Published 7 October 2026 · Version 2026-10-07
Jupiter Solutions — Privacy Notice
TODO — ICO data protection fee
☐ ICO fee checker indicates £52 is payable. Before paying, check whether JUPITER SOLUTIONS LTD is already registered and the annual ICO data protection fee is already being paid. If not, complete registration/payment and record the renewal details.
Status
Launch version — B2B sales, Sales Toolkit, managed NFC redirects, support and CRM
1. Who we are
JUPITER SOLUTIONS LTD is the controller responsible for the personal data described in this Privacy Notice.
Company number: 15230488
Registered office: Avc House, 21 Northampton Lane, Swansea, Wales, SA1 4EH
Business email: info@jupitersolutionsgroup.com
Support email: support@jupitersolutionsgroup.com
This notice explains how Jupiter Solutions (“Jupiter”, “we”, “us” or “our”) uses personal data when dealing with business customers, prospective business customers, business contacts, suppliers and people who interact with Jupiter-managed NFC routes.
2. Scope of this notice
This launch notice covers:
• founder-led and representative-led B2B sales;
• the Jupiter Sales Toolkit;
• customer/business registration;
• order and payment administration;
• HubSpot CRM records;
• Google Review Card setup;
• Jupiter-controlled redirects;
• support and fault handling;
• Growth/Pro referral attribution;
• limited operational/security analytics; and
• business-to-business marketing and follow-up.
It does not describe future Customer Action Hub features, Wi-Fi capture, loyalty programmes, private-feedback collection, detailed end-customer profiling or partner advertising that has not yet been launched. We will update the notice before introducing materially different personal-data processing.
3. Personal data we may collect
Business customer and prospect data
We may collect:
• name;
• job title or role;
• business name;
• business address;
• business email address;
• business telephone/mobile number;
• correspondence and support messages;
• sales/contact history;
• products or services discussed;
• order, tier and quantity;
• payment status and transaction references;
• fulfilment/delivery information;
• referral attribution and Jupiter credit records;
• customer preferences relevant to the business relationship; and
• notes reasonably necessary to manage the account, sale or follow-up.
We generally do not need special-category personal data and ask that it is not provided unless genuinely necessary.
Business/listing data
We may store information about the business and its public Google Business Profile, including:
• business/listing name;
• address;
• Google place/listing identifiers;
• selected review destination;
• public business contact information; and
• relevant publicly available business information.
Some of this is information about a business rather than personal data. UK data-protection law applies where the information identifies or relates to an individual.
Order, NFC asset and redirect data
We may record:
• order/reference number;
• product/tier and quantity;
• NFC asset/card identifiers;
• supplier/batch information where relevant;
• programming and test status;
• redirect slug/identifier;
• destination configuration and history;
• activation, fulfilment and support status; and
• changes made to the managed destination.
Payment data
Payments may be processed by third-party payment providers such as Stripe. Jupiter may receive transaction identifiers, payment status, amount, payment method type and related order information.
We do not intend to store full payment-card numbers or card security codes in the Jupiter Sales Toolkit or HubSpot.
Redirect and operational data
When a device uses a Jupiter-managed redirect, our systems may process limited technical information needed to deliver, secure and understand the service, which may include:
• date/time of a request;
• route/redirect identifier;
• technical request information such as IP address where received by our infrastructure;
• browser/device or user-agent information;
• response/error information;
• approximate technical/geographic information derived from network data where provided by infrastructure; and
• aggregate interaction counts.
At launch, this information is intended for routing, security, troubleshooting, operational measurement and aggregate product analytics—not detailed behavioural profiling of people leaving reviews.
Support data
If you contact us, we may retain the information you provide, relevant account/order information and records of how the issue was investigated and resolved.
4. How we obtain personal data
We may obtain personal data:
• directly from you during a sales visit, registration, order or support interaction;
• from another authorised person at your business;
• from publicly available business sources, including business websites and public business listings;
• through Google Places/Google Business Profile-related services used to identify the business selected during setup;
• through our Sales Toolkit and managed redirect infrastructure;
• from HubSpot or other systems used to manage the relationship;
• from payment providers in connection with a transaction;
• through referrals; and
• from a sales representative acting for Jupiter.
