Publication draft
Your privacy
How City Travel uses information to help you find a stop, plan a journey and keep up with your lines.
Prepared for the app launch. Highlighted details are awaiting the publisher’s confirmation.
Who looks after your information
City Travel is an independent travel app for London. This notice covers the iPhone app, the service that provides its travel information and alerts, and these support pages.
- Data controller
- Publisher legal name to add
- Contact address
- Publisher contact address to add
- Privacy enquiries
- protonguyemailuk@protonmail.ch
Your choices, at a glance
- You can use the app without creating an account. It does not connect to your Oyster or contactless payment account.
- Location access and background disruption alerts are optional. You can select stops and journey endpoints manually.
- Saved stops and app preferences are kept on your device. Some information is sent to the services that answer your travel requests or deliver notifications.
- Feedback is sent only when you submit it. An email address is optional.
City Travel has no advertising or third-party behavioural analytics SDK. Apple and the hosting providers process information involved in delivering their services, as explained below.
Location and travel requests
Finding your way
If you allow location access, the app receives your location, its accuracy and time, and available direction and speed information from your iPhone. It uses these to find nearby stops, position you on the map and follow an active journey. Location can continue while the screen is locked during a journey you have started. Ending the journey stops that journey's background location use.
The app does not build a stored location-history database. Its current position and journey progress are held during the app session. A saved destination and route preferences can help you plan again after an interruption; this is described under information kept on your iPhone. Nearby stops can also be found around an area you choose, rather than your own position.
Getting results
Travel requests pass through the app's service, hosted by Cloudflare. Nearby stop searches include the chosen latitude, longitude and search radius. Stop searches include the text you enter. Journey planning includes the starting point and destination, selected travel time and route preferences, such as transport modes, walking choices and accessibility options. These details are sent to Transport for London (TfL) to return matching results.
For nearby cycle docks, the chosen coordinates reach the app's service. That service filters a shared TfL dock catalogue; it does not send your chosen centre to TfL for that request. Departure and line-status requests use the relevant stop or line identifiers.
Accessibility options describe the routes you want to see. The app does not ask you to provide a medical diagnosis.
Apple Maps
The iPhone app uses Apple Maps for its map, place search and walking directions. Search text, relevant map area and route endpoints are handled by Apple to return results. If you choose to open directions in Apple Maps, the destination coordinates and available starting point are passed to that app. Apple's handling of this information is described in Apple Maps & Privacy.
Disruption alerts
When you enable background alerts, the app registers an Apple notification token, a random installation identifier and your selected line identifiers with the app's service. It also sends a credential to authenticate changes to that registration; the service stores a hash of that credential.
If you enable alerts for an active journey, the registration includes the journey's line identifiers and an expiry time. It does not include your precise location, starting point, destination or route path. The expiry limits how long those lines are eligible for active-journey alerts; it is not an automatic deletion time for the saved record.
Cloudflare stores the registration, its update times and the information needed to manage delivery. Apple Push Notification service receives the device token and notification content, such as a line name and disruption message. A test notification is sent only when you request one in the app.
You can turn off Background alerts in the app's Notifications settings. The service removes the registration and its queued alerts once the change is confirmed. If the phone is offline, the app keeps the request and retries when you reopen it with a connection. A limited security record remains so an old request cannot restore a cancelled registration.
Information kept on your iPhone
The app saves your favourite stops and their stop details, selected city, journey filters, appearance and accessibility preferences, onboarding state and notification choices on your device. It holds active journey results and unsent feedback drafts in memory while the app is running.
When you start a journey, the app also saves its destination, route preferences and a timestamp on your device so it can offer a fresh plan after an interruption. It does not save a travelled GPS trace for this feature. The offer is eligible for up to 12 hours; that limit does not automatically erase the stored value. Ending or dismissing the journey, resetting the app or starting another journey clears or replaces it. Restoring a suggestion does not silently restart location tracking.
Home Screen widgets use a shared on-device snapshot of the last nearby or selected area's stops, departures, line status and selected alert lines. The widget snapshot does not contain precise coordinates. Widgets can request updated departures for those stops and line status from the app's service when iOS permits a refresh.
Live Activities show journey details such as the destination, current leg, next instruction and arrival estimate on the Lock Screen or Dynamic Island. Updates are supplied locally by the app; they do not use a separate remote Live Activity push service in this version. Remember that this information may be visible to someone looking at your screen.
The notification identifier and credential are kept in your iPhone's Keychain and can survive an app reinstall. When the app reopens without alert preferences, it attempts to retire an earlier registration. Reinstalling alone is not a confirmed server deletion.
Siri shortcuts and spoken directions
On supported iPhones, City Travel's App Shortcuts can open journey planning, retrieve departures for a saved stop and check a line's service status. The saved-stop catalogue used by these shortcuts is held locally on your device. A live shortcut sends the stop or line identifier to the app's travel service to answer the request.
Apple operates Siri and handles voice interactions according to your iPhone's Siri settings and Siri & Dictation privacy information. City Travel does not receive a recording of your voice from these shortcuts.
Optional spoken walking instructions use Apple's speech synthesiser to read route instructions aloud. This is audio output: the app does not record your microphone. Guidance can play while the phone is locked during an active walk. You can mute it in the active journey or end the journey.
