90 Day Protocol

Catalyst Advisory Services, Inc. · Last updated 26 August 2026

Privacy Policy

This Privacy Policy (the Policy) explains how Catalyst Advisory Services, Inc. (the Company, we, us, or our) handles information in connection with 90dayprotocol.com and the pages, forms, downloads, emails, trainings, and calls we operate under the 90 Day Protocol name (together, the Site).

Dexter Montgomery is a pen name. The civil name of the author is not a public brand and is not a second controller.

This Policy is written for a United States adult business. It is not a promise of European, Canadian, or other foreign privacy rights. If you do not want information handled as this Policy says, do not use the Site and do not buy from us.

Money, refunds, arbitration, and liability are in the Terms of Service. If this Policy and the Terms conflict on a money or dispute issue, the Terms control. If they conflict on how we handle personal information, this Policy controls.

Contents

  1. Who this covers
  2. What we collect
  3. How we collect it
  4. How we use it
  5. When we share it
  6. We do not sell the mailing list
  7. Analytics, ads, and measurement
  8. Cookies and similar tools
  9. Payments
  10. Email
  11. Forms
  12. Calls and recordings
  13. How long we keep it
  14. Security
  15. Your choices
  16. State privacy laws
  17. Children
  18. Sensitive information and other people
  19. Crisis, 988, and professional limits
  20. People outside the United States
  21. Changes
  22. Contact

1. Who this covers

This Policy covers information we handle as a business about visitors, buyers, form submitters, email subscribers, and people who book or sit on a call. It does not cover Amazon’s handling of a book purchase you make on Amazon, a card network’s handling of a chargeback, or a host’s or processor’s own independent records.

The Site is for people 18 and older. We do not knowingly deal with children. See Section 17.

2. What we collect

We collect information that identifies you, can be linked to you, or that we reasonably associate with you (personal information), and we collect technical and commercial records that may or may not identify you. Categories include:

We do not ask you for a Social Security number, a medical diagnosis, or your children’s names. If you send that anyway, Section 18 applies.

3. How we collect it

We collect it when you visit a page, submit a form, download a file, click a mailto or a checkout link, buy, request a refund, email us, or sit on a call. We collect it automatically from your browser and from our host, form tool, payment processor, email tool, and analytics or ads tools when those tools are on.

On this draft folder, the First 24 Hours form is wired to open a thanks page in your browser. Email is not stored by that draft submit. After the folder is hosted (we intend Netlify), that form posts to the host’s form tool and the host holds the submission. Nothing is mailed from the draft pages.

The live domain 90dayprotocol.com may already run Google Analytics under measurement ID G-L5N2WE91P0. That is an existing property. We did not invent a second ID. These draft pages do not include an ads pixel. See Section 7.

We may also receive information from a processor (Stripe or a later processor), a card network on a chargeback, a host, an email vendor, or a public source we use to prevent fraud.

4. How we use it

We use personal information for our legitimate business purposes, including to:

We may create de-identified or aggregated records (counts, conversion rates, common questions) and use those for any purpose. We will not try to re-identify a record we have treated as de-identified, except to test that the de-identification worked or as the law requires.

We do not have to use information to give you legal advice, medical advice, or crisis care. Reading a form or an email does not make us your lawyer.

5. When we share it

We share personal information with people who help us run the business, and when the law or a dispute requires it. That includes:

We do not have to get a second signature from you before we share with a processor we already use to fulfill what you asked for. Those processors have their own terms and privacy notices. We are not responsible for a processor’s independent use, except to the extent a refund right in the Terms still applies to money we actually received.

6. We do not sell the mailing list

If a mailing list is added, that list will not be sold, rented, or traded to an unrelated company as a stand-alone list of names and emails. We use it to send protocol updates, book notices, training notices, and other messages from Catalyst Advisory Services, Inc. You can leave it.

That sentence does not mean we forfeit ordinary business uses. Sharing with a processor, using an email vendor, measuring our own ads, transferring the business, or disclosing under Section 5 is not a sale, rental, or trade of the list.

We do not sell personal information for money as a data-broker would. If a state law uses a broader word than “sale” (including some definitions of “share” for cross-context advertising), Section 16 applies. We do not promise a permanent bar on advertising measurement. See Section 7.