Where we obtain personal data from another source rather than directly from the individual, we provide privacy information as required by applicable data-protection law.
5. Why we use personal data and our lawful bases
Orders and contract administration
Purpose: process orders, take/confirm payment, configure products, deliver/hand over cards, operate purchased functionality and provide support.
Lawful basis: performance of a contract, or steps requested before entering into a contract, where the individual is personally party to it; and/or legitimate interests where we are dealing with a representative of a business customer.
Managed redirects and product operation
Purpose: operate Jupiter-controlled routes, maintain destinations, diagnose faults, secure the service and keep the purchased product functioning.
Lawful basis: contract where applicable and/or Jupiter’s legitimate interests in delivering, securing and maintaining its B2B products.
CRM and customer relationship management
Purpose: maintain account history, remember previous interactions, manage follow-ups, provide support and understand the business relationship.
Lawful basis: contract where applicable and/or legitimate interests in running and developing our business and providing effective customer service.
B2B sales prospecting and follow-up
Purpose: identify businesses that may benefit from Jupiter products, avoid repeatedly approaching the same business, record sales outcomes and carry out proportionate B2B follow-up.
Lawful basis: legitimate interests where appropriate. Electronic marketing is also handled in accordance with PECR, including the different rules that can apply to corporate subscribers and sole traders/individual subscribers.
Referral programme
Purpose: attribute eligible Growth/Pro referrals, prevent abuse and calculate/maintain Jupiter account credits.
Lawful basis: contract where referral benefits form part of the purchased service and/or legitimate interests in operating and protecting the referral programme.
Operational analytics and improvement
Purpose: understand whether redirects work, measure aggregate usage, troubleshoot errors, prevent abuse and improve the product.
Lawful basis: legitimate interests in operating, securing and improving Jupiter’s services. Where a technology requires consent under applicable electronic-communications rules, we will obtain consent before using it unless an exemption applies.
Legal, accounting and compliance
Purpose: maintain records, respond to lawful requests, establish or defend legal claims, comply with tax/accounting requirements and meet legal obligations.
Lawful basis: legal obligation and/or legitimate interests in protecting Jupiter’s legal rights.
6. Legitimate interests
Where we rely on legitimate interests, the interests may include:
• selling and improving relevant B2B products;
• managing business relationships;
• providing support;
• maintaining secure and reliable redirects;
• preventing fraud, misuse and duplicate referral claims;
• keeping proportionate sales records so businesses are not repeatedly approached unnecessarily; and
• understanding aggregate product performance.
We consider whether our interests are necessary and balanced against the rights and reasonable expectations of the individuals concerned. You can object to processing based on legitimate interests in certain circumstances.
7. B2B marketing
We may contact business contacts about Jupiter products or services where permitted by law.
The rules differ depending on the type of business/contact and communication channel. In particular, electronic marketing to sole traders and certain partnerships can be treated differently from marketing to corporate subscribers.
Where required, we will obtain consent. Where consent is not required, we will still provide a clear way to opt out of direct marketing.
You can ask us to stop direct marketing at any time by contacting us or using an unsubscribe/opt-out method provided with the communication. We will maintain a minimal suppression record where necessary so that we can respect the opt-out.
8. Who we share personal data with
We may use carefully selected service providers to operate Jupiter, which may include:
• CRM providers such as HubSpot;
• payment providers such as Stripe;
• automation/workflow providers such as n8n or infrastructure used to run those workflows;
• website, cloud, database, redirect and hosting providers;
• email/communications providers;
• professional advisers such as accountants, insurers or legal advisers;
• delivery/fulfilment providers where relevant; and
• public authorities or regulators where disclosure is legally required.
Providers acting as processors are expected to handle personal data only for the agreed purposes and with appropriate safeguards.
We do not sell personal data to third parties.
9. International transfers
Some technology providers may process personal data outside the United Kingdom.
Where UK personal data is transferred internationally, we will use an appropriate lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another permitted safeguard.
