Privacy Policy
Last updated: 14 July 2026
This policy explains what personal information PlatformWatch collects, why we collect it, and the choices and rights you have.
PlatformWatch is operated by Platform Watch Limited, a company registered in England and Wales (company number 17338786), whose registered office is at Unit A, 82 James Carter Road, Mildenhall, England, IP28 7DE ("we", "us", "our"). We are the data controller responsible for your personal data.
We are registered with the UK Information Commissioner's Office (ICO), registration number ZC177646.
If you have any questions about this policy or your data, contact us at jett@platformwatch.co.uk.
What we collect
- Account information: your email address (used for sign-in, handled by our authentication provider), the username you choose, and an optional display name and profile photo.
- Reports you submit: a photo (optional for some users), the station or train service, the type of activity (for example, revenue protection, plain-clothes, British Transport Police, or security/rail-safe officers), an optional note, and the time. This includes on-train reports tied to a specific service.
- Your interactions: confirm/dismiss votes, "all clear" markings, content you flag, users you block or follow, stations you save, and trains you choose to be alerted about.
- Private messages: if you exchange direct messages within the app (for example with PlatformWatch staff), we store the message text, any photo a staff member attaches, and the time, so the conversation can be delivered and shown to its participants.
- Approximate location: only if you allow it, to centre the map near you and to check you are close to a station when you vote on a report. We do not track or store a history of your location.
- Notifications: if you turn on alerts, a device notification token so we can send you updates about your saved stations or trains you follow.
- Purchases (VIP): if you buy a VIP subscription, our payment providers process the payment and tell us your subscription status and the identifiers needed to manage it. We do NOT receive or store your full card number.
- Profile statistics: your report count, trust score, rank and leaderboard position (calculated by us from your activity).
- Live train look-ups: when you view live times, the station or service you look up is sent to the relevant rail data provider so we can fetch those times.
- Device verification: to prevent abuse and ban evasion we use an anonymous per-device signal — on iOS, a token from Apple's DeviceCheck anti-fraud service; on Android, your device's app-scoped Android ID (stored only as a one-way hash). We use it solely to stop a device that has been banned from creating new accounts; it does not identify you and is not used to track you across other apps.
- Sign-up security check: when you create an account, the network address (IP) your sign-up comes from is used to prevent abuse — we limit how many accounts can be created from one network (storing only a one-way hash, never the raw address), and the address is checked against an anti-fraud lookup service to detect sign-ups from VPNs, proxies and data-centre networks, which are not allowed. This happens only at sign-up; we do not store your raw IP address.
- Basic technical information needed to operate and secure the service.
What other people can see
PlatformWatch is a community app, so some information is visible to other signed-in users:
- Your username, display name, profile photo, and any staff, VIP or Trusted+ badge.
- Reports you post — the station or train, activity type, time, optional note, and photo — while they are active.
- Your report count, rank, follower and following counts, and your position on the public leaderboard.
Report photos are automatically deleted about 3 hours after posting. On the website, station and report information may be visible to signed-in users; photos are only shown to signed-in users through short-lived links.
Private messages are not public: a conversation is visible only to its two participants. New-message notifications never include the message text. Official staff conversations are marked with a verified staff badge.
How we use your data, and our legal bases
- To provide the app, your account, and any VIP subscription you buy (performance of our contract with you).
- To show crowdsourced station and train activity, ranks and the leaderboard to other passengers (our legitimate interest in running the service).
- To keep the community safe — moderation, content flagging, blocking, preventing abuse, rate-limiting, and enforcing account and device-level bans (our legitimate interest in safety, and compliance with our legal obligations).
- To take payment for VIP and keep records of purchases (performance of our contract, and compliance with our legal and tax obligations).
- To send notifications about stations you save or trains you follow (only with your consent, which you can withdraw any time).
- To centre the map near you, and to confirm you are near a station when voting, using approximate location (only with your consent).
Photos and other people
Report photos are intended only to verify the presence of station or on-train activity. Please do not photograph people’s faces or ID badges, or post content meant to identify or target individuals. To protect everyone’s privacy, report photos are automatically deleted about 3 hours after they are posted, and are only ever shown to signed-in users through short-lived, expiring links.
Payments
VIP is an optional paid subscription. We use established payment providers so that your card details are handled securely and never reach us:
- On iOS, purchases are processed by Apple and managed through RevenueCat, which tells us your subscription status.
