Privacy Policy

Last updated: 6 October 2026

Who we are and how to contact us

This policy covers the departureboard.io website, iOS app, widgets and associated services. In this policy, “we” means the operator of departureboard.io. For privacy questions, access to your information or an erasure request, email [email protected].

Account and journey information

We use Firebase Authentication to support sign-in with Apple, Google and Microsoft. We receive an account identifier and, where provided, your name, email address, email-verification status and profile picture. Apple may provide a private relay email address. We do not receive your identity provider password. A guest session also has an identifier, even if you do not sign in. We store saved journeys, favourites, journey schedules, tracked trains, sharing links, account preferences and subscription status to provide those features across your devices. Journey searches and tracked trains can reveal places you travel; we do not need access to your device’s GPS location to provide departure boards.

Service activity and technical information

Our service records activity such as opening a journey board, favourites or the Onboard Hub. These records can include your account or guest identifier, journey and station details, time, subscription tier, IP address, device and browser information, referring page and response status. We use them to understand service use, investigate problems and operate the service. Hosting and security systems also process connection and request logs to deliver requests and protect the service. These server records are separate from the optional app analytics described below and are not disabled by the app’s analytics switch.

Optional app analytics and website analytics

Optional Firebase Analytics in the iOS app is on by default. You can enable or disable it in Settings → Privacy → Share optional app analytics. If enabled, it records screen views, interactions, app and device information, an app-instance identifier and approximate region derived from your IP address. These records may be linked to the app installation; we do not describe them as anonymous. Turning the switch off stops future optional app analytics and resets locally held analytics data. It does not erase records already received by Google. App features remain available either way. The website separately uses Google Analytics and browser cookies to measure page views and interactions; the iOS setting does not control website analytics. You can restrict website cookies using your browser settings. We do not use the iOS advertising identifier or use app analytics for advertising personalization.

Notifications, widgets and sharing

When you enable notifications or Live Activities, we process installation identifiers, delivery tokens, device information, notification preferences and the journeys needed to deliver updates through Firebase Messaging and Apple’s push services. You can change notification permissions in your device settings and notification preferences in the app. Marketing notifications require a separate opt-in. The app and its widgets share local account and journey information so widgets can display your boards. If you share a journey, anyone with its sharing link can view the journey information that the link makes available. Only share it with people you intend to give access to.

Subscriptions and payments

Apple processes subscriptions purchased in the iOS app; Stripe processes subscriptions purchased on the website. We process subscription and transaction identifiers, purchase status, prices and renewal information to enable Pro and handle billing. We do not receive your full payment-card details from App Store purchases. Payment providers process payment and transaction information under their own privacy policies. Deleting your departureboard.io account does not cancel an App Store subscription; manage or cancel it in your Apple account’s subscription settings.

Service providers and international processing

We use Google Cloud and Firebase for hosting, authentication, storage, messaging and analytics, Cloudflare for delivery and security, and Apple and Stripe for the services described above. Your selected sign-in provider processes the authentication request. Train-data providers receive the journey or service queries needed to answer your requests. We may disclose information when required by law or necessary to protect the service and its users. We require service providers handling personal information on our behalf to protect it and use it for the services they provide. Providers may process information outside your country, including outside the UK and EEA; applicable provider terms describe their international-transfer safeguards. See Google’s privacy policy, Cloudflare’s privacy policy, Apple’s privacy policy and Stripe’s privacy policy.

Retention and account deletion

We retain account and saved-journey information while providing your account. You can initiate account deletion in Settings → Delete account. This deletes your Firebase sign-in, closes access to the account and stops renewal of subscriptions billed through our website.

Your choices and rights

You can use basic departure searches without a named account, manage saved journeys in the app, turn optional app analytics off and change notification permissions. Depending on the law that applies to you, you may have rights to access, correct, erase or receive a copy of your personal information, or to object to or restrict processing. Contact us using the address above; we may need to verify that a request is yours. Where processing relies on consent, you can withdraw it without affecting processing that happened before withdrawal. You can also raise a concern with your local data-protection authority, including the UK Information Commissioner’s Office.

Changes to this policy

We will update this page when our practices change and show the date of the latest update. If a change requires a new choice or consent, we will ask for it.

Terms of Service