Privacy Policy

Last Updated: January 26, 2026

Effective Date: January 26, 2026

Summary: We collect only the information necessary to provide our model railroad rental and sales services. We never sell your personal data to third parties. Your payment information is processed securely through PayPal.

1. Introduction

RentaRailroad.com ("we," "us," "our," or the "Company") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website rentarailroad.com (the "Site") and use our model railroad equipment rental and sales services (the "Services").

By accessing or using our Site and Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Site or use our Services.

This Privacy Policy applies to all visitors, users, and others who access or use the Site, including:

  • Browsing visitors who view our catalog
  • Registered users with accounts
  • Customers who make purchases or rentals
  • Forum participants
  • Newsletter subscribers

2. Information We Collect

2.1 Information You Provide Directly

We collect information you voluntarily provide when you:

Category Data Collected Purpose
Account Registration Name, email address, password (encrypted), phone number (optional) Create and manage your account
Profile Information Display name, profile image, shipping address, billing address Personalize your experience, process orders
Payment Verification PayPal email address, PayPal account verification status Process payments securely
Order Information Shipping address, billing address, order details, rental dates Fulfill purchases and rentals
Communications Contact form submissions, support requests, feedback Respond to inquiries, improve services
User-Generated Content Forum posts, topic replies, item reviews, ratings Enable community features
Newsletter Subscription Email address, subscription preferences Send newsletters and updates
Wishlist Items saved to wishlist Save items for future reference
2.2 Information Collected Automatically

When you access our Site, we automatically collect certain information, including:

  • Device Information: Browser type and version, operating system, device type, screen resolution
  • Log Data: IP address, access times, pages viewed, referring URL, exit pages
  • Usage Data: Features used, links clicked, search queries, browsing patterns
  • Location Data: General geographic location based on IP address (city/region level only)
  • Session Information: Session identifiers, shopping cart contents
2.3 Information from Third Parties

We may receive information from third parties, including:

  • PayPal: Payment confirmation, transaction status, payer verification (we do NOT receive your full credit card number)
  • Shipping Carriers: Delivery confirmation, tracking updates
2.4 Sensitive Information

We do NOT collect:

  • Social Security numbers or government-issued ID numbers
  • Full credit card numbers (handled entirely by PayPal)
  • Biometric data
  • Health or medical information
  • Racial or ethnic origin
  • Political opinions or religious beliefs
  • Sexual orientation

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery
  • Process and fulfill your purchases and rental orders
  • Calculate rental periods, fees, and deposits
  • Arrange shipping and delivery
  • Process returns and refunds
  • Manage rental return tracking and late fees
  • Send order confirmations and shipping notifications
3.2 Account Management
  • Create and maintain your user account
  • Authenticate your identity
  • Manage your profile and preferences
  • Enable password recovery
3.3 Customer Support
  • Respond to your inquiries and requests
  • Provide technical support
  • Resolve disputes and troubleshoot issues
  • Communicate about your orders and rentals
3.4 Communication
  • Send transactional emails (order confirmations, shipping updates, rental reminders)
  • Send newsletters and promotional content (with your consent)
  • Notify you of changes to our services or policies
  • Send push notifications (if enabled)
3.5 Improvement and Analytics
  • Analyze usage patterns to improve our Site and Services
  • Understand customer preferences and behavior
  • Develop new features and services
  • Conduct research and analytics
  • Optimize search functionality based on search analytics
3.6 Security and Fraud Prevention
  • Detect and prevent fraudulent transactions
  • Monitor for suspicious activity
  • Protect against unauthorized access
  • Enforce our Terms of Service
3.7 Legal Compliance
  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Establish, exercise, or defend legal claims
  • Maintain records as required by law

5. Information Sharing and Disclosure

We do NOT sell your personal information to third parties.

