Railbase

Privacy Policy

Version: 2.1 Effective date: 18 August 2026

This Privacy Policy explains how Silkway Tech LLC, a Wyoming limited liability company ("we", "us"), operator of Railbase and the website at railbase.app (the "Service"), collects, uses, and shares personal data. Mailing address: 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA. Contact: support@railbase.app.

Scope. This policy covers railbase.app, Product commerce and distribution, Account, billing, licensing, support, analytics, and compliance systems we operate. It does not cover the application data inside a Railbase deployment you self-host on your own servers. For a self-hosted deployment, you are normally the controller or operator responsible for your users, tenants, records, files, logs, Products and Components, integrations, cookies, and compliance notices.

1. Data we collect

  • Account data — email address, account memberships, accepted invitations, owner/admin/billing/deployment/member roles, per-company scopes, login/session records, password hashes where configured, security notices, ownership transfers, export events, and closure status.
  • Billing and tax data — processed primarily by Stripe and Stripe Tax. We receive and store Stripe customer/subscription/invoice/credit-note identifiers, billing country, region and address, company legal name, VAT/GST/tax ID and validation status, Product subscription, Product Plan and Component-breakdown state, net price, tax, total, refunds, chargebacks, credit-note adjustments, invoice links, and payment metadata. We do not store full card numbers.
  • Licence, company, Product, and distribution data — registered companies and identifiers, Products and Product Plans purchased, included Components and composition fingerprints, role/quota selections, licence metadata and entitlement provenance, activation and validation requests, deployments and scoped machine-credential registries, node state, versions/downloads, artifact grants, and Account-link or owned-Product installation events from self-hosted Railbase consoles. Portable Account exports deliberately exclude bearer tokens and private authentication material.
  • KYC, KYB, representative, sanctions-screening, manual-review, and appeal data — buyer name, company name, registration number, tax ID, country, screening context, verdict, sanctions-snapshot date/status, matched source and program, jurisdiction-review requirement, match summary, company-identity and match fingerprints, approval basis, evidence summary and references, distinguishing facts, requester/reviewer identity, solo-operator exception, review notes, validity/expiry, revalidation events, and an appeal statement/status/outcome. We use company-verification status to decide Core download and update eligibility and screen at trial, purchase, renewal, subscription reactivation, Basic/Pro/Max plan change, bundle re-download, and periodic active-subscriber/company boundaries. We also keep company (tenant) registration records and review rationale. When optional enhanced KYB/KYC is enabled, Sumsub collects in its hosted workflow the registry records, company documents, ownership and management details, directors, ultimate beneficial owners and representatives, and identity evidence it requires, which may include names, roles, ownership percentages, addresses, dates of birth, identity-document/passport information, images, liveness/biometric results, PEP, sanctions and adverse-media results, aliases and transliterations. railbase.app stores the opaque provider applicant/verification identifiers, company-identity fingerprint, status and decision fields, rejection labels, applicant-safe moderation text, timestamps, and a hash of each authenticated webhook payload. We do not ordinarily store the provider's company-document or identity-document images or full webhook body. Screening, registration, enforcement, and detailed manual-review records are operator-only; the submitting account can see its own appeal state.
  • Restricted-funds case data — where money was received before a sanctions/export hit, we keep the case identifier, payer and affected-company identifiers, product and amount/currency, Stripe customer/subscription/invoice/payment/refund identifiers, screening-match evidence, access-freeze event, internal and legal classification, reporting deadline, Stripe support reference, regulator/filing reference, custody/control reference, accounting status, legal basis/authorization reference, operator decisions, and an append-only case history. These records are operator-only and do not include full card numbers.
  • Agreement-acceptance records — when you accept our Terms, Privacy Policy, EULA, or Product & Suite Subscription Agreement (including the Suite Schedule that applies to the selected Product Plan), we record your email address, which document and exact version/hash you accepted, the context of acceptance, the date and time, and your IP address at that moment. These records exist solely as evidence that the agreement was made. Historical records may refer to Component terms that were separately accepted before legal obligations moved to the Product and Suite level; their exact text remains available in the corresponding Git release history.
  • Support, reviews, and development requests — support messages, Product reviews, ratings, author names, verified-owner status, custom-development requests, budget/timeline fields, specifications, and optional uploaded files you submit to us.
  • Technical and usage data — IP-derived salted hash, country, browser/user-agent, referrer host, pages viewed, download events, selected language, dwell time, scroll depth, CTA clicks, performance signals, JavaScript error metadata, and server logs. We do not store raw IP addresses in our page-view and download analytics tables.
  • Export-control assessment data — transaction/distribution context, registered-company and payer country/region, network-derived country/region and VPN/proxy/Tor/relay/hosting flags where optional network verification is enabled, allow/hold/deny/unavailable decision, reason codes, policy version, and a salted IP hash. The append-only assessment ledger does not store the raw request IP. The network provider necessarily receives that IP to perform the lookup.
  • Cookies and local storage — sign-in/security cookies, language and theme preferences, CSRF state, OAuth/SAML state in self-hosted deployments, and localStorage values used by Railbase-generated frontends. See our Cookie Policy.
  • Communications data — emails we send or receive, including transactional receipts, renewal notices, support acknowledgements, security notices, and delivery status.

