Privacy Policy
Last updated: January 2026
1. Introduction
Mind the Delay ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our TfL refund automation service.
2. Information We Collect
Account Information
- Email address (for account creation and communication)
- Name (if provided via OAuth)
TfL Credentials
- TfL account username and password (encrypted)
- These are used solely to access your TfL account for journey history and refund submission
Journey Data
- Journey history downloaded from your TfL account
- Journey dates, times, stations, and fares
- Delay analysis results
Payment Information
Payment processing is handled by Stripe. We do not store your full payment card details. We retain only the information necessary to manage your subscription.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Access your TfL account to download journey history
- Analyze journeys for delay refund eligibility
- Submit refund claims to TfL on your behalf
- Process subscription payments
- Send service-related communications
- Improve and optimize the Service
4. Data Security
We implement robust security measures to protect your data:
- Encryption: TfL credentials are encrypted using AES-256-CBC encryption
- Secure Storage: Data is stored in secure, access-controlled databases
- HTTPS: All data transmission is encrypted using TLS
- Access Controls: Strict internal access controls limit who can access user data
5. Data Sharing
We do not sell your personal information. We may share data with:
- TfL: Your credentials and refund claims are submitted to TfL to provide the Service
- Payment Processors: Stripe processes subscription payments
- Service Providers: Cloud hosting and infrastructure providers who help us operate the Service
- Legal Requirements: When required by law or to protect our rights
6. Data Retention
We retain your data for as long as your account is active. Journey data is retained to provide historical analysis and track refund submissions. Upon account deletion, we will delete your TfL credentials and personal data within 30 days, though some data may be retained for legal or accounting purposes.
7. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a portable format
- Object: Object to processing of your personal data
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@mindthedelay.com
9. Third-Party Services
Our Service integrates with:
- TfL: To access journey history and submit refunds
- Stripe: For payment processing
- Google/Microsoft: For OAuth authentication (optional)
Each of these services has their own privacy policy governing their use of your data.
10. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: privacy@mindthedelay.com