Legal

Privacy Policy

This policy explains what information ninty9 collects and how it is used for orders and course access.

Entrance gate and capacity queue

The secure entrance uses a random HttpOnly browser cookie. ninty9 stores only a one-way hash of that random token together with acceptance, queue, readiness, and short active-lease times. The gate record does not contain a name, email address, or the readable cookie token. Acceptance expires after exactly 216 hours, ready places expire after one hour, and inactive expired gate records are removed after 14 days.

Information collected

During checkout, ninty9 collects the customer name, surname, email address, phone number, and product order details. The Contact Us form collects the details and message needed to answer a customer enquiry.

Learner and guardian information

For online courses, ninty9 collects the purchaser’s name, checkout email address, account details and required consent. For each learner, it collects a name, dashboard language, and visual avatar choices. The avatar stores a skin-tone choice and boy or girl character, not race. After a paid order is confirmed, the purchaser chooses a ninty9 password through a one-use email link. The system also keeps course access, answers, marks, progress and necessary administrative decisions.

Parent accounts and learner links

A paid order creates a student account for its checkout email. The account can hold every paid online subject from that order. This relationship is stored on the server and is never inferred from a surname or a shared email address. The one-use account-activation link is sent only to the checkout email. Student portal access does not grant access to another customer’s records.

How information is used

Customer information is used to process manual EFT orders, verify payment, and deliver purchased products. Course information is used to manage secure login, course access, automatic and manual marking, progress reports, parent communication, and certificates.

Payment information

ninty9 accepts EFT payments only. The website does not collect card details and ninty9 does not accept card payments. EFT payment is made manually through the customer's bank, and access is issued only after the payment reflects and is confirmed.

Data storage

Order details are emailed to ninty9 and a private backup copy is kept on the server. Customer enquiries, learner, account-activation, login and progress information are stored in a secured database. ninty9 authenticates customers with their verified checkout email and chosen password.

Transactional email delivery

Payment, protected-download, password-activation and access-ready messages are sent by the server. ninty9 uses Brevo as its authenticated production transactional email provider. The production website does not fall back to the hosting server’s unauthenticated PHP mail service. The provider receives the recipient address and message content needed for delivery. Secret delivery credentials and password-setup tokens are never handled by the browser.

Who has access

Only the ninty9 Principal has administrative access to learner and guardian records. Learners can see only their own assigned courses and progress. Verified guardians can see access, orders and progress summaries only for their actively linked learners. ninty9 does not sell personal information to third parties.

How long information is kept

A pending learner registration or consent request expires after 7 days, while a parent-created learner invitation may remain available for up to 30 days. Uncompleted registration details are deleted 30 days after expiry. One-use consent, invitation and order-claim links expire according to their purpose; expired or used token records are removed on a bounded schedule. Course access lasts for the period on the purchased product. After access ends, a 90-day grace period applies before learner course and progress records are deleted unless access is extended. Order information may be retained longer for payment, tax or business records.

Consent and requests

A parent or legal guardian must provide accurate checkout details and give any consent required at checkout before a minor learner account becomes active. The paid order, verified checkout email and password activation are service requirements, not marketing consent. ninty9 does not use learner consent for marketing. Any future marketing consent must be separate, optional and off by default. A parent or guardian may request correction or, where applicable, deletion of personal information.

Public website analytics

After a visitor has passed the entrance, ninty9 uses Google Analytics 4 on public pages to understand page visits and privacy-safe actions such as resource-link clicks, Resource Finder activity, product views, and add-to-cart starts. ninty9 does not intentionally send names, email addresses, learner details, customer references, ticket contents, or free-text searches to analytics. Google may process device, browser, and cookie identifiers under its terms. Visitors can block or remove analytics cookies in their browser settings without losing access to the website.