We may share your information only in the following circumstances:

5.1 Service Providers

We share information with trusted third parties who assist us in operating our business:

  • PayPal: Payment processing (see PayPal Privacy Policy)
  • Shipping Carriers: USPS, UPS, FedEx for order delivery (name, address, phone for delivery purposes)
  • Web Hosting: Our hosting provider stores and serves our website
  • Email Services: Transactional and marketing email delivery

These service providers are contractually obligated to use your information only for the services they provide to us and must maintain appropriate security measures.

5.2 Legal Requirements

We may disclose your information when required by law or in good faith belief that such action is necessary to:

  • Comply with a legal obligation, subpoena, or court order
  • Protect and defend our rights or property
  • Prevent or investigate possible wrongdoing
  • Protect the personal safety of users or the public
  • Protect against legal liability
5.3 Business Transfers

If RentaRailroad.com is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Site of any change in ownership or uses of your information.

5.4 With Your Consent

We may share your information for other purposes with your explicit consent.

5.5 Publicly Visible Information

The following information may be visible to other users:

  • Forum posts and replies (username, post content, date)
  • Item reviews (username, rating, review text, date)
  • Profile display name and profile image (if set)

Note: Your email address, physical address, and phone number are NEVER publicly displayed.

6. Cookies and Tracking Technologies

6.1 What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and improve your experience.

6.2 Types of Cookies We Use
Cookie Type Purpose Duration
Essential Cookies Required for site functionality: login sessions, shopping cart, security tokens (CSRF protection) Session / Up to 30 days
Preference Cookies Remember your settings: display preferences, recently viewed items Up to 1 year
Analytics Cookies Understand how visitors use our site: page views, navigation patterns Up to 2 years
6.3 Other Tracking Technologies
  • Local Storage: Used to store cart contents and user preferences
  • Session Storage: Temporary data during your browsing session
  • Push Notification Tokens: If you enable push notifications
6.4 Managing Cookies

You can control cookies through your browser settings:

  • Chrome: Settings > Privacy and Security > Cookies
  • Firefox: Options > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy & Security > Cookies

Note: Disabling essential cookies may prevent you from using certain features like the shopping cart or user login.

6.5 Do Not Track

Some browsers offer a "Do Not Track" (DNT) feature. We currently do not respond to DNT signals, as there is no industry standard for handling such requests. We do not track users across third-party websites.

7. Data Retention

We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

Data Type Retention Period Reason
Account Information Until account deletion + 30 days Account recovery period
Order/Transaction Records 7 years Tax and legal compliance
Rental Records 7 years after rental completion Dispute resolution, legal compliance
Payment Records 7 years Financial record-keeping requirements
Contact Form Submissions 2 years Customer service history
Forum Posts/Reviews Until deleted by user or moderation Community content
Search Logs (Raw) 90 days Analytics, then aggregated
Activity Logs 1 year Security and audit
Newsletter Preferences Until unsubscribe Email preferences

After the retention period, data is either:

  • Deleted: Permanently removed from our systems
  • Anonymized: Personal identifiers removed, aggregate data retained for analytics

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

8.1 Technical Safeguards
  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS)
  • Encryption at Rest: Sensitive data is encrypted in our database
  • Password Security: Passwords are hashed using industry-standard algorithms (never stored in plain text)
  • CSRF Protection: All forms protected against cross-site request forgery
  • Rate Limiting: Protection against brute force attacks
  • Secure Payment Processing: Payment handled entirely by PayPal's PCI-compliant systems
8.2 Organizational Safeguards
  • Access to personal data limited to authorized personnel only
  • Regular security reviews and updates
  • Secure backup procedures
  • Incident response procedures
8.3 Your Responsibilities

You can help protect your information by:

  • Using a strong, unique password for your account
  • Not sharing your login credentials with others
  • Logging out when using shared devices
  • Keeping your email account secure (used for password recovery)
  • Notifying us immediately if you suspect unauthorized access
8.4 Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours of discovery
  • Provide details about what information was affected
  • Describe the steps we are taking to address the breach
  • Offer guidance on protective measures you can take
  • Report to relevant authorities as required by law

9. Your Rights and Choices

You have the following rights regarding your personal information:

9.1 Access

You can request a copy of the personal information we hold about you. Most of this information is available in your account settings.

