← All legal documents

Retention schedule

Draft, published while still under review. It may change before launch. Written against what the code actually does (docs/legal/data-inventory.md). Placeholders in [brackets] need your decision.

Last updated: [date] · Controller: [legal name and address] · Contact: [email]

What this covers

Everything the service holds about you, how long we hold it, and what makes it go when the time comes. It is the detail behind the "How long we keep it" section of our privacy policy.

Where a period is kept by something the service does automatically, the last column says so. Where it depends on somebody doing it, the last column says that instead, because a schedule you cannot check is not worth reading.

The schedule

What we holdHow long we keep itWhat makes that happen
Your email addressAs long as you have an accountNothing deletes it on a schedule. Closing your account keeps the address, because the claim records and the authority trail we keep afterwards are tied to it.
Your Oyster or contactless card numberAs long as you have an accountClosing your account deletes it, together with the journeys it was read from.
Your journey history: the date, time, start and end station, fare and card of each journey8 weeksA sweep that runs when our worker starts and again after every status check, so it cannot be left undone. A check also reads at most 8 weeks back, which is all TfL itself keeps, so nothing older ever reaches us in the first place. Closing your account deletes all of them without waiting for the sweep.
Copies of the TfL pages we read during a check, and the CSV files we download from them30 daysA sweep that runs when our worker starts and again after every status check, so it cannot be left undone. Closing your account deletes them without waiting for it.
Our estimate of whether a journey was delayed, and the evidence behind itWith the journey it describesDeleted in the same sweep that removes the journey, and on the same transaction, so an estimate never outlives what it describes.
Your refunds, including TfL's own record of how long each delay wasKept after your account closes, and finally deleted after [period]Deliberate. You and TfL may both need the record later, so nothing deletes it when you close your account.
Your standing authority: the wording you accepted, when you accepted it, and the limits you set[6 years] after your account closesKept through account closure. Deletion at that point is something we do, not something that happens by itself.
The record of every delay we showed you, every approval you gave, every claim we submitted and everything we refused to do[6 years] after your account closesThe same. That record is only ever added to, never edited.
The progress of a check, including the live-view link while one is runningThe link is cleared the moment the check endsCleared on the path where a check finishes and on the path where it fails, so it cannot be left sitting in our database. The progress record itself goes when you close your account.
A sign-in in progress: hashed IP address, state and the live-view linkThe link is cleared the moment the sign-in ends; the row itself for 30 daysThe link is cleared automatically, the same way a check's is. The same sweep that runs when our worker starts and after every status check gives up on a sign-in nobody finished, deletes the browser profile behind it on the next sweep after that, and deletes the row itself 30 days after the sign-in ended.

Our copies of Transport for London's published network status and station information hold nothing about you. They are the same for every account, so no retention period applies to them.

Closing your account

Ask us to close your account and we do all of the following.

What we delete

  • The browser profile holding your signed-in TfL cookies, any browser still running on it, and any sign-in connection left over from an earlier version of the service. Once those are gone there is no route from us into your TfL account.
  • Everything in your folder on our server: the browser profile, the saved cookies, the CSV files we downloaded and the copies of the pages we read.
  • Your journeys, your card, our delay estimates, the approvals you gave and the records of the checks that read them.

What we keep

  • Your refunds: what we asked TfL for, and what TfL decided. You and TfL may both need this later.
  • The record of who authorised what, and of anything we refused to do.
  • The wording of any standing authority you accepted, and when you accepted it.
  • Your account itself, marked closed, with your email address on it, because the records above are tied to it.

We write the closure into that record before we delete anything, so the fact that you closed the account outlives the data it describes. The browser profile goes first: if that step fails, nothing of yours has been deleted yet and we can try again. Doing it the other way round could leave a browser holding your TfL session with nothing here to say that it exists.

There is one exception, and we would rather tell you about it than leave it out. If the profile cannot be reached at all, we can still close the account and delete everything else, and then remove the profile by hand. Taking that route is a deliberate choice by one of us, it names the profile in the closure record, and it exists so that a request to close your account is never held up by a problem at our end.