Railbase

The authoritative legal document is in English. Navigation and explanatory site content are localized.

Cookie Policy

Version: 3.4 Effective date: 15 September 2026

This Cookie Policy explains how Silkway Tech LLC uses cookies and similar browser storage on railbase.app and how Railbase on-premise deployments and the public demo at core.railbase.app may use cookies and local storage. Railbase is one product; its modules do not create separate public services. The public demo is a demonstration environment, not a hosted production offer. It should be read together with our Privacy Policy.

1. What cookies and similar storage are

Cookies are small text values stored by your browser. Similar technologies include localStorage, sessionStorage, and browser-managed security state. We use these technologies for authentication, security, language selection, preferences, and embedded checkout flows.

Basic first-party page statistics remain cookieless. Optional journey analytics use a separate identifier only after you choose Allow analytics. When Google measurement is configured, its analytics and advertising-measurement choices are separate, unchecked by default, and do not enable personalized advertising.

2. railbase.app cookies and storage

Name or storage key Type Purpose Typical duration
rb_measure Preference, HttpOnly cookie Remembers your analytics choice across railbase.app and core.railbase.app. Up to 1 year
rb_journey Optional analytics, HttpOnly cookie Joins a consenting visit across the website, public demo and verified Account. Grants no access. 30 days
_ga, _ga_* Optional Google analytics cookies Pseudonymous browser and session measurement across the site and public demo, only after separate Google analytics permission. Configured for up to 30 days
_gcl_* (if set by Google) Optional advertising measurement Associates an advertising click with a permitted conversion; only with advertising-measurement permission. Provider-managed; removed on withdrawal where accessible
sess Necessary, HttpOnly cookie Keeps an Account user authenticated and is checked against a server-side session registry on every authenticated request. Ends after 30 minutes without real user activity, after 30 days absolute, on Account/session revocation, or on sign-out
rb_account Necessary preference cookie Remembers which accepted billing account a team member selected; every request revalidates membership. Up to 1 year, or until cleared
lang Preference cookie Remembers selected site language for redirects and future visits. Up to 1 year
theme Preference localStorage Remembers light/dark theme. Until changed or cleared
Stripe.js / Stripe iframe storage Necessary third-party payment storage Enables secure payment collection, fraud prevention, and checkout/payment processing by Stripe. Controlled by Stripe

Session cookies use HttpOnly, SameSite, and production Secure attributes as applicable. Account pages send private/no-store cache directives. The browser reports only real interaction through a throttled activity endpoint; a quiet open tab does not keep the session alive, and history/back-forward restoration revalidates the session. Only storage required by browser-side interface code is readable by that code; HttpOnly preferences such as the analytics choice are set by the server, not exposed through document.cookie.

railbase.app does not expose a browser-based operator console and does not set an operator cookie. Railbase Cockpit authenticates through the dedicated Operator API. Its short-lived access token remains in process memory, while the revocable refresh credential is stored in the operating system keychain rather than website cookies or localStorage.

3. Basic statistics and optional journey analytics

Basic railbase.app page statistics are recorded without analytics cookies; optional cross-site journey analytics are separate and require the choice described below. We may record page views, download events, referrer host, browser/user-agent, country derived from IP, a salted hash of IP address, dwell time, scroll depth, CTA clicks, basic performance signals, JavaScript error metadata, and bot/AI crawler classification. These analytics do not set a cookie or localStorage tracking ID and are used for security, reliability, Product improvement, and distribution reporting.

With permission, the journey identifier links Product and Account entry, demo sign-in/persona/process stages, verified-company readiness, provider-confirmed payments, installer requests and authenticated deployment outcomes. It stores no demo credentials, document contents or ordinary business records. Identifiers and journey events are retained for at most 180 days; removing permission deletes the current journey association. GPC and DNT disable journey collection. Permission never gates visiting the demo or purchasing. Basic cookieless statistics continue independently.

Optional network export verification, when enabled, also does not set a cookie or persistent browser identifier. It evaluates the request IP at request time as described in the Privacy Policy; the export assessment ledger stores a salted IP hash and derived location/privacy signals, not the raw IP.

Optional Google Analytics and advertising measurement

The Google Ads destination of our existing Google tag is activated only with advertising-measurement permission. Analytics-only permission does not activate that destination. Purchases are measured through our linked Google Analytics conversion; adding the Ads destination does not create a second purchase event.

When enabled by us, Google Analytics is loaded only after your separate affirmative choice; we use Basic Consent Mode, not pre-consent Google measurement pings. The Google analytics checkbox and advertising-measurement checkbox are unchecked for a new decision. Advertising measurement requires Google analytics permission, while Google analytics can be allowed without advertising measurement. Click Allow analytics to save the choices shown; Decline analytics refuses both Railbase journey analytics and Google measurement. Closing the panel is not consent.

