Go2.ws Privacy Policy
Last updated: 4 August 2026
We collect the information needed to create accounts, run links and QR codes, keep go2.ws secure and understand whether the service is working properly.
We do not sell your personal information. We do not use it to build advertising profiles.
AWS Cognito provides account registration and sign-in. Like most online services, we also keep limited technical records when someone creates or follows a link.
Questions or privacy requests can be sent to dpo@go2.ws.
1. A quick introduction
go2.ws is an independent online service operated from the United Kingdom.
For data protection purposes, go2.ws and its operator decide how and why personal information is used through the service.
This policy explains what we collect, why we need it and the choices available to you. It is a privacy notice, not something we ask you to consent to as a whole.
2. Information we collect
When you create an account
We collect account information such as your email address, account identifier, sign-in activity and any profile details you choose to provide.
Account registration and authentication are provided through Amazon Web Services Cognito. Cognito stores and verifies account credentials so go2.ws does not need to store your password in readable form.
When you create links, QR codes or use the API
We process:
- destination URLs and generated short codes;
- link and gateway settings;
- QR-code settings while generating a QR code;
- uploaded images used in QR-code designs;
- the account connected with managed links;
- API credentials;
- creator IP address, rate-limit records and request records; and
- timestamps, error records and other information needed to operate the feature.
Please do not place passwords, authentication tokens or sensitive personal information inside a short code or destination URL.
When someone follows a link or visits go2.ws
Our systems may record technical information such as:
- the go2.ws link requested;
- IP address;
- date and time;
- browser, device and operating-system information;
- referring page, where it is provided; and
- redirect, gateway, security and error information.
We use this information to deliver the redirect, protect visitors, detect abuse, investigate faults and produce service or link statistics where available.
When you contact us
We keep your message, contact details and any information you provide so we can respond and keep an appropriate record of the conversation.
3. Why we use information
We use personal information to:
- provide accounts, links, QR codes, redirects and API access;
- remember settings and authenticate users;
- operate the safety gateway;
- detect phishing, malware, fraud, spam and other abuse;
- protect go2.ws, its users and the wider internet;
- diagnose faults and improve reliability;
- respond to questions, reports and legal requests; and
- meet legal and regulatory obligations.
We do not use a working link as proof that its destination is safe, and automated checks will not identify every threat.
4. Our legal reasons
Depending on the situation, we use information because:
- it is needed to provide the service you requested and meet our Terms;
- it supports our legitimate interests in running, securing and improving go2.ws;
- we need to meet a legal obligation; or
- you have given specific consent, where consent is required.
Where we rely on legitimate interests, we consider the purpose, whether the processing is necessary and its effect on people’s rights.
5. Who helps us run go2.ws
We use trusted service providers to operate go2.ws. This currently includes Amazon Web Services, including AWS Cognito for account registration and authentication and AWS infrastructure for parts of the service.
These providers process information for us under their own security and contractual commitments. We may also share limited information:
- with security services used to identify harmful destinations or activity;
- with professional advisers when reasonably necessary;
- with authorities or affected parties where required or permitted by law; or
- as part of a sale, transfer or reorganisation of the go2.ws service.
We do not sell personal information.
6. International processing
go2.ws is available globally and some providers operate internationally. Information may therefore be processed outside the country where you live.
Where data-protection law requires safeguards for an international transfer, we use the safeguards made available by our providers or another lawful transfer mechanism.
7. Cookies and local storage
go2.ws may use cookies or similar browser storage where needed for sign-in, security, preferences and the basic operation of the service.
For example, the service may use browser storage to remember theme choices, reuse a recently generated anonymous short URL in the same browser, keep an admin sign-in session, or remember interface preferences.
We do not currently use this technology for third-party advertising. If we introduce non-essential analytics, advertising or similar tracking, we will update this policy and request consent where the law requires it.
8. How long we keep information
We keep account information while an account remains open and for a reasonable period afterwards where needed for security, recovery, disputes or legal obligations.
Links, uploaded QR design images, redirect records, API logs, rate-limit records and abuse reports may be kept for different periods depending on their purpose. Rate-limit records are intended to expire automatically after a short operational period. Security and abuse records may be retained for longer when needed to protect the service, prevent repeat misuse or comply with law.
Deleted information may remain in protected backups until those backups are safely replaced. We do not keep personal information for longer than reasonably necessary for the purpose for which it was collected.
9. Your choices and rights
Depending on where you live and why we use your information, you may have the right to:
- ask for a copy of your personal information;
- correct inaccurate information;
- ask us to delete or restrict information;
- object to particular uses;
- receive certain information in a portable format; or
- withdraw consent where we rely on consent.
These rights are not absolute, and sometimes the law allows or requires us to retain information.
To make a request, email dpo@go2.ws. We may need to confirm your identity before acting.
10. Children
You must be at least 18 years old and legally able to agree to the Terms where you live to create links, hold an account or use the API.
Visitors of any age may encounter a go2.ws link. We do not knowingly invite children to create accounts or links. If you believe a child has provided account information in breach of our Terms, contact dpo@go2.ws.
11. Keeping information secure
We use technical and organisational measures intended to protect personal information, including managed authentication and access controls.
No online system can promise perfect security. Please protect your sign-in details and API credentials, and tell us promptly if you think they have been compromised.
12. Changes and contact
We may update this policy when the service, our providers or the law changes. The latest version will always show its date.
For privacy, safety, legal or general enquiries, contact:
Email: dpo@go2.ws