eutrain Privacy Policy v1.4
eutrain PRIVACY POLICY
Website, mobile application and other digital services
Controller: SMEA GLOBAL LIMITED
Effective date: 10 August 2026
Last updated: 10 August 2026
Version: 1.4
Privacy contact: service@eutrain.com
eutrain Privacy Policy
Effective date: 10 August 2026 Last updated: 10 August 2026 Version: 1.4
This Privacy Policy explains how SMEA GLOBAL LIMITED ("SMEA", "eutrain", "we", "us" or "our") collects, uses, stores, shares and otherwise processes personal information when you use eutrain.com, our mobile applications, and other digital products, interfaces, channels, booking, ticketing, account and customer-support services that we make available from time to time (together, the "Services").
This Policy also explains the choices and rights available to you. Privacy laws differ by location, so some sections apply only where the relevant law applies to you or to our processing.
1. Who We Are
SMEA GLOBAL LIMITED is the operator of the Services and the controller or data user responsible for the processing described in this Policy, except where another organisation acts as an independent controller.
Legal entity: SMEA GLOBAL LIMITED Registration / Business Registration No.: 78535087 D-U-N-S Number: 773233955 Registered address: Room 22, 11/F, China United Plaza, 1008 Tai Nan West Street, Lai Chi Kok, Kowloon, Hong Kong Privacy contact: service@eutrain.com
2. Scope of This Policy
This Policy applies when you:
-
create or use a eutrain account;
-
search for rail journeys, fares or travel information;
-
book, pay for, change, cancel or request a refund for a ticket;
-
save passenger profiles, railcards, loyalty cards or discount information;
-
use our website, mobile application or other digital product, interface or channel;
-
receive service, disruption, ticketing or account communications;
-
contact us by email, online chat or an AI-enabled customer-support tool;
-
receive marketing from us or interact with our advertising, referral or affiliate links; or
-
otherwise interact with the Services.
This Policy does not govern a railway operator, payment service, digital-wallet provider, app store, platform provider, linked website or other third party when that party processes personal information for its own purposes. Its own privacy policy will apply to that processing.
3. Our Role in Rail Bookings
eutrain is a rail-ticketing platform. We make tickets and related services offered by railway operators available through direct technical connections and through ticketing, distribution and API partners. Depending on the journey, railway operators may include Trenitalia, Italo, Deutsche Bahn (DB), Eurostar, iryo and other operators serving the selected route.
To search, price, book, issue, exchange, cancel or refund a ticket, we transmit the information required by the relevant operator and ticketing partner. The information required varies by operator, route, ticket type, passenger category and applicable law.
For booking fulfilment and travel operations, a railway operator or ticketing partner may act as:
-
our processor, when it handles information only on our documented instructions;
-
a separate independent controller, when it determines its own legal or operational purposes, such as carriage, passenger safety, mandatory recordkeeping, fraud prevention, disruption notices or legal claims; or
-
a joint controller with us in limited circumstances where the purposes and means of processing are jointly determined.
Where another organisation is an independent or joint controller, its own privacy notice may also apply.
4. Personal Information We Collect
The personal information we collect depends on the Service you use, the journey you book, the device and platform you use, and the requirements of the relevant railway operator.
4.1 Account and contact information
An account is required to book through eutrain. We may collect:
-
full name, username and account identifier;
-
email address, telephone number and billing or correspondence address;
-
password, authentication information and security settings;
-
preferred language, currency, country or region;
-
account preferences and communication choices; and
-
saved passenger profiles and saved travel preferences.
We store passwords in protected form and do not have access to a readable copy of your password.
4.2 Passenger and travel-document information
Depending on operator requirements, we may collect information about you and other passengers, including:
-
full legal name and title;
-
date of birth, age or age category;
-
gender, where required by an operator or travel rule;
-
nationality and country of residence;
-
passport, identity-card or other government-issued document type, number, issuing country and expiry date;
-
railcard, loyalty-card, membership-card or discount-card details;
-
accessibility or assistance requirements that you choose to provide;
-
emergency contact information where required; and
-
other information required to issue or validate a ticket.