Google receives the pseudonymous browser/session identifiers and sanitized event metadata described in the Privacy Policy. Its browser requests also expose request IP and browser technical information to Google. Google signals, personalized advertising and contact-data enhanced conversions are not enabled. The integration does not read Customer Vaults or run in Customer on-premise deployments. See how Google uses information from partner sites.

Google choices and browser-ID bindings are stored on our server against the consenting journey. A changed decision clears that journey's local Google identifiers and delivery records. Unsent events expire after 48 hours; remaining local delivery records last no longer than the journey retention of 180 days. Accessible Google measurement cookies are cleared when you withdraw. Other open site/demo tabs check the shared preference at most every 30 seconds while visible and when returning to the page; an in-flight request cannot be recalled. Previously sent Google data follows Google's configured retention and deletion procedures, not just the deletion of local cookies. You may contact support@railbase.app about erasure.

4. Self-hosted Railbase cookies and storage

If you run Railbase on your own server, your deployment may set cookies and local storage values such as:

Name or storage key Type Purpose
railbase_session Necessary cookie Authenticates app users in the self-hosted deployment.
railbase_csrf Necessary security cookie Double-submit CSRF protection for cookie-authenticated requests. This cookie must be readable by the SPA so it can mirror the value into the X-CSRF-Token header.
railbase_oauth_state Necessary security cookie Protects OAuth/OIDC sign-in flow state, including provider, nonce, return URL, and PKCE verifier where applicable.
railbase_saml_state Necessary security cookie Protects SAML sign-in flow state and request binding.
rb_token, rb_tenant_id or similar Local storage Used by site-user and Component frontends to attach the app-user bearer token and selected company (X-Tenant) to API calls.
UI preference keys Local storage or cookies Theme, language, sidebar state, or similar interface preferences.

Your organization is responsible for disclosing and managing cookies, localStorage, analytics, consent, and third-party scripts in your own self-hosted deployment and its configured workflows and installed modules. Company work and installation-wide system work use the same canonical human identity with separate authorization scopes; there is no separate legacy /_/ administrator audience.

5. Component storage

Components reuse Railbase site-user identity and company selection unless their documentation identifies an additional necessary key. Their declared UI is delivered inside the signed encrypted Component bundle and mounted by the site shell; Component business data is normally stored server-side in the Customer's Vault, not in browser cookies.

6. Consent

Optional journey analytics are off until you choose Allow analytics. The site provides Allow analytics and Decline analytics controls and an Analytics preferences control to revisit your choice. Closing the panel, navigating the site or ignoring the controls is not consent.

The rb_measure preference remembers the choice for up to one year. Choosing Decline analytics stops optional journey collection, clears the journey cookie and removes the current journey association; necessary Account, billing, security and agreement records are not erased by that choice. GPC and DNT disable journey collection. Refusing optional analytics does not prevent browsing, using the public demo or purchasing. Basic cookieless statistics continue independently as described in the Privacy Policy.

Authentication, security and payment storage serve their stated functions separately from optional journey consent. If we introduce materially different optional processing, we update the notice and obtain consent where required rather than treating continued use as permission.

7. Managing cookies

You can block or delete cookies and localStorage in your browser settings. Blocking necessary cookies may prevent sign-in, checkout, CSRF protection, OAuth/SAML sign-in, admin access, or language/theme preferences from working correctly.

Where a learning page embeds YouTube, its privacy-enhanced player contacts Google/YouTube and may use player-related browser storage and process interaction data under Google's terms. The Analytics preferences control covers Railbase's optional journey analytics and the separate Google measurement choices, not third-party video or payment providers. The privacy-enhanced domain is not a promise of zero third-party processing. See the Privacy Policy and YouTube's embedding guidance.

8. Contact

Questions about cookies or privacy can be sent to support@railbase.app.

9. Mobile and workflow-related storage

Workflow Studio and company Workflows use the authenticated deployment's permitted session and interface state; browser storage does not grant company authority. A supplied Mobile client can hold device-local session/context data and use device permissions for supported notifications, camera or microphone actions. These native mechanisms are not website advertising cookies. The deployment controls notification payloads; Apple/Google delivery and external AI processing are described in the Privacy Policy. This section does not announce a production Mobile Store release or offline execution capability.

Edition and existing records. This edition clarifies the current Railbase offering and the processing described above. It does not retroactively amend accepted Orders, prices, invoices or stored agreement-acceptance evidence. Any change affecting existing contractual rights follows the applicable notice and acceptance process; publication alone is not a new acceptance.