Skip to main content

Help us improve the Digital Marketplace - send your feedback

R2C ONLINE LIMITED

Fleet Management Software

r2c Online is a cloud-based fleet and workshop management platform. It enables organisations to track vehicles, schedule maintenance, manage jobs, monitor technician performance, store compliance records securely, and communicate with internal teams and external repairers, improving efficiency, accuracy, and visibility across all fleet and workshop operations.

Features

  • Cloud-based browser platform for fleet and workshop management
  • Real-time tracking of vehicles, jobs, and maintenance
  • Digital job cards with defect reporting and updates
  • Mobile app for drivers, offline capable
  • API integrations with external systems
  • Secure document library for inspections and compliance records
  • Customisable reporting and data export
  • Workshop scheduling and technician workload management
  • Communication with external repairers via r2c network
  • Audit trail with time-stamped actions for accountability

Benefits

  • Manage fleet and workshop operations from any browser, anywhere
  • Track vehicles, jobs, and maintenance in real time
  • Create and update digital job cards and defect reports instantly
  • Complete and update jobs on the move
  • Integrate seamlessly with finance and operational systems
  • Access compliance and inspection records securely
  • Plan workloads and optimise technician utilisation
  • Produce reports quickly for operational decision-making
  • Communicate directly with repairers across r2c network
  • Ensure accountability through full time-stamped audit trails

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at elliott.frost-palmer@corpay.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 2 9 3 1 0 6 4 2 4 8 6 5 8 4

Contact

R2C ONLINE LIMITED Elliott Frost-Palmer
Telephone: 07519997687
Email: elliott.frost-palmer@corpay.com

About the service

Service categories

Applications

Supply chain management

  • Logistics and transportation management
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
The service has minimal constraints for buyers. As a cloud-hosted, browser-based solution, it does not depend on specific hardware configurations and can be accessed from standard devices with a modern web browser. Internet connectivity is required for all areas of the solution except the driver pre-use check app, which can operate offline. Planned maintenance may occasionally be required to apply updates or improvements; this is scheduled outside normal business hours wherever possible, with advance notice provided. Standard support is available Monday to Friday, with limited weekend support unless otherwise agreed.
System requirements
  • Internet Connection
  • Laptop, Desktop, or Tablet

User support

Email or online ticketing support
Yes
Support response times
Support is available Monday to Friday during business hours. Response times depend on issue priority. Priority 1 issues, affecting more than 5% of users or causing system-wide outages, receive a response within 1 hour and are resolved within 4 business hours. Priority 2 issues receive a response within 4 hours and are resolved within 48 business hours. Priority 3 and 4 issues, which do not impact core functionality or are cosmetic, receive a response within 4 hours and are reviewed for future development. Requests raised at weekends are responded to on the next business day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
The r2c web chat is accessible directly within the platform and enables users to communicate in real time with a member of the r2c Support Team during support hours. Users can use live chat to ask questions, raise issues, log support tickets, and submit queries requiring technical or operational support. The service is intended for guidance, troubleshooting, and issue reporting. While support staff can investigate and resolve issues or escalate them as appropriate, requests relating to system changes or enhancements may require formal assessment and cannot always be actioned immediately via web chat.
Web chat accessibility testing
The r2c web chat has not yet been formally tested with assistive technology users. However, accessibility has been considered in the design of the platform, and the web chat uses standard, widely supported web components that are compatible with common assistive technologies such as screen readers and keyboard navigation. We recognise the importance of inclusive access and are committed to undertaking formal accessibility testing with assistive technology users and making improvements where required as part of our ongoing product development and continuous improvement approach.
Onsite support
Yes, at extra cost
Support levels
We provide structured support levels designed to meet differing customer needs. All customers receive access to standard remote support during business hours, including issue logging, troubleshooting, and incident management in line with agreed response priorities. In addition, all customers are assigned a dedicated Account Manager who acts as the primary point of contact, oversees service delivery, and coordinates support and escalation activities.

Where required, on-site training and support from experienced support staff or engineers can be provided. On-site support is typically priced at £1,500 per day. This can include user training, operational support, or technical assistance. Technical account management is included as part of the standard service and does not incur an additional charge.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We provide flexible and comprehensive support to help users start using r2c quickly and effectively. Our onboarding approach is tailored to an organisation’s preferred method of learning, ensuring all users can confidently access and navigate the platform.
Training can be delivered online, allowing users to join live sessions from any location, interact with trainers, and ask questions in real time. Alternatively, we can provide on-site training, where our trainers visit the organisation to deliver practical, hands-on guidance tailored to the team’s specific workflow and processes. This ensures that both office-based and field staff, such as drivers or mobile technicians, fully understand how to use the system in their daily operations.
In addition to live training, we provide comprehensive user documentation covering all key features of the platform, including job management, scheduling, reporting, defect tracking, compliance records, and communication tools. The documentation is clear, easy to follow, and can be referred to at any time, helping new users become self-sufficient quickly.
Our flexible approach ensures organisations can choose the training method that works best for them, supporting a smooth adoption of the platform and maximising efficiency, accuracy, and productivity from the outset.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When the contract ends, users are provided with read-only access to their r2c platform at no extra cost. During this time, they can download and extract their data directly from the system in standard formats for their own records or migration to another solution. No data can be modified during this period, ensuring data integrity while allowing users full access to retrieve their information.
End-of-contract process
At the end of the contract, the service transitions into an agreed off-boarding period. During this time, customers are given read-only access to their r2c account so they can download and extract all required data. No changes can be made to the system during this period, ensuring data integrity.

