What we collect, why we collect it, who else sees it, and what you can ask us to do about it. Written to be read, not to be survived.
This policy explains how Jupeak Solutions Pvt. Ltd. handles personal data on jupeakone.com, in the Jupeak One application, and across the free tools and calculators we publish. It is written for India's Digital Personal Data Protection Act, 2023 (DPDP Act) and applies to everyone who visits our site or uses our product.
Jupeak Solutions Pvt. Ltd. is an Indian company, founded in 2008, based in Varanasi, Uttar Pradesh. We build Jupeak One — an ERP, CRM, billing, inventory and accounting platform for Indian businesses.
In DPDP Act language we are the Data Fiduciary for the personal data described in this policy. Our full contact details, including our Grievance Officer, are in section 16.
Most of this policy is about data we decide the purpose for. But a large part of what sits in Jupeak One is your customers' data, which you put there.
| Role | What it covers | Who decides |
|---|---|---|
| Data Fiduciary | Your account: name, email, phone, company details, billing, support conversations, how you use the product, and anything you give us on the marketing site. | We do. This policy governs it. |
| Data Processor | The business data you enter — your customers, suppliers, employees, invoices, ledgers, stock. We store and process it strictly on your instructions. | You do. You are the Data Fiduciary to your own customers; we act on your behalf. |
In plain terms: we do not sell, rent, mine or advertise against the business data inside your account. We do not use your customer lists, ledgers or transaction data to train AI models. We access it only to run the service, to fix a fault you have reported, or where the law compels us.
| Purpose | What that means |
|---|---|
| Run the service | Create and secure your account, store your data, deliver the features you subscribed to. |
| Billing | Take payment, raise invoices, chase failed renewals, meet our tax obligations. |
| Support | Answer your questions and investigate faults you report. |
| Service messages | Reminders, daily summaries, security alerts and product notices. You can change or switch these off in Settings → Notifications. |
| Improve the product | Aggregated, de-identified usage patterns — which features are used, where people get stuck. |
| Marketing | Tell you about relevant features and offers. Always with an unsubscribe. |
| Legal and safety | Prevent fraud and abuse, enforce our terms, and comply with Indian law. |
We rely on your consent where the DPDP Act requires it, and on legitimate uses as defined in that Act for the rest — for example, providing a service you have specifically asked for. Where we ask for consent, you can withdraw it at any time; see section 12.
Subscription payments are processed by Razorpay Software Private Limited, an RBI-authorised payment aggregator. When you pay, you are handed to Razorpay's secure environment.
We never see or store your full card number, CVV, UPI PIN, or net-banking credentials. Those go directly to the payment gateway, which is PCI-DSS compliant. What we receive back is limited to what we need for our books: whether the payment succeeded, the amount, the date, a transaction reference, the payment method type, and the last four digits of the instrument.
We keep invoices and payment records for as long as Indian tax and company law requires — currently eight financial years. Razorpay's own handling of your payment data is governed by Razorpay's privacy policy.
We use cookies and similar technologies to keep you signed in, to remember preferences, to understand how the site is used, and to measure our advertising.
| Type | What it does | Can you refuse? |
|---|---|---|
| Essential | Sign-in sessions, security, load balancing, remembering your consent choices. | No — the service cannot work without these. |
| Preference | Language, theme, and layout choices. | Yes. |
| Analytics | Google Analytics 4 and our own first-party measurement, to see which pages and features are used. | Yes. |
| Advertising | Meta Pixel and Google Ads tags, to measure which ads bring people to us and to show relevant ads afterwards, including remarketing. | Yes. |
Advertising and analytics tags may set their own cookies and receive your IP address, the pages you viewed and a pseudonymous identifier. They may combine that with data they already hold about you. We do not send them your name, phone number, or any of the business data inside your Jupeak One account.
Analytics and advertising cookies do not load until you allow them. You are asked on your first visit, and you can change your mind whenever you like.
Jupeak One includes AI features — Asha, our assistant, plus AI summaries, scoring and drafting. We want to be specific about what that involves, because "AI" is often used to gloss over exactly this.
We send service messages — daily summaries, reminders, alerts and account notices — by email, in-app notification, web push and, where you have opted in, WhatsApp.
We do not sell personal data. We share it only with service providers who help us run Jupeak One, and only as far as each needs. Every one of them is bound by contract to protect it and to use it for nothing else.
| Provider | What for | Where |
|---|---|---|
| Razorpay | Payment processing | India |
| Anthropic | AI features (see section 7) | United States |
| Meta Platforms | WhatsApp Business messaging; advertising measurement | United States |
| Analytics and advertising measurement | United States | |
| Cloudinary | Storing documents and images you upload | United States / EU |
| GoDaddy | Outbound email delivery | India / United States |
| Bolna | Automated voice calls, where a customer has enabled them | India |
We may also disclose data where the law requires it — a court order, a valid request from a government or regulator — or to establish or defend a legal claim, or to protect the safety of a person. If Jupeak is ever acquired or merged, data may transfer to the successor, and we will tell you before that happens.
No system is perfectly secure. If a breach occurs that affects your data, we will notify you and the Data Protection Board of India as the DPDP Act requires.
Under the DPDP Act you may:
Most of this you can do yourself in the product. For anything else, write to our Grievance Officer below. We respond within 30 days, and we will not charge you for a reasonable request.
If you are a customer of one of our customers and want your data corrected or removed, please contact that business directly — they control it, and we act on their instructions. We will help them do it.
Jupeak One is a business product and is not directed at children. We do not knowingly collect personal data of anyone under 18. As the DPDP Act requires, we do not use children's data for tracking, behavioural monitoring or targeted advertising. If you believe a child's data has reached us, tell us and we will delete it.
Your business data is stored on servers in India. Some of the providers in section 9 — notably our AI, advertising and messaging providers — process limited data outside India. Where that happens we rely on contractual safeguards and transfer only what is necessary. We do not transfer data to any country that the Government of India has restricted.
We update this policy when the product or the law changes. The date at the top always reflects the current version. If a change materially affects your rights, we will tell you by email or in-app notice before it takes effect.
Questions about privacy, or want to exercise a right? Start here. If we have not resolved your complaint to your satisfaction, you may escalate to the Data Protection Board of India.
Appointed under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.