Privacy Policy

Last updated: 19 July 2026

Go2Payments ("we", "us") is operated by Autify Digital Ltd, a company registered in England and Wales (company no. 12782507) with its registered office at Cumberland House, 35 Park Row, Nottingham, NG1 6EE. This policy explains what personal data we process when you use our website and service — which lets businesses collect card payments on their Xero invoices and through standalone payment links — and the choices you have. For anything privacy-related, contact us at helpdesk@autify.co.uk.

Who this policy covers

What we collect and why

Merchant account data

Your name, email address, company name, role, and password (stored hashed). If you sign up or sign in with Xero, we also receive your name, email address and Xero user ID from Xero's identity service. We use this to provide and secure your account (performance of our contract with you). For this data we act as a data controller.

Xero data

When you connect a Xero organisation you authorise us, via OAuth, to access your invoices, contacts and account settings. This can include your customers' names, email addresses and billing details as they appear on invoices. We access this data only to operate the service — showing invoices, creating payment links, pre-filling payment pages, and posting payments and refunds back to Xero. We act as a processor of this data on the merchant's behalf; the merchant remains the controller. OAuth tokens are stored encrypted, and are revoked and deleted when you disconnect. We never sell this data or use it for advertising.

Payment data

Card payments are processed by the merchant's own payment provider (for example Tyl by NatWest or Lloyds Cardnet, operating on Fiserv infrastructure) on that provider's secure hosted payment page. Card numbers never touch our servers and we do not store them. We store the transaction outcome: amount, currency, status, a transaction reference, and the payer name/email where the payment provider or invoice supplies them, so that payments can be reconciled to invoices and refunds handled. On some payment pages (for example a merchant's open "pay now" page) we ask the payer directly for their name, email address and a payment reference, which we use to record the payment, send confirmation, and pass to the merchant and their payment provider.

Technical data and cookies

We use strictly necessary cookies only: a session cookie and a security (CSRF) token. We do not use advertising or analytics cookies. Public payment pages may be protected by Cloudflare Turnstile to block automated abuse, which processes limited technical data (such as IP address and browser characteristics) for that purpose. Our server logs record requests, including IP addresses, for security and troubleshooting (legitimate interests).

Who we share data with

We never sell personal data.

International transfers

We aim to keep data in the UK/EEA. Where a provider processes data elsewhere, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses.

How long we keep data

Security

All traffic is encrypted in transit (TLS). OAuth tokens and payment-gateway credentials are encrypted at rest. Access to production systems is restricted, and inbound webhooks are verified by cryptographic signature before being trusted.

Your rights

Under UK GDPR you can ask us for access to, correction or deletion of your personal data, restriction of or objection to its processing, and portability. Email helpdesk@autify.co.uk and we'll respond within one month. If you're a merchant's customer, we may refer your request to the merchant, since they control their invoicing data. You can also complain to the UK Information Commissioner's Office (ico.org.uk).

Changes

We'll post any changes to this policy on this page and, for material changes, notify merchants by email or in-app notice.