← Back to Tacit Labs

Introduction and organisational info

We, at Tacit Labs Ltd, are dedicated to serving our customers and contacts to the best of our abilities. Tacit Labs Ltd is registered in England and Wales under company number 17110976, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, and is the data controller for the processing described in this policy. Part of our commitment involves the responsible management of personal information collected through our websites, tacitlabs.co.uk and refundmyrail.co.uk, and any related interactions. Our primary goals in processing this information include:

It is our policy to process personal information with the utmost respect for privacy and security. We adhere to all relevant regulations and guidelines to ensure that the data we handle is protected against unauthorised access, disclosure, alteration, and destruction. Our practices are designed to safeguard the confidentiality and integrity of your personal information, while enabling us to deliver the services you trust us with.

Your privacy is our priority. We are committed to processing your personal information transparently and with your safety in mind. This commitment extends to our collaboration with third-party services that may process personal information on our behalf, such as in the case of delivering the emails you sign up for. Rest assured, all activities are conducted in strict compliance with applicable privacy laws.

Scope and application

Our privacy policy is designed to protect the personal information of all our stakeholders, including website visitors, registered users, and customers. Whether you are just browsing our websites, using our services as a registered user, or engaging with us as a valued customer, we ensure that your personal data is processed with the highest standards of privacy and security. This policy outlines our practices and your rights related to personal information.

This policy covers the pages of tacitlabs.co.uk, including the product pages within it; refundmyrail.co.uk, our product site for RefundMyRail; and the signup service at waitlist.tacitlabs.co.uk that handles every waitlist and newsletter form across our sites. The same policy is published on both sites, because the same things happen on both. Cookies, and the advertising and analytics that depend on your consent, are described in our Cookie Notice.

Data collection and processing

Our commitment to transparency and data protection extends to how we collect and use your personal information. Tacit Labs is a UK software studio building consumer apps, and we gather personal data when you sign up to hear from us through our website or provide information to us directly.

The following list details the types of personal information we may process:

Please note, that we only process information that is essential for delivering our services, complying with legal obligations, or enhancing your user experience. Your privacy is paramount, and we are dedicated to handling your personal information responsibly and in accordance with all applicable laws.

At Tacit Labs Ltd, we believe in using personal information responsibly and ethically. The data we collect serves multiple purposes, all aimed at enhancing the services we offer and ensuring the highest level of satisfaction among our users, customers, and employees. Here are the key ways in which we use the personal information collected:

Your privacy is our priority. We process your personal information transparently and in accordance with your preferences and applicable privacy laws. We are committed to ensuring that your data is used solely for the purposes for which it was collected and in ways that you have authorised.

Our legal grounds

UK data protection law requires a legal basis for each thing we do with personal information. Ours are:

What we do Legal basis Why
Waitlist and newsletter signups, and the emails they bring Your consent You opt in through the form and confirm by email, and you can withdraw at any time using the removal link in every email we send
The advertising tags, and the hashed-email signup reports to Meta, Google, Reddit and TikTok Your consent Nothing loads and nothing is sent unless you accept the Marketing category on the banner
Product analytics (PostHog) Your consent Loads only if you accept the Statistics category on the banner
Bot protection on our forms (Cloudflare Turnstile) Our legitimate interests An unprotected form fills with automated submissions, some of which send confirmation emails to people who never asked for them
Cookie-free site measurement (Cloudflare Web Analytics) Our legitimate interests Understanding and improving our own website; it stores nothing on your device and identifies nobody
Keeping the record of your consent choices Legal obligation We must be able to show that you were asked and what you answered

Cookie-free site measurement

Every page of tacitlabs.co.uk and of refundmyrail.co.uk loads Cloudflare Web Analytics, a privacy-first measurement script operated by Cloudflare, Inc., the same provider that already serves both websites. It tells us in aggregate which pages are visited, roughly where in the world visits come from, and how quickly pages load, so that we can improve them.