7. Analytics, ads, and measurement

These draft pages do not include an ads pixel. We have not turned Google Ads spend on. You click spend. We have not invented an ads conversion ID.

The live domain may already run Google Analytics (G-L5N2WE91P0). When this folder is the live Site, we may run the same or a later analytics property, and we may add conversion or remarketing tags for our own ads (including Google Ads) so we can tell whether a click became a protocol download, a training sale, or a call booking.

Those tools may set cookies or read device identifiers, and they may receive your IP address and page URL. Google and similar vendors may use that information under their own policies, including to improve their services. We use those tools to measure and to improve our own marketing, not to build a dossier we sell.

We do not run ads against crisis queries. That is an ads rule, not a promise that a vendor will never see a page URL that mentions 988.

If we later add a third-party ads pixel, we may update this Policy. Continued use after that update is acceptance. We do not need a separate click for analytics or first-party measurement that this section already describes.

8. Cookies and similar tools

The Site may use cookies, local storage, pixels, and similar tools for hosting, security, forms, checkout, email, analytics, and ads measurement. Google Fonts and the host also see ordinary request data when your browser loads a file.

We do not promise to honor a “Do Not Track” browser signal. Those signals are not uniform. You can block cookies in your browser. Blocking them may break a form, a checkout, or a login link. That is your choice.

A cookie banner is not required for this Site under Nevada law as we understand it, and we do not commit to one. If a later tool or a later law makes a banner the cheaper way to stay compliant, we may add one without shrinking the uses in this Policy.

9. Payments

When checkout is on, payment is handled by a processor (we intend Stripe) on a Catalyst Advisory Services, Inc. account. The processor collects card or bank data. We receive confirmation, limited card descriptors, and what we need to fulfill, refund, or contest a claim. Checkout is off until we turn it on. A placeholder token on a draft page is not a live charge and is not a request for your card.

Do not send a full card number, a bank login, or a government ID by email. If you do, we may delete the message after we have what we need to tell you to use the processor, or we may keep it if a dispute has already started.

10. Email

Transactional email (receipts, access, refunds, call times) is part of the purchase. You cannot unsubscribe from a message we have to send to complete or unwind a sale, but you can unsubscribe from marketing.

When a list is on, we intend to use MailerLite or a similar vendor. Unsubscribe links will be in marketing mail. An unsubscribe stops marketing. It does not delete a receipt, a chargeback file, or a record we keep under Section 13.

If you give us an email on a form, you agree we may use it for the protocol, for our own book and training notices, and for the uses in Section 4, until you leave the list.

11. Forms

The First 24 Hours form asks for a name and an email. On the draft, submit opens thanks and does not store the fields. After host drop, Netlify Forms (or a later form tool) holds the submission. We may export that list into an email vendor. We do not have to publish what you type. We may drop a submission that is abusive, unlawful, or empty.

A honeypot field is there to stop bots. Do not put real data in a hidden field.

12. Calls and recordings

If The 45-Minute Call is recorded, we say so at the start of the hour. Staying on the line after that notice is consent to the recording for quality, notes, training our own process, and a dispute about what was said. We do not sell call recordings. We may keep a recording as long as Section 13 allows, including for a later chargeback or arbitration.

A recording is not legal advice and is not an attorney-client conversation. See the Terms, Section 20.

13. How long we keep it

We keep personal information as long as we have a business need for it, and longer if a law, a card-network rule, a tax rule, an insurance requirement, a refund window, a chargeback window, or an actual or reasonably anticipated dispute requires it.

We do not promise a deletion date. We do not promise to honor a deletion request that would leave us unable to prove a sale, a refund, a chargeback defense, an opt-out, or a license you already granted. When we delete or de-identify, residual copies may remain in backups until those backups rotate.

If you unsubscribe from marketing, we may keep the email on a suppression list so we do not mail you again.

14. Security

We use reasonable administrative and technical measures for a small static site and a small catalog of digital products. No method of transmission or storage is completely secure. We do not warrant that the Site or our vendors will never be breached. If a breach happens that the law requires us to report to you, we will do that. We do not owe a credit-monitoring product unless a statute or a written agreement says so.

