Botric

Privacy policy

Effective and last updated: 4 September 2026

This policy explains how Botric ("Botric", "we", "us" or "our") handles personal data in connection with botric.co.uk, UK Passenger Transport at ukpt.botric.co.uk, its account services and its API (together, the "Services"). Botric is the controller of personal data we collect directly through the Services. Questions and data-rights requests may be sent to Support@botric.co.uk.

Information we collect

  • Account information: email address, a securely hashed password, verification status and account timestamps.
  • Authentication and API information: hashed session tokens, hashed API credentials, API-key names, plan and rate-limit information. Plaintext passwords, session tokens and API keys are not stored.
  • API usage information: API key identifier, endpoint, request method, response status, latency, record count and request time. Our application usage log does not store request bodies, IP addresses or user-agent strings.
  • Technical and security information: IP address, browser or device information, requested URL, timestamps and diagnostic information may be processed in server, proxy, security and anti-abuse logs.
  • Communications: information you include when contacting support or responding to an operational email.
  • Advertising and analytics information: cookie identifiers, IP address, device/browser information, page URLs, interactions and approximate location may be processed when Google services are enabled, subject to applicable consent choices.

How and why we use information

We process information to provide accounts and API access, authenticate users, issue and administer API keys, deliver verification and password-reset emails, enforce usage limits, secure and troubleshoot the Services, prevent fraud and abuse, understand service performance, comply with legal obligations, and establish or defend legal claims.

Where applicable, our legal bases are performance of our contract with you, our legitimate interests in operating and securing the Services, compliance with law, and consent for non-essential cookies, personalised advertising or analytics where consent is required.

Cookies, local storage and similar technologies

We use an essential, secure HTTP-only ukpt_session cookie to keep signed-in users authenticated. It may remain for up to 30 days. We also use session storage to remember when an advertisement has been dismissed for the current browser session. These functions are necessary to provide features requested by the user.

Google Analytics and Google AdSense may use cookies, web beacons, IP addresses and other identifiers to provide analytics, select and deliver advertisements, measure advertising, limit repeated ads, detect fraud and, where permitted by your choices, personalise advertising. Google may receive the page URL and information sent automatically by your browser. Learn how Google uses information from sites that use its services, review Google's Business Data Responsibility information, and manage personalisation through Google Ads Settings.

Our self-hosted Umami analytics service is used to understand aggregate website activity and is configured as a privacy-focused service. Google advertising and Google Analytics do not load unless you accept optional cookies. You can reject them without losing access to the Services and may revisit your choice at any time through "Cookie preferences" in the website footer.

Who receives information

We do not sell personal data. Information may be shared only as necessary with service providers acting for us, including hosting and infrastructure providers, transactional email services, Cloudflare Turnstile for bot prevention, and analytics providers. When advertising or Google Analytics is enabled, Google and the advertising partners selected in our Google publisher settings may receive and independently process data for advertising, measurement, security and personalisation in accordance with the user's choices.

We may also disclose information where required by law, to protect users or the Services, in connection with a corporate reorganisation, or with your direction or consent. Some providers may process data outside the United Kingdom; where required, appropriate safeguards are used by the relevant provider.

Retention and security

Account information is normally retained while the account remains active. Sessions expire after no more than 30 days, verification links after 24 hours and password-reset links after one hour. API usage and security records are kept for as long as reasonably necessary for allowance calculation, auditing, fraud prevention, troubleshooting and legal compliance. Support correspondence is retained only while needed to address the request and meet legitimate operational or legal requirements.

Deleting an account removes the user record and revokes associated sessions and API keys. Some aggregated or de-identified usage records, backups, security logs or records required by law may remain for a limited period. We use access controls, encryption in transit, one-way hashing and other proportionate safeguards, but no internet service can guarantee absolute security.

Your rights

Depending on your location, you may have rights to access, correct, erase, restrict or object to processing of your personal data, obtain a portable copy, and withdraw consent without affecting earlier lawful processing. You may delete your UK Passenger Transport account from the account dashboard or contact Support@botric.co.uk. We may need to verify your identity before completing a request.

UK users may complain to the Information Commissioner's Office, although we encourage you to contact us first so we can address the concern.

Children, external links and changes

The Services are intended for a general audience and are not directed at children under 13. We do not knowingly request personal data from children. The Services link to external websites whose privacy practices are controlled by their respective operators.

We may update this policy to reflect operational, legal or regulatory changes. The current version will remain published at this URL with its effective date. Material changes will be highlighted through an appropriate notice where required.