TrainCompass.com

Privacy Policy

This Privacy Policy explains how Nova Group Sp. z o.o., operating TrainCompass, collects, uses, stores, and shares personal data when you use our website, create an account, search routes, make a booking, contact support, or otherwise interact with our services.

Effective date: March 12, 2026Last updated: March 12, 2026

1. Data controller

The controller of your personal data is:

Nova Group Sp. z o.o.

Tax ID (NIP): PL7011215529

Żurawia 6/12 Lok. 745

00-503 Warszawa

Poland

Email: letsride@traincompass.com

If we have appointed a data protection officer or other dedicated privacy contact, their details are: [insert if applicable].

2. Scope of this Policy

This Privacy Policy applies to personal data processed in connection with:

  1. visiting the TrainCompass website,
  2. creating and using an account,
  3. searching routes and timetables,
  4. making and managing bookings,
  5. receiving ticket delivery emails and transaction communications,
  6. contacting support by email, chat, voice, or forms,
  7. using My Trips and passenger profile features,
  8. security, fraud prevention, and service improvement.

This Policy does not replace any operator-specific privacy information that may apply to the underlying rail service where relevant.

3. What personal data we collect

Depending on how you use TrainCompass, we may collect the following categories of personal data:

3.1 Data you provide directly

  1. name,
  2. email address,
  3. phone number, if provided,
  4. account login details,
  5. passenger details you enter for a booking,
  6. booking and trip details,
  7. preferences such as language, currency, and saved passenger profiles,
  8. support messages, email correspondence, chat messages, and voice support transcripts where applicable.

3.2 Booking and transaction data

  1. booking reference,
  2. order and ticket information,
  3. route, date, time, passengers, and related journey data,
  4. transaction status,
  5. payment-related metadata necessary to process or trace a payment, such as payment status, transaction identifiers, and in limited cases the last 4 digits of a card if needed for support or tracing.

We do not intentionally collect full payment card numbers, CVV codes, passwords, or one-time codes through support channels.

3.3 Technical and usage data

  1. IP address,
  2. browser and device information,
  3. operating system,
  4. language and regional settings,
  5. logs relating to use of the website and support tools,
  6. timestamps and interaction data,
  7. cookie and similar technology data, where applicable.

3.4 Data obtained from third parties

We may receive personal data from:

  1. payment providers,
  2. rail operators or booking partners,
  3. service providers involved in ticket issuance, support, email delivery, hosting, analytics, or fraud prevention,
  4. communication providers used for support services.

5. Whether providing data is required

Providing some personal data is necessary for us to provide bookings or support.

For example:

  1. without booking and passenger details, we may be unable to process a booking,
  2. without an email address, we may be unable to deliver your ticket or confirmation,
  3. without certain transaction details, we may be unable to investigate payment issues.

Where data is optional, we will generally indicate this.

6. Recipients of personal data

We may share personal data with the following categories of recipients, only where necessary:

  1. rail operators, booking partners, or ticketing partners involved in fulfilling the journey,
  2. payment processors and payment service providers,
  3. hosting and infrastructure providers,
  4. email delivery providers,
  5. customer support and communications providers,
  6. analytics, monitoring, and security providers,
  7. legal, accounting, tax, or compliance advisers where necessary,
  8. public authorities or courts where required by law.

Where third parties process personal data on our behalf, we require them to act under appropriate contractual and legal safeguards.

7. International transfers

Some of our service providers or technical infrastructure may process personal data outside the European Economic Area (EEA).

Where personal data is transferred outside the EEA, we will ensure that an appropriate transfer mechanism is in place, such as:

  1. an adequacy decision issued by the European Commission,
  2. the European Commission’s Standard Contractual Clauses,
  3. or another lawful transfer mechanism recognized under applicable data protection law.

If you would like more information about the safeguards used for international transfers, you may contact us at letsride@traincompass.com.

8. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Retention periods may vary depending on the category of data and the purpose of processing. In general:

8.1 Account data

We retain account-related data for as long as the account remains active and for a reasonable period afterward where needed for security, legal, or dispute-handling purposes.

8.2 Booking and transaction data

We retain booking, order, and transaction-related data for as long as necessary to perform the contract, provide support, handle claims or complaints, and comply with legal obligations such as tax and accounting retention requirements.