That measurement sets no cookies, stores nothing on and reads nothing from your device, does not fingerprint you, and does not follow you to other websites. We receive only aggregate statistics: we never see your IP address or anything else that identifies you. As with any web request, Cloudflare transiently processes your IP address in order to deliver the script, exactly as it already does to serve every page of this site as our host, and we never receive or store it. We cannot stop counting one person on request, because we hold nothing that tells us which visits are yours; if you would rather not be counted, most content blockers block the script (beacon.min.js) without affecting how the site works.

Bot protection on our forms

Our signup forms use Cloudflare Turnstile to distinguish people from automated scripts. To perform that check, Cloudflare transiently processes signals from your browser together with your IP address, which we pass through to Turnstile's verification service on your behalf. Turnstile is a security control rather than a tracking tool: it sets no cross-site tracking cookies, and we never store your IP address or the signals it processes. Without a check like this, a signup form fills with automated submissions, some of which send confirmation emails to people who never asked for them.

The check keeps one item on your device, holding Turnstile's own state for it. It needs no permission from you, because it is part of doing the job you asked the form to do, and it stays until you clear this site's data. It is listed by name in the Necessary table of our Cookie Notice.

Data storage and protection

Data storage

Data protection measures

How long we keep your information

We keep personal information only for as long as the purpose it was collected for requires. The automatic periods below are enforced by our signup service itself rather than by policy alone.

What Kept for
A signup you never confirmed 30 days from submission, then deleted automatically
A confirmed product-waitlist signup Until you remove yourself, or until shortly after the product launches: within 90 days of announcing a launch we delete that product's entire waitlist
A confirmed newsletter subscription Until you unsubscribe
The advertising identifiers stored with a signup 180 days from signup, then cleared automatically; the signup itself continues
The record of your consent For as long as we hold the signup it relates to
Aggregate site measurement Held by Cloudflare under their own retention; it identifies nobody and we keep no copy

Retention for what you accept on the cookie banner, in summary. Every cookie's own lifetime is listed by name in our Cookie Notice:

What Kept for Described in
The four advertising tags' cookies (Meta, Google, Reddit, TikTok) From 90 days up to 2 years, per cookie Cookie Notice, Marketing tables
PostHog session replays 30 days "Product analytics in detail: PostHog", below
PostHog events and browser profiles Up to 7 years "Product analytics in detail: PostHog", below
The cookie recording your banner answer 12 months Cookie Notice, Necessary table
Cookiebot's log of your answer 1 year The processor table below
What the advertising providers hold for themselves after a report arrives Their own policies; we have no access and cannot delete it "Who is responsible for the advertising measurement", below

Data sharing and disclosure

At Tacit Labs Ltd, we are committed to safeguarding your personal information and ensuring it is treated with the utmost respect. This commitment extends to how we handle the sharing and disclosure of your data. Below we outline our practices in this area:

Sharing personal information

Service Provider Purpose(s) Collected personal data type(s)
TikTok (privacy policy) TikTok Information Technologies UK Limited Marketing and advertising; analytics and performance tracking Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; browser information and language; ad click identifiers; pages you visit on this site
Reddit (privacy policy) Reddit, Inc. Marketing and advertising Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; browser information and language; ad click identifiers; pages you visit on this site
PostHog (privacy policy) PostHog Inc. Analytics and performance tracking; user engagement and retention Device ID (cookie identifiers); IP address (used to derive an approximate location, then discarded rather than stored); IP-based approximate location; browser information and language; pages you visit on this site; interaction logs (e.g., clicks, time spent on pages)
Resend (privacy policy) Resend, Inc. Communication efforts Email address
Cookiebot (privacy policy) Usercentrics A/S Operating our consent banner and keeping the record of what you answered Your banner answer; the date and time; your IP address with the final part removed so it no longer identifies your connection; your browser's user-agent string; the page you answered on; a random reference
Google Analytics (privacy policy) Google Ireland Limited Marketing and advertising; analytics and performance tracking Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; browser information and language; operating system and version; pages you visit on this site; interaction logs (e.g., clicks, scrolling, time spent on pages)
Google Ads (privacy policy) Google Ireland Limited Analytics and performance tracking; marketing and advertising Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; ad click identifiers; interaction logs (e.g., clicks, time spent on pages)
Cloudflare (privacy policy) Cloudflare Inc. Authentication and security; customising and adapting user experience Device ID; IP address; operating system and version
Meta (privacy policy) Meta Platforms, Inc.; Meta Platforms Ireland Ltd. for EU and EEA visitors Analytics and performance tracking; marketing and advertising Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; browser information and language; operating system and version; ad click identifiers; pages you visit on this site; interaction logs (e.g., clicks, time spent on pages)