Government identification details and accessibility information are handled with additional care. We ask for them only where required for the journey, requested service, fraud prevention or legal compliance.
4.3 Search, journey and booking information
We may collect:
-
departure and arrival locations, travel dates, times and routes;
-
search history, viewed journeys, selected fares and booking attempts;
-
booking references, ticket numbers, seat and carriage details;
-
passenger categories and fare or discount eligibility;
-
purchases, exchanges, cancellations, missed or interrupted booking activity;
-
refund requests, chargebacks, complaints and travel claims;
-
fulfilment status, delivery method and ticket-download history;
-
disruption, delay, check-in and after-sales information; and
-
communications relating to a booking or journey.
4.4 Payment and transaction information
Payments may be made using payment cards, Apple Pay, Google Pay, Alipay, WeChat Pay and other methods made available through Airwallex or another licensed payment provider.
We do not store complete payment-card numbers or card security codes. Licensed payment and wallet providers process those details. We may receive and retain:
-
payment status and method;
-
transaction, merchant and payment-provider reference numbers;
-
currency, amount, date and time;
-
limited or masked payment details, such as card brand and last digits;
-
billing address and tax information;
-
fraud, authentication and risk results; and
-
refund and chargeback information.
Payment providers, wallet providers and financial institutions may process personal information as independent controllers under their own privacy notices.
4.5 Customer-support and AI interaction information
When you contact us by email, online chat or an AI-enabled support tool, we may collect:
-
the content of messages and attachments;
-
contact and account details;
-
relevant booking, ticket, passenger, payment-status, refund and journey information;
-
support case notes, outcomes, ratings and escalation history;
-
technical information needed to diagnose a problem; and
-
AI-generated replies, summaries, classifications or suggested actions.
Please do not provide passport details, payment-card information, health information or other sensitive information in a support message unless we ask for it and it is necessary to resolve your request.
4.6 Device, network, usage and approximate-location information
When you use the Services, we and our technology providers may automatically collect:
-
IP address and approximate location derived from it;
-
device type, model, operating system, browser and language;
-
app version, device or advertising identifiers and push-notification token;
-
date, time, duration and sequence of activity;
-
pages, screens, searches, links and features used;
-
referring website, campaign or affiliate identifier;
-
cookie, local-storage, SDK and similar identifiers;
-
diagnostic, crash, performance, security and error logs; and
-
network, login, authentication and fraud signals.
If you choose to enable a location-based feature, such as nearby-station functionality, we may process more precise location with your device permission. You can withdraw device permissions in your device settings.
4.7 Mobile application and other digital-service information
Depending on the platform and permissions you choose, we may collect or receive:
-
OpenID, UnionID or another platform-specific account identifier;
-
nickname, profile image or telephone number where you expressly authorise the platform to provide it;
-
app-installation, device and application-instance identifiers;
-
push-notification preferences and token;
-
files, images or camera input you choose to upload for customer support or verification;
-
platform analytics, digital-service usage and error information; and
-
information required by Apple, Google, another platform provider or the relevant app store to operate the Service.
We request access to camera, photo library, location, notifications or similar device features only when a feature needs it and subject to the permission controls provided by your device or platform.
4.8 Marketing, advertising, referral and affiliate information
We may collect:
-
newsletter subscription and consent records;
-
email delivery, opening and link-interaction information, where permitted;
-
campaign, advertising and conversion identifiers;
-
audience segment, referral-source and affiliate information;
-
advertising preferences and opt-out signals; and
-
inferred interests based on Service activity, where permitted.
4.9 Information obtained from other sources
We may receive personal information from:
-
passengers, account holders, family members or travel organisers booking for another person;
-
railway operators and ticketing, distribution or API partners;
-
payment processors, digital wallets, banks and fraud-prevention providers;
-
Apple, Google and other platform or sign-in providers;
-
customer-support, email, analytics, security and technology providers;
-
advertising, referral and affiliate partners; and
-
public authorities or publicly available sources where lawful and necessary.