8.3 Support communications

We may retain support emails, chat messages, voice transcripts, and complaint-related records for as long as necessary to resolve the matter, improve support quality, defend against claims, or comply with legal obligations.

8.4 Technical logs and security data

Technical logs, error logs, and security-related records may be retained for a limited period necessary for troubleshooting, service protection, abuse prevention, and evidentiary purposes.

8.5 Marketing and analytics data

Where data is processed for analytics or marketing purposes, retention will depend on the tool used, the legal basis, and the settings implemented. Further information may also be available in the Cookies Policy.

Once personal data is no longer needed, we will delete it, anonymize it, or otherwise securely dispose of it, unless further retention is required by law.

9. Data subject rights

Under the GDPR and applicable law, you may have the following rights, subject to the conditions and limitations set by law:

  1. the right of access to your personal data,
  2. the right to rectification of inaccurate or incomplete data,
  3. the right to erasure (“right to be forgotten”),
  4. the right to restriction of processing,
  5. the right to data portability,
  6. the right to object to processing based on legitimate interests,
  7. the right to withdraw consent at any time where processing is based on consent,
  8. the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless the legal conditions for such processing are met.

To exercise your rights, contact us at letsride@traincompass.com.

We may need to verify your identity before responding to a request, especially where the request concerns account, booking, or transaction data.

9.1 Right to object

Where processing is based on our legitimate interests, you may object on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you have the right to object at any time to such processing.

10. Right to lodge a complaint

If you believe that your personal data is being processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO).

You may also contact us first at letsride@traincompass.com, and we will do our best to address your concerns.

11. Cookies and similar technologies

TrainCompass may use cookies and similar technologies to:

  1. ensure the website functions properly,
  2. maintain sessions and preferences,
  3. remember language or currency settings,
  4. improve performance and usability,
  5. support analytics,
  6. support fraud prevention and security,
  7. support marketing or advertising where permitted and configured.

For more information, please see our Cookies Policy, including details on cookie categories, retention, and how to manage cookie preferences.

12. Support communications, chat, and voice tools

If you contact us through support channels such as email, chat, forms, or voice tools, we may process the information you provide, including:

  1. your contact details,
  2. booking details,
  3. support messages,
  4. troubleshooting information,
  5. transcripts of support interactions where applicable,
  6. technical metadata relating to the interaction.

Please do not send sensitive payment details such as full card numbers, CVV codes, passwords, or one-time codes through support channels.

Where voice support is used, the interaction may involve transcript processing and related technical event logs for service delivery, quality assurance, debugging, or security purposes.

If audio recording is ever enabled separately, we will clearly communicate the applicable conditions and legal basis.

14. Children’s data

TrainCompass is not intended for independent use by children without the involvement of a parent or guardian where such involvement is required under applicable law.

We do not knowingly collect personal data directly from children in a manner that violates applicable law. If you believe that personal data has been provided unlawfully by a child, please contact us at letsride@traincompass.com.

15. Security measures

We take appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction.

These measures may include, where appropriate:

  1. access controls,
  2. encryption in transit,
  3. secure hosting practices,
  4. monitoring and logging,
  5. provider due diligence,
  6. least-privilege internal access,
  7. fraud and abuse prevention measures.

No internet-based system can be guaranteed to be completely secure, but we aim to apply security measures proportionate to the risks involved.

17. Automated decision-making

TrainCompass may use automated processes to support fraud detection, routing logic, technical diagnostics, service optimization, or booking workflows.

However, we do not intend to rely on solely automated decision-making that produces legal effects concerning you or similarly significantly affects you unless the legal conditions for doing so are met and the required safeguards are provided.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, including due to:

  1. legal or regulatory changes,
  2. changes to our services or business model,
  3. new technical solutions or providers,
  4. clarification of our processing practices.

The updated version will be published on the website with an updated effective date and last updated date.

19. Contact

If you have questions about this Privacy Policy or how we process personal data, contact:

Nova Group Sp. z o.o.

Żurawia 6/12 Lok. 745

00-503 Warszawa

Poland

Email: letsride@traincompass.com

Helpful related pages

Questions about your data?

If you have questions about this Privacy Policy or how we process personal data, contact us.

TrainCompass support

Live Chat Support

Start a chat and we will help with date changes, ticket delivery, fees, disruptions, and privacy questions.

Email supportletsride@traincompass.com