Privacy Policy

Last updated: February 2026

1. Data Controller

Philipp Schmid
Steinenberg 10

88339 Bad Waldsee

Germany

Email: info@railwail.com

2. Overview of Data Processing

We only process personal data as far as necessary to provide our services. Processing is based on the GDPR (Art. 6(1)).

3. What Data We Collect

Account data: Name, email address (when registering via email or Google OAuth).

Payment data: Processed directly by Stripe. We do not store credit card information. We only receive transaction confirmations.

Usage data: IP address, device type, browser type, pages visited, time of access.

AI-generated content: Inputs and outputs when using our AI models.

4. Legal Basis for Processing

Contract performance (Art. 6(1)(b) GDPR): Account data, payment processing, provision of AI services.

Legitimate interest (Art. 6(1)(f) GDPR): Security, abuse prevention, technical optimization.

Consent (Art. 6(1)(a) GDPR): Analytics cookies, marketing cookies.

5. Third-Party Processors

Supabase (Singapore/USA): Authentication and database. Privacy policy: supabase.com/privacy

Stripe (USA): Payment processing. PCI DSS Level 1 certified. Privacy policy: stripe.com/privacy

Google (USA): Google Analytics for usage analysis, Google OAuth for sign-in. Privacy policy: policies.google.com/privacy

Vercel (USA): Hosting and analytics. Privacy policy: vercel.com/legal/privacy-policy

Twitter/X (USA): Conversion tracking pixel. Privacy policy: x.com/privacy

For data transfers to the USA, we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.

6. Cookies

We use necessary cookies for authentication and optional cookies for analytics and marketing. Analytics and marketing cookies are only set with your consent. See our Cookie Policy for details.

7. Data Retention

Account data: As long as your account is active. After account deletion, data is removed within 30 days.

Payment data: In accordance with statutory retention periods (up to 10 years).

Usage data: Maximum 26 months (Google Analytics).

AI-generated content: Not stored permanently unless you save it in your account.

8. Your Rights (Art. 15–21 GDPR)

You have the right to:

• Access your stored data (Art. 15)
• Rectification of inaccurate data (Art. 16)

• Erasure of your data (Art. 17)

• Restriction of processing (Art. 18)

• Data portability (Art. 20)

• Object to processing (Art. 21)

• Withdraw consent at any time

Contact us at info@railwail.com to exercise your rights.

9. Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20

70173 Stuttgart

https://www.baden-wuerttemberg.datenschutz.de

10. Changes

We may update this privacy policy at any time. Changes will be published on this page.

See also: Cookie Policy · Terms of Service · Impressum