
Privacy Policy
Budapest Keleti — photo: Follett, CC BY-SA 3.0, via Wikimedia Commons
Last updated 28 September 2026
Great Train Journeys is a place to read about railway journeys. We do not sell tickets, we do not take payments, and we do not ask you to create an account. The only personal information we hold is what you choose to type into the contact form or the newsletter box.
In short
- We never ask for card numbers, bank details or any payment information.
- We have no login, so there are no passwords to lose.
- The contact form stores your name, email address, chosen topic and message so we can reply.
- The newsletter box stores your email address, and nothing else — and only puts it on the list once you confirm it from an email we send you.
- We do not sell, rent or trade anything you send us.
- Maps, videos and comments come from Google, Facebook, YouTube and Vimeo — and none of them load until you ask for them. There is no cookie banner. That is explained below.
Who is responsible for your data
Great Train Journeys is a personal website run by Fabio Monte, who decides what is collected here and why. Under data-protection law that makes Fabio Monte the controller of this information — the person you can hold to everything on this page.
You can write about your data, or about anything on this page, to contact@greatrailwayjourneys.net.
We are not required to appoint a Data Protection Officer: this is a small editorial site that does not track visitors at scale or handle sensitive categories of data, which are the conditions that make one mandatory. Questions about this policy go to a person, not a department.
The fastest way to reach us about anything here is the contact form.
What we collect, and why
The contact form
When you send us a message we store the four things the form asks for, together with the date and time you sent it:
- Your name
- So we can address a reply to you. A first name is enough.
- Your email address
- So we can reply at all. We do not add it to the newsletter list.
- The topic you chose
- So the message reaches the right person — a copyright complaint is not read like feedback.
- Your message
- Please don't include anything sensitive. We only need enough to answer you.
Why we may hold it: we have a legitimate interest in reading and answering messages sent to us. You choose what to send; if you would rather not give a real name, we will still read the message.
The newsletter
If you enter an email address in the newsletter box in the footer, we store that address so we can send you occasional emails about new journeys and features. We store nothing else — no name, no country, no preferences. Why we hold it: your consent.
Entering the address is not what subscribes you. We send one email to that address with a link in it, and only pressing the button on the page it opens puts you on the list. Until then the address is stored but unused: we do not mail it, and it counts as nobody's consent.
The reason is simple. Typing an address into a box proves that somebody typed it — not that it was you. Anyone can enter a stranger's address, and one typed with a slip of a finger belongs to a real person who never asked us for anything. Asking the inbox itself is the only way to tell the difference.
If nobody confirms, we delete the address within a week. An unconfirmed address is one we have no permission to hold, so there is nothing to justify keeping it any longer than it takes you to find the email. We keep no record that it was ever entered. If a confirmation email reaches you for a signup you did not make, you need do nothing at all — ignoring it is what makes it disappear.
Nothing happens when the link is merely opened, only when you press the button. Mail providers and company security systems routinely visit every link in a message to check it is safe, and a page that acted on arrival would subscribe people on their own mail server's say-so.
Leaving takes one click. Every email we send carries an unsubscribe link at the bottom, and following it brings you to a page with a single button. Pressing it deletes your address — we do not move it to a list of people who have left, so once you have gone there is nothing of yours to hold. You can also ask us and we will do it for you.
Both links — the one that joins and the one that leaves — carry a code that identifies your subscription, which is why they work without asking you to sign in or prove who you are. They are different codes, and neither can do the other's job. Leaving, like joining, waits for you to press the button, so a mail provider checking links for safety cannot unsubscribe you by accident either.
What we never collect
- Card numbers, bank details, or any other payment information — the site takes no money.
- Passwords or account credentials — there is nothing to log in to.
- Passport, identity or date-of-birth details.
- Health information, or any of the other special categories the law protects.
If a page ever asks you for any of the above, it is not us. Please tell us.
Information collected automatically
Server logs
Like every website, ours sits on a server that keeps short-lived technical logs of the requests it serves — the address requested, the time, the response, and the browser's IP address and user agent. These exist to keep the site running and to spot abuse. We do not use them to build a profile of you.
Links to booking and hotel partners
Some journey pages link to operators, ticket sellers and hotel booking sites. Those links go through our own site first (a /go/… address) so that we can count how often a card is useful before sending you on. What that count records is the card you clicked, the time, the page you came from and your browser's user-agent string. It is used in aggregate, to decide which recommendations earn their place. Your IP address is not recorded.
Those individual records last 90 days, which is long enough to look into a broken link or a sudden spike. After that they are added up into a plain daily total per card and the individual rows are deleted, so what remains is a number rather than anything that could describe a reader.
Once you arrive at the partner's site you are on their property and their privacy policy applies, not ours. Some of these links earn us a commission; that never changes what we write.
Content we embed from other companies
Parts of the site are built from services other companies run. Left alone, each of them contacts its company the moment a page opens — which hands over your IP address and the fact that you were on this page, whether or not you ever click anything.
