Reference

How we handle your account information

We collect the information needed to run your account, verify bKash, Nagad and Rocket deposits, and keep your login secure. This page explains what we gather, how we use it, and how you request changes or deletion.

Account dataPayment recordsDevice identifiersSession logsContact preferences
hbaji How we handle your account information
DATA HANDLING

Security, retention and third-party sharing

Your password is hashed so even our own database admins cannot read it. Payment details stay on the bKash, Nagad and Rocket side; we only log the transaction reference and the amount credited. Session tokens expire after twenty-four hours of inactivity and we purge closed-account records after the retention period required for financial audits.

Encryption at rest

Account records, transaction logs and chat transcripts sit in encrypted storage. Database queries require two-factor authentication and access logs are reviewed weekly to catch unauthorized attempts.

Cookie policy

We use session cookies to keep you logged in, functional cookies to remember language preference and device choice, and analytics cookies to measure page-load speed. You can block third-party cookies in your browser without breaking core account functions.

Retention periods

Active-account data stays as long as you keep logging in. Once you request deletion we mark the account closed, finish any pending withdrawals, then wipe personal identifiers after ninety days while keeping anonymized transaction totals for audit compliance.

Third-party processors

bKash, Nagad and Rocket receive the minimum detail needed to clear your deposit or withdrawal. Fraud-detection services see hashed device fingerprints and IP ranges but not your phone number or real name.

POLICY CONTACT

Request your data or ask us to delete it

If you want a copy of everything we hold, or you want us to remove your account and wipe the records, reach us through any of these channels. Privacy requests usually take two to five business days once we confirm your identity.

Live chat Open the chat widget on any page, tell the agent you need a data-access or deletion request, and we will ask for your registered phone number to verify it is you before proceeding.
Email support Send your request from the email address linked to your account so we can match it automatically. Include your username and phone number in the message body for faster confirmation.
Account settings Log in, open settings, scroll to the data-and-privacy section and click request my data or delete my account. We will send a confirmation code to your phone before completing either action.

Common questions about your data

We ask for your phone number, a password and a date of birth to verify you meet the age requirement. If you add an email address later we store that too for password-reset links.

Yes. We log the transaction reference, timestamp, amount and which wallet you used so we can match the deposit to your account and resolve any disputes if the amount does not credit correctly.

Log in, open account settings, scroll to data and privacy, then click request my data. We will email a JSON file with your profile details, transaction history, session logs and chat transcripts within three business days.

Open settings, choose delete my account, confirm with the OTP sent to your phone, then wait for pending withdrawals to clear. We wipe personal identifiers ninety days after closure while keeping anonymized totals for audit records.

Only with payment processors who clear your bKash, Nagad or Rocket transfers and fraud-detection services that flag duplicate accounts. We do not sell data to advertisers or share it with marketing platforms.

Session cookies keep you logged in, functional cookies remember your language choice, and analytics cookies measure load times. You can block third-party cookies in browser settings without losing access to your wallet or the lobby.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.