Privacy Policy

90 DAY PLAN mobile application
Effective date: August 19, 2026

1. General provisions

1.1. This Privacy Policy (the "Policy") explains how personal data is collected, used, stored, transferred and deleted in connection with the 90 DAY PLAN mobile application (the "App").

1.2. The data controller (the "Operator") is Individual Entrepreneur SRM GROUP, registered in the Republic of Kazakhstan. Details are set out in Section 2.

1.3. The Policy is prepared in accordance with the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 "On Personal Data and Their Protection" (as amended), and, where applicable to users located in the European Economic Area, with Regulation (EU) 2016/679 (GDPR). The Policy also reflects the requirements of Google Play and the Apple App Store.

1.4. By creating an account and using the App, the user confirms that they have read this Policy. Consent to the processing of personal data is given separately, by a distinct action in the App.

1.5. The current version of the Policy is always available at ninetydayplan.org and within the App.

2. Operator details

Operator Individual Entrepreneur SRM GROUP
IIN 781217000619
Registered address Turan Avenue 3, apt. 17, 010000, Republic of Kazakhstan
Contact e-mail ninetydayplan.app@gmail.com
Website https://ninetydayplan.org
Application 90 DAY PLAN (com.ninetydayplan)

3. What the App is

3.1. The App is a personal planning and activity tracking tool for professionals working in direct sales and network marketing. It allows the user to plan daily activity, keep checklists, schedule meetings, record contacts of their own clients and partners, and track personal statistics and income.

3.2. The App is a productivity tool. It is not affiliated with, endorsed by or operated on behalf of any particular direct sales company, unless expressly stated in the App.

4. Categories of data and how they are collected

4.1. Data provided by the user about themselves.
Name, e-mail address, phone number, and other profile details the user chooses to enter, including data related to their business activity: planned and completed tasks, meetings, notes, statistics and income figures the user records. Signing in to the App is performed using a one-time code sent to the e-mail address, so the e-mail address is processed both as contact data and as a means of authentication.

4.2. Data about third parties entered by the user.
The App allows the user to record contact details of their own clients and partners (for example name, phone number, status of interaction). These data are entered by the user at their own initiative. The user determines what data to enter and for what purpose, and is responsible for having a lawful basis to do so. The Operator processes these data solely on behalf of the user, for the purpose of providing the App functionality. See Section 9.

4.3. Data collected automatically.
Approximate location, device identifiers, the push notification token of the device, device and operating system information, application performance data and crash logs, and usage events. These data are collected through the services listed in Section 8.

4.4. The App does not collect precise location data, biometric data or special categories of personal data within the meaning of Article 9 GDPR.

4.5. The App does not collect payment card details. Payment is processed outside the App, as described in Section 10.

5. Purposes and legal bases

Data Purpose Legal basis
Account data (name, e-mail, phone) Creating and maintaining the user account, authentication by one-time code sent to the e-mail address, support Performance of the agreement with the user; consent
Activity data (tasks, meetings, statistics, income records) Providing the core functionality of the App Performance of the agreement with the user
Contact details of the user’s clients and partners Providing the personal CRM functionality on behalf of the user Processing on behalf of the user, who acts as the controller of these data
Approximate location, device identifiers, crash logs Ensuring the App works correctly, diagnosing errors, product analytics Consent of the data subject; for users in the European Economic Area, also the legitimate interest of the Operator in maintaining and improving the App
E-mail address Service notifications relating to the account and the subscription Performance of the agreement with the user

6. Storage periods

6.1. Account data and data entered by the user are stored while the account is active.

6.2. After the account is deleted, the data are deleted within 30 (thirty) calendar days, and sooner where applicable law so requires, except for data that the Operator is required to retain by law (for example accounting records relating to payments) or that are necessary to prevent fraud or resolve disputes.

6.3. Technical logs are stored for up to 12 (twelve) months.

7. Data location and cross-border transfer

7.1. Article 12(2) of the Law of the Republic of Kazakhstan No. 94-V provides that storage of personal data is carried out by the owner, the operator or a third party in a database located in the territory of the Republic of Kazakhstan.

7.2. The Operator informs users that the App infrastructure and hosting are currently located outside the Republic of Kazakhstan, and that the service providers listed in Section 8 are also located abroad: Google LLC and Resend, Inc. are established in the United States. Data are therefore transferred across borders. Cross-border transfer of personal data is governed by Article 16 of Law No. 94-V and, outside the cases listed in that Article, is carried out with the consent of the data subject. By giving consent to the processing of personal data, the user also consents to such cross-border transfer.

7.3. Under Article 16(2) of Law No. 94-V, cross-border transfer to a foreign state is permitted where that state ensures the protection of personal data. Under Article 16(3)(1), transfer to a state that does not ensure such protection is permitted where the data subject has given consent to it. The Operator relies on both grounds: the hosting jurisdiction provides a comparable level of protection, and the user gives express consent to cross-border transfer when creating an account. For users located in the European Economic Area, transfers are made on the basis of appropriate safeguards under Chapter V GDPR.

