TXC Toolkit Sign in

Privacy policy

What the TXC Toolkit records about you, and why

Not yet approved for publication. The organisational details below are marked [ ] and still have to be filled in and the whole page signed off by the authority's data protection officer before this tool is used by anyone outside the project team. Everything describing what the software does is accurate as built.

Last updated 02 August 2026

Who is responsible

The TXC Toolkit is operated by [data controller — organisation name and registered address], which is the data controller for the personal data described here.

For anything about this page, or to exercise any of the rights below, contact [data protection contact — email address]. The data protection officer is [DPO name and contact].

What the toolkit is

It's an internal tool for managing bus service data: stop records, timetables and route registrations. It isn't a public service and it has no passenger-facing side. Almost everything in it is operational transport data rather than data about people — the exceptions are set out below.

Your account

Holding an account means we store:

  • your email address, which is also how you sign in;
  • your name, as you or the person who invited you entered it;
  • the organisation you belong to, and whether the account is linked to a bus operator;
  • whether you're an administrator, and whether the account is pending, active or suspended;
  • a hash of your password — scrypt, so the password itself is not stored and cannot be read back out of the database by anyone, including us;
  • when the account was created, when the email address was confirmed, when you last signed in, and who invited you.

Some records you create carry your account as their author — a stop you added is stamped with who added it — so that colleagues can see where a change came from.

Why we hold it, and on what basis

To control who can reach the data, to let colleagues see who changed what, and to send the few emails the tool sends. The intended lawful basis under UK GDPR is [Article 6(1)(e) — public task, to be confirmed by the DPO], this being a tool for carrying out a statutory transport function.

No special category data is collected. There is no profiling and no automated decision-making.

Cookies

One cookie: the session cookie that keeps you signed in. It's strictly necessary for the tool to work, so it doesn't require consent, and it holds only a signed reference to your account.

There is no analytics, no advertising and no tracking of any kind — no Google Analytics, no tag manager, no third-party pixels.

The session reference includes a fingerprint of your password, which is what makes changing your password sign out every browser that was signed in as you.

Other services involved

Using the toolkit causes data to reach these third parties, and no others:

Third-party services and what reaches them
ServiceWhat reaches themWhen
Brevo (transactional email, EU-based) Your email address, your name, and the content of the message Only when the tool emails you: an invite, an address confirmation, or a password reset
unpkg and OpenFreeMap (map library and map tiles) Your IP address and the fact that your browser requested a map, as with any external resource a web page loads Only on the pages that show a map
OpenRouteService (road routing) Stop coordinates only — no personal data, and the request is made by our server, not by your browser When a route map draws its line along roads
Department for Transport Nothing. Data is downloaded from DfT, never sent to it by the tool When stop and locality reference data is refreshed

Nothing is sold, shared for marketing, or transferred outside the UK or EEA. Files you export leave the tool only because you download them and send them yourself.

Server logs

The web server keeps ordinary access logs — IP address, time, and the page requested — and the application records errors when something breaks. These are kept for [retention period for server logs] and used only for keeping the service running and secure.

Data inside the files you import

A TransXChange file is mostly timetable data, but it can also carry an operator's contact details — a telephone number, an email address and a postal address for the registered operator. Where a small operator gives a personal address or a personal mobile number, that is personal data about them, and it's stored here exactly as the file supplied it. It's used only to identify the operator of a service and it isn't published anywhere by this tool.

How long it's kept

  • Your account — for as long as you need access. When you leave, the account should be suspended and then removed on request.
  • Who-changed-what records — the audit log and the author stamped on a record are kept for [retention period], because their whole purpose is to explain a change long after it was made.
  • Bus service data — kept as a record of what was registered; it isn't deleted when an account is.

Your rights

Under UK data protection law you can ask for a copy of your personal data, ask for it to be corrected, ask for it to be deleted, object to how it's used, or ask us to restrict its use. Ask at [data protection contact — email address].

If you're unhappy with the response, you can complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

Changes to this policy

Changes are made on this page and the date at the top is updated. If a change affects what is collected or why, account holders are told directly rather than left to notice.