[go: up one dir, main page]

Citymapper's privacy policy

Last updated: August 14, 2025

Introduction
Who We Are & How To Contact Us
What Information Is Collected
How We Use Personal Information
How We Share Or Disclose Personal Information
How We Protect Your Personal Information
How We Store Your Personal Information
Your Communication Preferences
Your Rights
Children's Personal Information
Third-Party Websites
Cross-Border Transfers
Privacy Notice Updates
GDPR Notice
1. Legal Bases for Processing Personal Data
2. Retention of Personal Data
3. Your Privacy Rights
4. GDPR Notice Updates

Introduction

Citymapper Ltd. ("Citymapper", "we", "us", or "our") is an innovative journey planning and transportation technology company dedicated to transforming urban navigation. Citymapper is a wholly owned subsidiary of Via Transportation, Inc., and we provide technology solutions that cities, transit agencies, and other organizations can use to encourage urban journey planning by various methods and to promote public transit usage.

Citymapper is committed to the principles of transparency and protecting our users' privacy. This Privacy Notice explains how we collect, use, share, disclose, and otherwise process your personal information. It also explains how you can exercise the choices and rights you have regarding your personal information.

This Privacy Notice applies to:

  1. All users of our apps (including both free and paid versions of the "Citymapper App").

  2. Our website's users and visitors (including "www.citymapper.com").

3. Users of our platforms and dashboards, and other Citymapper products and services including those that Citymapper makes available to Enterprise Customers defined below.

Items 1 through 3 are collectively referred to in this Privacy Notice as the "Services". Accordingly, the covered users include but are not limited to individuals using our journey planning tools, visitors to our website, and any other individual interacting with our Services (collectively, "Users" or "you").

Enterprise Customers are cities, transit agencies, transport operators, school districts, educational agencies or institutions, universities, corporations and other governmental or institutional customers which use the Services — whether provided directly by Citymapper or jointly with its parent company, Via Transportation Inc., or any of its affiliates — to establish, monitor, optimize, operate and/or manage transportation, delivery, and logistics networks, as well as business partners or other entities which may use Services in order to arrange for transportation, delivery, or logistics services for Users.

Please note that all corporate entities and organizations referenced throughout this policy are defined to include their affiliates and agents. For example, when we say that we share information with Enterprise Customers, we may share information with employees, agents, affiliates, consultants, or subcontractors designated or authorized by these Enterprise Customers to receive such information.

Please read this Privacy Notice to ensure you understand it and agree with its terms before using the Services.

Who We Are & How To Contact Us

Citymapper is the "data controller" (as such term, or equivalent, is defined under applicable data protection laws) of the personal information collected through the Services which is subject to this Privacy Notice. Meaning, we control the processing of personal information described under this Privacy Notice and decide upon the purpose and means of collection and processing.

Our company is registered in England and Wales under company number 07370388 with a registered office at 138 Fetter Lane, London, EC4A 1BT, United Kingdom.

If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please contact our Data Protection Officer at support@citymapper.com. You can also reach us by mailing:

Attn: Data Protection Officer
Citymapper Ltd.
138 Fetter Lane
London, EC4A 1BT

Citymapper has appointed the Via Mobility DE GmbH, Rosa-Luxemburg-Str. 14.; 10178 Berlin, Germany, as its representative in the European Union pursuant to Article 27 GDPR.

We may provide different or additional disclosures to residents in certain countries, regions, or states, or as we are otherwise required in accordance with applicable laws in such jurisdictions, so please be sure to review such notices in addition to consulting this primary Privacy Notice. Specifically, our GDPR Notice further details specific information regarding our data processing practices we are required to disclose under the EU and the UK General Data Protection Regulations, including our lawful basis for processing personal data (collectively "GDPR").

What Information Is Collected

As used in this Privacy Notice, "personal information" or "personal data" is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual.

Depending on the nature of your interaction with us and our Services, we may collect the types of personal information detailed below, as follows (1) information you provide to us, (2) information collected automatically when you use the Services, and (3) information collected from other sources.

  1. Personal information you provide to us

In addition, when you plan a journey using our Services, and enter journey data, such as destinations and preferences, we collect and process this information. Some journey data may also be collected in real-time via location services. See "Location Information" for more details.

Note that you do not need to create a user account to use the Services. If you do not create a user account and use our Services, we will still collect personal information like journey data, destinations and preferences, as described in this Privacy Notice, including Location Information. The data will be linked to a unique ID randomly generated by Citymapper each time you install the Citymapper App, as further detailed under the "Device Information & Online Identifiers" below. This helps us keep track of your previous journey planning searches and enables us to find the best route for you. Note that if you do not create a user account, you may not be able to take advantage of certain features offered in the Services.