15. Your choices

You can refuse a form, refuse a cookie, leave a marketing list, cancel a call before it happens (see the Terms), or ask for a training refund inside the 14-day window (see the Terms). You can stop using the Site.

You may email the address on your receipt, or the contact method on About when it is posted, to ask what we have about you or to ask us to correct a name or an email. We will look at a reasonable request. We may refuse a request that is repetitive, abusive, unfounded, or that would interfere with security, a dispute, or another person’s privacy. We may ask you to prove you are the person you claim to be. We do not have to build a self-service portal.

We may charge a reasonable fee or refuse if a statute lets us, or if you ask for the same records more than once in a short period.

16. State privacy laws

Some United States state laws give residents extra rights if the business meets a size, revenue, or volume test. We are a small company. We do not represent that the California Consumer Privacy Act (as amended), the Virginia CDPA, or similar statutes currently apply to us. If one of those statutes does apply to a particular request, we will do what that statute actually requires, and no more as a gift.

We do not sell personal information for monetary consideration as Nevada’s online privacy law uses that idea. Nevada residents who want to send a “do not sell” request may use the contact method in Section 22. That request covers a sale for money. It does not stop processors, analytics, our own ads measurement, a transfer of the business, or a disclosure under Section 5.

If a later statute treats advertising measurement as a “share,” we may add a limited opt-out for that share. Until we post that mechanism, this Policy is the notice. We do not agree to process a request through an unofficial browser signal unless we later say we do.

Nothing in this section creates a private right you would not otherwise have. Mandatory consumer statutes control to the extent they apply and are not preempted.

17. Children

The Site is not directed at children under 18, and we do not knowingly collect personal information from them. If you are a parent or guardian and you think a child sent us information, use Section 22. We will delete it when we have confirmed the facts, unless we must keep a record of the request. Do not send us a child’s identifying information in a form or an email about your own situation.

18. Sensitive information and other people

Do not send us anyone else’s private papers, a child’s identifiers, a medical record, a court filing that is not yours to share, or a password. If you send sensitive information anyway, we may process it as needed to respond, to refuse the request, to secure the Site, or to defend the Company. We do not want that role. Sending it does not make us your lawyer, doctor, or records custodian.

If you mention a spouse, a lawyer, a judge, or another adult, that mention is your content. We may keep it as part of your file. We do not use the Site to contact her for you.

19. Crisis, 988, and professional limits

We are not a crisis line and we do not monitor the Site for people in danger. If tonight is worse than confusion, call or text 988 in the United States, or use 911, before you write to us. A form submission is not a request for emergency services and we may not see it in time.

The Site, the books, the protocol, the trainings, and the call are informational. They are not legal advice, not medical advice, and not mental-health treatment. Emailing us does not create an attorney-client relationship and is not a privileged legal consultation. We do not become a HIPAA covered entity by receiving a message about how you feel.

20. People outside the United States

The Site is operated from the United States. If you use it from another country, you transfer information to the United States and you use the Site at your own risk. We do not offer GDPR “controller” rights, a data-protection officer, or Standard Contractual Clauses as a default. If those regimes apply to a specific processing and cannot be waived, they apply only to that extent.

We do not target the Site at the European Union, the United Kingdom, or Switzerland as a separate market.

21. Changes

We may change this Policy. The “Last updated” line is the date of the current version. For a material change, the new version applies to information we collect after it is posted, and to information we already have to the extent the new use is compatible with the purposes in Section 4 or is required by law. We will not use a change to take away a refund right that already attached under the Terms.

A post on this page is notice. We do not have to email every visitor. Continued use after a change is acceptance. If you do not accept a change, stop using the Site and leave the list.

22. Contact

Questions about this Policy, a Nevada “do not sell” request, or a reasonable access or correction request: use the email on your receipt, or the contact method posted on About when the domain is live. Until a live contact method is posted, a notice you can prove you sent to the receipt address is enough.

We do not invent a privacy inbox on this page. Publisher: Catalyst Advisory Services, Inc., Las Vegas, Nevada, United States. Site: 90dayprotocol.com. Author credit: Dexter Montgomery (pen name).

Last updated 26 August 2026.