4.10 Sensitive and special-category information
Most information used for rail booking is not "special-category data" under the EU GDPR. However, government identifiers, financial information and account credentials are sensitive under some privacy laws. Accessibility requests may reveal health or disability information, which can be special-category data.
We process such information only where necessary and where an appropriate legal condition applies, such as your explicit consent, the provision of a service you requested, protection of legal claims, substantial public interest or another condition permitted by law. We do not use sensitive information to infer characteristics about you for advertising.
5. How We Use Personal Information and Our Legal Bases
Where the EU GDPR, UK GDPR or another law requires a legal basis, we rely on the basis shown below. More than one basis may apply depending on the context.
|
Purpose
|
Examples of processing
|
Main legal basis where required
|
|
Create and secure your account
|
Register, authenticate, save settings and passenger profiles, prevent unauthorised access
|
Performance of a contract; legitimate interests in account security
|
|
Search and provide travel options
|
Process routes, dates, passenger categories, availability and fares
|
Steps at your request before entering a contract; legitimate interests in operating the platform
|
|
Complete and manage bookings
|
Issue tickets, reserve seats, deliver tickets, manage changes, cancellations, refunds and disruptions
|
Performance of a contract; legal obligations
|
|
Process payments and prevent fraud
|
Authenticate payments, receive status, process refunds, detect abuse and chargebacks
|
Performance of a contract; legitimate interests; legal obligations
|
|
Provide customer support
|
Respond to email or chat, retrieve bookings, troubleshoot, manage complaints and claims
|
Performance of a contract; legitimate interests in service quality and dispute management
|
|
Operate AI-enabled support
|
Understand requests, draft replies, summarise cases, route or escalate support
|
Performance of a contract; legitimate interests; consent where required
|
|
Communicate service information
|
Send tickets, receipts, security alerts, disruption notices and account messages
|
Performance of a contract; legal obligations; legitimate interests
|
|
Improve and protect the Services
|
Analytics, testing, debugging, security monitoring and service development
|
Legitimate interests; consent for non-essential tracking where required
|
|
Personalise the experience
|
Remember language and currency, recommend relevant routes or content
|
Legitimate interests; consent where required
|
|
Marketing and advertising
|
Newsletters, promotions, measurement, audiences and targeted advertising
|
Consent; legitimate interests or soft opt-in where permitted
|
|
Meet legal and regulatory duties
|
Tax, accounting, sanctions, law-enforcement requests, consumer protection and recordkeeping
|
Legal obligations; public interest; legitimate interests
|
|
Establish and defend legal claims
|
Handle complaints, chargebacks, disputes, audits and litigation
|
Legitimate interests; legal claims; legal obligations
|
Our legitimate interests include operating a reliable ticketing platform, fulfilling user expectations, improving products, protecting users and the Services, preventing fraud, measuring business performance and communicating about similar services. We balance those interests against your rights and expectations. You may object to processing based on legitimate interests as described in Section 17.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out lawfully before withdrawal.
6. Information About Other Passengers
If you provide information about another passenger, you confirm that:
-
you are authorised to provide it and to make the relevant booking;
-
the information is accurate;
-
you have given the passenger access to this Policy, where reasonably possible; and
-
where required, you have obtained the consent of the passenger or the passenger's parent or guardian.
The account holder may be the main contact for the booking. Other passengers may contact us directly to exercise privacy rights, but we may need information to identify the relevant booking and verify the request.
7. AI-Enabled Customer Support and Automated Processing
Our online support may use artificial intelligence to identify the subject of a request, retrieve relevant account or booking information, generate or translate a response, summarise a conversation, suggest troubleshooting steps, route a case or prepare information for a human support agent.
We may provide the AI support system with the minimum account, booking, ticket, journey, refund or payment-status information reasonably needed to answer your request. We select providers under contractual privacy and security requirements and do not intentionally use customer-support content to train publicly available general-purpose AI models.