Personal information automatically collected when you use the Services

In addition, when you use our Services, we may collect approximate location data (for example country, city and ZIP) based on any automatically collected Device Information and Online Identifiers, as defined below.

  1. Personal information collected from other sources and Third Parties

Although we generally collect the personal information described above directly from you or from your device, we may also collect this information through other third parties that collect and share it with us through the provisions of our Services, as noted below. Please note that these third parties might further independently use your personal information as part of your relationship with them. To learn about third parties' privacy practices, please review their respective privacy notices. The third parties from which we may collect personal information and types of personal information include:

Use of Anonymized and Aggregated Data:

This Privacy Notice does not apply to anonymized, aggregated, or de-identified data. Once information is aggregated, anonymized, or de-identified in a way that cannot be associated with or linked to you, we may use and share it for various purposes. For example, we may share aggregated insights about demand patterns with our affiliates, partners, and Enterprise Customers to help them understand passenger behaviour, make smarter planning and operational decisions, or improve the Services and business operations.

Additionally, we may aggregate, anonymize or de-identify personal information for analytics purposes to help understand Users' needs and improve our services and offerings. For example, we may analyse how Users interact with the Services (such as the most viewed content, feature or click stream) to improve the way we present such content or develop better features, to measure effectiveness of our content and advertising campaigns, or otherwise to develop and train our artificial intelligence features and models.

How We Use Personal Information

We use the personal information described above to:

We work hard to improve the Services and add functionality, which we think will make it safer, more fun and more useful. New functionality may involve similar or incidental uses of your data to those set out above. We regularly review the way we use data and will update our Privacy Notice if anything changes.

How We Share Or Disclose Personal Information

We share your personal information with third parties, including our partners or service providers that help us provide our Services or otherwise for the purpose of improving and marketing our Services, as well as in cases needed to resolve claims. We take your privacy seriously, so when we do share your information with third parties, we try to disclose anonymized or aggregated data wherever possible. We also take reasonable and appropriate steps to limit the scope of information that is disclosed and to ensure that the third party is required to comply with data protection laws. We may share and disclose personal information in the following ways:

How We Protect Your Personal Information

We take the security of your personal information and our data seriously. We have implemented robust physical, technical, and organisational measures designed to help protect your personal information against unauthorised access, use, or disclosure. However, protecting your user credentials and limiting access to your devices remains your responsibility. Please take appropriate precautions to safeguard your accounts and personal information.

How We Store Your Personal Information

We retain your information for as long as necessary to fulfil the purposes set forth above (see the "How We Use Personal Information" paragraph of this Privacy Notice), all in accordance with applicable laws, or until an individual expresses a preference to delete its personal information (subject to certain exclusions entitling us to decline such request under applicable laws).

We retain your personal information to provide you our Services, or as long as required to fulfil our legal obligations including regulatory, tax, or accounting requirements. For example, we retain your User Account information and activities made thereunder for as long you retain the account, and thereafter, we retain certain information such as transactional information and information about rides or deliveries you make and receive to ensure we can perform legitimate business functions, such as accounting for tax obligations.

We will further retain certain personal information to maintain an accurate record of Users' interactions with the Citymapper Services provided and compliance with our obligations under applicable laws, as well as to have records in the event of any complaints or litigation.

If you request account deletion, or otherwise submit a deletion request, we will delete your information as set forth in the "Your Rights" section.

Unless otherwise required by applicable law, we may, at our discretion, delete or modify information in our systems without prior notice once we determine it is no longer needed.

Your Communication Preferences

In connection with the Services, we may send you email messages, SMS messages, push notifications, or other communications, including telephone calls, consistent with applicable laws.

You may ask us not to send you certain types of communications by:

If you request to opt out of marketing communications, please note that we may continue to send you non-marketing communications where permitted by law, which may include account verification and maintenance, status updates regarding specific transactions (such as transportation or delivery services you arranged using the Services), changes or updates to the Services or our ongoing business relationship, and any technical, administrative, legal, or security-related notices.

Your Rights

Under applicable data protection laws, Users are granted with choices, rights, and controls that they are entitled to exercise in connection with their personal information. Depending on your location, relationship with us, and applicable laws, you may have the following rights regarding your personal information:

You may exercise your rights as follows:

You can exercise any of the rights listed above by contacting us at support@citymapper.com and using the subject line "Data Subject Request". Please note that we may need to verify your identity before processing your request, which may require us to collect additional Personal Data from you. We may decline a request to exercise the rights listed above, consistent with applicable laws. Please also note that if your exercise of any of the rights listed above limits our ability to process Personal Data, we may not be able to provide some or all portions of the Services to you going forward. We will respond and fulfil your request within the timeframe required under applicable laws.

