Privacy Policy

Plain language. Last updated 12 September 2026.

Who we are

BookMyRail BD is an independent booking assistant for Bangladesh Railway e-tickets. We are not Bangladesh Railway or Shohoz. We act on your instructions, using your own railway account, to search and book seats faster.

What we collect

  • Your railway login — mobile number and password. Because our service auto-books on your behalf, we keep your password encrypted at rest so we can log in for you shortly before a scheduled sale opens (Bangladesh Railway sells 10 days ahead and railway sessions are short-lived, so a live session isn’t available at that moment otherwise). It is never displayed and never leaves our server in plain text. You can delete the saved password anytime from Account, which turns off advance auto-booking.
  • A short-lived login token so you don't re-enter your password on every action. It is encrypted at rest and expires automatically.
  • Booking details you request — route, date, class, seat preferences, and the bookings we hold for you.
  • Seat alerts — the routes and preferences you ask us to watch.
  • A visitor ID cookie (bmr_vid) plus basic usage events (page visits, searches, outcomes) so we can understand how the service is used and improve it.

How we use it

  • To sign in and perform the searches, holds, and bookings you ask for.
  • To send the confirmation OTP to your own phone via the railway system.
  • To notify you about seat alerts you created.
  • To measure and improve the product (aggregate analytics).

What we never do

  • Your railway password is stored encrypted at rest — never in plain text, never displayed to anyone, and deletable anytime from your account.
  • We never sell, rent, or share your personal data with advertisers.
  • We never touch your money or card — payment goes directly to Bangladesh Railway via bKash.
  • We never post, pay, or book without you confirming.

Cookies

We use a first-party session cookie/token to keep you logged in and a first-touch visitor cookie for privacy-preserving analytics. We do not use third-party advertising cookies.

Data retention & security

Login tokens are encrypted and short-lived. Your saved password is encrypted at rest with a key held separately from the database, is used only to sign in on your behalf, is never returned by any page or written to logs, and every use is recorded in an internal audit trail. Raw usage events auto-expire after 90 days. Data is stored on managed cloud infrastructure. You can delete a seat alert or your saved password anytime, and logging out clears your session.

Your choices

  • Log out at any time to end your session.
  • Delete your saved railway password anytime from Account.
  • Delete any seat alert you created.
  • Contact us to request deletion of your data.

Changes & contact

We may update this policy; material changes will be reflected here with a new date. See also our Terms of Service and Refund & Cancellation Policy.