AI outputs may be incomplete or incorrect. You may ask for a human agent where available, particularly if your request concerns a denied refund, suspected fraud, account restriction or another issue that materially affects you.
We may use automated tools to identify suspicious activity, payment risk, account abuse or security threats. We do not make decisions producing legal or similarly significant effects solely by automated means unless permitted by law and accompanied by required safeguards. Payment providers and railway operators may conduct their own automated fraud or eligibility checks under their own policies.
8. Cookies, SDKs and Similar Technologies
We use cookies, software development kits (SDKs), pixels, tags, local storage and similar technologies. Depending on the Service and your choices, these may include Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar, Sentry and PostHog.
We use these technologies for the following categories:
-
Strictly necessary: login, account security, booking flow, payment session, fraud prevention, language and privacy choices. These are used without consent where the law permits because the Service cannot function properly without them.
-
Functional: remember choices and provide enhanced features.
-
Analytics and performance: understand use, diagnose errors, measure performance and improve the Services.
-
Advertising and measurement: measure campaigns, attribute referrals, create audiences and show more relevant advertising on third-party services.
Where required by law, non-essential technologies are disabled until you consent. You can accept, reject or adjust them through our cookie banner, "Cookie Settings" or "Your Privacy Choices" control, and through device or app settings where applicable. Withdrawing consent does not affect the lawfulness of earlier processing.
Our Cookie Settings should be consulted for the current vendor list, individual cookies or SDKs, purposes and durations. Blocking some technologies may affect non-essential features but should not prevent access to core booking functions.
Browser "Do Not Track" signals are not interpreted consistently across the industry. Where legally required, we recognise valid opt-out preference signals such as Global Privacy Control (GPC) as a request to opt out of sale, sharing or targeted advertising for the browser or device sending the signal.
9. Marketing Communications
We may send marketing by email, app notification, in-service message or another channel where you have consented or where applicable law permits communications about similar services following a purchase.
You can stop marketing at any time by:
-
using the unsubscribe link in an email;
-
changing account, app or device notification settings;
-
using the relevant app, platform or service settings; or
-
contacting service@eutrain.com.
You will continue to receive non-marketing communications necessary for your account or booking, such as tickets, receipts, service messages, security alerts, changes, disruptions and refund updates.
We retain a limited suppression record after you opt out so that we can respect the request and demonstrate compliance.
10. Targeted Advertising, Sale and Sharing
We do not sell personal information for money. We may allow advertising and measurement partners such as Google, Meta and TikTok to receive online identifiers, device information, approximate location, browsing or interaction data and advertising events. They may use that information to measure advertising or show ads across different services.
Under some U.S. state privacy laws, these disclosures may be considered a "sale", "sharing" or use for "targeted advertising" even though no money is paid for the information. Where those laws apply, you may opt out through "Cookie Settings" or "Your Privacy Choices", by sending a valid GPC signal, or by contacting us. See Section 19 for additional U.S. disclosures.
We do not knowingly sell or share for cross-context behavioural advertising the personal information of children under 16.
11. When We Share Personal Information
We share personal information only as reasonably necessary for the purposes described in this Policy.
11.1 Railway operators
We share required passenger, booking, ticket and contact information with the operator for the selected journey, which may include Trenitalia, Italo, Deutsche Bahn (DB), Eurostar, iryo and other railway operators. Operators use it to check availability, issue and validate tickets, reserve seats, provide travel, manage disruptions and after-sales service, prevent fraud, meet passenger-safety duties and handle claims.
11.2 Ticketing, distribution and API partners
We may use third-party ticketing infrastructure, inventory, distribution and API partners to access fares, complete bookings, issue tickets and manage after-sales requests. We do not list every partner because the partner depends on the selected route and operator. We require partners to protect information according to their role and applicable law.
