Privacy Policy
Last updated: 19 July 2026
Go2Payments ("we", "us") is operated by Autify Digital Ltd, a company registered in England and Wales (company no. 12782507) with its registered office at Cumberland House, 35 Park Row, Nottingham, NG1 6EE. This policy explains what personal data we process when you use our website and service — which lets businesses collect card payments on their Xero invoices and through standalone payment links — and the choices you have. For anything privacy-related, contact us at helpdesk@autify.co.uk.
Who this policy covers
- Merchants — businesses that create an account and connect their Xero organisation.
- Payers — a merchant's customers, who pay an invoice or make an ad-hoc payment through one of our payment pages.
- Visitors — anyone browsing this website.
What we collect and why
Merchant account data
Your name, email address, company name, role, and password (stored hashed). If you sign up or sign in with Xero, we also receive your name, email address and Xero user ID from Xero's identity service. We use this to provide and secure your account (performance of our contract with you). For this data we act as a data controller.
Xero data
When you connect a Xero organisation you authorise us, via OAuth, to access your invoices, contacts and account settings. This can include your customers' names, email addresses and billing details as they appear on invoices. We access this data only to operate the service — showing invoices, creating payment links, pre-filling payment pages, and posting payments and refunds back to Xero. We act as a processor of this data on the merchant's behalf; the merchant remains the controller. OAuth tokens are stored encrypted, and are revoked and deleted when you disconnect. We never sell this data or use it for advertising.
Payment data
Card payments are processed by the merchant's own payment provider (for example Tyl by NatWest or Lloyds Cardnet, operating on Fiserv infrastructure) on that provider's secure hosted payment page. Card numbers never touch our servers and we do not store them. We store the transaction outcome: amount, currency, status, a transaction reference, and the payer name/email where the payment provider or invoice supplies them, so that payments can be reconciled to invoices and refunds handled. On some payment pages (for example a merchant's open "pay now" page) we ask the payer directly for their name, email address and a payment reference, which we use to record the payment, send confirmation, and pass to the merchant and their payment provider.
Technical data and cookies
We use strictly necessary cookies only: a session cookie and a security (CSRF) token. We do not use advertising or analytics cookies. Public payment pages may be protected by Cloudflare Turnstile to block automated abuse, which processes limited technical data (such as IP address and browser characteristics) for that purpose. Our server logs record requests, including IP addresses, for security and troubleshooting (legitimate interests).
Who we share data with
- Xero — to read invoices and write payments/refunds you initiate.
- Your payment provider (e.g. Tyl by NatWest, Lloyds Cardnet / Fiserv) — to create payment sessions and process refunds you initiate.
- Infrastructure providers — hosting and email delivery, under data-processing agreements.
- Authorities, where the law requires it.
We never sell personal data.
International transfers
We aim to keep data in the UK/EEA. Where a provider processes data elsewhere, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses.
How long we keep data
- User account data (name, email, login) — until you delete your login from your profile page, then deleted. Deleting a login does not close the merchant's account: the organisation's data (connections, payment links, transaction history) is retained until the merchant's account is closed via helpdesk@autify.co.uk, then deleted or anonymised.
- Xero OAuth tokens — deleted immediately on disconnect.
- Transaction records — retained for up to 6 years to meet accounting and legal obligations.
- Server logs — kept for a short rolling period for security purposes.
Security
All traffic is encrypted in transit (TLS). OAuth tokens and payment-gateway credentials are encrypted at rest. Access to production systems is restricted, and inbound webhooks are verified by cryptographic signature before being trusted.
Your rights
Under UK GDPR you can ask us for access to, correction or deletion of your personal data, restriction of or objection to its processing, and portability. Email helpdesk@autify.co.uk and we'll respond within one month. If you're a merchant's customer, we may refer your request to the merchant, since they control their invoicing data. You can also complain to the UK Information Commissioner's Office (ico.org.uk).
Changes
We'll post any changes to this policy on this page and, for material changes, notify merchants by email or in-app notice.