Privacy policy

In effect from 7 October 2026.

DokoRail (dokorail.jp) is a map of trains in Japan. You can use it without an account. This page explains what personal data the site handles, why, who else handles it for us, how long it is kept, and what you can do about it. It covers the EU and UK General Data Protection Regulation (GDPR) and Japan's Act on the Protection of Personal Information (APPI).

1. Who is responsible

DokoRail is a hobby site run by one person, Koen van den Heuvel (GitHub), who decides how the data described here is used.

Contact for anything on this page: [email protected]. Our postal address is available on request at the same address, and we will send it without delay.

2. In short

3. What we collect, why, and on what legal basis

3.1 Delivering the website

Each time your browser loads the site, Cloudflare (our host) receives the request: your IP address, the address of the page or file, the time, your browser's user agent, and the referring page. This is needed to send you the site and to protect it from attacks. The map position and the selected train or station are kept in the part of the address after #, which browsers never send to a server.

To decide whether to show the analytics question, the app asks our server /api/region. Cloudflare works out your country from your IP address. The server only answers "ask" or "do not ask". It does not store the country or the IP address.

Legal basis: legitimate interests (GDPR Art. 6(1)(f)) in running a working and secure website.

3.2 Usage analytics

We use two tools:

For both tools, page addresses are cut down before sending: the query string and the # part are removed (Google Analytics keeps only ?view=stock, to tell the train collection apart from the map). We never tell either tool who you are, and we do not create profiles linked to a name or email.

To tell visits apart, the tools store a random ID in your browser: PostHog in a cookie and local storage entry named ph_<project key>_posthog (kept for up to 1 year), and Google in the cookies _ga and _ga_<ID> (kept for up to 2 years). Both tools receive your IP address as part of the request. Google says Google Analytics 4 does not log or store IP addresses. PostHog uses the IP address to estimate your country and city, then throws the address away: it is not stored with the events.

Legal basis: in the EU, EEA and UK, and when your region is unknown, your consent (GDPR Art. 6(1)(a) and the ePrivacy rules on cookies). Nothing loads and no cookies or storage entries are set until you press Accept. Elsewhere, our legitimate interest in improving the app, with an opt-out in Settings.

3.3 Bug reports

Only if you open the bug report form and send it, we receive: the title, description and category you enter, an email address if you choose to give one, the app version, and, if you leave it attached, a technical snapshot. The snapshot holds the map position and zoom, the map time and speed, your display settings, the selected train or station and its position data, the state of the live train feed, and, for reports from the 3D train viewer, the screen size, pixel ratio and graphics card name. Do not put information in the report that you do not want us to see.

To stop spam, the form loads Cloudflare Turnstile (from challenges.cloudflare.com), which checks that a person is sending it. To limit how many reports one network can send per hour, your IP address is turned into a keyed hash (an HMAC; for IPv6 the first 64 bits of the address are used). The raw IP address is not stored by our application. Cloudflare may keep IP addresses in its own platform logs.

We use the report to find and fix the problem, and the email address only to reply about that report. Legal basis: legitimate interests in fixing faults and preventing abuse (GDPR Art. 6(1)(f)).

3.4 Stored on your device only

The app keeps your choices in your browser's local storage: theme, language, map settings, the lighter map mode, and your analytics choice (trains-analytics and trains-analytics-consent, which also records when you chose). For offline use, a service worker keeps copies of the app's files, line data, fonts and map tiles. None of this is sent to us. These are needed for features you use, so they do not need consent.

The locate button asks your browser for your position. The position is only used in your browser to move the map. It is not sent to us.

3.5 Content your browser loads from other services

Like any web page, these services receive your IP address when your browser fetches something from them. They act on their own terms, not on our behalf:

4. Who processes data for us

CompanyWhat forWhere
Cloudflare, Inc. (USA)Hosting and delivery of the site, the server functions, storage of bug reports (D1 database, R2 storage) and TurnstileCloudflare's global network, including the USA
PostHog, Inc. (USA)Usage analytics and session replaysEU cloud, Frankfurt, Germany
Google Ireland Limited / Google LLC (USA)Google Analytics 4Google's data centres, including the USA

5. Transfers to other countries

DokoRail is run from Japan. The European Commission and the UK have decided that Japan protects personal data to an adequate level, so data can come to us from the EU and UK under those decisions.

Cloudflare and Google may process data in the USA. Both are certified under the EU-US Data Privacy Framework and its UK extension, and their data processing terms include the EU Standard Contractual Clauses. PostHog stores our analytics data in the EU. PostHog, Inc. is a US company, and its data processing agreement includes the Standard Contractual Clauses for any access from outside the EU.

For the APPI (Article 28): the USA has no single federal law on personal data that matches the APPI. Some states have their own laws, such as California's CCPA. Each provider above has committed in its data processing terms to measures equivalent to those the APPI requires, including security measures and limits on use. Germany and the EU are covered by the GDPR. You can ask us for more detail.

6. How long data is kept

DataKept for
Bug reports, with our notes and review history180 days from when the report was sent
Technical snapshot attached to a bug report30 days from when the report was sent
Bug report submissions that were never finished24 hours
Per-hour and per-day report counters (hashed IP)Removed after the hour or day they count has passed
PostHog events and session replaysEvents 1 year, session replays 30 days
Google Analytics event data2 months (totals in reports, which hold no IDs, are kept longer)
Analytics IDs in your browserPostHog up to 1 year, Google up to 2 years, or until you reject or withdraw consent (the app then deletes them)
Cloudflare request logsWe do not store request logs ourselves. Cloudflare keeps its own logs for as long as it needs them to run and secure its network, as set out in the Cloudflare privacy policy
Settings and your analytics choice in your browserUntil you change them or clear the site's data

Deletion runs as a regular background job, so data can stay for a short time after these limits before it is actually removed.

7. Changing or withdrawing your analytics choice

Open Settings in the app and use the Share usage analytics switch. It is the same choice as the Accept and Reject buttons. Turning it off stops both tools straight away and deletes their cookies and IDs from your browser. Withdrawing consent does not affect what was collected before. You can also clear the site's data in your browser, which resets the choice so you will be asked again.

8. Your rights

Under the GDPR (EU, EEA and UK)

You can ask for access to your data, correction, deletion, restriction of use, and a copy in a portable format. You can object to use based on legitimate interests, and withdraw consent at any time. You can also complain to the data protection authority where you live or work. In the UK, this is the Information Commissioner's Office (ICO).

Under the APPI (Japan)

You can ask us to disclose the personal data we hold about you and the records of any provision to third parties, to correct, add to or delete it, and to stop using it or providing it to third parties. You can also contact the Personal Information Protection Commission (個人情報保護委員会).

How to ask

Write to [email protected]. We will reply within one month. Requests are free of charge. Because there are no accounts, we can only find analytics data if you send us the random ID from your browser, and a bug report if you tell us its reference number or the email address you gave. We may ask for information to confirm that a request is yours.

9. How we protect data

All traffic uses HTTPS. Bug reports are stored in private storage that is not reachable from the internet. Only the operator can read them, after signing in through Cloudflare Access. IP addresses for rate limits are stored only as keyed hashes. Analytics tools are set to collect as little as possible, as described above.

10. Changes to this policy

If we change what we collect, we will update this page and the date at the top. If a change needs your consent again, the app will ask again.