About this scorecard
A free, open-source, plain-language data-quality check for a transit agency's GTFS feed. It reads the feed an agency already publishes, runs the same validator the state and the apps use, and turns the result into a grade, the three things to fix, and why each one matters to riders.
Why it exists
A small agency often inherits its GTFS export from a vendor and has no way to know if it is any good. The most common failure is quiet: the feed silently expires and trip planners drop the agency, so riders are told the service does not exist. The official quality reports are thorough but technical. This fills the gap between them and the person at a 20-bus agency who just needs to know what to fix.
It is built first for two people sharing one screen: the transit manager who wants to know where they stand, and the state or program liaison who wants one page open during an agency check-in. A free open dataset now also serves analysts and state programs working across many feeds at once.
How it works
It scores on top of the canonical MobilityData GTFS validator rather than re-validating feeds, and adds the scoring, the trend, the plain-language fixes, and the alerts. The full methodology, with citations, is in docs/rubric.md, and the machine-readable weights are published at scoring.json. It is a data-quality lens, not an official compliance determination.
Every scorecard records how its feed copy was downloaded, and about our fetcher explains the same thing for the server operators who see the requests: identity, cadence, retries, and how to reach us.
What is free, and what is paid
Everything an agency or a rider touches is free, and stays free: the scorecard, the board one-pager, the prioritized fixes, the alerts, the badges, the read API, and the open dataset. Nothing was taken out of that to make room for a price.
One paid add-on exists, and it is for the people who support many agencies at once rather than for the agencies themselves: the program report bundle packages every agency in a program as one archive of those same board reports, under the program's own name and logo. The prices are on that page.
Buying it changes nothing about the scoring. A purchase buys no influence over grades, methodology, or which agencies are listed, and the bundle's numbers are the ones already published here. Sponsorship works the same way.
Who maintains it
Built and maintained by Chelsea Kelly-Reif, starting from the transit systems in Davis, California. It is open source under a public repository; contributions and corrections are welcome, and any agency can ask to be added or removed under the listing and removal policy. Organizations that want to help cover the hosting and data costs can read how on the support page.
What this site records about a visit
The site uses two measurement tools, PostHog and Google Analytics 4. One script loads both. It loads neither if you opt out with the link at the foot of every page, or if your browser sends Global Privacy Control or Do Not Track. The purpose is to learn which pages people land on and whether the paid bundle page is reached and acted on.
PostHog
PostHog counts page views. For each one it records the page opened (the path only, never the part of the address after a question mark or a hash), the family the page belongs to (home, agency, program, bundle, support, fix guide, directory, or other), and the domain of the site that linked here. It records two further events: when a checkout link on the bundle page is followed, the plan that link belongs to, and when the link to the bundle page at the end of an agency's scorecard is followed. That is the whole list for PostHog.
PostHog sets no cookie, and keeps nothing on your device beyond the current tab. A random visit id lives in the tab's session storage and is discarded when the tab closes, so two visits cannot be joined and no profile is built. Nothing you type is recorded: the script never reads a form or the page text, and the setup form after checkout, including the email address on it, is marked so that no measurement tool can read it. There is no session recording and no fingerprinting.
The events go to PostHog Cloud US, run by PostHog Inc. in the United States. As with any web request, PostHog's servers receive your IP address and browser identifier to deliver the request; the project is configured to discard the IP address rather than store it with the event. PostHog keeps the events for one year on the plan this project uses.
Google Analytics 4
Google Analytics records each page you open and how you use it. It gets the page path, again without the part after a question mark or a hash, and the page title. For the site that linked here, it gets only that site's main address. It also records how long you stay, how far you scroll, which links to other sites you follow, and which files you download. From your browser it learns the browser name, device type, screen size, and language. Google works out a rough location, such as a city and country, from your IP address. Google Analytics does not store the IP address itself.
On the bundle page and the setup page after checkout, Google Analytics also records three steps toward a purchase: the plans were shown, a checkout link was followed, and Stripe sent a buyer back after paying. Each step carries only plan ids, their prices, and the currency. The last one also carries an order number made by hashing Stripe's order reference, so the reference itself is never sent, and nothing about the buyer is. From the checkout link until Stripe sends you back, the plan you chose is kept in the tab's session storage under the name scorecard-checkout, and the browser discards it when the tab closes.
Outside the European Economic Area, the United Kingdom, or Switzerland, Google
Analytics sets two cookies on this site. The one named _ga holds a random
id for your browser. The other, whose name starts with _ga_, keeps track of
the current visit. Both last up to two years, and they let Google tell a returning
browser from a new one.
If you are in the European Economic Area, the United Kingdom, or Switzerland, no Google Analytics cookie is set and nothing is stored on your device. The script still loads from Google and sends a short notice for each page, with no cookie and no lasting id. Google uses these notices to estimate totals.
Google's ad features are off for every visitor. Google signals and ad personalization are both off, and no ad cookie is allowed. Your visit is not tied to a Google account, and it is not used for ads.
The data goes to Google LLC in the United States. Google keeps the detailed records for 14 months and then deletes them. Totals built from them, such as page view counts, are kept longer.
Saying no
To opt out of both tools, use the “Opt out of analytics” link at the foot of any page. It turns off PostHog and Google Analytics at once, and it also deletes the Google Analytics cookies and any plan kept for a checkout. Your choice is saved in this browser on this device, in the site's local storage under the name scorecard-analytics. It stays until you opt back in or clear the site's data. The link then reads “Opt back in to analytics”, and opting back in takes effect from the next page you open.
Your browser can say no for you, too. Turn on Global Privacy Control or Do Not Track, and the script checks both signals before it does anything. When either is set, it sends nothing to PostHog and loads nothing from Google. You can also block requests to us.i.posthog.com, www.googletagmanager.com, and google-analytics.com. Every part of the site works the same either way.
The project does not sell this data or share it beyond the two services named here. The script is the full record of what the site asks for and is published at web/src/measure.js. The decisions behind it are ADR 0055 for PostHog and ADR 0056 for Google Analytics.