Outside an enabled enhanced-verification workflow, we do not intentionally collect special-category or biometric data. The identity provider may process facial/liveness or other identity evidence where configured and lawful. Please do not send us unnecessary sensitive data or identity documents in support messages, reviews, development specifications, or uploaded files; use the provider's hosted verification workflow instead.

2. Self-hosted Railbase deployments

Railbase is self-hosted software. Data stored in your own Railbase instance remains under your control unless you choose to send it to us or to a third-party service. Your deployment may process user accounts, admin accounts, sessions, tenants, API tokens, audit logs, files, webhooks, backups, mailer data, OAuth/SAML/LDAP/WebAuthn/MFA data, Stripe integration data, Product/Component data, and application-specific records.

Control-plane exceptions are deliberate and documented. Paid acquisition and Product Plan changes occur only in the authenticated Account after required company verification. When you register a company, purchase or change a Product Plan, install an owned Product, activate a Component, pair a deployment, check a licence, send a heartbeat, or request an update, Railbase may send the stable Account/project key, selected company identifier and registered legal details, instance/node and version metadata, Product, Product Plan, composition fingerprint, Component entitlement state, and privacy-safe aggregate usage needed for that operation. Those flows do not upload the ordinary documents, records, files, or Component business data held in the Vault. If enhanced KYB/KYC is enabled, its hosted browser workflow sends verification materials directly to Sumsub; it does not read the ordinary contents of your self-hosted Vault.

If you send us database exports, logs, screenshots, support bundles, custom-development specifications, or other materials from your deployment, we process that submitted data to provide support, security review, debugging, development, or contractual services.

3. Translate Product data

The Railbase Translate Standalone Product runs through a technical Component inside your self-hosted Railbase deployment. Uploaded source files, translated results, glossary terms, translation jobs, language settings, and job history are stored in that deployment. Depending on the Component version and configuration, document text may be sent to third-party machine-translation engines such as Google Translate free endpoints, MyMemory, or Lingva instances. OCR may use local operating-system capabilities such as Apple Vision, Windows OCR, or Tesseract.

Do not process confidential, regulated, or highly sensitive documents through external translation engines unless you have confirmed that your configuration, vendor terms, and legal basis are appropriate. Machine translation can be inaccurate and should be reviewed by a qualified human before official use.

