Documentation

Go2.ws Privacy Policy

Last updated: 4 August 2026

We collect the information needed to create accounts, run links and QR codes, keep go2.ws secure and understand whether the service is working properly.

We do not sell your personal information. We do not use it to build advertising profiles.

AWS Cognito provides account registration and sign-in. Like most online services, we also keep limited technical records when someone creates or follows a link.

Questions or privacy requests can be sent to dpo@go2.ws.

1. A quick introduction

go2.ws is an independent online service operated from the United Kingdom.

For data protection purposes, go2.ws and its operator decide how and why personal information is used through the service.

This policy explains what we collect, why we need it and the choices available to you. It is a privacy notice, not something we ask you to consent to as a whole.

2. Information we collect

When you create an account

We collect account information such as your email address, account identifier, sign-in activity and any profile details you choose to provide.

Account registration and authentication are provided through Amazon Web Services Cognito. Cognito stores and verifies account credentials so go2.ws does not need to store your password in readable form.

When you create links, QR codes or use the API

We process:

Please do not place passwords, authentication tokens or sensitive personal information inside a short code or destination URL.

When someone follows a link or visits go2.ws

Our systems may record technical information such as:

We use this information to deliver the redirect, protect visitors, detect abuse, investigate faults and produce service or link statistics where available.

When you contact us

We keep your message, contact details and any information you provide so we can respond and keep an appropriate record of the conversation.

3. Why we use information

We use personal information to:

We do not use a working link as proof that its destination is safe, and automated checks will not identify every threat.

4. Our legal reasons

Depending on the situation, we use information because:

Where we rely on legitimate interests, we consider the purpose, whether the processing is necessary and its effect on people’s rights.

5. Who helps us run go2.ws

We use trusted service providers to operate go2.ws. This currently includes Amazon Web Services, including AWS Cognito for account registration and authentication and AWS infrastructure for parts of the service.

These providers process information for us under their own security and contractual commitments. We may also share limited information:

We do not sell personal information.

6. International processing

go2.ws is available globally and some providers operate internationally. Information may therefore be processed outside the country where you live.

Where data-protection law requires safeguards for an international transfer, we use the safeguards made available by our providers or another lawful transfer mechanism.

7. Cookies and local storage

go2.ws may use cookies or similar browser storage where needed for sign-in, security, preferences and the basic operation of the service.

For example, the service may use browser storage to remember theme choices, reuse a recently generated anonymous short URL in the same browser, keep an admin sign-in session, or remember interface preferences.

We do not currently use this technology for third-party advertising. If we introduce non-essential analytics, advertising or similar tracking, we will update this policy and request consent where the law requires it.

8. How long we keep information

We keep account information while an account remains open and for a reasonable period afterwards where needed for security, recovery, disputes or legal obligations.

Links, uploaded QR design images, redirect records, API logs, rate-limit records and abuse reports may be kept for different periods depending on their purpose. Rate-limit records are intended to expire automatically after a short operational period. Security and abuse records may be retained for longer when needed to protect the service, prevent repeat misuse or comply with law.

Deleted information may remain in protected backups until those backups are safely replaced. We do not keep personal information for longer than reasonably necessary for the purpose for which it was collected.

9. Your choices and rights

Depending on where you live and why we use your information, you may have the right to:

These rights are not absolute, and sometimes the law allows or requires us to retain information.

To make a request, email dpo@go2.ws. We may need to confirm your identity before acting.

10. Children

You must be at least 18 years old and legally able to agree to the Terms where you live to create links, hold an account or use the API.

Visitors of any age may encounter a go2.ws link. We do not knowingly invite children to create accounts or links. If you believe a child has provided account information in breach of our Terms, contact dpo@go2.ws.

11. Keeping information secure

We use technical and organisational measures intended to protect personal information, including managed authentication and access controls.

No online system can promise perfect security. Please protect your sign-in details and API credentials, and tell us promptly if you think they have been compromised.

12. Changes and contact

We may update this policy when the service, our providers or the law changes. The latest version will always show its date.

For privacy, safety, legal or general enquiries, contact:

Email: dpo@go2.ws