Transport Made Simple
Drive

Privacy notice

How Transport Made Simple Limited uses the information held about you in TMS Drive and in the TMS Drive app. Written for the colleagues who use it, not for lawyers.

Last updated 16 August 2026. Version 1.0. Transport Made Simple Limited, company number 15754458, Roswold House, Oak Drive, Diss, England, IP22 4GX.


Who this is for, and who we are

TMS Drive is an internal system for people who work for the Transport Made Simple group. It plans duties, records hours, handles leave and absence, and lets a driving colleague see their shifts and clock on and off. It is not a service for the travelling public. If you are a passenger, nothing here applies to you and this is the wrong page: please use the contact details on the operator website for the service you travelled on.

The data controller is Transport Made Simple Limited, company number 15754458, registered office Roswold House, Oak Drive, Diss, England, IP22 4GX. The group trades under several brands, including Central Connect, Simonds and Flagfinders.

For anything about this notice, or to exercise any of the rights below, write to tom.singleton@transportmadesimple.co.uk.

Where the information comes from

Almost all of it comes from TMS Insights, the group HR system. Insights is the source of truth for colleague records: no colleague exists in Drive who does not exist in Insights, and Drive does not let anybody create one. A nightly sync copies across the fields Insights owns, so a change made in HR reaches Drive without anybody retyping it.

The fields Drive receives from Insights are:

  • your name
  • your work email address
  • your mobile number, where HR holds one
  • your payroll reference
  • your depot
  • your job title
  • which company in the group you work for
  • whether you are currently working for us, whether a salary already covers your normal hours, your contracted weekly hours, the days per week you work and your annual leave entitlement
  • your line manager, where HR holds one

Drive does not receive or hold your bank details, your National Insurance number or your date of birth. That is a deliberate rule in the code, not an accident of what HR happened to send.

Everything else is created by the work itself: the duties you are given, the hours you work, the leave you ask for, the times you clock on and off, and the messages we send you.

What we hold, and why

Taking it in the order it accumulates.

Your work

The duties allocated to you, the rota line you sit on, the shifts you are down for, the vehicle allocated to a duty (its registration and fleet number), your planned and actual sign on and sign off times, the hours you worked and the hours that count towards pay. Weekly hours are reviewed and approved by a manager and then sent to Insights, which is what feeds payroll. Drive itself never talks to the payroll system and never stores a pay rate.

Why: we cannot run a bus operation without knowing who is driving what and when, and we cannot pay you correctly without a record of the hours. Lawful basis: performance of your contract with us (UK GDPR Article 6(1)(b)); our legal obligations to keep working time and pay records (Article 6(1)(c), including the Working Time Regulations 1998 and National Minimum Wage record keeping); and our legitimate interests in running a safe, lawful and properly resourced operation (Article 6(1)(f)).

Leave

Leave requests, the dates and the number of days, whether a request was approved or refused, who decided it and when, any reason you gave, and any note a manager wrote when refusing. If you cancel leave that had already been approved, that is recorded too, because it hands a body back to the depot that the roster had written off.

Lawful basis: your contract, and our legal obligation to give and record statutory annual leave.

Your app account

Your work email address, the status of the account (invited, registered, suspended), who invited you and when, when you registered, and when you last signed in. Your password is never stored. What is stored is a bcrypt hash of it, which cannot be turned back into the password. The tokens that keep you signed in are stored only as SHA-256 hashes, so a copy of that table is worth nothing to anybody who takes it. A sign in token lasts fifteen minutes before it is refreshed, the refresh token lasts thirty days, and a set password or reset link lasts twenty four hours and can be used once.

Sign in records, for portal users

If you use the Drive web portal rather than the app, we record each sign in: the time, the email address used, and whether you signed in with a password or arrived from Insights.

Lawful basis: our legitimate interests in keeping an operational system secure and knowing who has been in it.

Messages we send you

When we text or email you about a duty, we store the message exactly as it was sent, word for word, along with the number or address it went to, when it was sent, and whether the provider accepted it, refused it or nothing was sent at all. That covers the duty allocation message, the night before reminder, the alert when sign on has passed and nobody has clocked in, the message when a shift is taken off you, leave requests and cancellations, and the Sunday digest of next week.

Why we keep the body and not just the fact: what somebody actually read is what they will later ask about. Storing only "a reminder was sent" cannot answer "what did it say".

Location: what is captured, when, and what happens to a refusal

This is the part of the system people care most about, so it is set out in full and without softening. This is workplace location monitoring.

When

At the moment you press clock in, and at the moment you press clock out. At no other time. The app does not follow you during a shift, does not record where the bus goes, and does not track you when it is closed or in the background. There are exactly two moments, and you start both of them.

What

  • latitude and longitude, as your handset reports them
  • the accuracy figure your handset gives with the fix, in metres, which is the phone saying how wrong it might be
  • the time your handset thinks it is, kept alongside our own server time so that a phone with a wrong clock can be spotted rather than acted on

What we do with it

Our server, never the app, works out how far you are from your depot and compares that against the depot radius (250 metres unless a depot has its own figure). We store the distance it calculated and the radius that was in force at the time, so that changing a depot radius later cannot quietly rewrite whether a clock in from last month was inside it.

A refused clock in is recorded too, with its location

If the system says no, whether because you were too far away, too early, had no duty allocated, were already clocked in, or the location fix was too old, the attempt is still written down, marked as refused, with the reason, the time and the coordinates it was refused on.

