StackLégal

Hosting and network

GDPR Railway

In an indie stack, Railway is used for Hosting for applications and databases. Entity cited: Railway Corporation. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Railway

Yes. Public Data Processing Addendum. Transfers: the DPA defines the Data Privacy Framework and the standard contractual clauses.

Read the DPA

Stated role

For Personal Data, the DPA states that the customer is controller and Railway is processor, or sub-processor if the customer is itself a processor. The Privacy Policy, for the data it covers, presents Railway as controller.

Personal data

Annex A cites profile or contact data and payment data, Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. The Privacy Policy also cites device data and IP address. Data subjects according to the annex: customers and employees of the customer.

Sub-processors of Railway

The DPA points the list to trust.railway.com. The named table was not in the public text of the Trust Center home page on 5 October 2026. Names: not disclosed.

List published by the vendor

Transfers outside the EU

Hosting / location

The DPA states that the primary operations are in the United States and that the transfer to the United States is necessary, with a local-storage option for the Paid Services. The Privacy Policy indicates possible hosting in the United States, the Netherlands, Singapore, or another place offered and chosen for the Paid Services. The documentation publishes four regions: US West Metal (California), US East Metal (Virginia), EU West Metal (Amsterdam), and Southeast Asia Metal (Singapore).

EU–United States Data Privacy Framework

The Trust Center displays the notices “EU-US DPF” and “Swiss-US DPF”. Official search for “Railway” and “Railway Corporation” on the list on 5 October 2026: no participant under that name. Status on the list: not disclosed.

Cookies

The Privacy Policy describes essential, functional, and performance cookies. It does not publish the names. Names: not disclosed.

Typical use, written by StackLégal and not by the vendor: Hosting for applications and databases.

History

Last update: October 5, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 5, 2026.

Frequently asked questions

Is Railway a processor within the meaning of the GDPR?

For Personal Data, the DPA states that the customer is controller and Railway is processor, or sub-processor if the customer is itself a processor. The Privacy Policy, for the data it covers, presents Railway as controller.

What DPA does Railway publish?

Yes. Public Data Processing Addendum. Transfers: the DPA defines the Data Privacy Framework and the standard contractual clauses. https://railway.com/legal/dpa

Which further sub-processors does Railway publish?

The DPA points the list to trust.railway.com. The named table was not in the public text of the Trust Center home page on 5 October 2026. Names: not disclosed. https://trust.railway.com/

Where does Railway state that it processes data, including outside the EU?

The DPA states that the primary operations are in the United States and that the transfer to the United States is necessary, with a local-storage option for the Paid Services. The Privacy Policy indicates possible hosting in the United States, the Netherlands, Singapore, or another place offered and chosen for the Paid Services. The documentation publishes four regions: US West Metal (California), US East Metal (Virginia), EU West Metal (Amsterdam), and Southeast Asia Metal (Singapore).

Is Railway registered under the EU–United States Data Privacy Framework?

The Trust Center displays the notices “EU-US DPF” and “Swiss-US DPF”. Official search for “Railway” and “Railway Corporation” on the list on 5 October 2026: no participant under that name. Status on the list: not disclosed.

Which personal data does Railway mention?

Annex A cites profile or contact data and payment data, Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. The Privacy Policy also cites device data and IP address. Data subjects according to the annex: customers and employees of the customer.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.