4. How we use data

We use personal data to provide and maintain the Service; create and manage Accounts; process payments, Product subscriptions, renewals, Product Plan changes, refunds, tax calculation, invoicing, and accounting; issue and validate Product and Component entitlements; operate authenticated Core and owned-Product distribution; verify and register the companies licences are issued to; fail closed when current screening cannot be completed; block downloads, transactions, Component grants, renewals, or entitlements where a compliance decision requires it; freeze and lawfully dispose of already-received restricted funds; contact Stripe; assess and make required regulatory filings; preserve custody, accounting and legal-decision evidence; keep evidence of agreement acceptance and enforcement; provide support and custom-development intake; moderate reviews; send transactional emails; detect, prevent, and investigate fraud, abuse, security incidents, chargebacks, and sanctions/export risks; comply with legal obligations; improve reliability, security, and Product quality; and understand high-level usage of the website and Product distribution service.

5. Legal bases for EEA/UK users

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract — Account access, downloads, Product purchases, billing, subscriptions, licence issuance, support, and Product/Component delivery, including recording your acceptance of the agreements that form the contract.
  • Legitimate interests — security, fraud prevention, abuse prevention, basic first-party analytics, product improvement, review moderation, support operations, sanctions-risk management, and keeping evidence of agreement acceptance for the defense of legal claims.
  • Legal obligation — tax, accounting, sanctions/export controls, and legally required records.
  • Consent — where required, such as optional marketing or non-essential cookies if we introduce them.

Verification decisions

Our screening and enhanced-verification gates use submitted identity attributes, current compliance data and the provider's review result to classify a company as approved, pending/on hold, requiring resubmission, or rejected. The practical effects may include refusing Core distribution, a Product trial where expressly offered, purchase, renewal, reactivation, Product Plan change or Component grant, or suspending a Product/Component entitlement. Missing, inactive, or stale sanctions data prevents a new transaction-boundary decision but is recorded as unavailability, not as a sanctions match; it does not alone revoke an existing paid-period entitlement. Periodic sanctions enforcement waits for a current snapshot. When a current screen later detects a match, the detecting request or sweep records the evidence and changes the affected server-side distribution/entitlement state; a connected instance receives that state on heartbeat and an offline node is bounded by its current validation lease. The enhanced control is off by default; if we enable it, a missing or non-approved provider decision fails closed and a manual ordinary sanctions approval does not override it. A human sanctions approval requires structured evidence, authorized review and a fresh snapshot, expires within 30 days, and is invalidated by identity or match changes. You may appeal through Account → Companies or contact support@railbase.app to contest a result or correct company identity data. The appeal itself changes no access; a human outcome is recorded separately, subject to legal restrictions on what we may disclose or change.

The always-on export-destination gate separately compares registered-company and payer country/region with the current destination policy. A registered region is required where the policy distinguishes prohibited territories inside a country. Optional IPinfo network verification is off by default. When enabled, unavailable verification fails closed; prohibited network locations, Tor, and open proxies are denied; browser VPN/private relay/hosting signals and country conflicts are held for retry or review. Server-hosting/VPN signals are not by themselves treated as suspicious for normal self-hosted update or bundle requests. These decisions can refuse or hold the same distribution and commercial operations listed above. You may request human review, but we cannot override a legal prohibition.

6. How we share data

We do not sell personal data. We share data with service providers and counterparties that help us operate the Service:

  • Stripe (including Stripe Billing and Stripe Tax) — payments, subscriptions, invoices and credit notes, billing portal, tax calculation and obligation reporting, tax IDs, refunds, disputes, payment-risk services, and support/investigation of a restricted-funds case. Stripe's validation of a tax ID does not necessarily verify that the identifier belongs to the named company.
  • Hosting infrastructure — hosting railbase.app, the licensing/distribution server, databases, backups, and logs.
  • Transactional email provider — sending receipts, license notices, support acknowledgements, security notices, and service emails.
  • GitHub and release infrastructure — source/release synchronization, issue or development workflow, and artifact distribution where applicable.
  • Compliance data sources — sanctions-list data used to screen buyers and active subscribers.
  • IPinfo — only while optional network export verification is enabled, to derive request country/region and VPN, proxy, Tor, relay, or hosting indicators. IPinfo receives the request IP; railbase.app retains the derived assessment and salted IP hash rather than the raw IP in the assessment ledger.
  • Sumsub — only while enhanced KYB/KYC is enabled, to host and perform company, ownership, management, UBO/director/representative, identity, PEP, sanctions, adverse-media, alias and fuzzy/transliteration verification and to return authenticated status decisions. Sumsub receives the account email and registered-company details needed to create and bind the applicant, plus the materials you submit directly in its workflow. Its processing is also governed by its own privacy notice and applicable terms.
  • Third-party translation engines — only when the self-hosted Translate Product/Component or a related customer configuration sends document text to those engines.

