Privacy
How personal data is handled
way2.me uses personal data only for the purpose for which it was provided, to operate and protect the website, and - only after consent - to measure site usage.
Controller and privacy contact
The operator of way2.me is responsible for the processing described here. Privacy requests can be sent to mail@way2.me.
Inquiries, offers and email
When you contact us or submit an offer, we process the details you provide, such as your name, email address, optional company and phone details, the relevant domain, offer amount and message. We use this information only to receive, review, answer and administer that specific inquiry or potential transaction. We do not add these addresses to marketing lists without a separate legal basis.
Offer data and its communication history are stored with the relevant inquiry. Contact form messages, their submission and consent timestamps, and our replies and email sending status are stored in our support inbox. Notifications and replies are delivered by email. Email delivery providers, hosting providers, database providers and - if a transaction proceeds - escrow and transfer providers process data only as needed to provide their services.
Security and abuse prevention
To protect forms and private offer access, shortened non-reversible hashes derived from an IP address or user-agent value may be stored. Server providers may also process ordinary request and security logs. These values are used for rate limiting, abuse prevention, troubleshooting and service security, not for advertising.
Aggregate referral measurement
way2.me records daily aggregate counts for recognized referral channels such as Google, Bing, ChatGPT, Copilot or another referring host. This limited aggregation does not set an analytics cookie, store a full referring URL or create a visitor profile.
Cookies and first-party analytics
A necessary first-party cookie named way2_cookie_consent stores consent version 3, your analytics choice and decision time for up to six months. It is required to remember your choice.
If you allow analytics, way2_analytics_visitor stores a random pseudonymous visitor ID for up to six months and way2_analytics_session keeps a session active for 30 minutes after the latest recorded event. Both cookies are first-party, are not available to client-side scripts and are not used for advertising.
First-party analytics records page paths, page visits, navigation, outbound links, explicitly marked calls to action, scroll milestones, timestamps, the referring host, permitted UTM source and campaign values, the site host, and broad device and browser categories. The request IP is used transiently in the application to look up an approximate country, region and city in a locally hosted GeoLite2 City database; the IP, coordinates and full address are not stored. Location results are approximate and can be missing or incorrect. It does not record form values, passwords, messages, mouse movements, screenshots, full page content or session replays. Email addresses and browser fingerprints are not stored in the analytics tables.
This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.
Purpose, legal basis and retention
First-party analytics is used to understand portfolio demand, navigation problems and conversion paths. It relies on consent. Raw analytics events are removed after 90 days. Pseudonymous visitor and session records are retained for no longer than 13 months. Inquiry and transaction data is retained only while needed for the relevant request, legal obligations and claims.
You can withdraw analytics consent at any time through “Cookie settings” in the footer. Withdrawal immediately stops future recording and removes the analytics cookies from the browser. Previously collected data remains subject to the stated retention period unless deletion is required or requested under applicable law.
Recipients and transfers
The analytics implementation and GeoLite2 lookup are operated by way2.me within the existing application, local database file and PostgreSQL database. If operator notifications are enabled, Discord receives a final summary after 30 minutes without session activity: new or returning status, time and duration, hosts and page paths, event counts, acquisition labels, broad device and browser categories, and the approximate location result. Discord does not receive IP addresses, coordinates, form values, email addresses, passwords, messages, cookies, full visitor identifiers or replay data through this alert. The protected admin link contains the session identifier needed to open the timeline. No advertising network or tracking pixel receives analytics events. Hosting, database and notification infrastructure providers process data only to operate the service under their applicable safeguards; Discord may process data in other countries as described in its privacy information.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, or withdraw consent for future processing. You may also complain to the competent data protection authority. We do not sell personal data or use inquiry addresses for unrelated advertising.