So we do not load them. In place of each one you get a still panel with a button on it, and nothing reaches the company behind it until you press that button. There is no cookie banner on this site, because a banner interrupts everybody on arrival — including the many readers who never open a video at all.
Press the button once and that service stays available for the rest of the site, so you are not asked again on the next journey. These are the four:
- Google Maps — the home page
- The world map is a Google map.
- Facebook — every journey page
- Journey pages carry a Facebook comments box, which runs Facebook's script. Facebook can set cookies through it, and if you are signed in to Facebook it can associate the visit with your account.
- YouTube — journey pages that carry a video
- YouTube belongs to Google. Its player appears on the journey pages that have a video, and only those — if a page has no video, YouTube is never involved.
- Vimeo — journey pages that carry a video
- Where a journey's video is hosted on Vimeo rather than YouTube, Vimeo's player is used instead. Only one of the two ever appears on a given page.
Once you have allowed one, we have no access to whatever that company then collects, and we cannot delete it for you — but you can stop it happening again below.
What you have allowed to load
This is the current setting on this device. Turning something back off applies immediately and stops it loading anywhere on the site from now on.
Cookies and other storage on your device
We set no cookies of our own — no analytics, no advertising, no tracking pixels. We store exactly two things, and both are choices you made: the list above of which embeds you have allowed, and whether you switched on the accessibility view. Both are short notes kept on your own device, neither contains an identifier and neither is ever sent to us. Without them we would have to ask you again on every page, which is the opposite of the point.
Anything else stored on your device comes from an embed you allowed: Facebook, Google Maps, or the YouTube and Vimeo players.
And it is not only cookies. A video player can write a unique identifier into your browser's local storage instead, which does the same job and lasts just as long — the YouTube player does this as soon as the player loads, before you press play, and it does it on the "privacy-enhanced" youtube-nocookie address too. Switching to that address is the fix people usually assume works; it does not, which is why the player waits for you here rather than loading quietly behind a different domain name.
You can clear or block all of it from your browser settings at any time, and nothing on this site depends on it.
How long we keep things
These are not intentions. Deleting on time is done by the site itself, on a schedule, without anybody having to remember — a retention period nothing enforces is just a sentence on a page.
- Contact messages
- Deleted 24 months after you send them, so we can pick up an earlier thread until then. Complaints, including copyright complaints, are kept up to six years as a record of how they were handled. Six years is a limit we set ourselves — long enough to show a complaint was dealt with properly, short enough that the correspondence does not sit here indefinitely.
- Newsletter addresses
- Kept until you unsubscribe or ask us to remove them, and deleted immediately when you do.
- Newsletter signups you never confirmed
- Deleted after 7 days. Until it is confirmed we have no permission to hold the address, so it goes whether or not anyone asks.
- Clicks on partner links
- Individual records for 90 days, then added up into daily totals per card and deleted. The totals are kept, and they are not tied to a name, an email address or an IP address.
- Server logs
- Kept on our own server for up to 30 days, then deleted.
Who we share it with
Nobody, for money, ever. We do not sell, rent, trade or hand over mailing lists. The only parties who touch this information are the suppliers who make the site run — our hosting and database provider, and the service that delivers newsletter emails — and only so far as they need to in order to do that job.
We will also disclose information if a law or a valid court order requires it.
Where your data is held
Contact messages and newsletter addresses are stored in our own database. The embedded services listed above are run by companies based outside Europe, so loading a page that uses them involves an international transfer of your IP address to them under their own terms.
Your rights
If you are in the UK or the European Economic Area, you have the right to:
- ask what we hold about you, and get a copy;
- have anything inaccurate corrected;
- have it deleted;
- ask us to stop using it, or restrict how we use it;
- receive it in a portable form;
- object to our using it on legitimate-interest grounds;
- withdraw consent to the newsletter at any time, without affecting emails already sent.
Ask through the contact form and choose the topic "Other". We will answer within one month. There is no charge. In practice, for most people the whole of what we hold is one contact message and possibly an email address, so "delete everything" is a quick request to honour.
If you are not satisfied with how we have handled it, you can complain to your national data-protection authority. In Portugal this is the CNPD; elsewhere in the EEA, your country's equivalent.
Children
This site is written for adults planning journeys. It is not aimed at children, we do not profile visitors, and nothing here needs an age to work.
The newsletter is the one thing that relies on consent, and the age at which a person can give that consent themselves is set by each country — 13 in Portugal and the United Kingdom, 16 in Germany, Ireland and the Netherlands, 15 in France. Rather than police an age we cannot verify, we simply do not knowingly keep information sent to us by a child. If you are a parent or guardian and believe your child has sent us something, tell us and we will delete it.
Security
The site is served over HTTPS, form submissions are validated before they are stored, and access to the database is limited to the people who run the site. No website can promise perfect security, but there is very little here worth stealing: no passwords, no payment details, no identity documents. That is deliberate.
Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. Substantial changes will be noted on the home page as well.
Getting in touch
Every question about this policy — including requests to see, correct or delete what we hold — goes through the contact form.