Privacy & usage measurement
The Journey Ledger is first-party measurement of how the publication works: arrivals, active reading, coarse depth, Rail travel, Orange navigation, Fare exposure and boarding stages. It supports aggregate owner analysis.
A signed first-party cookie holds a random session identifier. It expires after 30 minutes, and a later visit starts a new journey. It is not a persistent person identifier. We do not use browser fingerprinting, advertising identifiers or cross-site tracking, and do not sell Journey Ledger analytics.
Journey Ledger does not store names, emails, account profiles, payment details or Orange questions. Account and payment services continue to operate separately. Verified payment milestones are measured server-side without copying those private records into analytics.
Events expire after 90 days and are then excluded from analysis. Expired rows are deleted in bounded batches during subsequent collection requests; physical deletion depends on later collection, rather than a guaranteed scheduled deletion time. Temporary abuse counters expire separately. An hourly keyed hash may be used for security rate limits; raw IP addresses are not stored as analytics identity.
Known self-declared crawlers and securely recognized internal testing are separated. Measurement is incomplete: delivery may fail, automation may be undetected, and a journey is not proof of a human reader. Analytics failure does not prevent reading or boarding.
The owner dashboard shows aggregates, not individual visitor histories. For questions, Contact the Train.
