Privacy, plainly explained

Privacy Notice

TrainSight turns voluntary, pseudonymous location signals into shared railway insights. This notice explains what we collect, why we use it, and how you stay in control.

Effective August 2, 2026

The short version

Your trip helps the network, without a rider profile.

You do not need to give TrainSight your name, email address, or a passenger account to contribute GPS data. We use a random browser or app installation identifier so live signals can be validated and combined without attaching them to your identity.

No passenger account

GPS contribution works without a name or sign-in.

Random identifier

Signals use a browser client ID or mobile installation ID.

Near-rail sharing

Passenger GPS is sent when you are near a supported rail corridor.

Your choice

Use app controls or device settings to stop location sharing.

Anonymous versus pseudonymous

We treat location data as protected data.

TrainSight commonly describes passenger GPS as anonymous because it is not submitted with a rider's name or account. More precisely, it is pseudonymous: precise location is paired with a random identifier that can distinguish one browser or app installation from another. We therefore handle it as personal data and apply the protections described here.

01 / Scope

Where this notice applies

This notice covers the TrainSight passenger website, Android beta app, location-contribution features, station alerts, and related service analytics. It does not cover railway-operator hardware trackers, employee or team records, or third-party websites opened from TrainSight; those may have separate terms or notices.

For this service, the personal information controller is TrainSight (TrainSight project team), Philippines.

02 / Anonymous GPS

How passenger GPS works

1

You grant permission

Your browser or phone asks for location access. The mobile app may also request background access for trip tracking and station alerts.

2

The app checks the signal

TrainSight checks rail proximity and filters stale, noisy, duplicate, or implausible readings. Some of this happens on your device.

3

A random ID contributes

When Location Contribution is on and you are near a supported rail line, validated readings are sent with a random client or installation ID.

4

Signals become rail insights

Readings are matched to the rail route and combined into train positions, ETAs, movement status, and crowd estimates. The public map does not display a named rider trail.

Near a rail line: The mobile app may check location on-device while farther away so it can conserve battery and detect when you approach a line, but passenger GPS reports are designed to be transmitted only within about 500 metres of a supported rail corridor. If rail-route data is temporarily unavailable, the server performs the proximity check.

03 / Data we handle

What TrainSight may collect

Location contribution

  • Precise latitude and longitude
  • Time of the reading, speed, heading, and accuracy
  • Location provider and mock-location indicators
  • Derived rail line, route position, movement, and proximity information

Random identifiers

  • A random browser client ID stored in site data
  • A random mobile installation ID and securely stored credential
  • A temporary anonymous advertising session ID for contextual ad measurement

App and service data

  • Platform, app version, package, and environment
  • IP address, request time, and similar security or server-log data
  • Theme, display, alert, and station-subscription preferences

Optional notifications and contact

  • Push notification token when notifications are enabled
  • Selected station or service-alert subscriptions
  • Any name, email, or message you choose to send when contacting us

Some settings, cached rail data, alert state, and a recent location used for app functions may remain locally on your device. TrainSight does not ask for your contacts, photos, microphone, or camera for passenger GPS contribution.

04 / Why we use it

Purpose and basis of processing

  • Live railway information: estimate train location, direction, speed, arrival time, crowd level, and service status.
  • Trip features: show your location on your device, provide station proximity alerts, and support voice or notification features you enable.
  • Integrity and safety: detect spoofed, stale, duplicate, off-rail, or implausible GPS reports and protect the service from abuse.
  • Service reliability: maintain short reconnect continuity, diagnose failures, measure accuracy, and improve prediction models.
  • Contextual sponsored content: select and measure ads using train, line, station, and temporary session context—not a named passenger profile.

We rely on your consent for device location and notifications, shown through the browser or operating-system permission prompts and the Location Contribution control. We also process limited technical data where necessary to provide, secure, and improve the service. You can withdraw a permission at any time, although related features will stop working.

05 / Your choices

How to stop or reset collection

In TrainSight

Turn off Location Contribution in TrainSight settings. This stops new GPS packets from being contributed while allowing non-location parts of the service to continue.

In your browser

Block location permission for the TrainSight site. Clearing the site's storage also removes the locally stored random browser ID and preferences.

On your phone

Change TrainSight's Location permission to Never, While Using, or your preferred operating-system setting. Revoke background location or notification permission separately. Clearing app data or uninstalling removes locally stored app data.

Turning off sharing prevents new contributions. It does not remove de-identified or aggregated rail statistics already created from earlier readings. You may contact us about identifiable or pseudonymous records that are still retained.

06 / Retention

How long data is kept

Live GPS working state Normally expires after about 150 seconds without a fresh contribution.
Reconnect association A random contributor ID may remain available for trip continuity for up to about 10 minutes.
Operational and diagnostic logs Rotating logs are configured for no more than 90 days. Exact raw-GPS diagnostic logging is off by default; when explicitly enabled for troubleshooting, the contributor ID is replaced with a one-way pseudonymous hash.
Installation and notification records Kept while the installation, credential, push token, or alert subscription remains active or is reasonably needed for security and service delivery.
Data on your device Kept until you clear TrainSight site/app data, reset the setting, or uninstall the app.
Aggregated rail statistics May be kept longer when they no longer identify or single out a browser, installation, or rider.

We may retain specific records longer when reasonably required to investigate abuse, protect legal rights, comply with law, or preserve an active request. We will remove or de-identify data when the purpose no longer applies.

07 / Sharing

Who may receive data

  • Authorized TrainSight team members who operate, secure, support, or improve the service.
  • Infrastructure providers that host, connect, monitor, or protect TrainSight and receive only the data needed for those functions.
  • Map providers, including CARTO and OpenStreetMap-based services, which may receive map-tile requests and normal network information such as an IP address.
  • Notification providers, including Expo and the applicable Apple or Google delivery service, when you enable push notifications.
  • Authorities or advisers when disclosure is required by law or reasonably necessary to protect users, the public, TrainSight, or legal rights.

Public users and potential transport or research partners may receive aggregated railway outputs such as estimated train position, ETA, crowd level, and performance statistics. TrainSight does not expose your random contributor ID as a public rider identity, and raw rider GPS is not used to build a named advertising profile.

08 / Security

How we protect information

TrainSight uses measures designed to reduce privacy risk, including random identifiers, hashed mobile credentials, short-lived live GPS state, rail-proximity filters, restricted log access, transport security, rate limits, and separation of high-volume diagnostic GPS logs from ordinary service logs. No system is completely secure, so we continually review safeguards and limit collection to what the service needs.

09 / Your rights

Philippine data privacy rights

Subject to the Data Privacy Act of 2012 and applicable limitations, you may ask to be informed about processing, access data about you, object or withdraw consent, correct inaccurate data, request erasure or blocking, obtain portable data where applicable, seek damages, or file a complaint with the National Privacy Commission.

Because TrainSight does not require a passenger account, we may need the random client or installation ID and other details to verify that a record belongs to your device. In some cases, we may be unable to link an aggregated rail record back to you.

Learn about data-subject rights from the National Privacy Commission

10 / Children

Children's privacy

TrainSight is a general public-transport service and is not designed to create profiles of children. Parents or guardians who believe a child's data was provided in a way that requires review or deletion should contact us.

11 / Changes

Updates to this notice

We may update this notice as TrainSight changes. We will revise the effective date on this page and provide additional notice in the app or website when a change materially affects how personal data is handled.

Questions or requests

Contact TrainSight

For access, correction, objection, deletion, or other privacy concerns, email the TrainSight project team. Use the subject line Privacy Request and include enough detail for us to understand your request.

Email a Privacy Request