That is deliberate and it is in your favour more often than not. "I did try, at 05:38, and it would not let me" is a question a depot can answer with that row and cannot answer without it. If the refusals were discarded, an attempt that failed would look identical to no attempt at all.

Why we do this at all

Because clocking on is what pay is built from, and a clock in from somewhere other than the depot means either a mistake worth correcting or hours claimed that were not worked. Recording the location makes that a question somebody can ask, rather than a fact nobody holds.

Lawful basis: our legitimate interests (UK GDPR Article 6(1)(f)) in paying accurately, in knowing that duties are being started from the depot, and in being able to answer a pay query with evidence. We have weighed that against your privacy, which is why the capture is limited to two moments you trigger yourself rather than continuous tracking, and why nothing about your location is used outside pay and attendance. You have the right to object to this processing: see your rights below.

Being straight with you about two things. First, a clock in refusal is an automated decision taken by the server against the depot radius. It does not decide your pay on its own: a refused clock in is visible to your depot, and hours can be and are corrected by a person. Second, we have not yet completed a formal data protection impact assessment for the location monitoring. That work is outstanding and this notice will be updated when it is done.

Sickness absence: information about your health

Information about your health is special category data under Article 9 of the UK GDPR. It gets stricter treatment than everything else on this page, so it is set out separately.

What Drive holds:

  • absences recorded as sickness, with the start date, the end date where the absence has ended, the working days it covered, whether it affects pay, and who recorded it
  • any reason recorded against the absence, which may describe a medical condition or symptom
  • your return to work record, where one has been completed
  • your Bradford Factor score, which is a number calculated from how many separate absences you have had and how long each one lasted

Article 6 basis: our legal obligations and our legitimate interests in managing attendance and covering duties safely.

Article 9 condition: Article 9(2)(b), processing necessary for carrying out our obligations and exercising our rights in the field of employment and social security law. In UK law that condition is used with Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018, which requires us to keep an appropriate policy document covering how we handle this information and how long we keep it.

Honestly: the appropriate policy document required by Schedule 1 is being put in place, and we would rather say that here than imply it already exists. Absence information is visible only to HR and to managers with responsibility for your depot, never to other driving colleagues, and it is never sent to the app.

Who else sees it

Inside the group, your record is visible to your managers, to the depot planning your duties, and to HR. Managers are scoped to their own depots. Pay figures are restricted further again.

Outside the group, the information sits with a small number of suppliers who process it on our instructions and for no purpose of their own:

  • Vercel, which hosts the application
  • Railway, which hosts the database everything is stored in
  • Resend, which delivers our emails
  • Twilio, which delivers our text messages

Approved weekly hours are passed to TMS Insights, which is part of the same group and the same data controller, and Insights is what sends pay information to the group payroll provider. Drive has no connection to the payroll provider itself.

We do not sell your information, we do not use it for advertising, and there is no analytics or tracking product in the app or in this website.

Where it is held: we cannot state this precisely yet. Vercel and Railway both operate in multiple regions and the region for this deployment has not been confirmed and written down, so we are not going to claim it is held in the United Kingdom until somebody has checked. Some of these suppliers are based in the United States, and where information is transferred outside the UK it is covered by the transfer terms in their standard data processing agreements. This paragraph will be replaced with the confirmed position.

How long we keep it

Some of this is decided by the design and some of it is not decided yet.

What is fixed:

  • a sign in token expires after thirty days, and a set password or reset link after twenty four hours
  • clock events are never edited. A correction is a new record, because a history that can be rewritten cannot answer a pay query
  • when you leave, your record stays rather than vanishing, because a duty you worked last week still needs your name against it and the hours still have to reconcile. You are excluded from allocation, not deleted

What is not settled: we have not yet set retention periods for clock events, absence records, leave history, message history or sign in logs. That work is under review. We would rather tell you it is under review than print a number nobody has agreed to and nothing enforces. When the periods are set, this page will say what they are.

Your rights

Under UK data protection law you can ask us to:

  • Show you what we hold about you, and give you a copy. This is a subject access request and we have one month to answer it
  • Correct anything that is wrong or incomplete
  • Delete information, where we have no continuing reason to hold it. Records we are legally required to keep, such as working time and pay records, cannot be deleted on request
  • Restrict what we do with it while a dispute about it is sorted out
  • Object to processing we do on the basis of legitimate interests. That includes the location captured at clock in and clock out. If you object we have to stop unless we can show compelling grounds that override your objection, and we have to actually consider it rather than refuse by reflex
  • Receive it in a portable form, for the information you gave us or that we hold under your contract

None of this costs anything. Ask at tom.singleton@transportmadesimple.co.uk, or through your depot if you would rather not email directly.

Complaining

Come to us first if you can, at tom.singleton@transportmadesimple.co.uk. We would rather fix something than have you told to wait by somebody else.

You do not have to, and you never lose the right to go to the regulator. The Information Commissioner is the UK supervisory authority for data protection and you can complain to them directly:

  • ico.org.uk/make-a-complaint
  • helpline 0303 123 1113
  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Changes to this notice

If we change what we collect or why, this page changes and the date at the top changes with it. Anything that materially affects you will also be told to you directly rather than left for you to notice.

See also the terms of use for the app, how to get help and what the app is and who it is for.

Transport Made Simple Limited. Brands include Central Connect, Simonds and Flagfinders.