Advertising measurement when you confirm a signup

While Marketing consent is active, the four tags report page views and a few named events from your browser: viewing a product page, submitting or confirming a signup, and clicking a store button. Those signals carry an event name and the app's name only, and never your email address or any other detail you typed. The Google tag alone also collects three standard interactions automatically: how far down a page you scroll; clicks on links that take you away from our site, which tells Google the address of the link you clicked; and, if we ever add a search box, the words you type into it. The Meta, Reddit and TikTok tags collect no equivalent.

If you accepted the Marketing category on our cookie banner and then join a waitlist or the newsletter, one more thing is shared, and it is the only time anything you typed reaches an advertising provider. When you confirm your signup, our server tells Meta, Google, Reddit and TikTok that a confirmation happened, so we can tell which advertising was worth paying for. Each report carries a SHA-256 hash of your email address, a fixed-length scramble of it, together with the identifiers that provider's own cookies placed in your browser when you first submitted the form and any advertising click identifier you arrived with. The provider compares our hash against a hash of the addresses it already holds, which tells it whether you are one of the people it showed our ad to. We send it from our server rather than your browser for a plain reason: you confirm by clicking a link in an email, often on a different device, where those browser identifiers no longer exist.

Three limits on that. The hash is the only form of your address we send. We do not send your IP address or your browser's user-agent string, even though all four providers accept both. And if you refused the banner, or never answered it, none of this happens: we record none of the identifiers a report needs, we make no report, and your signup works exactly the same way.

One thing refusing afterwards cannot reach, and we would rather say so than let you find out: if you accepted, submitted a signup, and have not yet clicked the confirmation link, the details needed to report that one confirmation were recorded when you submitted the form, and confirming later will still be reported. If you would rather it were not, do not click the confirmation link, or use the removal link in the same email, which deletes the signup outright and prevents any report. The next section sets out who is responsible for which part of this measurement.

Who is responsible for the advertising measurement

Responsibility for the four advertising providers splits by stage, and the split decides who you can take a complaint to:

Stage Who is responsible What that means for you
While the data is being collected and sent We and the provider are joint controllers: we chose to place the tags and decide which events they report; the provider supplies the tag and defines what it can send Exercise any of your rights for this stage against either of us, without working out which: privacy@tacitlabs.co.uk, or our European representative named at the top of this policy
Once it has arrived The provider alone, as an independent controller: what it does next is its own decision, taken for its own purposes, and it may combine the data with your account and use it for advertising We have no access to that copy and cannot delete it for you. Exercise your rights through your account with the provider, or by contacting it directly

The essence of the joint arrangement, which we are required to make available to you, is this: the provider is responsible for telling you how it processes the data and for handling your rights once it holds it, and we are responsible for having legal grounds for the collection, which is your consent, and for asking you first. You can hold either of us to our half. Each provider sets its half out in its own terms:

Provider Its privacy policy Where its half of the arrangement is set out
Meta Data Policy Controller Addendum (EEA) and UK Controller Addendum, both within its Business Tools Terms
Google Privacy Policy Ads Data Processing Terms
Reddit Privacy Policy Advertising Agreement and its Advertising Data Processing Agreement
TikTok Privacy Policy Business Products Terms

Google fills two roles, and the split runs between them rather than between Google and the other three. For ordinary Google Analytics measurement, Google acts as our processor rather than a controller, meaning it handles that data only on our instructions. That holds because the setting which would share it into Google's own advertising products is switched off, and we say so here because if we ever switched it on this paragraph would stop being true. The confirmation report above is the ordinary case: joint while the conversion is being reported, and Google's own decision afterwards.

