Before publishing: have a New Jersey attorney review this document against your actual data practices. It is a working template built around the practices described below — not legal advice.
Last updated: 2026
This policy explains how B2B Systems Group (“we,” “us”) handles information collected through b2bsystemsgroup.com/ and in the course of providing our services. B2B Systems Group is a registered trade name of Vascad LLC, a New Jersey limited liability company, which is the entity responsible for the data described below.
Information we collect
Information you give us
- Contact details you submit through forms: name, business name, email address, phone number, service area and the content of your message.
- Information you provide by phone, text or email.
- Billing information for clients, processed by our payment provider — we do not store full card numbers.
- Account access you grant us to deliver services (for example, manager access to a Google Business Profile).
Information collected automatically
- Standard server log data: IP address, browser type, referring page, pages viewed and timestamps.
- Analytics data via Google Analytics 4, used to understand which pages are useful.
- Cookies and similar technologies, described below.
- Call tracking data if you call a tracked number: the number dialed, call duration and, where enabled, a recording. Where calls are recorded you will be told at the start of the call.
How we use it
- To respond to your enquiry and provide the services you request.
- To send information you asked for and, for clients, service-related communications.
- To improve the website and understand how people use it.
- To meet legal, tax and accounting obligations.
- To detect and prevent fraud and abuse.
We do not sell, rent or trade your personal information. We do not add enquiries to a marketing list without asking first.
Cookies
We use cookies for essential site function, analytics, and — where advertising is running — conversion measurement. Analytics and advertising cookies do not load until you accept them. You can change your choice at any time using the control in the footer, and we honour Global Privacy Control signals automatically.
A full inventory of every cookie, who sets it and how long it lasts is in our Cookie Policy.
Third parties we share data with
We share information only with service providers who help us operate, and only what they need:
- Web hosting and content delivery providers
- Google (Analytics, Search Console, Ads, Business Profile)
- Email and CRM providers
- Call tracking provider
- Calendly, for appointment scheduling
- Payment processor
- Professional advisers where legally required
We may also disclose information where required by law or to protect our legal rights.
Client data
When delivering services we may access systems containing your customers’ personal information. In that relationship you are the controller and we are the processor: we access only what the work requires, act only on your documented instructions, do not use the data for any other purpose, and delete or return it at the end of the engagement.
Clients in regulated fields should have written terms with us covering this:
- Healthcare, dental and mental health practices — where our work touches protected health information we will sign a HIPAA Business Associate Agreement before that work begins, and we will tell you plainly when a tool you have asked for is not HIPAA-appropriate.
- Law firms — we treat all client-matter information as confidential and work within New Jersey and New York attorney advertising and confidentiality rules.
- Financial, insurance, mortgage and lending firms — we work within the disclosure and safeguarding requirements applicable to your sector.
- All clients — a Data Processing Addendum is available on request and we recommend one wherever we touch customer records.
How long we keep it
- Enquiries that don’t become clients: up to 24 months.
- Client records: for the engagement plus 7 years for tax and legal purposes.
- Analytics data: 14 months.
- Call recordings: 12 months unless part of a client record.
Your rights
Depending on where you live — including under the New Jersey Data Privacy Act and, for California residents, the CCPA/CPRA — you may have the right to:
- Know what personal information we hold about you
- Request a copy of it
- Request correction of inaccurate information
- Request deletion, subject to legal retention requirements
- Opt out of targeted advertising and any sale or sharing of personal data (we do not sell data)
- Not be discriminated against for exercising these rights
To exercise any of these, email sales@b2bsystemsgroup.com with “Privacy Request” in the subject line, or call (201) 677-2824. We respond within 45 days and may extend once by a further 45 days for complex requests, telling you why within the original period. We may need to verify your identity first, and we will ask only for what is necessary.
If we decline — your right to appeal
If we refuse a request we will tell you why in writing. You may appeal by replying to that decision or emailing sales@b2bsystemsgroup.com with “Privacy Appeal” in the subject line. A different person will review it and we will respond within 45 days with written reasons. If the appeal is denied, we will give you a method to complain to the New Jersey Division of Consumer Affairs or the Office of the New Jersey Attorney General.
Universal opt-out signals
If your browser or an extension sends a Global Privacy Control signal, we treat it as a valid opt-out of targeted advertising and of any sale or sharing of personal data. This applies automatically; you do not need to contact us. Full detail and the controls are on Your Privacy Choices.
Authorised agents
You may use an authorised agent to make a request. We will ask for proof of their authority and may still verify your identity directly.
Security
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data we hold, as required by the New York SHIELD Act for the private information of New York residents and by New Jersey law. In practice that includes encryption in transit, access controls on a least-privilege basis, two-factor authentication on business systems, a password manager for credentials, vendor due diligence, and removal of access within 24 hours of an engagement or employment ending.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant authorities within the timeframes required by New Jersey and New York breach-notification law.
Children
This site is not directed at children under 16 and we do not knowingly collect their information.
Text messages
If you provide a mobile number and consent, we may text you about your enquiry or your services. Message and data rates may apply. Reply STOP to opt out at any time and HELP for assistance. We do not send marketing texts without express written consent, and consent is never a condition of purchase.
We do not share, sell, rent or otherwise disclose mobile phone numbers, or the fact that you consented to receive text messages, to any third party or affiliate for their own marketing purposes. The only parties who process this data are the messaging and CRM providers acting on our instructions to deliver messages, under contract, with no right to use it for anything else. Full detail is in our SMS Terms.
Changes
We may update this policy. Material changes will be posted here with a revised date, and clients will be notified directly.
Contact
Vascad LLC, trading as B2B Systems Group
Email: sales@b2bsystemsgroup.com
Phone: (201) 677-2824
Service-area business — northern & central New Jersey and New York City
Hours: Sun–Thu 9:00 AM – 6:00 PM · Fri 9:00 AM – 3:00 PM · Sat closed