Privacy policy
TransitRadar (transitradar.co.uk) is a live railway and bus data explorer. This page explains what we store and why. The short version: an email address if you ask for an API key or for journey alerts, and otherwise nothing beyond ordinary server logs and a cookieless count of page views.
What we collect
- Email address — when you request an API key, we store the email you give us against that key so we can attribute usage and attach a subscription to it.
- Email address, for journey alerts — if you ask us to email you about a journey you are tracking, we store that address against that journey only. We send you a confirmation link first and nothing is sent until you open it, so an address typed by somebody else never starts receiving mail. Every alert carries an unsubscribe link, and the subscription is deleted within a few days of the journey — we do not keep a mailing list and never use these addresses for anything else.
- Usage metadata — API requests are rate-limited per key; standard server logs (IP address, request path, timestamp) are kept briefly for abuse prevention.
- Page views — we use Cloudflare Web Analytics to count which pages get read and how quickly they load. It sets no cookies, stores nothing in your browser and gives you no identifier, so it cannot recognise you on a later visit or follow you to another site. What reaches us is aggregate: the page, the site you came from, a country, a browser, and load timings. Any tracker blocker stops it, and the site works exactly the same without it.
- Nothing else — no profiling, no attempt to identify individual visitors, no sale of data.
Browsing the site requires no account and no key at all, so for most visitors we hold nothing that identifies them.
Location
The maps have a "find my location" button. If you press it, your browser asks your permission and the position is used in the page to centre the map or to plan a journey from where you are. It is not sent to our servers and it is not stored. Nothing reads your location unless you press the button.
Shared journey links
If you share a live journey, we store that journey and issue a random token for it so that whoever you send the link to can follow it without an account. The link is excluded from search engines and expires after the day of travel, at which point the journey is deleted. Anyone holding the link can view it, which is the purpose of it — treat it as public.
Payments
We do not take payments and there is no paid plan at the moment, so we hold no card or billing data of any kind.
Advertising and cookies
The site shows adverts, which may be served by Google AdSense. Google and its partners use cookies to serve and measure ads; in the UK and EEA you will be asked for consent before any personalised advertising cookie is set, and you can decline. The only cookie-like storage we use ourselves is your API key and your light/dark theme choice, kept in your browser's local storage so they survive a reload.
Data sources
Live rail data is provided by Network Rail Open Data and National Rail Enquiries, bus data by the Department for Transport's Bus Open Data Service, and map data by OpenStreetMap contributors. The data sources page lists every feed in full. Queries you make — station searches, routes, journeys — are processed to answer the request and are not stored beyond ordinary server logs.
Your rights and contact
To have your API key and email removed, or for any privacy question, contact [email protected] or use the contact page.