When you submit a request, we will take steps to verify your identity and your request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for denial and how to remedy any deficiencies, where applicable.

Certain rights can be easily executed independently by you without the need to contact us, and for example:

Children's Personal Information

Our Services are not directed to children, and we do not knowingly collect or solicit personal information directly from children. When we use the word "children", we refer to anyone under the applicable age of consent for privacy purposes in relevant local jurisdictions (typically between 13 and 16 years old). If you are a child, please do not submit any personal information to us or otherwise use our Services without parental or legal guardian consent. We encourage parents and legal guardians to monitor their children's internet use and to help enforce our Privacy Notice by instructing their children never to provide personal information without their permission.

Protecting the privacy of children is important to us. If we learn that we collected information from a child without appropriate parental or legal guardian consent, we will take steps to delete it and may close the relevant account without notice. If you have reason to believe that a child has provided personal information to us without consent, please contact us at support@citymapper.com.

Third-Party Websites

Our websites and Services may include links to or redirect you to third-party websites, plug-ins and applications, including social media services where you may connect with us or where you interact with third party ads displayed on our Services. Third-party websites may also reference or link to our websites and online services. Except where we post, link to, or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to, and we are not responsible for, any personal information practices of third-party websites and online services or the practices of other third parties. To learn about the personal information practices of third parties, please review their respective privacy notices or policies.

Cross-Border Transfers

Due to our global operation, we share personal information with third parties (such as our service providers and affiliated companies) located globally, including outside the EEA and UK. Accordingly, your personal information might be shared outside the territory from which you use our Services. When transferring your personal information across borders, including to our affiliates and third parties under the circumstances described in this Privacy Notice, we ensure compliance with all applicable legal requirements. We monitor regulatory developments with respect to cross-border data transfer and, where appropriate, we rely on adequacy decisions (meaning transfer to countries the European Commission or the United Kingdom Government has deemed to adequately safeguard such data) or otherwise we transfer personal information based on the Standard Contractual Clauses and the International Data Transfer Addendum adopted by the European Commission and the UK ICO, to ensure your data is protected.

Transfers of personal data to Via affiliates or to our Service providers located in the United States are made based on such entities' certification and compliance with the principles of the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, as set forth by the U.S. Department of Commerce (collectively, the "DPF"). Where an entity is not certified under the DPF, or if the DPF is no longer considered a valid transfer mechanism, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable, to safeguard such transfers. To learn more about the DPF program, and to view Via Transportation, Inc.'s certification in the DPF list of participants, please visit https://www.dataprivacyframework.gov/.

Privacy Notice Updates

We will update this Privacy Notice from time to time, including to address changes in the Services, clarify or update our processes, and to comply with changing laws and regulations. When we make changes to this Privacy Notice, we will change the "Last Updated" date at the beginning of this Privacy Notice. If the changes apply to only one section of the Privacy Notice, we may update only that section's "Last Updated" date. If we make material changes, we will notify you, including through a pop-up notification on the Citymapper App, websites or by other means, including email or a prominently posted notice at the beginning of this Privacy Notice. All changes shall be effective from the date of publication unless otherwise provided in the notification, and subject to applicable laws. We encourage you to review this Privacy Notice periodically. By using the Services after an update, you agree to the updated version of the Privacy Notice.

GDPR Notice

Last updated: August 14, 2025

The information in this GDPR Notice supplements the information provided under the main Privacy Notice and provides Users with additional information required to be disclosed under the General Data Protection Regulation ("GDPR"), including our lawful basis for processing personal information. The terms used in this GDPR Notice have the same definitions provided in the Citymapper Privacy Notice, unless they are expressly given a new definition here. Please note that personal data, as defined below and under the GDPR ("Personal Data"), includes the term "personal information" used under the main Citymapper Privacy Notice.

Our legal basis for processing Personal Data depends on the type and the specific context in which we collect and use it. The table below illustrates the categories of Personal Data we collect, provides examples of how we use Personal Data within each category, and describes the legal bases for our processing of each category of Personal Data. Additional details about our use of Personal Data can be found in the "How We Use Personal Information" section of the Privacy Notice.

In the table below, "Performance of a contract" refers to processing for the purpose of performance of our agreements with Users and Enterprise Customers, including our Terms of Use.

As described in the table, in certain circumstances, we may ask for your consent to collect and process Personal Data for the purposes described below. Where we rely on consent, you have the right to withdraw your consent at any time, in which case we will cease that collection and use of your Personal Data for the purpose for which you provided consent.