Feedback and support
If you send feedback in the app, the service receives your chosen feedback type, title and message, city, app version and platform, and an optional reply email address. It records a random submission reference, receipt time and a hash of the submitted fields to recognise retries.
The form does not automatically attach device identifiers, location coordinates, screenshots or diagnostic logs. Anything you type into the message is included, so avoid adding information that is not needed to explain the issue.
Feedback is stored in a private Cloudflare database and is available through authorised administration access. There is no public feedback feed. The service acknowledges receipt in the app; it does not automatically send an email response. If you contact the support address directly, the message and correspondence will also need to be handled to answer your enquiry.
Services that handle information
- Cloudflare
- Hosts the app's travel service and database for feedback and notification registrations. Requests pass through its network. The service uses the connecting IP address for rate limiting to reduce abuse. It does not write that IP address into the feedback or notification records.
- Transport for London
- Receives relevant search and journey details through the app's service to provide transport results. The app's service makes these requests using its own connection; it does not deliberately forward your device IP address to TfL.
- Apple
- Provides iPhone location services, Maps, notification delivery and the system features used by widgets and Live Activities. Apple also operates App Store distribution and its own platform services.
The app's service is configured without application request tracing and does not deliberately log search text, coordinates, feedback bodies or notification credentials. This does not mean that Cloudflare has no network, security or operational records.
Read the providers' own information: Cloudflare privacy policy, TfL privacy and cookies and Apple privacy policy.
Why information is used
The purposes of processing are set out below. The legal bases for the final publication will be completed by the publisher against the way the released app and its services operate.
- Return the travel results you request
- Confirm the lawful basis for requested travel information
- Provide optional location features
- Confirm the lawful basis for optional location features
- Deliver the alerts you choose
- Confirm the lawful basis for optional notifications
- Handle feedback and support enquiries
- Confirm the lawful basis for handling feedback and support
- Protect the service against misuse
- Confirm the lawful basis and interests for preventing abuse
Your iPhone's permission controls let you decide whether the app can access location and display notifications. Those controls are separate from identifying the legal basis for processing personal information.
How long information is kept
Travel information
The app's service temporarily caches travel responses. Nearby-stop and search results can be reused for up to five minutes, and journey results for no more than 30 seconds. Cache keys and results can include the coordinates, search text or journey details used for the request. These cache lifetimes do not describe a hosting provider's logs or backups.
Feedback and correspondence
The current feedback service has no automatic deletion schedule. Add the feedback and support retention period or deletion criteria.
Notification records
Active registrations remain until they are updated or successfully cancelled. A token rejected by Apple is marked inactive; that does not itself delete the saved registration. Add the retention period or deletion criteria for inactive registrations.
After a confirmed cancellation, the remaining security record contains the installation identifier, credential hash, revision number and cancellation time. There is no automatic deletion schedule for that record in the current service. Add the retention period or deletion criteria for notification security records.
Queued disruption messages expire after 30 minutes and are removed by delivery processing when it runs, or after successful delivery or cancellation. An expiry prevents delivery after that time; it is not a promise that every stored copy is erased at that instant.
Providers and backups
Deleted database records may remain in recovery history or backups until those copies expire. Confirm provider log and backup retention, including the active D1 recovery window.
Changing your choices or clearing data
- Location: change access in iPhone Settings. You can still choose a stop or starting point manually. End an active journey when you no longer want it followed.
- Notifications: turn off Background alerts in the app and allow the cancellation to finish. iPhone notification settings can also prevent alerts from being shown.
- Saved stops and preferences: remove favourites individually, or use Reset app in Settings to clear app choices and end the active trip.
- Feedback already sent: Reset app does not delete it from the service. Use the privacy contact above and, if available, include the submission reference.
Resetting also requests notification cleanup. Keep the app installed and reopen it with a connection if the cancellation is still pending. Resetting does not remove the limited security record described above.
Your privacy rights
Depending on the information and legal basis involved, UK data protection law gives you rights to request access, correction, deletion, restriction or a portable copy of your personal information. You can contact protonguyemailuk@protonmail.ch to make a request.
Your right to object
You may have the right to object to processing based on legitimate interests. Where processing relies on your consent, you can withdraw it. Withdrawal does not change the lawfulness of processing that took place before you withdrew consent.
Because the app does not use an account, enough information may be needed to locate the relevant record and verify a request. A feedback reference can help; do not send notification credentials or other secret information.
You can also complain to the UK's Information Commissioner's Office. Visit the ICO's complaints page or contact the ICO.
Processing outside the UK
Cloudflare and Apple operate international services. Confirm processing locations, applicable transfer safeguards and how to request a copy.
A database's storage location does not, by itself, establish where every network request, support message, log or backup is processed.
These pages and younger travellers
These static pages do not include analytics scripts, advertising, external fonts or embedded social media. Add the chosen website host, its request logging and any security cookies.
Confirm the intended audience and any safeguards for children.
Changes to this notice
This page will be updated when the app's handling of information changes. The published version will show its effective date so you can see when it was last revised.
Effective date: Effective date to add.