The end-of-contract process and read-only access are included in the contract price. Secure decommissioning of the account and data deletion in line with data protection and retention policies is also included.

Any additional support requested during off-boarding, such as bespoke data exports, extended access periods, or consultancy support, would be chargeable separately if required.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is accessible online through the platform or available as a downloadable PDF. This allows users to access guidance at any time, on any device. The materials provide clear, step-by-step instructions to support system use, account setup, and secure offboarding, ensuring consistent and easy-to-follow processes for all users.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The driver app is designed specifically for mobile devices, enabling users to complete tasks such as pre-use vehicle checks while offline, in the field, or on the move. In contrast, the desktop service is browser-based and provides full access to the platform’s core functionality, including reporting, administration, configuration, and analytics. While the mobile app focuses on task completion and data capture, the desktop version is intended for management, oversight, and detailed interaction with the system. Both platforms synchronise data automatically when the mobile app reconnects to the internet, ensuring consistency across mobile and desktop environments.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service provides a user-friendly interface accessible via both web browser and mobile app.

The web interface is designed for desktop use, offering full access to all platform features, including administration, reporting, configuration, analytics, and user management. It is browser-based, requiring no additional software or plugins, and supports standard desktop navigation, filtering, and data export functions.

The mobile app, designed for drivers and field users, focuses on task completion, such as pre-use vehicle checks, and can operate offline, syncing data automatically when internet connectivity is restored. Both interfaces are intuitive, consistent, and ensure seamless interaction across devices.
Accessibility standards
None or don’t know
Description of accessibility
Our service is designed to be accessible to a wide range of users. The web interface is browser-based and supports standard accessibility features such as keyboard navigation, screen readers, and adjustable browser zoom and contrast settings. The mobile app is designed for ease of use in the field, with a clear, simple layout for task completion. All users can access core functionality, including reporting, administration, and data entry, without the need for specialist hardware or software. Accessibility considerations have been integrated into the design to support users.
Accessibility testing
We have not yet conducted formal testing of the service interface with users of assistive technology. However, accessibility considerations have been incorporated into the design, including support for standard screen readers, keyboard navigation, and browser accessibility features. The interface uses widely supported web components to ensure compatibility with assistive tools. We are committed to conducting formal accessibility testing with assistive technology users in the future and to making any necessary improvements, ensuring the platform remains inclusive and usable for all users, including those with visual, motor, or other accessibility needs.
API
Yes
What users can and can't do using the API
Our service provides a set of APIs, including the Finance API, Jobsheet API, and Asset Update API, with additional APIs continually being developed.

What users can do:

Setup: Users can configure integrations and automate workflows by connecting their systems to our APIs. This includes creating jobsheets, updating asset information, and accessing finance-related data.

Changes: Users can update records, submit new data, and retrieve information programmatically, enabling automation and seamless integration with existing systems.

Limitations:

Certain administrative configurations, such as user permissions or system-wide settings, cannot be modified through the API and must be managed via the web interface.

API usage may be subject to rate limits to ensure system stability.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the system through both the web interface and supported APIs within defined limits.

Customisation capabilities include:

Asset fields: Users can add or modify up to 50 existing asset fields to capture the data they need.

Users: New users can be added to the system.

Authorisation limits and roles: Users can adjust authorisation thresholds and customise user roles to match organisational requirements.

Who can customise:

Only administrator-level users have the permissions required to make these customisations, ensuring control over changes that affect system configuration and security.

This ensures flexibility while maintaining appropriate governance and security.

Scaling

Independence of resources
R2c ensure users are not affected by demand from other customers through a combination of cloud-based architecture, resource isolation, and active monitoring. The service is hosted in a private, managed cloud environment, with customer data logically isolated to prevent cross-tenant impact. Platform resources are scaled to meet demand, and performance is continuously monitored to identify and address potential bottlenecks.

Analytics

Service usage metrics
Yes
Metrics types
The service provides a range of metrics to support transparency, performance monitoring, and operational oversight. These include system availability and uptime, incident and support ticket volumes, response and resolution times against agreed priority levels, and platform usage metrics such as active users and feature adoption. Operational metrics are also available through reporting, including job completion rates, asset status, and compliance data where applicable.
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from the r2c platform using built-in standard reports and export tools available through the web interface. Data can be downloaded in standard formats, such as CSV, excel, word enabling easy analysis, reporting, or migration to other systems. We also have data lakes available that can extract and process data via flat files or APIs.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
R2c Online provides a secure, cloud-hosted environment with continuous monitoring to ensure high availability. We use reasonable endeavours to maintain 99.9% uptime annually, excluding scheduled maintenance, updates, or events beyond our control (e.g., force majeure, third-party failures, or security incidents).

