Transit OS

Privacy

What we hold, and what we do with it.

Written to be read. If anything here is unclear, that is a fault in this page and we would like to hear about it.


On this website

If you send us a message, we store what you typed — your name, email, agency, and note — so that we can reply and remember the conversation. That is the only thing this site collects about you deliberately.

We do not run advertising trackers, third-party analytics scripts, or session recording. There is no cookie banner because there are no tracking cookies to consent to. Our host records ordinary request logs including IP addresses, which are used for rate limiting and abuse prevention and are not used to build a profile of you.

We use a short-lived rate-limiting counter keyed on your IP address to stop automated abuse of the contact form. It expires within the hour.

Industry news

Our news page fetches public RSS feeds from trade publications, stores the headline, link, publication date and a one-line condensation, and links back to the publisher. We do not reproduce articles and we do not track what you click. If you publish one of those feeds and would rather not appear, email us and we will remove you the same day.

In the product

If you become a customer, we hold the operational data you put in — lines, runs, stops, vehicles, crew, maintenance records, incidents, and any rider or contact records you choose to keep. It is stored scoped to your organisation and is not visible to other customers.

We do not sell it, broker it, or use it to train machine-learning models. Where the product uses a language model for a small convenience — condensing a headline, explaining a feed error, drafting a notice you then edit — the text sent is the minimum needed for that job, and the output is a draft that a person approves. It is not retained for training by us.

Our staff can access customer data only to provide support or to investigate a fault, and that access is logged in the same audit trail you can see.

Getting it back, or getting rid of it

  • Export. A complete export in open formats is available to you at any time, on every plan, without asking us.
  • Deletion. Ask and we delete your organisation's data. It leaves live systems immediately and rolls out of backups within thirty days.
  • Correction. You can edit anything you have entered. If something we hold about you is wrong and you cannot reach it, tell us and we will correct it.

Email

Transactional email — password resets, invitations, receipts, security notices — is sent because you or a colleague did something that requires it. Any non-essential mail carries a one-click unsubscribe, and unsubscribing adds you to a suppression list we check before every send.

Sub-processors

The application, its database, its file storage and its email sending all run on Cloudflare. Payment processing, where you enable it, is handled by your payment provider — money moves to your account, not through ours. We will tell customers before adding a sub-processor that can reach customer data.

Breach

If customer data is exposed, we will tell affected customers within 72 hours of confirming it, including what we know, what we do not yet know, and what we are doing. We would rather send an incomplete notification quickly than a tidy one late.

Children

This is software for transit operators. It is not directed at children and we do not knowingly collect information from them.

Changes

If we change this in a way that materially affects customers, we will email customers rather than quietly updating a date at the bottom of a page.

Contact

hello@transit-os.app. A person reads it.


More about who we are →