7.4. The Operator keeps the storage architecture under review in the light of the requirement of Article 12(2) of Law No. 94-V.

8. Third parties and processors

8.1. The Operator engages the following service providers, which process data on the Operator’s instructions:

Provider Service Data processed
Google LLC, United States (Firebase Analytics) Product analytics Device identifiers, usage events, technical data
Google LLC, United States (Firebase Cloud Messaging) Push notifications Push notification token, device identifiers
Resend, Inc. (United States) Delivery of e-mails, including one-time codes for signing in E-mail address, delivery status
Hosting provider (servers located outside the Republic of Kazakhstan) Storage of application data Account data and data entered by the user
Payment service provider Processing of subscription payments made on the website Payment transaction data. Card details are handled by the payment provider and are not stored by the Operator

8.2. These providers act as processors. They are not permitted to use the data for their own independent purposes.

8.3. The Operator does not sell personal data and does not transfer personal data to third parties for their own marketing purposes.

8.4. Data may be disclosed to competent public authorities where this is required by applicable law.

9. Data of third parties entered by the user

9.1. Where the user enters into the App contact details of their own clients or partners, the user determines the purposes and means of processing those data and therefore acts as the controller in respect of them.

9.2. In respect of such data the Operator acts as a processor and processes them only to provide the App functionality to that user.

9.3. The user is responsible for ensuring that they have a lawful basis for entering and using such data, including obtaining consent where this is required by applicable law, and for informing those individuals as required.

9.4. If an individual whose data have been entered into the App by a user contacts the Operator, the Operator will, where it is able to identify the relevant user, forward the request to that user and assist in responding to it. Where the Operator is not able to identify the relevant user, it will inform the individual accordingly.

10. Subscription and payments

10.1. The App provides a free trial period. After the trial period expires, continued access to the paid functionality requires a subscription.

10.2. Subscription payments are processed outside the App by a third-party payment service provider. The Operator does not receive or store full payment card details.

10.3. Information on the price, the billing period, the date of the first charge and the procedure for cancelling the subscription is provided before the purchase is completed and is set out in the Terms of Use.

11. User rights

11.1. Under Article 24 of Law No. 94-V the user has the right to obtain information about the processing of their personal data, to request access, rectification, blocking or deletion of their data, to withdraw consent, and to lodge a complaint with the competent supervisory authority.

11.2. Users located in the European Economic Area additionally have the rights provided by Articles 15 to 22 GDPR, including the right to data portability and the right to object to processing.

11.3. Requests are sent to ninetydayplan.app@gmail.com. The Operator responds within the time limits established by applicable law and in any event no later than 30 (thirty) calendar days. Where applicable law establishes shorter time limits, those shorter limits apply. In particular, under Article 8(7) of Law No. 94-V, where the data subject withdraws consent, the Operator terminates processing within fifteen working days, unless storage or processing is required by the legislation of the Republic of Kazakhstan, or provides a reasoned refusal.

12. Account and data deletion

12.1. The user may delete their account at any time in the App: Profile, Settings, Delete Account.

12.2. The user may also request deletion without installing the App, by using the support page at https://ninetydayplan.org/support or by sending a request to ninetydayplan.app@gmail.com. The page is publicly accessible and does not require signing in.

12.3. Deletion of the account results in deletion of the account data and of the data entered by the user, including records about the user’s clients and partners, within 30 (thirty) calendar days, and sooner where applicable law so requires. Where deletion of the account also constitutes withdrawal of consent, the shorter period established by Article 8(7) of Law No. 94-V applies.

12.4. The Operator may retain certain data after deletion where retention is required by law, or is necessary to prevent fraud or to resolve disputes. Such data are retained only for the period required and are then deleted.

12.5. Deleting the App from the device does not by itself delete the account. Deletion must be requested using one of the methods above.

12.6. If the user has an active subscription, the subscription should be cancelled separately, as described in the Terms of Use.

13. Security

13.1. Data are transmitted over encrypted connections.

13.2. Access to personal data is limited to persons who need it to perform their duties and who are bound by confidentiality obligations.

13.3. The Operator applies organisational and technical measures appropriate to the risk, including access control, backups and monitoring.

14. Children

14.1. The App is intended for adults engaged in professional activity. The App is not directed at children.

14.2. If the Operator becomes aware that data of a child have been collected without the consent required by applicable law, such data will be deleted.

15. Changes to this Policy

15.1. The Operator may update this Policy. The current version is published at ninetydayplan.org and in the App, with the effective date indicated.

15.2. Where changes materially affect the rights of users, the Operator will notify users through the App or by e-mail.

16. Contact

Questions relating to this Policy and to the processing of personal data are sent to ninetydayplan.app@gmail.com.