When we process Personal Data based on our legitimate interests, it is for the purpose of operating our Services, ensuring that the our Services remain relevant and function well for each User, developing new and innovative services and features, and preventing fraud while promoting the safety and security of Users, Enterprise Customers, our Company, our contractual counterparties, and the general public.

Category of Personal Data Purposes of Processing Legal Bases for Processing
User Account Information, and Single Sign-On as described in the Privacy Notice. Setting up and managing User Accounts Performance of a contract
Providing the Services Performance of a contract
Personalizing the Services

Legitimate interests;

Consent

Improving the Services & analytics Legitimate interests
Facilitating safety, security, and fraud prevention Legitimate interests
Providing & improving customer support Performance of a contract; Legitimate interests
Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interests
Compliance with regulations or lawful requests & enforcement of our terms, policies and agreements Compliance with legal obligations; Legitimate interests
Payment Information, as described in the Privacy Notice. Providing the Services Performance of a contract
Facilitating safety, security, and fraud prevention Legitimate interests
Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interests
Compliance with regulations or lawful requests & enforcement of our terms, policies and agreements Compliance with legal obligations; Legitimate interests
Saved and Shared Preferences, as described in the Privacy Notice. Providing the Services

Performance of a contract.

In app permissions are further based on Consent.

Personalizing the Services

Legitimate interests;

Consent

Contact Information and Contact Communications, Social Media as described in the Privacy Notice. Providing the Services, including sending transactional messages. Performance of a contract
Improving the Services & analytics

Legitimate interests;

Consent (where we use Cookies for such purposes)

Facilitating safety, security, and fraud prevention Legitimate interests
Providing & improving customer support Performance of a contract; Legitimate interests
Advertising & marketing communications

Legitimate interests;

Consent (where we use Cookies for such purposes or when you sign up to receive our marketing communications)

Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interests
Compliance with regulations or lawful requests & enforcement of our terms, policies and agreements Compliance with legal obligations; Legitimate interests
Location Information, as described in the Privacy Notice. Providing the Services

Performance of a contract;

GPS permissions are based on your consent.

Personalizing the Services

Legitimate interests;

Consent (where we use Cookies)

Targeted advertising Consent
Improving the Services & analytics

Legitimate interests;

Consent (where we use Cookies)

Facilitating safety, security, and fraud prevention Legitimate interests
Providing & improving customer support Performance of a contract; Legitimate interests
Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interests
Compliance with regulations or lawful requests & enforcement of our terms, policies and agreements Compliance with legal obligations; Legitimate interests

Device Information, Online Identifiers and Usage Information as described in the Privacy Notice.

This information may be collected and stored by us, or by our third-party service providers and business partners, using cookies, related technologies, and third-party analytics tools. Certain cookies are processed only with your consent. Please see our Cookie Notice for details about how you can provide or withdraw consent to such processing.

Providing the Services Performance of a contract
Personalizing the Services

Legitimate interests;

Consent (where we use Cookies)

Targeted advertising Consent
Improving the Services & analytics

Legitimate interests;

Consent (where we use Cookies)

Facilitating safety, security, and fraud prevention Legitimate interests
Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interests
Compliance with regulations or lawful requests & enforcement of our terms, policies and agreements Compliance with legal obligations; Legitimate interests
Survey and Rewards Program Information, as defined in the Privacy Notice. Personalizing the Services Legitimate interests
Enabling you to participate in a surveys, quizzes, contests, interviews, rewards programs or promotions Consent
Improving the Services & analytics Legitimate interests
Internal operations of the Services, monitoring & record keeping Compliance with legal obligations; Legitimate interest
Facilitating safety, security, and fraud prevention Legitimate interests
Inferences as defined in the Privacy Notice. Personalizing the Services Legitimate interests

2. Retention of Personal Data

We retain your Personal Data for as long as necessary for the purposes and legal bases set out in the Privacy Notice.

3. Your Privacy Rights

Your rights with respect to your personal data are set forth in the "Your Rights" section of our main Privacy Notice and are subject to certain limitations under applicable laws.

4. GDPR Notice Updates

We may revise this GDPR Notice from time to time. When we make changes to this GDPR Notice, we will change the applicable "Last Updated" date. If we make material changes, we will notify you including through a pop-up notification on our apps, websites, or by other means, including email or a prominently posted notice at the beginning of this GDPR Notice. All changes shall be effective from the date of publication unless otherwise provided in the notification and subject to applicable laws. Please review this GDPR Notice from time to time to check whether we have made any changes.