Your transport account is sensitive. We treat it that way.
Claimmyfare is built around the assumption that connection data deserves the same care as financial credentials — because to you, it effectively is.
Encryption at rest and in transit
Sensitive connection data is encrypted using strong, managed key infrastructure.
Secure authentication
You authenticate with TfL directly through TfL's own sign-in flow. We never see or store your TfL password.
Customer-level isolation
Every customer's journeys, claims and connection data are isolated — access is scoped per account.
No credentials in logs
Authentication material is never written to application logs, error trackers or analytics.
Secure session handling
Claimmyfare authentication uses secure, HTTP-only cookies with CSRF protection.
Audit trails
Sensitive actions — connecting, disconnecting, claim submission — are recorded in an audit log.
Controlled access
Internal access to customer data is limited to what's needed, and is itself logged.
Data deletion on disconnect
Disconnecting your TfL account removes stored connection data from active systems.
We do not attempt to bypass multi-factor authentication, defeat CAPTCHA or other anti-bot mechanisms, or circumvent any security control. If TfL requires you to re-authenticate, Claimmyfare will always ask you to do so directly rather than attempting to work around it.
Claimmyfare is an independent service and is not affiliated with or endorsed by TfL.