Legal Notice & Privacy Policy
Last updated: August 2026. This Legal Notice and Privacy Policy outlines how Go2Auth ("we", "our", or "us") operates, processes data, and governs the use of our passwordless authentication service.
1. Overview & Service Scope
Go2Auth is a closed, zero-dependency authentication ecosystem providing lightning-fast passwordless email verification via simple API integration and webhooks. We adhere strictly to minimalism and data minimization principles.
2. Privacy Policy & Data Minimization
Our core priority is absolute user privacy. Unlike traditional authentication providers, Go2Auth is engineered not to store personal or sensitive user data:
- No Plaintext Email Storage: End-user email addresses are never stored as plaintext in our database. They are processed exclusively using one-way cryptographic salted hashing.
- Transit-Only Processing: Plaintext email addresses appear only in transit during the initial authentication phase (inside the magic link and immediate webhook payload) so your backend can map the user securely.
- No Third-Party Trackers: We do not employ third-party analytics trackers, marketing pixels, or external SDKs.
3. Cookie Policy (Strictly Necessary HTTP Cookies)
No Tracking Cookies & No Consent Banner Required
Go2Auth does not use advertising, tracking, or analytics cookies. Due to using exclusively strictly necessary technical cookies, no cookie consent banner is required.
We utilize exclusively a single, secure, domain-specific HTTP-only cookie with a 30-day lifespan solely for session management on the client side. This cookie is strictly necessary for the technical operation of the authentication proxy model, eliminating the requirement for permanent email storage in our database. Under applicable ePrivacy regulations, because this cookie is strictly necessary for the service requested by the user, prior consent or a cookie consent banner is not required.
4. Service Usage & Authentication Workflow
Using Go2Auth involves specific operational components managed by developers and site owners:
- Magic Link Authentication: Users initiate authentication via simple links containing public API keys (
pk=PUBLIC_API_KEY). Requests are protected against bots using strict token rate-limiting. - Service Configuration: Account administrators can configure service parameters through our dashboard interface, including:
- Brand Name customization
- Webhook Endpoint URL configuration
- Return URL settings
- Interface Language selection (supporting 26 languages)
5. Subscriptions, Upgrades, Cancellation & Consumer Rights
Go2Auth offers transparent pricing tiers (Free Tier with standard limits, e.g., 1,500 requests/month, and Pro Access at $6/month featuring unlimited webhooks, custom branding, and full language support).
Secure Payment Processing via Paddle: All subscription payments, upgrades, billing transactions, and global tax compliance are securely handled by our official merchant of record and payment partner, Paddle. Paddle ensures a seamless, secure checkout experience for all supported payment methods and invoicing requirements.
Consumer Right of Withdrawal (B2C / EU Consumers)
If you purchase a Pro subscription as a consumer (natural person acting outside their trade, business, or profession) residing in the European Union, you acknowledge and agree that digital services begin immediately upon successful subscription and activation. By initiating the service, you expressly consent to the immediate performance of the contract and acknowledge that you thereby lose your statutory 14-day right of withdrawal.
Cancellation Policy
You may cancel your Pro subscription at any time through your account interface. Upon cancellation:
- Your Pro features and current plan remain fully active until the end of your current billing cycle. You will not lose access immediately.
- Once the billing cycle concludes, your account is automatically transitioned to the Free plan tier with standard usage limits.
6. Security & Secret Key Management
Webhooks transmit event notifications securely via signed POST requests using X-Signature headers. Administrators are responsible for securing their WEBHOOK_SECRET_KEY.
Our dashboard provides a secure mechanism to renew or update secret keys if compromised. Re-renewing immediately overwrites the current key; future webhooks signed with the old key will subsequently fail verification.
7. Service Provider & Contact
The service is operated by Zsidi László (Sole Proprietor).
- Address: 8800 Nagykanizsa, Kodály Zoltán utca 8/A, Hungary
- Contact Email: laszlo@zsidi.com
- GitHub:
8. Hosting & Infrastructure Provider (Data Processor)
Our service infrastructure, API endpoints, and data storage are hosted on Virtual Private Servers (VPS) provided by our infrastructure partner:
- Company Name: ByteFly Kft.
- Registered Address: 9022 Győr, Batthyány tér 6. 1. em. 6. ajtó, Hungary
- Tax Number: 32192236-2-08 (EU VAT: HU32192236)
- Company Registration Number: 08-09-035442
- Contact: info@vipy.hu | Phone (urgent): +36 29 200 368
- Role: Acts as our data processor, securely hosting the application infrastructure under strict data protection standards.