← RailGuard

Privacy Notice

Last updated 28 September 2026

This notice explains how RailGuard, a trading name of UNICHAT-APP LTD (a UK-registered company), handles personal data when you use RailGuard. UNICHAT-APP LTD is the data controller for the data described here. Where you upload data about your own staff or customers, you are the controller and we process it on your behalf.

Data we collect and why

  • Account data (name, email, password hash, role, workspace) — to create and run your account (contract).
  • Agent and transaction data (spend requests, merchants, agent reasoning, approvals, audit logs) — to provide the Service (contract).
  • Technical data (IP address, device and browser info, request logs, API key usage) — for security, rate limiting and fraud prevention (legitimate interests).
  • Support and sales messages — to respond to you (legitimate interests / contract).
  • Usage data — to improve the product (legitimate interests).

Who we share it with

  • Service providers such as hosting, database, email and AI processing providers, under contract.
  • Paddle, our Merchant of Record, for sales, subscription management, payments, tax and invoicing.
  • Payment rails you connect (e.g. Stripe, Ramp) and Slack/Teams channels you configure.
  • Professional advisers, and authorities where required by law.

International transfers

Some providers process data outside the UK/EEA. Where they do, we rely on adequacy decisions or Standard Contractual Clauses (including the UK Addendum).

Retention

We keep account data while your account is active. Audit logs are kept for your plan's retention period (90 days, 1 year, or as agreed). Data is deleted or anonymised when no longer needed, and within 90 days of account closure unless the law requires longer.

Your rights

Under UK GDPR you can request access, rectification, erasure, restriction, portability, and object to processing, and withdraw consent at any time. We respond within one month. You may complain to the Information Commissioner's Office (ico.org.uk). Contact us via the form on our Pricing page.

Security

We use encryption in transit, hashed API keys, access controls, role-based permissions and append-only audit logs.

Cookies

We only use essential cookies and local storage needed to keep you signed in and remember your workspace. We do not use advertising cookies.