- On the website and Android, purchases are processed by Stripe (and, where applicable, Google Play).
- These providers receive the information needed to take payment; we receive your subscription status and the identifiers required to manage it, not your full card number.
Cookies and local storage
We do not use advertising or third-party tracking cookies.
The app and website store a sign-in token on your own device (in app storage or your browser’s local storage) so you stay logged in. On the website, when you sign up we use Cloudflare Turnstile, a privacy-friendly "are you human?" check that helps block bots; it may set a strictly necessary cookie for that purpose.
Who we share it with
We do not sell your personal data. We use a small number of trusted providers ("processors") to run the service:
- Supabase — our database, sign-in and photo storage, hosted in the European Union (Frankfurt, Germany).
- Expo, together with Apple (APNs) and Google (FCM) — to deliver push notifications, if you turn them on.
- Apple and Google — if you use "Sign in with Apple" or "Sign in with Google", the app store you download PlatformWatch from, and (on iOS) Apple’s DeviceCheck anti-fraud service used to recognise and block banned devices.
- RevenueCat and Stripe — to process and manage VIP subscription payments (see "Payments" above).
- Cloudflare — the Turnstile bot check on website sign-up.
- Netlify — hosting for our website.
- ipapi.is — an anti-fraud lookup that receives the network address (IP) of a sign-up attempt, solely to check whether it comes from a VPN, proxy or data-centre network. Used only at sign-up; it receives nothing else about you.
- National Rail Enquiries / Rail Data Marketplace and Transport for London — receive the station or service you look up, so we can return live train times. They do not receive your identity.
- Discord — we operate staff moderation and operational channels on Discord. New reports (including a temporary, expiring link to the photo), and limited operational logs (such as a daily sign-up count and VIP purchase events), are posted there so our team can moderate content and run the service. These channels are staff-only.
- Our own moderators and admins can see and act on content and accounts to keep the community safe; their actions are logged.
Automated decisions
Some safety features work automatically: your trust score and rank are calculated from your activity; a report may be hidden automatically once enough different users flag or dismiss it; and abuse controls (rate limits, account and device bans) may apply automatically. These do not have legal effects on you, but if a decision affects you and you think it is wrong, email us and a person will review it.
Where your data is stored, and international transfers
Your core data is stored in the European Union (Frankfurt, Germany) through Supabase. Some providers — for example push-notification delivery, payments (RevenueCat, Stripe), the bot check (Cloudflare) and our staff Discord — are based in, or process limited data in, the United States or other countries outside the UK and EU. Where data is transferred outside the UK, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or Standard Contractual Clauses.
How long we keep it
- Report photos: deleted automatically about 3 hours after posting.
- Reports: become inactive about 3 hours after posting and are removed from public view.
- Account data (email, username, profile): kept until you delete your account.
- Private messages: kept so the conversation remains available to its participants, and deleted when your account is deleted.
- Purchase and subscription records: kept while your subscription is active and afterwards for as long as we are legally required to keep financial records (generally up to 6 years for UK tax purposes).
- Device verification: an anonymous per-device token or identifier (stored hashed on Android) and any ban flag, kept only as long as needed to prevent abuse and enforce bans.
- Moderation records: kept only as long as needed to keep the community safe and to meet our legal obligations.
Your rights
Under UK data protection law you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, to withdraw consent at any time, and to ask that a decision made automatically is reviewed by a person.
- You can delete your account and all associated data at any time in the app: Profile → Delete account.
- You can contact us about any of these rights at jett@platformwatch.co.uk.
- You also have the right to complain to the ICO (ico.org.uk).
Children
PlatformWatch is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child under 13 has given us personal data, contact us and we will delete it.
How we protect your data
- Data is encrypted in transit.
- Row-level database security rules ensure you can only access the data you are allowed to.
- Report photos are kept in a private store and shared only through short-lived signed links, then deleted automatically.
- We collect the minimum data we need.
Changes to this policy
We may update this policy from time to time. When we do, we’ll post the new version here and update the "Last updated" date above.
Contact
Platform Watch Limited (company number 17338786), Unit A, 82 James Carter Road, Mildenhall, England, IP28 7DE.
For any privacy question or request, email jett@platformwatch.co.uk. You can also complain to the UK Information Commissioner's Office at ico.org.uk.
This document is provided in good faith and is not legal advice.