11.3 Payment and financial-service providers
We share transaction and authentication information with Airwallex and with payment methods or wallet providers such as Apple Pay, Google Pay, Alipay and WeChat Pay, as applicable. Banks, card networks and fraud-prevention providers may also receive information needed to authorise, settle, refund or protect a payment.
11.4 Technology and operational providers
We use providers for hosting, content delivery, security, authentication, email, customer support, AI tools, analytics, error monitoring, data management and communications. They receive only the information reasonably needed for the service they provide and are subject to contractual restrictions where they act as processors.
11.5 Advertising, referral and affiliate partners
Subject to your choices and applicable law, advertising, analytics, referral and affiliate partners may receive device, usage, campaign, conversion and purchase-event information to measure referrals and advertising. We do not provide passport numbers or full payment-card information to advertising partners.
11.6 Corporate group, representatives and professional advisers
We may share information with affiliates, representatives and operational teams that support the Services, and with accountants, auditors, insurers, lawyers and other professional advisers where necessary and subject to confidentiality duties.
11.7 Authorities, safety and legal rights
We may disclose information where we reasonably believe this is necessary to:
-
comply with a law, court order, regulatory request or lawful process;
-
cooperate with railway, transport, customs, immigration, tax, consumer-protection or law-enforcement authorities;
-
protect the safety, rights and property of users, passengers, eutrain or others;
-
investigate fraud, cyber incidents, abuse or violations of our terms; or
-
establish, exercise or defend legal claims.
We assess requests and disclose only information that we reasonably believe is legally required or justified.
11.8 Business transactions
If we are involved in a merger, financing, restructuring, acquisition, sale of assets, insolvency or transfer of all or part of the business, information may be disclosed under appropriate confidentiality and security measures. We will provide notice if required where a new controller will use information in a materially different way.
12. International Data Transfers
eutrain operates internationally. Our principal hosting environment is located in Frankfurt, Germany. However:
-
SMEA is established in Hong Kong;
-
authorised customer-support and technical personnel in Mainland China may access account, booking and support information;
-
railway operators and ticketing partners may be located in the country of travel or another country;
-
payment, cloud, communications, analytics, security and advertising providers may process information in multiple countries; and
-
information may be accessed from Hong Kong, the European Economic Area, Mainland China, the United Kingdom, the United States and other locations where our providers or partners operate.
Privacy protections and government-access rules may differ from those in your country. Where the EU GDPR or UK GDPR applies to a restricted transfer, we use an available lawful transfer mechanism, which may include:
-
an adequacy decision;
-
the European Commission's Standard Contractual Clauses;
-
the United Kingdom International Data Transfer Agreement or UK Addendum;
-
binding corporate rules, approved certification or another legally recognised mechanism; or
-
a permitted exception for a specific situation, such as a transfer necessary to perform your booking, where applicable.
Where appropriate, we conduct transfer-risk assessments and use supplementary contractual, organisational and technical safeguards, including access controls, encryption, minimisation and logging. You may contact us for information about the safeguards relevant to your information, subject to lawful redactions.
13. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including booking fulfilment, customer support, accounting, fraud prevention, legal compliance and the establishment or defence of claims. The following schedule is our general standard; a shorter or longer period may apply if required by law, an operator's documented requirement, an active dispute, a legal hold or a specific risk.