Meta also fills two roles, split along a different line. The hashed email address in the confirmation report is matched by Meta acting as our processor, on our instructions under its Data Processing Terms; the joint-then-independent arrangement above covers the event data. And because we are a UK business, our counterparty for all of this is Meta Platforms, Inc., while the joint controllership for our EU and EEA visitors sits with Meta Platforms Ireland Limited. PostHog is the contrast: our processor for everything it holds, described in the next section, so there is no second party for you to take a complaint to.

Product analytics in detail: PostHog

When you accept the Statistics category, we load one tool. PostHog is operated by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, United States. It is product analytics, measuring how this site is used; it is not advertising and sends nothing to any advertising platform. PostHog is our processor: it holds this data only on our documented instructions, under a data processing agreement that also forbids it from selling or sharing the data and from using it to train AI models, so every right you have about it is exercised against us at privacy@tacitlabs.co.uk.

When active, PostHog receives the address of each page you view, standard browser and device information, and your IP address, which is used to work out an approximate location, never finer than a city or district, and is then discarded rather than stored. It records which pages you view, clicks and interactions with our own page elements, where your pointer moves and where on a page you click, clicks that landed on something which turned out not to be clickable, that a form was submitted but never the values typed into it, page performance, unhandled page errors, and a masked replay of the visit: every value you type and every piece of text on the page is masked, and web addresses inside a replay have their query strings stripped, so a replay shows the shape of a visit and not its content.

PostHog keeps a profile for each browser, so that a returning browser can be told from a new one. It holds the identifiers PostHog set, the properties above, and the approximate location both as it stands now and as it was on your first visit. It holds no name and no email address, and we deliberately never attach either. Session replays are deleted after 30 days, a period we set rather than one PostHog's plan decides. Everything else is held for up to seven years, and you can ask us to delete it sooner at any time. Feature flags let us show part of a page to some visitors and not others without publishing a new version of the site; they read the browser profile described above and collect nothing beyond it. Surveys let us ask you a question on the page; what you answer goes to PostHog attached to that browser profile, and you are free to dismiss the question without answering.

Data processing agreements

When we share your data with third-party service providers, we do so under the protection of Data Processing Agreements (DPAs) that ensure your information is managed in accordance with GDPR and other relevant data protection laws. These agreements mandate that third parties implement adequate technical and organisational measures to ensure the security of your data.

Transparency and control

We believe in transparency and providing you with control over your personal information. You will always be informed about any significant changes to our sharing practices, and where applicable, you will have the option to consent to such changes.

Your trust is important to us, and we strive to ensure that your personal information is disclosed only in accordance with this policy and when there is a justified reason to do so. For any queries or concerns about how we share and disclose personal information, please reach out to us at privacy@tacitlabs.co.uk.

International data transfers

We may transfer your personal information to locations outside of your country of residence, including to countries with different data protection laws than your own. Every such transfer is protected by a recognised safeguard, and this table names each recipient, where it processes, and what protects the transfer. What data each recipient receives is set out in the tables under Data sharing and disclosure.

