Privacy
Last updated: 8 September 2026
This website is a set of static files. It sets no cookie, loads no third party resource, runs no analytics, and has no form that posts anywhere. The fonts are served from this domain. There is nothing to opt out of, which is why there is no banner asking you to.
Who is responsible
The data controller is MP Informatica Srl, Strada di Santa Bona Nuova 33/B, 31100 Treviso, Italy. Bookrail is a product of MP Informatica Srl. Contact: hello@bookrail.dev. The full company details are on the legal notice.
What is processed when you visit this site
One thing: the access log of the web server. Every request writes a line containing your IP address, the user agent your browser sends, the URL requested, the response status and the time. Nothing else is recorded, and nothing is combined with anything.
- Purpose: security and diagnostics. Detecting abuse, and finding out why a page is broken.
- Legal basis: legitimate interest, Article 6(1)(f) GDPR, in keeping the service available and secure.
- Retention: 14 days, then the log rotates and the lines are gone.
- Where: one server in Europe. No copy leaves it, and no processor receives it.
- Recipients: none. There is no analytics provider, no CDN, no tag manager and no advertising network.
If you write to us
Mail sent to hello@bookrail.dev is processed for the purpose of answering it, on the basis of Article 6(1)(b) or 6(1)(f) GDPR depending on whether the exchange is about a contract. It is kept as long as the conversation is useful and then deleted. It is not used for marketing, and there is no mailing list.
When you use the API
This is the part that grows. When you build on the Bookrail API, data about your customers, a name, an email address, a booking, passes through the API and is stored in the project you own. In that relationship you are the controller and Bookrail is the processor: we process that data on your instructions, for the purpose of running your bookings, and for nothing else.
Today the API is in early access, issued by hand and without a signed agreement in place. The terms of service and the data processing agreement that complete this section are being written and will be published here and linked from this page. Until they exist, do not put personal data you cannot afford to lose into a test project.
Your rights
Under Articles 15 to 22 GDPR you may ask for access to your personal data, its correction or erasure, a restriction of processing, portability, and you may object to processing based on legitimate interest. Write to hello@bookrail.dev. In practice, for a visit to this website, the only data that exists is a log line that is deleted within 14 days, and finding it requires the IP address and the approximate time of the visit.
You may also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma.
Changes
If this notice changes, the date at the top changes with it. There is no version of this page that says one thing and does another: what the server does is what is written above.