10. How long we keep information
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, support, security and dispute-resolution requirements.
At launch, our retention approach is:
• order, invoice and core accounting records — retained in line with applicable company/tax record-keeping requirements;
• customer/account and support records — retained while the relationship/product remains active and for a reasonable period afterwards where needed for support, legal claims or business records;
• managed redirect configuration/history — retained while needed to operate/support deployed products and for a reasonable operational history afterwards;
• unsuccessful prospect/sales notes — periodically reviewed and deleted or minimised when no longer reasonably useful;
• direct-marketing suppression records — retained as necessary to ensure an opt-out continues to be respected;
• detailed technical logs — kept for a limited operational/security period and then deleted, anonymised or aggregated where practicable; and
• aggregate/non-identifying statistics — may be retained for longer where they no longer constitute personal data.
We will refine and document specific operational retention periods as the Sales Toolkit and production infrastructure mature.
11. Security
We use proportionate technical and organisational measures designed to protect personal data.
These include, as appropriate:
• access controls and authenticated internal tools;
• limiting access according to business need;
• secure hosted infrastructure;
• appropriate payment-provider separation;
• system and audit records;
• backups and recovery controls;
• software/security maintenance; and
• procedures for responding to suspected personal-data breaches.
No system can guarantee absolute security, but we work to reduce risks proportionately.
12. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights including:
• access to your personal data;
• correction of inaccurate information;
• deletion in certain circumstances;
• restriction of processing in certain circumstances;
• objection to processing, including an absolute right to object to direct marketing;
• data portability in certain circumstances; and
• rights relating to certain solely automated decisions.
Not every right applies to every type of processing.
To exercise a right, contact:
support@jupitersolutionsgroup.com
We may need to verify identity before acting on a request.
13. Complaints
If you have concerns about how we use personal data, please contact us first so that we can try to resolve them.
You also have the right to complain to the UK Information Commissioner’s Office (ICO), the UK regulator for data protection.
14. Cookies and similar technologies
Our public website and Sales Toolkit may use technologies necessary to provide requested functionality, maintain security or remember essential settings.
We will not rely on this Privacy Notice alone to deploy non-essential cookies or similar tracking technologies that require consent. Where consent is required, an appropriate consent mechanism and cookie information will be provided.
A card tap opens a business-specific Jupiter landing page with a prominent Google review button leading to the confirmed Google review destination. Across Core, Growth and Pro, the page may later include subtle, clearly labelled advertising and promotions for Jupiter Solutions products at the bottom. Advertising and Jupiter product promotions together must occupy no more than 20% of the landing-page area, remain secondary to the review action, and never cover, delay or obstruct the Google review button. Both third-party advertising and Jupiter product promotions can be turned off for the business/location. These are planned page-display features, not a statement that advertising, profiling or advertising trackers are currently deployed. Any new advertising-related personal-data processing, cookies or tracking must be assessed before deployment and this notice updated where required. Turning off promotional content must also be respected by the page’s advertising integrations.
15. Automated decision-making
Jupiter does not currently intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing as part of the launch Google Review Card service.
If this changes materially, we will update this notice and provide any information required by law.
16. Changes to this notice
We may update this Privacy Notice as Jupiter’s products, systems or legal obligations change.
Where a change materially affects how existing customer/contact personal data is used, we will take reasonable steps to bring the change to affected people’s attention.
17. Contact details
JUPITER SOLUTIONS LTD
Company number: 15230488
Registered office: Avc House, 21 Northampton Lane, Swansea, Wales, SA1 4EH
Business email: info@jupitersolutionsgroup.com
Privacy/support enquiries: support@jupitersolutionsgroup.com
This online store uses Cloudflare Workers and D1 to host the site and securely hold orders, inventory, restock requests and aggregate card usage. Stripe processes payments; HubSpot manages business customer relationships. Paid customers can search Google Maps for their business: results are shown temporarily, and only the confirmed Place ID is retained. See Google’s Privacy Policy. Essential browser session storage preserves your selection and secure setup access; an essential owner-dashboard cookie is used only after owner sign-in. No advertising or marketing trackers are deployed.