Recipient Function Location of processing Legal basis Transfer safeguards
Cloudflare, Inc. (USA) Hosts our sites, the signup service and its database; the Turnstile bot check; cookie-free site measurement Data at rest in Cloudflare's Western Europe region Needed to run the service you asked for; our legitimate interests for the security check and measurement EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK International Data Transfer Addendum, in Cloudflare's data processing addendum
Resend, Inc. (USA) Delivers the emails the signup service sends you Resend's EU region Your consent, given at signup EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK Addendum, in Resend's data processing agreement
Usercentrics A/S, Havnegade 39, 1058 Copenhagen (Denmark) Operates the consent banner and holds the consent record Denmark Our legal obligation to evidence your consent None needed: no third-country transfer
PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114 (USA) Product analytics, if you accept Statistics Stored in PostHog's EU region; processing also in the United States and at its subprocessors' locations Your consent, via the banner's Statistics category European Commission standard contractual clauses with the UK Addendum; PostHog also participates in the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework
Meta Platforms, Inc. (USA), our counterparty as a UK business, and Meta Platforms Ireland Ltd. (Ireland) for our EU and EEA visitors Advertising measurement, if you accept Marketing United States; Ireland for EEA matters Your consent, via the banner's Marketing category Meta Platforms, Inc.'s certification under the EU-US Data Privacy Framework and its UK Extension; Meta's UK Data Transfer Addendum, incorporated into its Data Processing Terms
Google Ireland Limited (Ireland) Google Analytics and Google Ads, if you accept Marketing Ireland, with onward transfer to Google LLC (USA) Your consent, via the banner's Marketing category; for ordinary Analytics measurement Google acts as our processor EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK Addendum
Reddit, Inc. (USA), our counterparty as a UK business under its data processing agreement Advertising measurement, if you accept Marketing United States Your consent, via the banner's Marketing category Reddit's compliance with the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, with standard contractual clauses incorporating the UK International Data Transfer Addendum as the fallback, both in Reddit's Advertising Data Processing Agreement
TikTok Information Technologies UK Limited (UK) Advertising measurement, if you accept Marketing United Kingdom, with transfers to other TikTok group companies including in the United States Your consent, via the banner's Marketing category Standard contractual clauses incorporating the UK Addendum, as set out in TikTok's business products terms. TikTok is not certified under the Data Privacy Framework, so there is no second safeguard here

You can ask to see any of these safeguards. Where a transfer rests on standard contractual clauses or the UK International Data Transfer Addendum, you are entitled to a copy of the terms it rests on, and asking is the whole procedure: write to privacy@tacitlabs.co.uk and we will send you the relevant clauses or point you to where that provider publishes them. Certification under the Data Privacy Framework is a matter of public record, and you can look any of these companies up yourself on the Data Privacy Framework list without asking anyone.

User rights and choices

At Tacit Labs Ltd, we recognise and respect your rights regarding your personal information, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. We are committed to ensuring you can exercise your rights effectively. Below is an overview of your rights and how you can exercise them:

Your rights

Exercising your rights

To exercise any of these rights, please contact us at privacy@tacitlabs.co.uk. If you are in the EU or the EEA, you can also exercise any of them through our European representative, named at the top of this policy. We will respond to your request in accordance with applicable data protection laws and within the timeframes stipulated by those laws. Please note, in some cases, we may need to verify your identity as part of the process to ensure the security of your personal information.

We are committed to facilitating the exercise of your rights and to ensuring you have full control over your personal information. If you have any questions or concerns about how your personal information is handled, please do not hesitate to get in touch with us.

Cookies and tracking technologies

At Tacit Labs Ltd, we value your privacy and are committed to being transparent about our use of cookies and other tracking technologies on our websites. These technologies play a crucial role in ensuring the smooth operation of our digital platforms, enhancing your user experience, and providing insights that help us improve.

Understanding cookies and tracking technologies

Cookies are small data files placed on your device that enable us to remember your preferences and collect information about your website usage. Tracking technologies, such as web beacons and pixel tags, help us understand how you interact with our site and which pages you visit.

How we use these technologies

Our consent banner, operated for us by Cookiebot, groups cookies into four categories:

Your choices and consent

Upon your first visit, our website presents you with the cookie consent banner, showing a toggle for each optional category and three choices:

If you never answer the banner, nothing optional loads, exactly as if you had denied.