We may also disclose data to comply with law, enforce our Terms, prevent fraud or abuse, protect rights, safety, and security, or in connection with a merger, acquisition, financing, reorganization, or sale of assets.

7. International transfers

We are based in the United States and our providers, including Sumsub when enhanced verification is enabled and IPinfo when network export verification is enabled, may process data in the U.S., EEA, UK and other countries in which they or their verification/location sources operate. Where required for EEA/UK data, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses, UK addendum, adequacy decision, or another legally recognized transfer mechanism.

8. Retention

We keep personal data only for the purposes and legal bases described above. Our normal schedule is: active account/profile data for the account life; non-required profile fields deleted or de-identified within 30 days after a verified erasure review; invoice, credit-note, payment, refund, tax, contract and legal-acceptance evidence for 7 years; KYC/KYB/sanctions/export-control decision evidence for the relationship plus 5 years; restricted-funds case and transaction evidence for at least 10 years from the later of the transaction, blocking/rejection, unblocking, or case closure, or longer where an authority, licence, litigation hold, or applicable law requires; security, authentication, operator, licensing and deployment audit events for 24 months; first-party analytics/download events for 13 months; and support or development Submitted Materials for 24 months after case closure. Sumsub and IPinfo retain data they process under their applicable terms, our configuration and legal requirements; a request to us may therefore require coordination with a provider. Encrypted production backups rotate after 30 daily local snapshots and 90 days off site, so a deletion can remain in an encrypted backup until that backup expires.

Closing an account revokes service access immediately but does not itself erase records required for tax, accounting, sanctions/export compliance, security investigations, payment disputes, fraud prevention, legal claims or a litigation hold. A longer mandatory period overrides the normal schedule; once the obligation or hold ends, deletion resumes. A restored backup does not reactivate a closed account: current closure and revocation state must be reconciled before commerce or credentials can resume. Self-hosted Vault data follows your policy, not ours.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. EEA/UK residents have rights under the GDPR/UK GDPR. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing. We do not sell personal data and do not use cross-context behavioral advertising.

An account owner can download a portable JSON account export from Account management. To exercise other rights, contact support@railbase.app. We verify requests and may refuse or limit deletion where retention is required by legal obligation, establishment or defence of claims, security, tax, accounting, sanctions, or fraud-prevention requirements. Account closure and a privacy-erasure request are distinct: closure ends service access immediately; erasure is evaluated against those obligations.

10. Cookies

We use necessary cookies and similar storage for authentication, security, language selection, and preferences. Our first-party analytics are cookieless and do not set tracking identifiers. See our Cookie Policy for details.

11. Security

We use reasonable technical and organizational measures, including encryption in transit, AES-256-GCM envelope encryption for control-plane secrets and signing seeds at rest, access controls, signed artifacts and licence keys, Argon2id password hashing, CSRF protections, security headers, session inactivity expiry, audit logging, backups, and restricted operator access. The envelope master key is kept separately from the encrypted database values. No method is completely secure. For software you self-host, the security of that deployment, Products, Components, storage, backups, and integrations remains your responsibility.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it where required.

13. Changes

We may update this policy. Material changes will be posted here with a new effective date and, where appropriate, notified by email. Continued use after changes take effect constitutes acceptance.

14. Contact

Silkway Tech LLC — 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA · support@railbase.app