Incidents are reported through our Helpdesk during standard hours (08:00–17:30, Monday to Friday), with priority-based response times.

While we do not normally provide refunds if guaranteed availability is not met, our SLA ensures rapid response and resolution of service issues. Users are supported with guidance, workarounds, and escalation procedures to minimise disruption. Scheduled maintenance is typically outside core business hours to reduce impact, and advance notice is provided for updates or changes affecting the service.

This approach ensures that users can rely on the platform for operational continuity and rapid support in line with public sector expectations.
Approach to resilience
Detailed information on our data centre setup, redundancy, and resilience measures is available on request.
Outage reporting
In the event of a service outage, r2c provides email notifications to affected users. All incidents are logged and communicated promptly via email, including updates on resolution progress and expected restoration times.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces within the platform is restricted through role-based user permissions, ensuring users can only view or manage functions appropriate to their role. Administrative and configuration features are limited to authorised users only.
Access to support channels is also controlled. Customers provide a list of authorised users, and only those users are permitted to raise support queries or interact with the support team. This ensures support requests are validated, prevents unauthorised access, and maintains appropriate governance over system changes and issue escalation.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Here at r2c Online we follow a comprehensive set of information security policies and processes aligned with ISO/IEC 27001, which governs how we manage, monitor, and continually improve information security across all services. These policies cover areas such as access control, risk management, incident response, data protection, and supplier security.

Information security is overseen by a named board-level Compliance Director, who has overall responsibility and authority. Day-to-day security management is supported by defined roles and responsibilities across the organisation. Compliance with policies is ensured through regular risk assessments, internal audits, staff training, and ongoing monitoring. Security incidents are formally logged, reviewed, and escalated in line with our ISO 27001 incident management process, ensuring accountability and continuous improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our configuration and change management processes align with ITIL 4 and are supported by ISO27001 and Cyber Essentials compliance, using techniques compatible with CSA guidance. Service components are tracked throughout their lifecycle using documented configurations, version control, and change records. Cloud-facing applications follow a three-tier architecture with segregation of duties between development, testing, and production. All changes are formally assessed for operational and security impact before approval, tested in non-production environments, and deployed in a controlled manner to ensure service stability, security, and compliance.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management approach is supported by a SOX-audited control environment and a secure software development lifecycle (SDLC). Potential threats are assessed through continuous monitoring, regular code reviews, and engagement with regional information security specialists during product development. All changes are tracked through their lifecycle using CI/CD pipelines and code repositories, ensuring full auditability.
We operate a daily change board, enabling rapid prioritisation and deployment of security patches based on risk and severity. Patches are deployed promptly via controlled CI/CD processes. Threat intelligence is informed by vendor advisories, recognised vulnerability databases, industry guidance, and internal security assessments.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring approach uses continuous, automated monitoring and regular vulnerability scanning. We perform multiple security scans each week, frequent internal network scans using industry-standard tools, and conduct annual black box and grey box penetration testing. Threat intelligence is informed by Imperva and Rapid7. Vulnerabilities are assessed using CVSS scoring and aligned to our Priority 1–4 incident management process. Potential compromises are identified through alerts, scan results, and monitoring outputs. Critical vulnerabilities (CVSS 9+) are addressed within 4 hours, high-risk issues (CVSS 7–8.9) within 48 hours, and other findings are managed based on business risk and priority.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management approach uses documented, pre-defined processes for common incident types, maintained within Splunk. Analysts follow clear work instructions for each incident to ensure a consistent and effective response. Incidents can be reported manually by users, although the majority are machine-generated through automated monitoring and alerting. Incident reporting follows a rigorous and standardised process across the organisation. Where required, formal incident reports are produced and submitted to relevant regulatory or supervisory authorities. This ensures incidents are managed consistently, transparently, and in line with regulatory and internal governance requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We can provide a one-week trial of the service, giving users full access to the r2c platform using sample data. This allows customers to explore the system’s functionality, user interface, and key features without impacting live operations. The free trial can be provided for up to one week.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
NQA
ISO/IEC 27001 accreditation date
Tuesday 30 April 2024
What the ISO/IEC 27001 doesn’t cover
R2c Online ISO/IEC 27001 certification covers the information security management processes and controls that apply to the services, systems, and locations defined within the certified scope of our Information Security Management System (ISMS).

Items not covered are limited to activities or environments that fall outside this agreed scope, such as third-party systems not managed by R2C, customer-controlled environments, or business functions that are not directly involved in the delivery and support of our certified services.

r2c Online maintains a robust security framework and continually reviews and improves its controls to ensure effective protection of information assets and to support the ongoing secure delivery of our services.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
Bfc073da-f461-465e-971a-fc971de300e8
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at elliott.frost-palmer@corpay.com. Tell them what format you need. It will help if you say what assistive technology you use.