What they may do · DPDP §6(4)
What RailOne does with your data
RailOne's policy says it collects device, location and usage data, uses fingerprint or face recognition for sign-in, and keeps your data encrypted for at least three years after you delete your account; it says it does not sell data or use its ad ID to target ads.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
RailOne’s own policy says “Your Personal Information may be shared with law enforcement agencies and other Government Departments if the Ministry of Railways has good faith/belief that access, preservation, or disclosure of information is reasonably necessary to:”
Our summary states it does not sell or share personal information with any third party except as mandated by Indian law, and then discloses sharing with law enforcement agencies and other Government Departments in defined circumstances; it also names Firebase Analytics as receiving the device Ad_ID for analytics. The disclosed sharing is legal/governmental and analytics, not commercial or advertiser sharing.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
RailOne’s own policy says “However, the personal information will be retained in encrypted format for the purpose of legal requirements for a minimum of three years period.”
Our summary states that after account deletion personal information is still retained in encrypted form for a minimum of three years for legal requirements, i.e. beyond the point the user asked for removal.
-
Processes your face or other biometrics
Face matching, liveness checks or similar.
What this costs you. You can change a leaked password in a minute. You cannot change your face. A biometric breach is permanent in a way nothing else is.
Show me where they say that
RailOne’s own policy says “We use your biometric to provide you a better user experience and ease of access via fingerprint, pattern recognition or facial recognition with enhanced security.”
Our summary states biometrics — fingerprint, pattern recognition or facial recognition — are used for access and user experience.
What the policy does not mention
These are uses RailOne’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Builds an advertising profile of you
- Follows you onto other websites and apps
- Trains AI models on your content
RailOne is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does RailOne do with my personal data?
According to RailOne's own privacy policy, read on 2026-08-14, it discloses 3 of the six uses we track: shares your data with partners, keeps your records long-term, processes your face or other biometrics.
Can I withdraw my consent from RailOne?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Every use above is one RailOne declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy