Data privacy policy - Trenes.com

Privacy Policy
Trenes.com | Version: September 18, 2026

1. Controller and contact
The controller responsible for the processing activities described in this policy is Online Travel Solutions, S.L., Tax ID (NIF) B-66144098, with registered address at Calle Filipines, number 1, 08027 Barcelona, Spain, owner of www.trenes.com, hereinafter referred to as Trenes.com.
For privacy-related enquiries and to exercise your rights, you may write to info@trenes.com or contact us by post at the address indicated above, specifying "Data Protection".

2. Scope and source of the data
This policy explains how the data of people who visit the website, use an account, make or manage bookings, travel with tickets purchased through Trenes.com, request information or receive marketing communications are processed.
The data may come from you, from the person making a booking on your behalf, from your representative, or from the operators and providers involved in managing the booking, payment or an incident. Browsing data is obtained through use of the website and, where applicable, through technologies authorised in the cookie settings panel.
When you provide data relating to other people, you must have the necessary authorisation or representation and provide them with this information. Trenes.com remains responsible for its own transparency obligations and will inform data subjects in accordance with Article 14 of the General Data Protection Regulation when the data has not been obtained directly from them.

3. Categories of data
Depending on the functionality and service used, the following categories of data are processed:

  • Identification and contact details: first name, surname, email address, telephone number, address and, where required for the booking, identification document details and supporting documents for discounts.
  • Booking and travel: passengers, routes, dates, times, operator, fare, booking references, tickets, requested services and requests relating to changes, cancellations or claims.
  • Account and communications: data required for registration and access, preferences provided and the content of enquiries and interactions with customer service.
  • Payment and billing: information required to process the transaction, supporting documents, payment references and status, refunds and tax information requested for invoicing.
Technical and consent data: IP address, browser, device, activity logs, online identifiers and privacy choices. Additional analytics and advertising data depend on your preferences and are detailed in the Cookie Policy.
Only the data necessary for each purpose should be provided. Do not send bank passwords, authentication codes or full images of payment cards through customer service channels.
Mandatory fields will be identified in the forms. If you do not provide the information required to issue a ticket, process a payment or handle a request, the relevant action cannot be completed. Optional data and consents will not affect your ability to make a purchase.

4. Purposes and legal bases

4.1. Bookings, tickets and contracted services
We process the data necessary to request availability, manage and issue tickets, process payments, send documentation and operational notices, make changes or cancellations and provide the contracted services. The legal basis is the performance of a contract or the taking of pre-contractual measures at your request, in accordance with Article 6(1)(b) of the GDPR.
Where a passenger is not a party to the contract with Trenes.com, the processing of data strictly necessary to manage a booking made on their behalf is based on the legitimate interest in fulfilling that request and enabling the journey, pursuant to Article 6(1)(f), after assessing that person's rights and reasonable expectations. Legal obligations relating to transport will be fulfilled on the basis of Article 6(1)(c).
Messages concerning tickets, payments, changes or incidents that are necessary for the booking are not considered a subscription to advertising.

4.2. User account
Account data is used to provide the requested access and functionality and to manage the maintenance or closure of the account. The legal basis is the performance of the account service relationship, pursuant to Article 6(1)(b) of the GDPR. Creating an account does not, in itself, authorise the sending of promotional communications.

4.3. Enquiries, incidents and claims
The data necessary to respond to and follow up on the request is used. If the request is related to a purchase or to prior measures requested by you, the legal basis is Article 6(1)(b). For claims, rights and legally required customer service obligations, the legal basis is Article 6(1)(c), in connection with the applicable consumer, transport or data protection legislation.
General non-contractual enquiries are handled on the basis of the legitimate interest in responding to communications voluntarily addressed to Trenes.com, pursuant to Article 6(1)(f).

4.4. Invoicing and legal compliance

The data is used for invoicing, maintaining accounting documentation, complying with tax obligations and responding to valid requests from authorities. The legal basis is compliance with legal obligations, pursuant to Article 6(1)(c), arising, among other things, from applicable tax, accounting, consumer and transport legislation.
The establishment, exercise or defence of legal claims, where not based on a specific legal obligation, is based on the legitimate interest in protecting the rights of Trenes.com and the persons concerned, pursuant to Article 6(1)(f).

4.5. Security and fraud prevention

The data necessary to protect accounts and systems, detect unauthorised access, verify transactions and prevent or manage fraudulent use is processed. The legal basis is the legitimate interest in maintaining security and preventing fraud, pursuant to Article 6(1)(f), using proportionate measures and respecting the rights of data subjects. Measures necessary to comply with legal security obligations are also based on Article 6(1)(c).
A security check does not authorise the collection of excessive documentation or its use for other incompatible purposes.

4.6. Marketing communications

Promotional offers and news by email or equivalent electronic means will be sent with your consent, pursuant to Article 6(1)(a) of the GDPR, requested separately from the purchase or registration.
Where there is a prior contractual relationship and all the requirements of Article 21.2 of Spanish Law 34/2002 are met, communications concerning Trenes.com's own services similar to those previously contracted may be sent on the basis of the legitimate interest in informing customers about those services. In this case, a simple and free means of opting out will be provided both when the data is collected and in each communication. This possibility does not include third-party advertising and does not remove any other applicable legal requirements.
You may withdraw your consent or object to receiving such communications using the unsubscribe mechanism provided in each message or by writing to [info@trenes.com](mailto:info@trenes.com). Unsubscribing will not prevent you from receiving communications that are strictly necessary in relation to your bookings.

4.7. Analytics, personalisation and digital advertising

When you authorise the corresponding purposes, the technologies described in the Cookie Policy will make it possible to analyse use of the website, measure campaigns and display advertising related to interests inferred from browsing activity. Identifiers and interaction data may be used and advertising profiles may be created within the scope described. The legal basis is consent, pursuant to Article 6(1)(a), for processing activities that require it.
Information about the Google, Microsoft and Meta tools that are active, their purposes and the parties involved will be provided in the cookie inventory and in the supplementary information supplied by their providers. Accepting marketing communications does not constitute acceptance of advertising tracking, and vice versa.
You can manage each purpose or withdraw your consent through "Cookie Settings". Refusing analytics or advertising must not prevent you from purchasing the transport service.

4.8. Record of preferences and consents

Privacy choices and the evidence necessary to respect them and demonstrate compliance with applicable obligations are retained. The legal basis is Article 6(1)(c) of the GDPR, in connection with the accountability and consent-management obligations under the GDPR and Spanish Law 34/2002. Technical management is carried out through CookieFirst under the terms of the Cookie Policy.

4.9. Special needs and other specific processing activities

Do not include information concerning health, disability or other special categories of data in free-text fields unless it is necessary and a specific procedure has been provided for this purpose. For assistance requests, use the channel indicated for the relevant service.
If you ask Trenes.com to arrange assistance that requires health or disability data, only the strictly necessary functional information will be processed and communicated to the relevant operator or service provider. Before collecting it, you will be informed of its purpose, recipients and retention period, with the applicable legal basis under Article 6 as specified in section 4.1 and, where appropriate, your explicit consent pursuant to Article 9(2)(a) of the GDPR. Where there is a legal obligation, the relevant legislation and the condition under Article 9(2) authorising the processing will be identified. The data will be deleted once the assistance and related procedures have been completed, except for information that must be retained to comply with legal obligations or handle claims, on the corresponding legal basis. It will not be used for advertising.

5. Recipients and service providers

  • The data necessary to provide the service may be disclosed to the following recipients, depending on the service contracted:
  • Carriers and contracted service providers, in order to issue and manage tickets, provide transport services and resolve incidents. Operators will process the data for which they are responsible in accordance with their own obligations and privacy policies, accessible through the booking information.
  • Payment institutions and payment service providers, in order to collect, authenticate, verify and refund transactions, in accordance with their respective functions and obligations.
  • Insurers and intermediaries, when you request insurance or a service related to it, in accordance with the specific information for the product.
  • Public administrations, authorities and judicial bodies, where there is a legal obligation or a valid request.
Trenes.com uses hosting and infrastructure providers, maintenance providers, communications providers, customer service providers and other support services that may access data in order to provide their services. Where they act on behalf of Trenes.com, they will act as data processors, subject to the contract and safeguards required under Article 28 of the GDPR. Providers that determine their own purposes will be identified as controllers for the corresponding processing activities.
CookieFirst, provided by Digital Data Solutions B.V., based in the Netherlands, is used to manage cookie preferences and acts as a data processor on behalf of Trenes.com. Information about the provider is available at https://cookiefirst.com/legal/privacy-policy/. Other technology and advertising recipients involved will be identified in the inventory in the Cookie Policy and in the information relating to the corresponding service, indicating their legal identity and whether they act as processors, independent controllers or joint controllers. The use of a provider does not authorise the indiscriminate disclosure of data or its use for any purpose.

6. International transfers
The provision of certain services may involve transfers of or access to data from countries outside the European Economic Area. Information on their scope and the applicable safeguards will be provided for the services and recipients involved in each processing activity.
For the CookieFirst service, Digital Data Solutions B.V. states that its databases are hosted within the European Economic Area. This statement does not extend to all Trenes.com providers and does not, in itself, demonstrate the absence of international access. For any transfer outside this area, the recipient, country, purpose and the applicable adequacy decision or safeguard will be identified, including information on how to obtain further details about it.
Where transfers are made, they must be covered by an applicable adequacy decision, appropriate safeguards such as Standard Contractual Clauses and any necessary supplementary measures, or another mechanism permitted under the GDPR. You may request information and a copy of or reference to the applicable safeguards at info@trenes.com.
The location of a server in Europe does not, in itself, exclude the possibility of international access. The existence of an adequacy framework for a country does not mean that every recipient or transaction is covered by it.

7. Retention
Data will be retained for as long as necessary for each purpose, in accordance with the following criteria:

Bookings and services: until completion of the journey and all related procedures, including any outstanding incidents. Thereafter, only the information necessary to comply with record-keeping obligations and applicable liabilities will be retained.
Account: for as long as it remains active and is necessary for the requested functionality. After the account is closed, data that does not need to be retained for another legal reason will be deleted. Bookings that must be archived will not be retained for marketing purposes merely because they must be kept on record.
Enquiries and claims: until they have been resolved and, thereafter, for the period during which liabilities may arise from them.
Tax, accounting and contractual documentation: for the periods established by the legislation requiring each document to be retained. Retention will be limited to the data that must appear in the relevant document and will take into account interruptions to limitation periods and any pending proceedings.
Marketing communications: until you withdraw your consent or object to the processing, or until the purpose or legal basis justifying the communications no longer exists. The minimum suppression information necessary to respect the opt-out and the evidence strictly necessary to address potential liabilities may be retained.
Security logs: until completion of the security checks related to the recorded events and closure of the associated incidents; once that purpose has been fulfilled, they will be effectively deleted or anonymised, unless specific records must be retained to investigate an incident or comply with a legal obligation.
Cookies, identifiers and analytics or advertising data: the duration of each technology will be specified in the inventory. Associated data will be retained for as long as necessary for the measurement or campaign that led to its collection and while a valid legal basis exists; once that purpose has ended, the data will be effectively deleted or anonymised. For each service, the applicable retention period or criteria will be provided and, where an independent controller is involved, the information applicable to its processing activities will be provided. The duration of a cookie on the device does not necessarily correspond to the retention period for data obtained through it.
Evidence of consent: for the duration of the choice and thereafter only for the periods necessary to demonstrate its validity and address applicable liabilities, with restricted access.
Where the legal blocking of data applies, its ordinary use will be prevented and it will be retained solely for availability to the competent authorities during the applicable periods, in accordance with Article 32 of Spanish Organic Law 3/2018. Once those periods have expired, the data will be effectively deleted or anonymised.

8. Rights
In the circumstances provided for by law, you may request access to your data, rectification of inaccurate data, erasure, restriction of processing, data portability and objection to processing. You may also withdraw consent without affecting the lawfulness of processing carried out before its withdrawal.
You may object at any time to processing for direct marketing purposes, including profiling related to such purposes. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; the request will be handled in accordance with Article 21 of the GDPR.
Send your request to info@trenes.com or to the controller's postal address. Identify the right you wish to exercise and provide the information necessary to locate your data. Additional proof of identity will only be requested where there are reasonable doubts, and in a proportionate manner; a copy of your identity document is not generally required.
As a general rule, a response will be provided within one month of receipt. If the complexity or number of requests justifies a legally permitted extension, you will be informed within that first month. Exercising your rights is free of charge, without prejudice to the exceptions provided by law for requests that are manifestly unfounded or excessive.
You may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) through its official channels at www.aepd.es, or with the competent supervisory authority.

9. Profiling and automated decision-making
Authorised advertising processing may involve the creation of interest profiles based on browsing activity, under the terms set out in section 4.7 and the Cookie Policy.
A decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you may only be made in the circumstances permitted under Article 22 of the GDPR. Before such a process is implemented, you will be informed of its existence, legal basis, logic, significance and envisaged consequences. If a transaction is blocked or rejected, you may contact info@trenes.com to request a review and exercise the applicable safeguards.
Where Article 22 of the GDPR applies, its conditions and safeguards will be respected, including human intervention, the possibility of expressing your point of view and contesting the decision in the circumstances provided for by law.

10. Minors and security
Purchases are intended for adults, although a booking may include passengers who are minors. Their data will be used to manage the journey and comply with the corresponding obligations, with appropriate safeguards. Where the processing of minors' data requires consent, the specific rules concerning age and legal representation will apply.
Trenes.com will implement technical and organisational measures appropriate to the risk in order to protect data against unauthorised access, alteration, loss or improper disclosure. Security does not depend exclusively on the user, and the absolute absence of incidents cannot be guaranteed.

11. Changes to this policy
This policy will be updated when the processing activities or applicable obligations change. Relevant changes will be communicated through appropriate means. An update does not, in itself, authorise new incompatible uses of the data or replace any consent that may be required.