failures require follow-up; deletion of the database record alone does not remove the stored photo.
Older profile photos and uploads left by interrupted attempts currently remain in the member's storage folder until account deletion or a support-assisted cleanup. They are not automatically deleted when replaced. Public photo URLs can remain accessible while a file exists.
Provider logs, emails and backups
Resend states that email and log data is retained for 30 days on its Free, Pro and Scale plans and its backups persist for seven days. Deleting a RailFolio account does not itself erase an email already delivered to a recipient or immediately remove Resend's delivery records. An earlier removal request can be raised with Resend where needed.
Supabase's published Free-plan API/database log window is one day. This is not a promise that all provider-held security records disappear after one day.
Supabase's paid plans provide backup retention that varies by plan. RailFolio is currently using the Free plan. If independent backups are introduced, an appropriate expiry period will be established, and deletion will be reapplied if a backup is restored.
Your rights
Depending on the circumstances and lawful basis, you can request access to your personal information, correction of inaccurate information, deletion, restrictions on use, or transfer of information to you or another organisation. You may object to processing where that right applies. Where processing relies on consent, you can withdraw it.
Contact support@railfolio.com to exercise your rights. Rights have conditions and exceptions. Requests will be answered without undue delay and normally within one month, subject to applicable rules and any permitted extension.
Read more about these rights at the Information Commissioner's Office (ICO): ico.org.uk
Complaints
Please contact support@railfolio.com if you have concerns about your information. If you remain unhappy after raising your complaint, you can complain to the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Further information is available at: ico.org.uk/make-a-complaint
Age restriction and future changes
RailFolio is intended for adults aged 18 and over. New accounts must confirm during signup that the member is 18 or over. RailFolio does not knowingly accept under-18 accounts. If RailFolio learns that an account belongs to someone under 18, access may be restricted and the account and associated content may be deleted after an appropriate review. To report a possible under-18 account, contact support@railfolio.com.
Advertising is planned but has not been installed. The privacy notice and consent requirements will be reassessed before adverts, analytics or other new data uses are introduced.