9.2 Correction

You can update or correct your information through your account profile. For other corrections, contact us.

9.3 Deletion

You can request deletion of your account and personal information. Note that:

  • Some information must be retained for legal/business purposes (e.g., transaction records)
  • Forum posts may be anonymized rather than deleted (to preserve community discussions)
  • Reviews may be anonymized to maintain product rating integrity
9.4 Data Portability

You can request your data in a machine-readable format (JSON or CSV).

9.5 Marketing Opt-Out

You can opt out of marketing communications:

  • Email: Click "unsubscribe" in any marketing email
  • Push Notifications: Disable in your account settings or browser
  • Newsletter: Unsubscribe link in every newsletter

Note: You cannot opt out of transactional emails (order confirmations, rental reminders) while you have an active account or outstanding rentals.

9.6 Account Closure

You can close your account at any time by contacting us. Upon closure:

  • Your profile will be deactivated
  • You will no longer be able to log in
  • Outstanding rentals must be returned
  • Order history retained as legally required
9.7 Exercising Your Rights

To exercise any of these rights, contact us at:

  • Email: privacy@rentarailroad.com
  • Contact Form: /contact

We will respond to your request within 30 days. We may ask for verification of your identity before processing certain requests.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

10.1 Right to Know

You have the right to request disclosure of:

  • Categories of personal information collected
  • Specific pieces of personal information collected
  • Categories of sources from which information was collected
  • Business purposes for collecting information
  • Categories of third parties with whom information is shared
10.2 Right to Delete

You can request deletion of your personal information, subject to certain exceptions (legal obligations, completing transactions, security, etc.).

10.3 Right to Opt-Out of Sale

We do NOT sell your personal information. Therefore, there is no need to opt out of sales.

10.4 Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights. You will receive the same service and pricing regardless of whether you exercise these rights.

10.5 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.

10.6 Shine the Light

California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

10.7 Metrics (Annual Disclosure)

In the previous calendar year, we received and processed the following CCPA requests:

  • Requests to Know: [To be updated annually]
  • Requests to Delete: [To be updated annually]
  • Requests to Opt-Out: Not applicable (we do not sell data)

11. International Data Transfers

RentaRailroad.com is operated in the United States. If you are accessing our Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States.

By using our Site and Services, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.

For European Union (EU) Users

If you are located in the EU, we process your data in compliance with the General Data Protection Regulation (GDPR). Your rights include:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Rights related to automated decision-making (Article 22)

You also have the right to lodge a complaint with a supervisory authority in your country of residence.

12. Children's Privacy

Our Site and Services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at privacy@rentarailroad.com. We will promptly delete such information from our records.

For users between 13 and 18 years of age, we recommend parental or guardian supervision when using our Services, particularly when making purchases or participating in community features.

13. Third-Party Links and Services

Our Site may contain links to third-party websites, services, or content that are not operated by us. This Privacy Policy does not apply to third-party sites.

Third-party services we integrate with include:

We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices of third parties.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last Updated" date at the top of this page
  • For material changes, we will provide prominent notice (e.g., email notification, site banner)
  • We will obtain consent where required by law

We encourage you to review this Privacy Policy periodically. Your continued use of our Site and Services after changes are posted constitutes your acceptance of the updated Privacy Policy.

Version History
  • January 26, 2026: Initial comprehensive privacy policy (v1.0)

15. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

RentaRailroad.com

Email: privacy@rentarailroad.com

Contact Form: /contact

Response Time: We aim to respond to all privacy inquiries within 30 days.

This Privacy Policy was last reviewed and updated on January 26, 2026. It is designed to comply with applicable privacy laws including the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and General Data Protection Regulation (GDPR) where applicable.

Related Documents: Terms of Service | Contact Us