BR Fares Purchase Privacy Policy

Home Page | General Privacy Policy | Purchase Terms & Conditions

General Information

This page details the personal data processed as part of the ticket purchase functionality on this site. It should be read alongside the general privacy policy, which covers data processing that applies to all visitors (server logs, analytics, advertisements, and bot detection), and the purchase terms & conditions, which cover the contract of sale itself. This page covers only the additional data processing that occurs when you choose to purchase a ticket. If you have any questions about this privacy policy, you may contact us by e-mail on info@brfares.com. This privacy policy was last updated on 24 June 2026.

Tickets on this site are sold by BR Fares Ltd. Raileasy Ltd takes payment, issues your ticket and handles refunds and after-sales support. Card payments are processed by Braintree (a PayPal company). We collect certain data from you and pass it to these providers in order to complete your purchase.

Data Controller

BR Fares Ltd. is the data controller for the personal data we collect through this site, including the billing details you give us to make a purchase and the details held in your account.

To complete your purchase we pass certain data to Raileasy (see the Data Sharing section below). Raileasy is a separate data controller for taking payment, issuing your ticket, and handling refunds and after-sales, and for the purchase records it keeps afterwards — the transaction record of your booking, your e-tickets, any Ticket on Departure booking reference and any refund history — which it retains for its own rail settlement and other legal obligations.

Braintree is independently a controller in respect of the card data it captures directly.

Billing Details

To process a ticket purchase we need to collect your forename, surname, e-mail address, country, and postcode. Without these details the purchase cannot proceed, as they are required by the payment provider (Braintree) for 3D Secure card verification.

These billing details are used in the following ways:

Your billing details are not stored by us during a guest purchase. They exist only transiently in your browser session and in the communications with Braintree and Raileasy described above.

Payment Details

Card details (card number, expiry date, CVV) are entered directly into a payment form provided by Braintree. These details are captured by Braintree's servers and are never transmitted to or accessible by us. We receive only an anonymised payment token (nonce) which we pass to Raileasy to authorise the payment. We cannot identify your card from this token.

Temporary Payment Storage

During a guest purchase, if you select the Save these card details for future purchases option, your payment details will be held temporarily by Braintree against a randomly generated anonymous identifier. At this stage, the identifier is not linked to any user account or billing details in our systems.

This temporary storage enables you to create an account after your purchase without needing to re-enter your payment details. If you do not wish to create an account, you may click No thanks, delete saved payment details to have the details removed immediately. If you take no action, the details are automatically deleted promptly.

User Accounts

You may optionally create an account by setting a password. If you do so, your billing details (forename, surname, e-mail address, country, and postcode) are stored in our database (hosted in the UK) for the purpose of providing the account facility, including pre-filling billing details for future purchases. Your password is stored as a bcrypt hash; the plaintext password is never stored or logged.

Your account does not hold the records of your past purchases themselves. When you view your Purchase History, or re-download an e-ticket or booking reference, we retrieve those records from Raileasy — which holds them as a separate controller, as described under Data Controller above — and display them to you; we keep no copy of our own.

When you create an account, the anonymous identifier used for temporary payment storage (see above) becomes your permanent account reference, and the payment details held by Braintree become associated with your account. You may view, manage or remove your saved payment methods through the Manage saved payment methods link on the checkout page — this shows limited identifying details (such as the last four digits and expiry date for a card). Full payment details are never accessible to us. When adding a new payment method to an existing account, you may select the Save these card details for future purchases option to save it to your account.

Your e-mail address is used to send essential communications relating to your account, such as notification of contractual changes. We will not send marketing e-mails without your explicit consent. You may update your billing details via the checkout page, and request deletion of your account and all associated data by contacting info@brfares.com.

Session Data

If you create an account and log in, a HTTP-only session cookie is stored in your browser. This cookie contains a randomly-generated identifier and is used solely to maintain your authenticated session. It cannot be read by JavaScript and is transmitted only over HTTPS. Sessions expire after 24 hours, or after 60 days if you select "remember me" at login. You may end your session at any time by logging out.

Quickfares

The site offers an optional Quickfares feature, which lets you save a fare so that you can find and buy it again quickly. A saved Quickfare records only the details of the fare itself — its origin and destination, route, railcard, ticket type and the number of passengers — and never a travel date, payment details, or any other personal information.

For all users, including guests, your saved Quickfares are stored in your browser on the device you are using (in its local storage), so that the feature works without an account. If you create an account and log in, your Quickfares are additionally stored in our database (hosted in the UK), associated with your account, so that the same saved fares are available across your devices; any Quickfares you saved as a guest on a device are added to your account the first time you log in on it. When you log out, the account copy is hidden, and the browser shows only any Quickfares still stored locally on that device. Your Quickfares are used solely to provide this feature; they are never used for advertising, analytics or profiling, and are not shared with any third party.

The copy stored in your browser remains until you remove those Quickfares or clear your browser's storage. The copy stored with your account is kept for as long as the account exists, and is deleted together with the rest of your account data if you delete your account. Storing Quickfares in your browser is necessary to provide a feature you have chosen to use, and records your own selections; storing them with your account forms part of the account facility, which is provided on the basis of your consent.

Lawful Basis for Processing

Processing of your billing details and payment information during a purchase is necessary for the performance of the contract of sale between you and BR Fares Ltd.; performing that contract requires us to share those details with Raileasy so that your payment can be taken and your ticket issued.

The temporary payment storage described above is based on your consent, given by selecting the Save these card details for future purchases option in the payment form. You may withdraw this consent either immediately after the purchase via the No thanks, delete saved payment details option, or later during a checkout through the Manage saved payment methods link.

Processing of your data for account creation and management is based on your consent, given by your explicit action of creating an account. You may withdraw this consent by requesting account deletion (contact info@brfares.com).

Data Sharing

Your personal data is shared with the following third parties, and no others, as part of the purchase process:

Data Retention

For guest purchases where you do not create an account: we do not retain any billing details after the purchase session ends. Any payment details held temporarily by Braintree (see Temporary Payment Storage above) are deleted — either immediately if you use the deletion option provided, or automatically and promptly if you take no action.

Raileasy, as a separate controller, retains the records of your purchase — including the transaction record of your booking, your e-tickets, any Ticket on Departure booking reference and any refund history — for as long as its own rail settlement and other legal obligations require, whether or not you hold a BR Fares account. Braintree retains the card data it captures in accordance with its own policy and legal obligations.

For account holders, the billing details we hold and the payment methods saved at Braintree are retained for as long as the account exists. You may request deletion of your account and all data we hold for it by contacting info@brfares.com; this removes the account data in our systems, but does not affect the purchase records that Raileasy is independently required to keep.

Your Rights

Under the UK General Data Protection Regulation, you may have rights to:

To exercise any of these rights, contact info@brfares.com.

You also have the right to complain to us if you consider we have mishandled your personal data. To do so, contact us by e-mail on info@brfares.com. We will acknowledge your complaint within 30 days and respond as soon as we can. If you are not satisfied with our response, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.

General Privacy Policy | Purchase Terms & Conditions | Home Page