|
Data category
|
General retention period
|
Notes
|
|
Account, profile and saved passengers
|
While the account is active; deletion or de-identification generally within 30 days after account closure
|
Booking, financial, fraud and legal records may be retained separately; residual backup copies may remain for up to 90 days
|
|
Booking, ticket, exchange, cancellation and refund records
|
7 years after the transaction or completion of travel
|
Supports tax, accounting, consumer, audit, dispute and legal-claim requirements
|
|
Passport, identity-document and similar verification details
|
Normally deleted, masked or de-identified within 90 days after travel is completed
|
Retained longer only where an operator, law, fraud review, refund, dispute or claim requires it
|
|
Payment transaction records and masked payment details
|
7 years after the transaction
|
We do not retain full card numbers or card security codes
|
|
Failed payments and abandoned booking records
|
Up to 24 months
|
May be retained longer if linked to fraud, security, chargeback or a completed order
|
|
Customer-support and AI chat records
|
3 years after the case is closed
|
Complaint, refund, chargeback and legal-claim records may be retained for up to 7 years
|
|
Fraud, abuse and security case records
|
Up to 5 years after the case is closed
|
Longer where required for a legal claim, regulatory duty or ongoing threat
|
|
Server, authentication and security logs
|
Generally 12 months
|
Relevant logs may be isolated and retained for up to 24 months or for the duration of an investigation
|
|
Search, browsing and product-analytics data linked to an account or device
|
Generally up to 24 months
|
Aggregated or irreversibly de-identified statistics may be retained longer
|
|
Marketing subscription and engagement data
|
Until opt-out, or generally 24 months after the last meaningful interaction
|
Suppression records and proof of consent may be retained for up to 6 years
|
|
Cookie, SDK and advertising identifiers
|
As shown in Cookie Settings; generally from the session duration up to 24 months
|
Consent may be requested again at intervals required by law
|
|
Privacy requests, consents and legal-compliance records
|
6 years after closure or withdrawal
|
Used to demonstrate compliance and respect continuing preferences
|
|
Backups
|
Rolling deletion, generally within 90 days
|
Backups are protected and used for disaster recovery, not ordinary business access
|
When a retention period expires, we delete, securely destroy, aggregate or irreversibly de-identify the information. De-identified information may be retained and used where it can no longer reasonably identify an individual.
14. Security
We use technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:
-
encryption in transit and, where appropriate, at rest;
-
access controls based on job responsibilities and least privilege;
-
multi-factor authentication and account-security controls;
-
network, application, logging and vulnerability controls;
-
secure development, testing and incident-management practices;
-
contractual confidentiality and data-protection obligations;
-
payment processing by licensed providers rather than storage of complete card data; and
-
staff privacy and security training.
No system is completely secure. You are responsible for protecting your password, using a unique password, maintaining control of your email and devices, and notifying us promptly if you suspect unauthorised account activity.
If a personal-data breach occurs, we will investigate, mitigate harm and notify affected individuals and authorities where required by applicable law.
15. Children's and Minors' Information
The Services are not directed to children under 13, and a child under 13 may not create an account or make a booking unless we have implemented a legally valid parent or guardian process for the relevant location. If we learn that we collected a child's information in violation of applicable law, we will take reasonable steps to delete or otherwise lawfully handle it.
Users aged 13 to 17 may use the Services only where they have legal capacity under the law that applies to them, have any required parent or guardian permission, and comply with the railway operator's rules. Some operators permit minors to book or travel independently; others require an adult booking, consent form, accompaniment or specific passenger documentation.
We may process a minor passenger's information when an authorised adult, guardian, travel organiser or legally capable minor provides it for a permitted booking. We use it only for ticketing, travel, safety, legal and related service purposes. We do not knowingly use a minor's sensitive information for targeted advertising, and we do not knowingly sell or share the personal information of a child under 16 for cross-context behavioural advertising.
Parents or guardians may contact service@eutrain.com about a child's information. We may need to verify identity and authority.
16. Your Choices
Depending on the Service and your location, you can:
-
update account and saved-passenger information;
-
close your account through available account controls or by contacting us;
-
unsubscribe from marketing;
-
change cookie and advertising choices;
-
change mobile-app and device permissions;
-
disable push notifications;
-
ask for human review of an AI-supported customer-service outcome; and
-
exercise the privacy rights described below.
Closing an account does not require us to delete booking, payment, fraud, tax or legal records that must or may lawfully be retained.
17. Privacy Rights
Subject to applicable law and exceptions, you may have the right to:
-
request confirmation of whether we process your personal information;
-
access or obtain a copy of it;
-
correct inaccurate or incomplete information;
-
delete information;
-
restrict or limit processing;
-
object to processing based on legitimate interests or to direct marketing;
-
withdraw consent;
-
receive certain information in a portable format or request its transfer;
-
opt out of sale, sharing, targeted advertising or certain profiling;
-
limit the use or disclosure of sensitive personal information;
-
request information about the categories and recipients of disclosures;
-
obtain human intervention and contest certain automated decisions; and
-
complain to a privacy or data-protection authority.