Changing your mind

You can review or change your choice at any time, one category at a time, and refusing takes effect immediately rather than on your next visit. If you refuse Marketing, we tell each provider already running to stop, delete everything its tags stored on your device, cookies and other storage alike, discard any advertising click reference we were holding, and reload the page so that nothing any of them loaded is still running. If you refuse Statistics, the same happens for PostHog, including PostHog's own record of the refusal. The clearing works by name pattern rather than against a fixed list, so it still holds if a later version of a tag stores more, and it happens whether or not the provider's code is running at the time. Refusing one category leaves the other exactly as it was.

Withdrawing does not affect what a provider lawfully processed while your consent was active. For Meta, Google, Reddit and TikTok, their own copies are theirs: exercise your rights through your account with that provider or by contacting it directly. PostHog is different, because it holds its copy for us: ask us at privacy@tacitlabs.co.uk and we can have it deleted, and anything not deleted sooner expires on the retention schedule above.

Changes to our cookie use

We may update our use of cookies and tracking technologies to improve our services or comply with legal requirements. We will notify you of any significant changes and seek your consent where necessary.

For more detailed information about the cookies we use, their purposes, and how you can manage your preferences, please visit our detailed Cookie Notice.

Should you have any questions or concerns about our use of cookies and tracking technologies, please do not hesitate to contact us at privacy@tacitlabs.co.uk. Your privacy and the integrity of your personal data are of utmost importance to us.

Children's privacy

Our website, waitlists and newsletter are not aimed at children, and we do not knowingly collect personal information from anyone under the age of 13. If you are under 13, please do not sign up or send us personal information.

If we become aware that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe a child under 13 has signed up, contact us at privacy@tacitlabs.co.uk and we will delete their signup.

Direct marketing and communications

At Tacit Labs Ltd, we may use your personal information to send you direct marketing communications about our products, services, promotions, and other relevant information that we believe may be of interest to you. We are committed to ensuring that our direct marketing practices are transparent, lawful, and in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the ePrivacy Directive.

Obtaining consent for direct marketing

Types of direct marketing communications

We may use your personal information to send you direct marketing communications via various channels, including:

Managing your preferences

You have control over the direct marketing communications you receive from us. You can manage your communication preferences by using the unsubscribe link provided in every email we send.

Data breach notification procedures

At Tacit Labs Ltd, we understand the importance of protecting your personal information and take proactive measures to safeguard it. In the event of a data breach that poses a risk to your privacy rights and freedoms, we have established clear procedures for promptly identifying, assessing, and mitigating the impact of the breach. Our data breach notification procedures are designed to comply with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR).

Detection and assessment

Notification obligations

Communication channels

Support and assistance

In the event of a data breach, we are committed to providing affected individuals with the support and assistance they need, including guidance on steps they can take to mitigate the potential risks associated with the breach.

Point of contact: If you have any questions or concerns about a data breach or believe you may have been affected, please contact us immediately at privacy@tacitlabs.co.uk.

Policy updates and changes

At Tacit Labs Ltd, we are committed to keeping you informed about how we handle your personal information and any changes to our privacy practices. We may update this privacy policy from time to time to reflect changes in legal requirements, industry standards, or our business operations. We want to assure you that any updates will be communicated transparently and in accordance with applicable data protection laws.

Notification of changes

Opt-in consent for material changes

For material changes to our privacy policy that require your consent under applicable data protection laws, such as the General Data Protection Regulation (GDPR), we will seek your explicit opt-in consent before implementing the changes. You will have the opportunity to review the updated policy and provide your consent before any changes take effect.

This policy replaced an earlier notice

This policy replaces our Waitlist & Newsletter Privacy Notice with effect from 2026-08-18. That notice covered the signup forms alone and was retired at its version v1.5.0; everything it said is carried into this policy, unchanged in substance. If you signed up before that date, the notice you agreed to was the one in force at the time, and the version recorded against your signup identifies it.

Contact us

If you have any questions or concerns about our privacy policy or any updates to it, please don't hesitate to contact us at privacy@tacitlabs.co.uk. We are here to address any inquiries you may have and to ensure that you have the information you need to feel confident about how your personal information is handled.


Powered by Usercentrics.