Privacy information
Privacy Policy
How RouteBids handles enquiries, accounts, postcode-level route information and sealed-tender records.
About this notice
This draft explains how the RouteBids service is designed to handle personal information. The final published notice must identify the legal operator and relevant controllers, their contact details, lawful bases, retention periods and approved processors before it takes effect.
For the public website, enquiries, accounts and service security, the RouteBids operator may act as controller. A council normally determines why route information is entered and how it is used; RouteBids operates that workspace under the applicable agreement and authorised instructions.
Information handled
- Consultation enquiries, including the contact and organisation information supplied with the enquiry.
- Invited-user email addresses, roles and account status, together with password, authentication, MFA, session and security records.
- Council workspace details, provider references and participation or eligibility status. Provider licensing, insurance and qualification records are handled by councils outside RouteBids.
- Sealed submissions, receipts and revisions, together with evaluation, award, notification and audit records.
- Technical records needed to secure and operate the service, including request, rate-limit and delivery records.
Passenger-route information
RouteBids does not ask councils to enter passenger names. A route may include a council-assigned passenger reference, pickup and drop-off postcodes, planned times and limited transport or accessibility requirements.
The council keeps any information linking the reference to a named passenger outside RouteBids. This reduces identification risk but does not necessarily make the RouteBids information anonymous. Councils must not enter names, full addresses or unnecessary details.
Why information is used
Information is used to answer enquiries, create and secure invited accounts, operate separated council and provider workspaces, publish route opportunities, receive and protect sealed submissions, support controlled opening and evaluation, send operational notices and maintain security and audit records.
The responsible controller must document the applicable UK GDPR Article 6 lawful basis and, where health or disability information is included, the applicable Article 9 condition. No legal basis is invented or assumed by this draft.
Sharing and maps
Information is available only to authorised users and service personnel who need it for the relevant workspace or operation. Operational email is handed to the local Postfix/sendmail service and normal recipient mail infrastructure.
When map preview is enabled, entered postcodes are sent to Postcodes.io, calculated coordinates are sent to the public FOSSGIS OSRM service at routing.openstreetmap.de, and the browser requests the OpenStreetMap tiles needed for the visible map. Passenger references, account emails, tender values and live vehicle locations are not included in those map requests.
The approved hosting provider, hosting region, downstream mail providers and any international-transfer safeguards must be stated in the final notice. Information is otherwise disclosed only where needed to operate the service, follow authorised council instructions, protect RouteBids or comply with law.
Cookies and local browser storage
RouteBids uses a strictly necessary, secure HTTP-only session cookie to keep an authorised user signed in and enforce access controls. The workspace may also remember limited interface preferences in browser storage.
RouteBids does not currently use advertising or cross-site tracking cookies. Any future optional analytics or marketing technology would require a documented purpose and, where required, consent before activation.
Retention and security
Personal information is retained only for documented operational, contractual, procurement, security and legal purposes. The final notice must state the applicable periods or deletion criteria for enquiries, accounts, invitations, tender and audit records, security logs and backups.
RouteBids uses password hashing, revocable sessions, role and tenant controls, protected sealed prices, MFA safeguards and audit records. No security control provides an absolute guarantee.
Rights and complaints
Depending on the controller, purpose and lawful basis, individuals may have rights of access, correction, erasure, restriction, objection and portability. Route-data requests should normally be directed to the council responsible for that route; other requests may be sent to support@routebids.co.uk until a verified privacy contact is published.
Individuals may also raise concerns with the UK Information Commissioner's Office at ico.org.uk/make-a-complaint/.