To exercise a right, email service@eutrain.com with the subject "Privacy Request" and describe your request. Where available, you may also use account or privacy controls in the Services.
We may ask for information reasonably necessary to verify your identity, account or authority. We will not request more verification information than needed. An authorised agent may submit a request where permitted by law, but we may require proof of authority and may verify the request directly with you.
We respond within the period required by applicable law. Some rights are subject to exceptions, including where information is needed to complete a journey, comply with law, protect security or fraud-prevention interests, or establish or defend a legal claim. If we deny or limit a request, we will explain the reason where required and describe any available appeal or complaint route.
18. European Economic Area, United Kingdom and Switzerland
If the EU GDPR, UK GDPR or Swiss data-protection law applies, the controller is SMEA GLOBAL LIMITED. The processing purposes and legal bases are described in Section 5, international-transfer safeguards in Section 12, retention in Section 13 and rights in Section 17.
18.1 EU representative
SMEA has designated the following representative in the European Union for purposes of Article 27 of the EU GDPR. Individuals in the European Economic Area may contact the representative regarding EU GDPR matters, including questions about this Policy or requests to exercise applicable data-protection rights:
LU JIAWEI — EU Representative Via Ruggero Boscovich 14 20124 Milano, Italy Email: luweer@gmail.com
You may also contact SMEA directly at service@eutrain.com.
18.2 United Kingdom representative
At the effective date of this Policy, SMEA has not appointed a United Kingdom representative. UK users may contact us directly at service@eutrain.com. If our activities require appointment of a representative under Article 27 of the UK GDPR, we will make the appointment in writing and publish the representative's contact details in this Policy.
18.3 Supervisory-authority complaints
You may complain to the data-protection authority where you live, work or believe an infringement occurred. EEA authority details are available through the European Data Protection Board. UK users may contact the Information Commissioner's Office. Swiss users may contact the Federal Data Protection and Information Commissioner.
We encourage you to contact us first so that we can try to resolve the concern.
19. U.S. State Privacy Notice
This section supplements the rest of the Policy for residents of U.S. states with applicable comprehensive privacy laws. It applies only to the extent the relevant law applies to SMEA and does not create rights that the law does not provide.
19.1 Categories collected
In the preceding 12 months, we may have collected the following categories:
-
Identifiers: name, email, phone, address, account ID, IP address, device identifiers, platform identifiers, passport or identity-document number.
-
Customer-record information: contact, billing, account, payment-status and government-document information.
-
Protected or demographic characteristics: age, date of birth, gender or nationality where required for a ticket.
-
Commercial information: searches, bookings, tickets, purchases, refunds, cancellations and travel preferences.
-
Internet or electronic activity: browsing, searches, clicks, app activity, interactions with advertisements and logs.
-
Geolocation: approximate location from IP and precise location only where a feature is enabled with permission.
-
Audio, electronic or similar information: customer-support messages, chat content, attachments and AI-generated summaries. We do not ordinarily record telephone calls because telephone support is not a standard channel.
-
Sensitive personal information: account login credentials, government identifiers, precise location if enabled, and payment information processed by licensed providers.
-
Inferences: likely travel interests, language, region, route preferences or advertising segments.
We collect these categories from the sources described in Section 4.9 and use them for the business and commercial purposes described in Section 5.
19.2 Disclosure for business purposes
We may disclose the categories above to railway operators, ticketing and API partners, payment and wallet providers, cloud and security providers, customer-support and AI providers, analytics providers, professional advisers, affiliates and authorities for the purposes described in Section 11.
