Privacy

Make The Train helps you plan a train journey after a UK event. No account is required. We do not add advertising, analytics or tracking cookies.

Your journey information

We use your chosen event, destination station and optional finish-time adjustment to calculate your journey. We do not save individual searches or finish adjustments in the event catalogue or create a personal profile. Your browser history may retain the result URL.

Event search reads our stored catalogue. It does not send your search to Ticketmaster or API-Football. Train searches send station codes and travel times from our server to the rail timetable provider. We do not send the provider your IP address.

Custom location checks

In “My event isn’t listed”, typed venue names, addresses and postcodes are sent through our server to Google Maps Platform for location suggestions. Selecting a suggestion resolves its UK address and coordinates. When Google is used to estimate your transfer, it receives the selected coordinates, nearby railway station coordinates and your ready-to-leave time. Google processes these requests under the Google Privacy Policy. We do not send Google your IP address.

For local transfers confidently within London, we prefer TfL’s Journey API. Our server sends the selected coordinates or public venue gateway, candidate station coordinates and ready-to-leave time to TfL. We do not forward your IP address, typed search, or raw address. If TfL cannot provide a suitable route, we try Google; existing venue allowances or manual times remain available. TfL handles requests under its privacy policy. We cache only a small journey summary in server memory for two minutes, keyed by a hash of the route and time; no raw TfL response or custom check is stored in PostgreSQL.

Your location, chosen timings and custom result are held temporarily in this browser tab’s memory. They are not placed in the result URL, browser storage, cookies or PostgreSQL, and refreshing clears the custom result. We do not create location profiles or a search history. Google predictions, addresses and route durations are not cached on our server. Coordinates, place IDs, request counters and cryptographic proofs are held in bounded server memory for up to twenty minutes, with automatic expiry deletion even if no further requests arrive. This lets us verify the active check without storing your address or route details.

If you explicitly choose “Use postcode & manual transfer instead”, our server sends your postcode to Postcodes.io using an encrypted connection. That provider processes it under its own terms. This fallback covers England, Scotland and Wales; it rejects Northern Ireland postcodes before contacting Postcodes.io because of separate data licensing. It briefly caches coordinates against a salted postcode hash in memory for up to five minutes, removed on the next lookup after expiry or restart. We do not automatically send the same location to both providers.

Google location selection covers the United Kingdom, including Northern Ireland. The current National Rail station dataset covers Great Britain, so a Belfast location can be selected but a Northern Ireland rail journey cannot yet be calculated. Republic of Ireland and overseas locations are not supported. Location data credits and licences.

Custom requests send form data in a POST body. Application logs do not record raw addresses, postcodes, coordinates or these request bodies. Safe operational counters record the Google operation, HTTP status and matrix element count. Hosting infrastructure still handles normal technical request information. Rail providers receive only the selected station codes and journey times, not your custom location.

Security and hosting

Railway hosts the service and database. Hosting infrastructure processes technical request information, including IP addresses, to deliver and protect the service. We keep temporary, hashed client identifiers and request counts in server memory to limit automated abuse; entries expire after an hour of inactivity and are removed on the next check or restart. These records contain no event or destination.

Operational logs record random request references, timings, provider names and usage counters, categorical journey outcomes and technical error categories. These help us understand reliability, incomplete timetable results and unusual routes. We do not deliberately log search text, addresses, postcodes, coordinates, place IDs, selected events or stations, request bodies or credentials. Request references identify a technical request, not a person; we do not use them to build user profiles.

Railway controls infrastructure log retention. Hosting logs may contain normal technical request information. We do not maintain a separate analytics database or log warehouse.

External links, including National Rail, have their own privacy policies. This page describes the current service and will be updated if its data handling changes.

Operated by Make The Train. Contact: contact@makethetrain.com.