Reference

How We Handle Your Data and Account

This page sets out the legal basis on which we operate your account, how your data moves through our systems, and what rights you hold over that data.

Data TransparencyAccount RightsRegion-Dependent AccessbKash & Nagad ContextContact Paths
brocket How We Handle Your Data and Account
DATA AND ACCOUNT SECURITY

How We Protect What Belongs to You

Your account data, transaction history, and personal details sit behind layers of protection that we maintain and audit regularly. This section explains what happens to your information from the moment you hand it over, who can see it, and how you can request changes or deletion. We treat your data as yours — we hold it, we do not own it.

Encryption at Rest and in Transit All personal and financial data is encrypted both when stored on our servers and while moving between your device and our systems. This applies to bKash, Nagad, and Rocket transaction details as well as login credentials and identity documents you upload during verification.
Cookie Policy We use cookies to keep you logged in across sessions, remember your language preference, and track which pages load correctly. We do not use cookies to build advertising profiles. You can clear cookies from your browser settings at any time without losing account data on our side.
Data Retention Period We keep your account data for as long as your account remains active and for a defined period after closure, as required by applicable regulation. Once that retention window closes, we delete personal data from active systems and anonymise analytical records.
Who Can Access Your Data Only authorised staff with a documented business need can view personal account information. Access logs are maintained so we can audit who viewed what and when. Third-party processors such as payment providers receive only the minimum data needed to process your transaction.
Requesting Changes or Deletion You can update personal details directly in your account settings. For deletion, submit a request through the privacy form or live chat. We process deletion requests within a reasonable timeframe and confirm completion via your registered email address once the process finishes.
Account Security Measures Your account is protected by OTP verification sent to your registered mobile number each time you log in from a new device. If suspicious activity is detected we lock the account and contact you immediately through your verified phone number or email for re-authentication.
LEGAL CONTACT PATHS

Reach Us About Legal or Data Queries

If you have a question about your rights, a data request, or a dispute about how your information has been handled, you can reach the right team through three channels. We aim to acknowledge legal queries within one working day and resolve straightforward requests quickly, though complex cases may take longer depending on the documentation involved.

Live Chat Open the chat widget from any page on the site. Ask for the legal or data team specifically — the agent will escalate your query and you will receive a case reference number to track progress through your account inbox.
Email Send your request to our support email with the subject line containing your account ID and the word 'legal'. This routes your message directly to the compliance queue rather than general support, which speeds up handling considerably.
Account Request Form Inside your account settings, under the privacy tab, there is a structured form for data access requests, deletion requests, and consent withdrawal. The form captures exactly what our team needs so there is no back-and-forth asking for missing details.

Common Questions About Your Legal Rights

These are the questions our support team receives most often about legal matters, data handling, and account rights. If your question is not covered here, reach out through live chat or email and reference this page so the agent knows the context of your query.

We process your data based on the contractual relationship formed when you register an account. Certain processing, such as identity verification, is also necessary to meet regulatory obligations. You agreed to these conditions during sign-up and can review them inside your account settings.

Yes. Use the privacy form inside your account settings or contact support via live chat with your account ID. We compile a data export covering your personal details, transaction history, login records, and any documents you uploaded. The export is delivered to your registered email.

Submit a deletion request through the privacy form or tell the support team via live chat. We verify your identity through OTP before processing. Once confirmed, personal data is removed from active systems and we send a completion notice to your email after the retention period ends.

Transaction data is shared only with the payment provider involved in processing your specific deposit or withdrawal. We do not sell or share financial records with advertisers or unrelated third parties. Regulatory authorities may receive data only where required by applicable law.

We update this page and send a notification to your registered mobile number or email before changes take effect. You have the option to review the updated terms and, if you disagree, close your account and request data deletion before the new terms apply to your activity.

Access depends on your local law and eligible regions. We do not operate in jurisdictions where local regulation prohibits it. If you are unsure whether the platform is available in your area, contact support before depositing any funds through bKash, Nagad or Rocket.

We retain data for a defined period after account closure as required by applicable regulatory frameworks. Once that period ends, personal data is permanently deleted from active systems and any remaining records are anonymised so they cannot be linked back to you.

You can withdraw consent for certain types of processing — for example, marketing communications — without closing your account. However, if you withdraw consent for core processing such as identity verification, we may no longer be able to operate your account and it could be suspended.

Disputes are handled under the jurisdiction referenced in your account terms. We encourage you to contact support first so we can resolve matters directly. If that fails, the terms specify a resolution mechanism and jurisdiction. You can review these details in your account settings under the terms section.

Reach our compliance team through live chat, email, or the account privacy form. Quote your account ID and describe the concern. We investigate internally, provide a response within a reasonable timeframe, and if the issue is confirmed we take corrective action and notify you of the outcome.