19.3 Sale, sharing and targeted advertising
We do not sell personal information for money. In the preceding 12 months, subject to consent and opt-out choices, we may have disclosed identifiers, internet or electronic activity, approximate location and related inferences to Google, Meta, TikTok and other advertising or measurement partners. This may be considered sale, sharing or targeted advertising under certain state laws.
You can opt out through "Cookie Settings" or "Your Privacy Choices", by using a legally recognised opt-out preference signal such as GPC, or by contacting us. The opt-out applies to the browser, device or account that can reasonably be associated with the request, as required by law.
We use sensitive personal information only for permitted purposes such as providing requested travel, securing accounts, processing payments, preventing fraud and complying with law. We do not use it to infer characteristics for advertising.
19.4 U.S. rights and appeals
Depending on your state, you may have rights to access, correct, delete or obtain a portable copy of personal information; opt out of sale, sharing, targeted advertising or certain profiling; limit sensitive-data processing; obtain a list of specific third-party recipients where required; and appeal a refusal.
Submit a request or appeal to service@eutrain.com with the subject "U.S. Privacy Request". We will not discriminate against you for exercising a privacy right.
California residents may also use an authorised agent. If California's "Shine the Light" law applies, residents may request information about certain disclosures for third-party direct marketing by contacting us.
20. Canada
Where Canadian privacy law applies, you may request access to and correction of personal information, withdraw consent subject to legal or contractual restrictions, and ask questions about our privacy practices and service providers outside Canada.
We use contractual and other measures intended to provide a comparable level of protection when information is processed outside Canada, but it may be accessible to courts, law enforcement or national-security authorities under foreign law.
You may contact service@eutrain.com. You may also complain to the Office of the Privacy Commissioner of Canada or the relevant provincial privacy commissioner.
21. Hong Kong
SMEA handles personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) where it applies, including the Data Protection Principles relating to purpose and manner of collection, accuracy and retention, use, security, transparency, and access and correction.
You may request access to or correction of your personal data by contacting service@eutrain.com. We may use the forms and charge a reasonable fee permitted by law. We will not use personal data in direct marketing without taking the steps and obtaining any consent required by Hong Kong law. You may opt out of direct marketing at any time without charge.
You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
22. Mainland China
Where the Personal Information Protection Law of the People's Republic of China applies, we process personal information on an appropriate legal basis, provide required notices, and obtain separate or written consent where required, including for certain sensitive personal information, disclosures, public processing or cross-border transfers.
Sensitive personal information may include passport or identity information, financial-account information, precise location and information about minors under 14. We process it only for a specific and necessary purpose and apply heightened protection.
Personal information may be stored in Frankfurt, Germany and accessed or processed in Hong Kong, Mainland China and other locations described in Section 12. Where required, we will implement the applicable cross-border mechanism and obtain separate consent.
You may have rights to know, decide, restrict or refuse processing; access, copy, correct or supplement information; delete information in specified circumstances; withdraw consent; and request an explanation of our processing rules. A parent or guardian may exercise rights concerning a child under 14. Contact service@eutrain.com.
23. Third-Party Services and Links
The Services may link to railway operators, payment providers, digital wallets, app stores, maps, social networks, affiliates or other third parties. We do not control their independent processing, security or content. Review their privacy notices before providing information directly to them.
If you leave eutrain to complete a function on another service, that service may collect information about your visit and transaction independently.
24. Changes to This Policy
We may update this Policy to reflect changes in the Services, technology, partners, legal requirements or privacy practices. We will post the updated version with a revised "Last updated" date.
If a change materially affects your rights or how we use personal information, we will provide additional notice through the Services, by email or by another appropriate method, and seek consent where required. Earlier versions may be made available on request.
25. Contact Us
For privacy questions, rights requests or complaints, contact:
SMEA GLOBAL LIMITED Room 22, 11/F, China United Plaza 1008 Tai Nan West Street Lai Chi Kok, Kowloon, Hong Kong Email: service@eutrain.com
Please include enough information for us to understand your question or locate the relevant account, but do not send complete payment-card details or unnecessary identity documents by ordinary email.